Is my pc clean?

I had a hard time fighting off E2G and other malwares and I'm not sure whether I finished them off or not. Here is the log for your perusal:

Logfile of HijackThis v1.99.1
Scan saved at 1:43:01 PM, on 1/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\O&K Print Watch\WatchSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\sze\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM

FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_0.DLL
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM

FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_0.DLL
O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE

/P23 "EPSON Stylus C45 Series" /O6 "USB013" /M "Stylus C45"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX630 Series]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HP.EXE /P31 "EPSON Stylus Photo RX630 Series"

/O6 "USB005" /M "Stylus Photo RX630"
O4 - HKLM\..\Run: [EPSON Stylus C80 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE

/P23 "EPSON Stylus C80 Series" /O5 "LPT1:" /M "Stylus C80"
O4 - HKLM\..\Run: [EPSON Stylus C80 Series (Copy 1)]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P32 "EPSON Stylus C80 Series (Copy 1)" /O6

"USB014" /M "Stylus C80"
O4 - HKLM\..\Run: [EPSON Stylus CX6500 Series (Copy 1)]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EP.EXE /P35 "EPSON Stylus CX6500 Series (Copy

1)" /O6 "USB026" /M "Stylus CX6500"
O4 - HKLM\..\Run: [EPSON Stylus C67 Series (Copy 1)]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE /P32 "EPSON Stylus C67 Series (Copy 1)"

/O6 "USB033" /M "Stylus C67"
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series (Copy 1)]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P39 "EPSON Stylus Photo R300 Series (Copy

1)" /O6 "USB044" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [EPSON Stylus Photo R210 Series]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE /P30 "EPSON Stylus Photo R210 Series" /O6

"USB023" /M "Stylus Photo R210"
O4 - HKLM\..\Run: [Auto EPSON Stylus CX6500 Series (Copy 2) on PC1]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EP.EXE /P47 "Auto EPSON Stylus CX6500 Series

(Copy 2) on PC1" /O15 "\\PC1\Printer12" /M "Stylus CX6500"
O4 - HKLM\..\Run: [Auto EPSON Stylus CX6500 Series (Copy 1) on PC1]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EP.EXE /P47 "Auto EPSON Stylus CX6500 Series

(Copy 1) on PC1" /O15 "\\PC1\Printer13" /M "Stylus CX6500"
O4 - HKLM\..\Run: [Auto EPSON Stylus CX3500 Series (Copy 2) on PC1]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BP.EXE /P47 "Auto EPSON Stylus CX3500 Series

(Copy 2) on PC1" /O15 "\\PC1\Printer17" /M "Stylus CX3500"
O4 - HKLM\..\Run: [Auto EPSON Stylus CX3500 Series on PC1]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BP.EXE /P38 "Auto EPSON Stylus CX3500 Series on

PC1" /O15 "\\PC1\Printer19" /M "Stylus CX3500"
O4 - HKLM\..\Run: [Auto EPSON Stylus CX3500 Series (Copy 1) on PC1]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BP.EXE /P47 "Auto EPSON Stylus CX3500 Series

(Copy 1) on PC1" /O15 "\\PC1\Printer18" /M "Stylus CX3500"
O4 - HKLM\..\Run: [EPSON Stylus CX3100 (Copy 1)]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P28 "EPSON Stylus CX3100 (Copy 1)" /O5

"LPT1:" /M "Stylus CX3100"
O4 - HKLM\..\Run: [EPSON Stylus CX3500 Series (Copy 3)]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BP.EXE /P35 "EPSON Stylus CX3500 Series (Copy

3)" /O6 "USB047" /M "Stylus CX3500"
O4 - Global Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON

CardMonitor1.2.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk =

C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -

http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -

http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D508AC6D-A9E7-41B5-915C-44B25EA08A6E}: NameServer =

202.81.160.6 202.81.160.7
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program

Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program

Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common

Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program

Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: O&K Print Watch Service - Unknown owner - C:\Program Files\O&K Print Watch\WatchSrv.exe

=====================

Thanks in advance.

Comments

  • TroganTrogan London, UK
    edited January 2006
    That log is hard to read with all those spaces. Could you post a new HJT log please. :)
  • edited January 2006
    Certainly.

    Logfile of HijackThis v1.99.1
    Scan saved at 7:50:55 PM, on 1/5/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\Program Files\AVPersonal\AVGUARD.EXE
    C:\Program Files\AVPersonal\AVWUPSRV.EXE
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\Program Files\O&K Print Watch\WatchSrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3S2.EXE
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
    C:\WINDOWS\System32\devldr32.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\System32\irftp.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10MT2.EXE
    C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\sze\Desktop\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://mail.yahoo.com/
    O2 - BHO: Yahoo! Companion BHO-{02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_0.DLL
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_5_7_0.DLL
    O4 - HKLM\..\Run: [EPSON Stylus C45 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB013" /M "Stylus C45"
    O4 - HKLM\..\Run: [EPSON Stylus Photo RX630 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HP.EXE /P31 "EPSON Stylus Photo RX630 Series" /O6 "USB005" /M "Stylus Photo RX630"
    O4 - HKLM\..\Run: [EPSON Stylus C80 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C80 Series" /O5 "LPT1:" /M "Stylus C80"
    O4 - HKLM\..\Run: [EPSON Stylus C80 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P32 "EPSON Stylus C80 Series (Copy 1)" /O6 "USB014" /M "Stylus C80"
    O4 - HKLM\..\Run: [EPSON Stylus CX6500 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EP.EXE /P35 "EPSON Stylus CX6500 Series (Copy 1)" /O6 "USB026" /M "Stylus CX6500"
    O4 - HKLM\..\Run: [EPSON Stylus C67 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAP.EXE /P32 "EPSON Stylus C67 Series (Copy 1)" /O6 "USB033" /M "Stylus C67"
    O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P39 "EPSON Stylus Photo R300 Series (Copy 1)" /O6 "USB044" /M "Stylus Photo R300"
    O4 - HKLM\..\Run: [EPSON Stylus Photo R210 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3H2.EXE /P30 "EPSON Stylus Photo R210 Series" /O6 "USB023" /M "Stylus Photo R210"
    O4 - HKLM\..\Run: [Auto EPSON Stylus CX6500 Series (Copy 2) on PC1] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EP.EXE /P47 "Auto EPSON Stylus CX6500 Series (Copy 2) on PC1" /O15 "\\PC1\Printer12" /M "Stylus CX6500"
    O4 - HKLM\..\Run: [Auto EPSON Stylus CX6500 Series (Copy 1) on PC1] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EP.EXE /P47 "Auto EPSON Stylus CX6500 Series (Copy 1) on PC1" /O15 "\\PC1\Printer13" /M "Stylus CX6500"
    O4 - HKLM\..\Run: [Auto EPSON Stylus CX3500 Series (Copy 2) on PC1] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BP.EXE /P47 "Auto EPSON Stylus CX3500 Series (Copy 2) on PC1" /O15 "\\PC1\Printer17" /M "Stylus CX3500"
    O4 - HKLM\..\Run: [Auto EPSON Stylus CX3500 Series on PC1] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BP.EXE /P38 "Auto EPSON Stylus CX3500 Series on PC1" /O15 "\\PC1\Printer19" /M "Stylus CX3500"
    O4 - HKLM\..\Run: [Auto EPSON Stylus CX3500 Series (Copy 1) on PC1] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BP.EXE /P47 "Auto EPSON Stylus CX3500 Series (Copy 1) on PC1" /O15 "\\PC1\Printer18" /M "Stylus CX3500"
    O4 - HKLM\..\Run: [EPSON Stylus CX3100 (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P28 "EPSON Stylus CX3100 (Copy 1)" /O5 "LPT1:" /M "Stylus CX3100"
    O4 - HKLM\..\Run: [EPSON Stylus CX3500 Series (Copy 3)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BP.EXE /P35 "EPSON Stylus CX3500 Series (Copy 3)" /O6 "USB047" /M "Stylus CX3500"
    O4 - HKLM\..\Run: [EPSON Stylus C45 Series (Copy 2)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE /P32 "EPSON Stylus C45 Series (Copy 2)" /O6 "USB025" /M "Stylus C45"
    O4 - Global Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.2.exe
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D508AC6D-A9E7-41B5-915C-44B25EA08A6E}: NameServer = 202.81.160.6 202.81.160.7
    O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
    O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
    O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: O&K Print Watch Service - Unknown owner - C:\Program Files\O&K Print Watch\WatchSrv.exe
  • TroganTrogan London, UK
    edited January 2006
    How many printers do you have?
    -

    Go here and in the box provided, paste the following. Then press SUBMIT

    C:\WINDOWS\System32\irftp.exe

    The files will be scanned by various Anti-Virus scanners. Please post the results here.
    -


    Your log is clean. Are you having any specific problem?
  • edited January 2006
    Service load:
    0% 100%
    File: irftp.exe
    Status:
    OK
    MD5 cfe969a6e3dd25f1f975016c9bc67d2f
    Packers detected:
    -
    Scanner results
    AntiVir Found nothing
    ArcaVir Found nothing
    Avast Found nothing
    AVG Antivirus Found nothing
    BitDefender Found nothing
    ClamAV Found nothing
    Dr.Web Found nothing
    F-Prot Antivirus Found nothing
    Fortinet Found nothing
    Kaspersky Anti-Virus Found nothing
    NOD32 Found nothing
    Norman Virus Control Found nothing
    UNA Found nothing
    VBA32 Found nothing

    ==========================
  • TroganTrogan London, UK
    edited January 2006
    That file is clean.


    Are you having any problems?
Sign In or Register to comment.