about blank pop ups and audible unseen pop ups, please help [RESOLVED], malware, spyware |
![]() ![]() |
about blank pop ups and audible unseen pop ups, please help [RESOLVED], malware, spyware |
Jul 13 2008, 05:32 PM
Post
#1
|
|
|
New Member ![]() Posts: 9 OS: Windows XP |
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:11:58 PM, on 7/13/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure PC Protection Plus\Common\FSMA32.EXE C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe C:\Program Files\F-Secure PC Protection Plus\Common\FSMB32.EXE C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\F-Secure PC Protection Plus\Common\FCH32.EXE C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fssm32.exe C:\Program Files\F-Secure PC Protection Plus\Common\FAMEH32.EXE C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsqh.exe C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsaua.exe C:\Program Files\F-Secure PC Protection Plus\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsus.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsav32.exe C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\F-Secure PC Protection Plus\Common\FSM32.EXE C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe C:\WINDOWS\ss245sd.exe C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\Lexmark 1200 Series\lxczbmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\F-Secure PC Protection Plus\FSGUI\fsguidll.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\SNDVOL32.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure PC Protection Plus\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure PC Protection Plus\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" O4 - HKLM\..\Run: [ss245sd] C:\WINDOWS\ss245sd.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Somr] "C:\WINDOWS\WNSXS~1\userinit.exe" -vt yazb O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1207882469734 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\FWES\Program\fsdfwd.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\Common\FSMA32.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe -- End of file - 8160 bytes |
|
|
Jul 13 2008, 06:31 PM
Post
#2
|
|
![]() GeekU Teacher Posts: 9,279 From: Somewhere OS: Windows xp home |
Hello glamchick
Welcome to G2Go. ===================== Please download Deckard's System Scanner (DSS) and save it to your Desktop.
|
|
|
Jul 14 2008, 11:30 AM
Post
#3
|
|
|
New Member ![]() Posts: 9 OS: Windows XP |
hi kahdah, thanks for the quick reply. here are the docs. you asked for
Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: Intel® Pentium® 4 CPU 3.00GHz CPU 1: Intel® Pentium® 4 CPU 3.00GHz Percentage of Memory in Use: 70% Physical Memory (total/avail): 247.48 MiB / 73.2 MiB Pagefile Memory (total/avail): 606.38 MiB / 259.65 MiB Virtual Memory (total/avail): 2047.88 MiB / 1915.67 MiB C: is Fixed (NTFS) - 27.93 GiB total, 17.89 GiB free. D: is CDROM (No Media) E: is CDROM (CDFS) G: is Fixed (NTFS) - 186.31 GiB total, 150.87 GiB free. \\.\PHYSICALDRIVE0 - ST330011A - 27.94 GiB - 1 partition \PARTITION0 (bootable) - Installable File System - 27.93 GiB - C: \\.\PHYSICALDRIVE1 - Maxtor OneTouch III USB Device - 186.31 GiB - 1 partition \PARTITION0 - Installable File System - 186.31 GiB - G: -- Security Center ------------------------------------------------------------- AUOptions is set to notify before download. Windows Internal Firewall is disabled. FirstRunDisabled is set. AntiVirusDisableNotify is set. FirewallDisableNotify is set. UpdatesDisableNotify is set. FW: F-Secure PC Protection Plus 7.03 v7.03 (F-Secure Corporation) AV: F-Secure PC Protection Plus 7.03 v7.03 (F-Secure Corporation) [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\dd\Application Data CLASSPATH=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=X-EB38B09690364 ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\dd LOGONSERVER=\\X-EB38B09690364 NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\QuickTime\QTSystem\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 3 Stepping 4, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0304 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA=C:\Program Files\QuickTime\QTSystem\QTJava.zip SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\dd\LOCALS~1\Temp TMP=C:\DOCUME~1\dd\LOCALS~1\Temp USERDOMAIN=X-EB38B09690364 USERNAME=dd USERPROFILE=C:\Documents and Settings\dd windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- dd (admin) -- Add/Remove Programs --------------------------------------------------------- --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware Scanner" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Spyware" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus Client Security Installer" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Anti-Virus" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Automatic Update Agent" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure DAAS" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Diagnostics" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure E-mail Scanning" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure FWES" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure GateKeeper Interface" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Gemini" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure GUI" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Help" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure HIPS" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Internet Shield" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Localization API" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Management Agent" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Pegasus Engine" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Protocol Scanner" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Spam Control" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Spam Scanner" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure TNB" --> "C:\Program Files\F-Secure PC Protection Plus\Uninstall\fsuninst.exe" /UninstRegKey:"F-Secure Uninstall" --> C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE --> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL --> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL --> C:\WINDOWS\UNRecode.exe /UNINSTALL --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Adobe AIR --> C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall Adobe AIR --> MsiExec.exe /I{197A3012-8C85-4FD3-AB66-9EC7E13DB92E} Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001} Adobe Shockwave Player --> C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543} Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4} CA Yahoo! Anti-Spy (remove only) --> "C:\Program Files\CA Yahoo! Anti-Spy\uninstall.exe" DJ Mix Master 1.4 --> "C:\Program Files\DJ Mix Master\unins000.exe" F-Secure PC Protection Plus --> "C:\Program Files\F-Secure PC Protection Plus\FSGUI\PostInstall.exe" /tUnInstall Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29} Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll" HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Intel® Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572 iTunes --> MsiExec.exe /I{80FD852F-5AAC-4129-B931-06AAFFA43138} Java 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040} Karaoke for DirectX (remove only) --> "C:\Program Files\KaraokeDX\uninstall.exe" Lexmark 1200 Series --> C:\WINDOWS\system32\spool\drivers\w32x86\3\LXCZUN5C.EXE -dLexmark 1200 Series LimeWire 4.18.2 --> "C:\Program Files\LimeWire\uninstall.exe" Maxtor Backup --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{9C3F9580-F5CF-4288-894E-9FF0EB24A21C} /l1033 Maxtor OneTouch III --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{60EEB642-E9E0-45A2-A676-B9D8FE17C4A9} /l1033 Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9} Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Motorola Phone Tools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}\setup.exe" -l0x9 -removeonly Nero 7 Essentials --> MsiExec.exe /X{282E3F81-CC37-44AF-8156-C35104D21033} neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} Power CD+G Burner --> "C:\Program Files\Doblon\Power CD+G Burner\unins000.exe" QuickTime --> MsiExec.exe /I{BFD96B89-B769-4CD6-B11E-E79FFD46F067} Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll Yahoo! Mail Advisor --> C:\PROGRA~1\Yahoo!\Common\UNINST~1.EXE Yahoo! Search Protection --> C:\PROGRA~1\Yahoo!\SEARCH~1\UNINST~1.EXE Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE -- Application Event Log ------------------------------------------------------- Event Record #/Type1798 / Error Event Submitted/Written: 07/14/2008 00:20:48 PM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 2 2008-07-14 12:20:46-05:00 x-eb38b09690364 X-EB38B09690364\dd F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\dd\Local Settings\Temp\zfe2.0xe. Infection: Trojan-Downloader.Win32.Zlob.ljr Event Record #/Type1797 / Error Event Submitted/Written: 07/14/2008 00:20:48 PM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 1 2008-07-14 12:20:47-05:00 x-eb38b09690364 X-EB38B09690364\dd F-Secure Anti-Virus Malicious code found in file C:\Documents and Settings\dd\Local Settings\Temp\zfe2.0xe. Infection: Trojan-Downloader.Win32.Zlob.ljr Event Record #/Type1790 / Error Event Submitted/Written: 07/14/2008 00:08:53 AM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 15 2008-07-14 00:08:52-05:00 x-eb38b09690364 X-EB38B09690364\dd F-Secure Anti-Virus Scanning of \DEVICE\HARDDISKVOLUME1\PROGRAM FILES\F-SECURE PC PROTECTION PLUS\FSAUA\SUBSCRIPTIONS\AVH_AVPE was aborted due to exceeded scanning time limit. The file may be in use or reading it was too slow (e.g. network connection was under stress). Event Record #/Type1789 / Error Event Submitted/Written: 07/14/2008 00:01:10 AM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 14 2008-07-14 00:01:08-05:00 x-eb38b09690364 X-EB38B09690364\dd F-Secure Anti-Virus Scanning of \DEVICE\HARDDISKVOLUME1\WINDOWS\MEDIA\WINDOWS XP HARDWARE INSERT.WAV was aborted due to exceeded scanning time limit. The file may be in use or reading it was too slow (e.g. network connection was under stress). Event Record #/Type1787 / Error Event Submitted/Written: 07/13/2008 09:05:51 PM Event ID/Source: 103 / F-Secure Anti-Virus Event Description: 13 2008-07-13 21:05:45-05:00 x-eb38b09690364 X-EB38B09690364\dd F-Secure Anti-Virus Scanning of \DEVICE\HARDDISKVOLUME1\WINDOWS\SYSTEM32\MSG711.ACM was aborted due to exceeded scanning time limit. The file may be in use or reading it was too slow (e.g. network connection was under stress). -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type2675 / Error Event Submitted/Written: 07/14/2008 11:25:46 AM Event ID/Source: 29 / W32Time Event Description: The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time. Event Record #/Type2674 / Error Event Submitted/Written: 07/14/2008 11:25:46 AM Event ID/Source: 17 / W32Time Event Description: Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) Event Record #/Type2673 / Warning Event Submitted/Written: 07/14/2008 11:25:46 AM Event ID/Source: 2504 / Server Event Description: The server could not bind to the transport \Device\NetBT_Tcpip_{0FFA6755-A9FE-4EFF-9898-AC28E900A61F}. Event Record #/Type2672 / Error Event Submitted/Written: 07/14/2008 11:25:42 AM Event ID/Source: 1000 / Dhcp Event Description: Your computer has lost the lease to its IP address 192.168.100.2 on the Network Card with network address 001185B349AD. Event Record #/Type2671 / Warning Event Submitted/Written: 07/14/2008 11:25:42 AM Event ID/Source: 1003 / Dhcp Event Description: Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 001185B349AD. The following error occurred: %%121. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. -- End of Deckard's System Scanner: finished at 2008-07-14 12:22:03 ------------ Deckard's System Scanner v20071014.68 Run by dd on 2008-07-14 12:19:15 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 70: 2008-07-14 17:19:33 UTC - RP123 - Deckard's System Scanner Restore Point 69: 2008-07-14 02:04:01 UTC - RP122 - System Checkpoint 68: 2008-07-11 16:20:30 UTC - RP121 - System Checkpoint 67: 2008-07-10 16:16:35 UTC - RP120 - Removed eBay Desktop 66: 2008-07-10 14:49:54 UTC - RP119 - System Checkpoint -- First Restore Point -- 1: 2008-04-16 21:54:13 UTC - RP54 - Installed Windows Media Player 11 Backed up registry hives. Performed disk cleanup. Total Physical Memory: 248 MiB (512 MiB recommended). -- HijackThis (run as dd.exe) -------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:21:31 PM, on 7/14/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure PC Protection Plus\Common\FSMA32.EXE C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\FSGK32.EXE C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe C:\Program Files\F-Secure PC Protection Plus\Common\FSMB32.EXE C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\F-Secure PC Protection Plus\Common\FCH32.EXE C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fssm32.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsqh.exe C:\Program Files\F-Secure PC Protection Plus\Common\FAMEH32.EXE C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsaua.exe C:\Program Files\F-Secure PC Protection Plus\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsus.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsav32.exe C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\F-Secure PC Protection Plus\Common\FSM32.EXE C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe C:\WINDOWS\ss245sd.exe C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\Lexmark 1200 Series\lxczbmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\F-Secure PC Protection Plus\FSGUI\fsguidll.exe C:\Documents and Settings\dd\My Documents\dss.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\dd.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure PC Protection Plus\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure PC Protection Plus\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" O4 - HKLM\..\Run: [ss245sd] C:\WINDOWS\ss245sd.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Somr] "C:\WINDOWS\WNSXS~1\userinit.exe" -vt yazb O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1207882469734 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsaua.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\FWES\Program\fsdfwd.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\Common\FSMA32.EXE O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe -- End of file - 8111 bytes -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ----------- backup-20080514-233223-427 O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file) backup-20080514-233223-730 F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe, backup-20080514-233224-154 O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file) backup-20080514-233224-245 O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file) backup-20080514-233224-454 O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file) backup-20080514-233224-530 O2 - BHO: BndFibu7 IE Helper - {8041E642-8CFC-4720-BC9D-D2DB8904286F} - C:\Program Files\QdrDrive\QdrDrive12.dll (file missing) backup-20080514-233224-564 O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll backup-20080514-233224-570 O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file) backup-20080514-233224-922 O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file) backup-20080514-233224-924 O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll (file missing) backup-20080514-233224-934 O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file) backup-20080514-233225-559 O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file) backup-20080529-000727-162 O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing) backup-20080529-000730-819 O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.gateietool.com/redirect.php (file missing) backup-20080529-000731-138 O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab backup-20080612-001210-446 O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} (Imikimi_activex_plugin Control) - http://imikimi.com/download/imikimi_plugin_0.5.1.cab -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R0 FSFW (F-Secure Firewall Driver) - c:\windows\system32\drivers\fsdfw.sys <Not Verified; F-Secure Corporation; F-Secure Internet Shield> R1 F-Secure HIPS - c:\program files\f-secure pc protection plus\hips\fshs.sys -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service> R2 MaxBackServiceInt - "c:\program files\maxtor\maxtor backup\maxbackserviceint.exe" <Not Verified; ; MaxBackServiceInt Module> R2 NTService1 (MaxSyncService) - "c:\program files\maxtor\onetouch\utils\syncservices.exe" <Not Verified; ; SyncServices> S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe -- Device Manager: Disabled ---------------------------------------------------- Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318} Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard Device ID: ACPI\PNP0303\4&369939D9&0 Manufacturer: (Standard keyboards) Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard PNP Device ID: ACPI\PNP0303\4&369939D9&0 Service: i8042prt -- Scheduled Tasks ------------------------------------------------------------- 2008-07-13 19:05:27 526 --a------ C:\WINDOWS\Tasks\Scheduled scanning task.job -- Files created between 2008-06-14 and 2008-07-14 ----------------------------- 2008-07-09 09:18:13 0 d-------- C:\Program Files\Common Files\Adobe AIR 2008-07-09 09:03:53 0 d-------- C:\Documents and Settings\All Users\Application Data\NOS 2008-07-09 09:03:46 0 d-------- C:\Program Files\NOS 2008-06-14 21:35:46 356352 --a------ C:\WINDOWS\eSellerateEngine.dll <Not Verified; eSellerate Inc.; eSellerateEngine> 2008-06-14 21:35:45 24576 --a------ C:\WINDOWS\system32\SmartSubClass.dll <Not Verified; VBSmart; VBSmart SubClass> 2008-06-14 21:35:45 81332 --a------ C:\WINDOWS\system32\BASS.DLL 2008-06-14 21:35:44 28672 --a------ C:\WINDOWS\system32\SmartMenuXP.dll <Not Verified; VBSmart; SmartMenuXP Library> 2008-06-14 21:35:44 81920 --a------ C:\WINDOWS\system32\eSellerateControl350.dll <Not Verified; eSellerate Inc.; eSellerate ActiveX Control> 2008-06-14 21:35:40 0 d-------- C:\Program Files\DJ Mix Master 2008-06-14 21:35:40 0 d-------- C:\Documents and Settings\All Users\Application Data\Pianosoft -- Find3M Report --------------------------------------------------------------- 2008-07-13 17:47:47 0 d-------- C:\Program Files\CA Yahoo! Anti-Spy 2008-07-11 16:10:12 0 d-------- C:\Documents and Settings\dd\Application Data\LimeWire 2008-07-09 09:22:28 0 d-------- C:\Program Files\Common Files\Adobe 2008-07-09 09:18:13 0 d-------- C:\Program Files\Common Files 2008-06-30 13:46:53 0 d-------- C:\Program Files\Power_Karaoke 2008-06-30 13:46:53 0 d-------- C:\Program Files\Conduit 2008-06-13 19:43:42 0 d-------- C:\Program Files\Common Files\cdrdao 2008-06-13 19:43:34 0 d-------- C:\Program Files\Doblon 2008-06-13 19:35:29 0 d-------- C:\Documents and Settings\dd\Application Data\Doblon 2008-06-13 18:47:07 0 d-------- C:\Program Files\KaraokeDX 2008-06-13 18:36:10 0 d-------- C:\Documents and Settings\dd\Application Data\Ahead 2008-06-12 01:16:15 0 d-------- C:\Program Files\LimeWire 2008-06-09 17:21:39 0 d-------- C:\Program Files\Google 2008-06-01 22:19:14 0 d-------- C:\Documents and Settings\dd\Application Data\Help -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] 06/11/2008 10:33 PM 75128 --a------ C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" [06/18/2004 03:31 AM C:\WINDOWS\SOUNDMAN.EXE] "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06/05/2004 10:45 PM] "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06/05/2004 10:41 PM] "F-Secure Manager"="C:\Program Files\F-Secure PC Protection Plus\Common\FSM32.exe" [02/13/2008 05:38 AM] "F-Secure TNB"="C:\Program Files\F-Secure PC Protection Plus\FSGUI\TNBUtil.exe" [02/13/2008 05:38 AM] "MaxtorOneTouch"="C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [03/27/2006 04:04 PM] "@"="" [] "mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [10/17/2005 05:24 PM] "ss245sd"="C:\WINDOWS\ss245sd.exe" [01/08/2008 11:55 AM] "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [08/03/2004 03:56 AM] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 AM] "Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [07/13/2006 12:22 AM] "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [01/10/2008 11:41 AM] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [02/01/2008 12:13 AM] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [06/12/2008 02:38 AM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [03/22/2007 09:49 AM] "Somr"="C:\WINDOWS\WNSXS~1\userinit.exe" [] "YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [01/10/2008 11:41 AM] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/13/2008 05:44 PM] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] "some"=C:\Program Files\NetProject\scit.exe "start"=C:\Program Files\NetProject\sbmntr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Philips Intelligent Agent] NOT_IN_USE_DUMMY_PATH [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "wuauserv"=2 (0x2) -- End of Deckard's System Scanner: finished at 2008-07-14 12:22:03 ------------ |
|
|
Jul 14 2008, 06:39 PM
Post
#4
|
|
![]() GeekU Teacher Posts: 9,279 From: Somewhere OS: Windows xp home |
Please download SmitfraudFix (by S!Ri) to your Desktop.
Double-click SmitfraudFix.exe Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. **If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. http://www.beyondlogic.org/consulting/proc...processutil.htm |
|
|
Jul 14 2008, 11:36 PM
Post
#5
|
|
|
New Member ![]() Posts: 9 OS: Windows XP |
Step 2 is completed, here is the file youre asking for.
SmitFraudFix v2.329 Scan done at 0:29:53.66, Tue 07/15/2008 Run from C:\Documents and Settings\dd\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\F-Secure PC Protection Plus\Common\FSM32.EXE C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe C:\WINDOWS\ss245sd.exe C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\Lexmark 1200 Series\lxczbmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure PC Protection Plus\Common\FSMA32.EXE C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\FSGK32.EXE C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe C:\Program Files\F-Secure PC Protection Plus\Common\FSMB32.EXE C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\F-Secure PC Protection Plus\Common\FCH32.EXE C:\Program Files\F-Secure PC Protection Plus\Common\FAMEH32.EXE C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsqh.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsaua.exe C:\Program Files\F-Secure PC Protection Plus\FSGUI\fsguidll.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fssm32.exe C:\Program Files\F-Secure PC Protection Plus\FWES\Program\fsdfwd.exe C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsus.exe C:\WINDOWS\system32\WgaTray.exe C:\Program Files\F-Secure PC Protection Plus\Anti-Virus\fsav32.exe C:\Program Files\F-Secure PC Protection Plus\FSGUI\fsavgui.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\winfrun32.bin FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\dd »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\dd\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\dd\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\NetProject\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, following keys are not inevitably infected!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» VACFix !!!Attention, following keys are not inevitably infected!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix !!!Attention, following keys are not inevitably infected!!! 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\SYSTEM32\\Userinit.exe," "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Broadcom NetXtreme Gigabit Ethernet for hp - Packet Scheduler Miniport DNS Server Search Order: 64.233.207.2 DNS Server Search Order: 64.233.207.16 HKLM\SYSTEM\CCS\Services\Tcpip\..\{0FFA6755-A9FE-4EFF-9898-AC28E900A61F}: DhcpNameServer=64.233.207.2 64.233.207.16 HKLM\SYSTEM\CS1\Services\Tcpip\..\{0FFA6755-A9FE-4EFF-9898-AC28E900A61F}: DhcpNameServer=64.233.207.2 64.233.207.16 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=64.233.207.2 64.233.207.16 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=64.233.207.2 64.233.207.16 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End |
|
|
Jul 15 2008, 03:13 AM
Post
#6
|
|
![]() GeekU Teacher Posts: 9,279 From: Somewhere OS: Windows xp home |
Please download the OTMoveIt2 by OldTimer.
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. =============================== Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley. =============================== Then please post back with a new dss log and the other logs Mbam and OT Move it |
|
|
Jul 16 2008, 12:13 AM
Post
#7
|
|
|
New Member ![]() Posts: 9 OS: Windows XP |
hi kahdah, ive done each task you have instructed and here are both log files C:\Program Files\NetProject moved successfully. C:\WINDOWS\system32\winfrun32.bin moved successfully. C:\WINDOWS\ss245sd.exe moved successfully. < purity > C:\WINDOWS\WіnSxS\WіnSxS moved successfully. Folder move failed. C:\WINDOWS\WіnSxS scheduled to be moved on reboot. File/Folder not found. File/Folder not found. OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07152008_235650 Files moved on Reboot... C:\WINDOWS\WіnSxS moved successfully. Malwarebytes' Anti-Malware 1.20 Database version: 957 Windows 5.1.2600 Service Pack 2 1:09:16 AM 7/16/2008 mbam-log-7-16-2008 (01-09-16).txt Scan type: Quick Scan Objects scanned: 47342 Time elapsed: 13 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 10 Registry Values Infected: 3 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 39 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\{5a148cf2-9c7b-4499-8e25-c9383a5e8680} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{daa07812-5c88-4ccc-8d25-10fef65b77b1} (Adware.ISM) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\BndFibu7.DLL (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\bndfibu7.band (Adware.ISM) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\bndfibu7.band.1 (Adware.ISM) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\bndfibu7.bho (Adware.ISM) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\bndfibu7.bho.1 (Adware.ISM) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\NetProject (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\SYSTEM\sysold (Adware.Tagasaurus) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\some (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\start (Trojan.Zlob) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\NetProject (Trojan.Zlob) -> Quarantined and deleted successfully. C:\Program Files\Sysmnt (Fake.Dropped.Malware) -> Quarantined and deleted successfully. Files Infected: C:\Program Files\Sysmnt\Ssmgr.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\avifile32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\avisynthex32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\aviwrap32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\bjam.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\browserad.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\cdsm32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\changeurl_30.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\msa64chk.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully. C:\WINDOWS\msapasrc.dll (Fake.Dropped.Malware) |