PDA

View Full Version : unknown program (WXP-Home)



andrewski31683
04-10-2005, 07:38 PM
i have recently noticed a program that sort of "flashes in and out". what i mean is, a box on the taskbar appears for NO LONGER than a second. maybe less. but there is no main window that opens, no name in the box on the taskbar, nothing. just a box that flashes and my pointer is busy for just about a second. is there anyway that i can look at an even log of all the programs that have been opened or closed or that have opened or closed in the past. i would like to find out what this program exactly is and somehow delete its files. it interrupts a lot of my programs like if i am playing a game, it takes me straight to my desktop automatically, and if my monitor is automatically shut off or sleeping, this program turns it on and it interrupts my screensaver if i have it on. can anyone help??? thats all the information that i can give you to best describe my problem. thank you so much.

Remi_Woler
04-28-2005, 05:14 PM
Weird. I am having the same problem. I'm quite sure that it is not a spyware thing, because I scanned with 5 scanners, and have 2 constantly running (Spybot S&D, CounterSpy). I am quite sure it is not a virus/trojan, because I scanned with 2 online scans, and 3 installed scanners, where one is constantly running (NOD32). There is nothing in the syslogs. I frequently check my registry for errors with Norton Systemdoctor and tools like that. I have un-installed almost any program that might cause it, but I still cannot figure this one out. Even a HiJackThis log looks fine. All I know is that the proces is executed every 10~15 minutes, and only shows the well-known 'hanging application' icon in the most left side of the taskbar entry.

It really bugs me off, but I am out of options. Maybe somebody here knows something to check?

monkey_1
04-28-2005, 09:54 PM
Post here your HijackThis log...

<font color=orange>Mono</font color=orange>

Remi_Woler
04-29-2005, 07:10 AM
Logfile of HijackThis v1.99.1
Scan saved at 15:52:35, on 29-4-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
NOTE: Known running process have an about stated between the ( )

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIAudioi\SBADeck\ADeck.exe (VIA Audio drivers)
C:\Program Files\D-Tools\daemon.exe (Daemon tools, www.daemon-tools.cc)
C:\Program Files\MSI\Live Update 3\LMonitor.exe (MSI Bios/driver update monitor)
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (HP driver thingy)
C:\Program Files\Eset\nod32kui.exe (NOD32 AntiVirus)
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (HP Software Update Service)
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe (CounterSpy)
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe (CounterSpy)
C:\Program Files\MessengerPlus! 3\MsgPlus.exe (An add-on for MSN Messenger (installed with no adds)
C:\Program Files\EasyPHP1-8\EasyPHP.exe (Set of Apache/PHP/MySQL for win32)
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\EASYPH~1\Apache\apache.exe (Apache itself, part of EasyPHP)
C:\Program Files\Hercules\Audio\Hercules DJ Console\DJConsoleMixer.exe (Hercules DJ Console tray icon)
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI driver part)
C:\program files\valve\steam\steam.exe (the new all-in-one solution from Valve for Half-Life, Counter-Strike etc)
C:\Program Files\Messenger\msmsgs.exe (Windows Messenger needed for sidebar)
C:\Program Files\Serv-U\ServUTray.exe (Serv-U FTP Server tray icon)
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspn et_admin.exe
C:\Program Files\Desktop Sidebar\dsidebar.exe (Nice Longhorn-style sidebar www.desktopsidebar.com)
C:\Program Files\MSN Messenger\msnmsgr.exe (MSN Messenger 7 Beta)
C:\PROGRA~1\EASYPH~1\MySql\bin\mysqld.exe (Mysql daemon, part of EasyPHP)
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI driver part, dunno why it is stated twice)
C:\PROGRA~1\EASYPH~1\Apache\apache.exe (Once again Apache, dunno why it is stated twice)
C:\Program Files\MSI\Core Center\CoreCenter.exe (MSI Control Panel for System Info)
C:\Program Files\Eset\nod32krn.exe (NOD32 Antivirus part)
C:\Program Files\MSI\DigiCell\DigiCell.exe (MSI system values monitor (cpu heat etc))
C:\Program Files\Serv-U\ServUDaemon.exe (Serv-U FTP Server daemon process)
C:\Program Files\AVerTV\QuickTV.exe (VCR-like program for my TV card)
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe (RAID management tool for my 2nd Raid card)
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\VIA\RAID\raid_tool.exe (RAID management tool for my on-board Raid card)
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\mIRC\mirc.exe (The well-known IRC client for win32)
C:\Program Files\Maxthon\Maxthon.exe (My browser, successor of MyIE2+)
C:\Program Files\WinRAR\WinRAR.exe (RAR handling app, used for opening the hijackthis archive)
C:\DOCUME~1\Remi\LOCALS~1\Temp\Rar$EX00.688\Hijack This.exe (hijackthis itself)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/firefox
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AAAE1C1A-89F7-4AF6-ABD1-F8FBCFA47408} - (no file)
O2 - BHO: (no name) - {E5A1691B-D188-4419-AD02-90002030B8EE} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Realtime Audio Engine] mmrtkrnl.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [sunasDTServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [EasyPHP] "C:\Program Files\EasyPHP1-8\EasyPHP.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DJ Console] C:\Program Files\Hercules\Audio\Hercules DJ Console\DJConsoleMixer.exe -hide
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ServUTrayIcon] C:\Program Files\Serv-U\ServUTray.exe
O4 - HKCU\..\Run: [SIDEBAR] "C:\Program Files\Desktop Sidebar\dsidebar.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: DigiCell.lnk = C:\Program Files\MSI\DigiCell\DigiCell.exe
O4 - Global Startup: QuickTV.lnk = C:\Program Files\AVerTV\QuickTV.exe
O4 - Global Startup: SATARaid.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Gelijkwaardige pagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Koppelingspagina's - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1106414014623
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O23 - Service: Apache - Unknown owner - C:\PROGRA~1\EASYPH~1\Apache\apache.exe" --ntservice (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySQL - Unknown owner - C:\PROGRA~1\EASYPH~1\MySql\bin\mysqld.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Serv-U FTP Server (Serv-U) - Cat Soft - C:\Program Files\Serv-U\ServUDaemon.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

monkey_1
04-29-2005, 07:30 PM
Do you really need the motherboard's stuff?

O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: DigiCell.lnk = C:\Program Files\MSI\DigiCell\DigiCell.exe

If you use NOD as your antivirus, uninstall Norton Systemworks

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Delete these entries in HijackThis:

O2 - BHO: (no name) - {AAAE1C1A-89F7-4AF6-ABD1-F8FBCFA47408} - (no file)
O2 - BHO: (no name) - {E5A1691B-D188-4419-AD02-90002030B8EE} - (no file)

<font color=orange>Mono</font color=orange>

Remi_Woler
04-30-2005, 02:38 PM
The above suggestions didn't help. The real problem was a component of HP software installation. After disabling the startup of hpcmpmgr.exe (HP Component Manager) the process disappeared, and never came back. Thanks to BrokenHope (IRC) who gave the golden advise. Thanks to monkey_1 for helping, and thanks to everybody who thought about it, just for thinking.