cromwell_4 Posted September 29, 2006 Report Share Posted September 29, 2006 One of my users had a virtual memory error. Everything looks ok. I have run Spybot and Adaware. Could you please have a quick look at the log below and let me know if there are any issues?Many thanks for all of your help.Logfile of HijackThis v1.99.1Scan saved at 10:04:35, on 29/09/2006Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\spoolsv.exeC:\WINNT\System32\svchost.exeC:\WINNT\floplock.exeC:\Program Files\Network Associates\VirusScan\Mcshield.exeC:\Program Files\Network Associates\VirusScan\VsTskMgr.exeC:\program files\notes\ntmulti.exeC:\WINNT\system32\regsvc.exeC:\WINNT\system32\MSTask.exeC:\WINNT\System32\WBEM\WinMgmt.exeC:\WINNT\system32\svchost.exeC:\Program Files\McAfee\Common Framework\FrameworkService.exeC:\WINNT\Explorer.ExeC:\WINNT\System32\igfxtray.exeC:\WINNT\System32\hkcmd.exeC:\Program Files\Network Associates\VirusScan\SHSTAT.EXEC:\Program Files\McAfee\Common Framework\UpdaterUI.exeC:\WINNT\system32\internat.exeC:\Program Files\WinZip\WZQKPICK.EXEC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\Internet Explorer\IEXPLORE.EXEE:\HijackThis\HijackThis.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blankR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.51.87.140:8080R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 213.62.*;170.230.*;*.cpb.com;*.soups.com;62.185.95.179;129.39.225.188;<local>R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missingO1 - Hosts: 170.230.110.20 ocieO1 - Hosts: 170.230.107.200 ftp.campbellplace.com www.campbellplace.comO1 - Hosts: 194.118.99.14 GBBSERVER1 KGLHUB01O1 - Hosts: 213.62.238.230 GBBIPMSO1 - Hosts: 195.118.243.105 GBCAMP01 GBCAMP01-IPO1 - Hosts: 195.51.85.1 PUURSO1 - Hosts: 195.118.243.101 GBBDGM1O1 - Hosts: 32.77.1.31 DMCAMUS02O1 - Hosts: 32.77.1.28 DMCAMUS06O1 - Hosts: 170.230.46.6 DACAMUS04 DACAMUS04.SOUPS.COMO1 - Hosts: 170.230.115.80 campbellcornerO1 - Hosts: 213.62.238.15 DMKGLUK01O1 - Hosts: 195.118.243.108 DHDIEBE01O1 - Hosts: 195.118.243.100 Y2CAMD00 Y2CAMD00-IPO1 - Hosts: 194.253.61.57 COMFIERYO1 - Hosts: 194.253.61.73 GENFIERYO1 - Hosts: 213.62.238.49 GBBTOWERO1 - Hosts: 203.8.80.233 DMSYDAU01O1 - Hosts: 203.8.80.234 DMSYDAU02O1 - Hosts: 141.94.135.6 FIREWALL1O1 - Hosts: 141.94.135.4 FIREWALL2O1 - Hosts: 213.62.238.12 EKGLAPP02O1 - Hosts: 213.62.238.20 EKGLCMB01O1 - Hosts: 170.230.105.27 DACAMUS02O1 - Hosts: 128.1.0.9 S4441272O1 - Hosts: 128.1.0.10 CBS270O1 - Hosts: 195.118.243.109 EURAPP01O1 - Hosts: 213.62.238.11 GBBSERVER2O1 - Hosts: 213.62.238.23 GBBSQLO1 - Hosts: 170.230.236.44 GBBCOGNOSO1 - Hosts: 170.230.113.75 CAMPBELLDW01O1 - Hosts: 170.230.46.5 DACAMUS03 DACAMUS03.SOUPS.COMO1 - Hosts: 213.62.238.17 DAKGLUK01O1 - Hosts: 170.230.185.20 DMASHUK10O1 - Hosts: 170.230.240.20 DMWORUK10O1 - Hosts: 170.230.197.20 DMCRAUK10O1 - Hosts: 213.62.238.30 GBBPSOFTO1 - Hosts: 213.62.238.40 GBBIPMS2O1 - Hosts: 213.62.238.5 FIREWALLO1 - Hosts: 195.118.243.110 EUCAMD00O1 - Hosts: 170.230.113.75 WHQDWH41O1 - Hosts: 170.230.104.217 DDACAMUS01O1 - Hosts: 170.230.240.15 EWORCMB01O1 - Hosts: 170.230.185.15 EASHCMB01O1 - Hosts: 170.230.197.50 ECRACMB01O1 - Hosts: 170.230.191.3 DMDUNFR10O1 - Hosts: 213.62.238.34 GBBCITRIXO1 - Hosts: 213.62.238.18 EKGLAPP04O1 - Hosts: 170.230.185.20 DMASHUK10O1 - Hosts: 170.230.189.178 DAKARSE01O1 - Hosts: 170.230.113.149 psacpt PSACPTO1 - Hosts: 170.230.128.36 DMTORCA01O1 - Hosts: 170.230.243.9 CAMBOURNE-UNITYO1 - Hosts: 170.230.243.7 CAMBOURNE-PUBO1 - Hosts: 170.230.215.123 DMHBUAU10O1 - Hosts: 170.230.115.101 DMCAMUS12O1 - Hosts: 170.230.46.11 DMCAMUS10O1 - Hosts: 213.62.238.25 DGKGLUK01O1 - Hosts: 170.230.236.42 DMCAMUK10O1 - Hosts: 170.230.115.80 CAMPBELLCORNERO1 - Hosts: 195.51.83.8 DMBOUFR10O1 - Hosts: 170.230.113.198 DCCAMUS01O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dllO3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocxO4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logonO4 - HKLM\..\Run: [igfxTray] C:\WINNT\System32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exeO4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\cwbsvstr.exe"O4 - HKLM\..\Run: [Client Access Help Update] "C:\Program Files\IBM\Client Access\cwbinhlp.exe"O4 - HKLM\..\Run: [Client Access Check Version] "C:\Program Files\IBM\Client Access\cwbckver.exe" LOGINO4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Program Files\IBM\Client Access\cwbwlwiz.exe"O4 - HKLM\..\Run: [shStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UpdaterUI.exe" /StartedFromRunKeyO4 - HKCU\..\Run: [internat.exe] internat.exeO4 - Startup: dg_connect_eukinapp09.batO4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXEO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO14 - IERESET.INF: START_PAGE_URL=about:blankO16 - DPF: Oracle Sales Analyzer 6,4,0 Patch 5 - http://iri.cpgnetwork.co.uk/osaweb/java/osa640.cabO16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://dccamus01.soups.com/qp2.cabO16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://dmcamuk10/iNotes6.cabO16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocxO16 - DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} (DDSC Class) - http://portal.som.cranfield.ac.uk/msc/Port...rces/msddsc.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ouk.comO17 - HKLM\System\CCS\Services\Tcpip\..\{6B4BD674-3036-4F86-921D-3A2D75D2D051}: NameServer = 170.230.236.46,170.230.236.36O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ouk.comO17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ouk.com,europe.soups.com,eu.cpb.com,cpb.com,soups.com,oie.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ouk.comO17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = ouk.com,europe.soups.com,eu.cpb.com,cpb.com,soups.com,oie.comO17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ouk.com,europe.soups.com,eu.cpb.com,cpb.com,soups.com,oie.comO20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dllO23 - Service: Client Access Express Remote Command (Cwbrxd) - IBM Corporation - C:\WINNT\CWBRXD.EXEO23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exeO23 - Service: floppylock - Unknown owner - C:\WINNT\floplock.exeO23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exeO23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exeO23 - Service: Multi-user Cleanup Service - Unknown owner - C:\program files\notes\ntmulti.exeO23 - Service: OracleOracle_homeClientCache - Unknown owner - C:\orant\BIN\ONRSD.EXEO23 - Service: PictureTaker - LANovation - C:\WINNT\System32\PCTKRNT.SYS Quote Link to post Share on other sites
therock247uk Posted September 29, 2006 Report Share Posted September 29, 2006 Looks clean to me... Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.