Can't get rid of psw.x-vir [Resolved] - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

Can't get rid of psw.x-vir [Resolved] I'm seeing this all over the web, but can't get it off hubby&#

#1 shampton2

  • Group: Member
  • Posts: 29
  • Joined: 08-June 05

  Posted 25 October 2007 - 11:23 PM

My husband said that when he went to a site to download a sound effect for a project a couple of days ago, a Windows pop up told him that it had detected some type of security threat or breach, and it recommended to install the update. So, he clicked it and now he gets all these popups like every 30 sec - 2 min. He is running Win XP Pro on a Dell Precision WS 370. The trojan is called the "Black door" (that is not a typo on MY part) and it comes up with all kinds of worms, viruses, and trojans. The filename that comes up is psw.x-vir. I would greatly appreciate anyone's help in getting rid of this thing. I told my hubby that I would have his computer cleaned by the time he gets back from LA, which will be Monday night.

Thank you,
Summarah

#2 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 27 October 2007 - 06:38 AM

Hello shampton2

Welcome to G2Go. :)

* Click here to download HJTsetup.exe
  • Save HJTsetup.exe to your desktop.
  • Doubleclick on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.


#3 shampton2

  • Group: Member
  • Posts: 29
  • Joined: 08-June 05

Posted 29 October 2007 - 10:49 AM

Hi Kahdah. Thank you for helping me. Here is the HiJackThis log that came from my husband's computer.

Summarah

Logfile of HijackThis v1.99.1
Scan saved at 12:43:17 PM, on 10/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\Program Files\Dell\RAID Storage Manager\StorServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.n...lbar2.0/search/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\xdsbsvfh.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [80964974] rundll32.exe "C:\WINDOWS\system32\pawdcfar.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fbbfd91b06754b1eb0ad955642dae019
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fbbfd91b06754b1eb0ad955642dae019
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp...oads/msxml4.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...147/mcfscan.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - c:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RAID Storage Manager Agent (RAIDStorAgent) - Dell - c:\Program Files\Dell\RAID Storage Manager\StorServ.exe

#4 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 29 October 2007 - 07:24 PM

You are welcome. :)
=============
Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

#5 shampton2

  • Group: Member
  • Posts: 29
  • Joined: 08-June 05

Posted 29 October 2007 - 09:02 PM

Kahdah - While I was downloading this file, my husband's computer went into screen saver mode, and although I entered the password several times correctly on both his and my profile, I could not get back in, so I had to shut it down. The blue screen of death came up and said there was a fatal error at logon, gave some numbers that I didn't write down, and said it had to shut down. Since then, I rebooted, downloaded the file onto his computer over the network, ran it, and saved the log file back to my computer. The problem seems to have disappeared now, because there have been no popups for the past 10 minutes. Nonetheless, if you would kindly review the log file information below for problems, I would be most appreciative.

Regards,
Summarah

SmitFraudFix v2.244

Scan done at 22:59:04.50, Mon 10/29/2007
Run from C:\Documents and Settings\Keith Hampton\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\Program Files\Dell\RAID Storage Manager\StorServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe

ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ hosts


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\WINDOWS


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\WINDOWS\system


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\WINDOWS\Web


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\WINDOWS\system32


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\WINDOWS\system32\LogFiles


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\Documents and Settings\Keith Hampton


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\Documents and Settings\Keith Hampton\Application Data


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Start Menu


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\DOCUME~1\KEITHH~1\FAVORI~1


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Desktop


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ C:\Program Files


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Corrupted keys


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Desktop Components



ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\GOOGLE\\GOOGLE~1\\GOEC62~1.DLL "


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Rustock



ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ DNS

Description: N1 Wireless USB Network Adapter #5 - Packet Scheduler Miniport
DNS Server Search Order: 68.87.68.162
DNS Server Search Order: 68.87.74.162

Description: N1 Wireless USB Network Adapter #5 - Packet Scheduler Miniport
DNS Server Search Order: 68.87.68.162
DNS Server Search Order: 68.87.74.162

Description: N1 Wireless USB Network Adapter #5 - Packet Scheduler Miniport
DNS Server Search Order: 68.87.68.162
DNS Server Search Order: 68.87.74.162

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0A2B2AD3-CBBD-4454-9F95-F256ACFD8B18}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CCS\Services\Tcpip\..\{4DEFE6B1-62EC-48CE-A0FE-A0F9E41EE2D6}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CCS\Services\Tcpip\..\{81E04AE2-B89A-40A1-8840-FF4204BBD394}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0A2B2AD3-CBBD-4454-9F95-F256ACFD8B18}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4DEFE6B1-62EC-48CE-A0FE-A0F9E41EE2D6}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CS1\Services\Tcpip\..\{81E04AE2-B89A-40A1-8840-FF4204BBD394}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CS3\Services\Tcpip\..\{0A2B2AD3-CBBD-4454-9F95-F256ACFD8B18}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CS3\Services\Tcpip\..\{4DEFE6B1-62EC-48CE-A0FE-A0F9E41EE2D6}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CS3\Services\Tcpip\..\{81E04AE2-B89A-40A1-8840-FF4204BBD394}: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=68.87.68.162 68.87.74.162
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=68.87.68.162 68.87.74.162


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ Scanning for wininet.dll infection


ŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧŧ End

#6 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 29 October 2007 - 09:15 PM

Please download SUPERAntiSpyware Home Edition (free version).
–Install it and double-click the icon on your desktop to run it.
  • It will ask if you want to update the program definitions, click Yes.
  • Under Configuration and Preferences, click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked:
  • Close browsers before scanning
  • Scan for tracking cookies
  • Scan for Alternate Data streams
  • Terminate memory threats before quarantining.
  • Please leave the others unchecked.
  • Click the Close button to leave the control center screen.
=============================================
After that Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\xdsbsvfh.dll
    C:\WINDOWS\system32\pawdcfar.dll



  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
    Click "Exit" to close OTMoveIt.

    **When ready to Reply on the forum, please Paste the content of the latest log which is located at the root of the drive where the OTMoveIt folder is:
    C:\_OTMoveIt\MovedFiles\********_******.log
    (where "********_******" is the "date_time")
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes and then boot into Safe Mode.
===============================================================
*Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.

Then run Superantispyware.
  • Double click on the icon to start Superantispyware.
  • On the main screen, under Scan for Harmful Software click Scan your computer.
  • On the left check C:\Fixed Drive.
  • On the right, under Complete Scan, choose Perform Complete Scan.
  • Click Next to start the scan. Please be patient while it scans your computer.
  • After the scan is complete a summary box will appear. Click OK.
  • Make sure everything in the white box has a check next to it, then click Next.
  • It will quarantine what it found and if it asks if you want to reboot, click Yes.
1. To retrieve the removal information for me please do the following:
2. After reboot, double-click the SUPERAntispyware icon on your desktop.
3. Click Preferences. Click the Statistics/Logs tab.
4. Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
5. It will open in your default text editor (such as Notepad/Wordpad).
6. Please highlight everything in the notepad, then right-click and choose copy.
7. Click close and close again to exit the program.
Save the log information. If needed (still infected) paste this info along with your HijackThis log.

===========================================================
Please post back with these logs:
Superantispyware
OTMove it log
New Hijackthis log


#7 shampton2

  • Group: Member
  • Posts: 29
  • Joined: 08-June 05

Posted 29 October 2007 - 09:25 PM

Kahdah - Will I be able to *completely* remove all of these programs once I'm done with them? Will they interfere in any way with his editing programs, specifically Avid?

#8 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 29 October 2007 - 09:30 PM

Yes we will completely remove them when we are done.
They will not interfere with his editing program.

#9 shampton2

  • Group: Member
  • Posts: 29
  • Joined: 08-June 05

Posted 29 October 2007 - 09:56 PM

MoveIt cannot find those 2 .dll files. What should I do?

#10 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 30 October 2007 - 03:24 AM

Please continue on with the rest of the instructions.

#11 shampton2

  • Group: Member
  • Posts: 29
  • Joined: 08-June 05

  Posted 30 October 2007 - 10:39 AM

Here are the requested log files:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/30/2007 at 12:05 PM

Application Version : 3.9.1008

Core Rules Database Version : 3333
Trace Rules Database Version: 1334

Scan type : Complete Scan
Total Scan Time : 02:34:34

Memory items scanned : 166
Memory threats detected : 0
Registry items scanned : 5813
Registry threats detected : 31
File items scanned : 71160
File threats detected : 106

Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{06A13FFB-C2ED-4B54-8E6B-F4C72A21DB02}
HKCR\CLSID\{06A13FFB-C2ED-4B54-8E6B-F4C72A21DB02}
HKCR\CLSID\{06A13FFB-C2ED-4B54-8E6B-F4C72A21DB02}\InprocServer32
HKCR\CLSID\{06A13FFB-C2ED-4B54-8E6B-F4C72A21DB02}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\AWVTQ.DLL
HKLM\Software\Classes\CLSID\{86882CA4-BE70-4BCE-AEA5-CF40EB8E0BC3}
HKCR\CLSID\{86882CA4-BE70-4BCE-AEA5-CF40EB8E0BC3}
HKCR\CLSID\{86882CA4-BE70-4BCE-AEA5-CF40EB8E0BC3}\InprocServer32
HKCR\CLSID\{86882CA4-BE70-4BCE-AEA5-CF40EB8E0BC3}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\HGGFGFF.DLL
HKLM\Software\Classes\CLSID\{89AD4D75-2429-462e-BD4E-443F233F6033}
HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}
HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}\InprocServer32
HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\HMVVHMCA.DLL
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06A13FFB-C2ED-4B54-8E6B-F4C72A21DB02}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{86882CA4-BE70-4BCE-AEA5-CF40EB8E0BC3}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{89AD4D75-2429-462e-BD4E-443F233F6033}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{86882CA4-BE70-4BCE-AEA5-CF40EB8E0BC3}
HKCR\CLSID\{86882CA4-BE70-4BCE-AEA5-CF40EB8E0BC3}
HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\XDSBSVFH.DLL
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKU\S-1-5-21-3982779950-1534651121-2193738209-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{11A69AE4-FBED-4832-A2BF-45AF82825583}

Adware.Tracking Cookie
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@freeadultmedia[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@revenue[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@adserver01.verio[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@wt.sexsearch[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@hornymatches[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@exchange.ggmedia[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@[bleep]aroo[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@ads[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@adultfriendfinder[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@heavycom.122.2o7[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@realmedia[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@adultadworld[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@eyewonder[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@eas.apm.emediate[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@ads.adgoto[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@gostats[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@cgi-bin[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@bestsellerantivirus[3].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@cbs.112.2o7[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@atdmt[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@offers.intermediainteractive[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@specificclick[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@sale.bestsellerantivirus[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@tribalfusion[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@brightcove.112.2o7[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@www.eroticlick[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@adbrite[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@tremor.adbureau[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@ads.as4x.tmcs[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@advertising[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@bs.serving-sys[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@id14943[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@view-12490[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@ad1.clickhype[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@serving-sys[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@iacas.adbureau[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@sex-video[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@questionmarket[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@anad.tacoda[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@ads[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@ads[3].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@kinxxx[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@sexbuddies[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@zedo[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@2o7[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@humornsex[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@interclick[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@1069369214[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@anat.tacoda[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@clicksor[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@traffic.grayvee[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@mediaplex[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@da-tracking[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@adopt.specificclick[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@eroticlick[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@tour.sexsearchcom[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@[bleep]porns[2].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@www.burstbeacon[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@ads.pointroll[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@id12373[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@tacoda[1].txt
C:\Documents and Settings\Keith Hampton\Cookies\keith hampton@Brianna_Love_[bleep]s_Her_Best_Friends_Brother_video[1].txt
C:\Documents and Settings\Summarah Hampton\Cookies\summarah hampton@adopt.specificclick[2].txt
C:\Documents and Settings\Summarah Hampton\Cookies\summarah hampton@adserver[1].txt
C:\Documents and Settings\Summarah Hampton\Cookies\summarah hampton@atdmt[1].txt
C:\Documents and Settings\Summarah Hampton\Cookies\summarah hampton@atwola[1].txt
C:\Documents and Settings\Summarah Hampton\Cookies\summarah hampton@specificclick[1].txt

Malware.LocusSoftware Inc/BestSellerAntivirus
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\APPLICATION DATA\INSTALL_EN[1].EXE
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\NI.UGA6P_0001_N119M1510\SETUP.EXE

Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO1.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO12.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO13.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO14.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO15.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO16.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO2.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO3.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO3D.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO3E.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO3F.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO4.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO40.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO41.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO5.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO6.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO7.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO8.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO83.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO84.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO85.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO86.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO87.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICO9.TMP
C:\DOCUMENTS AND SETTINGS\KEITH HAMPTON\LOCAL SETTINGS\TEMP\ICOA.TMP
C:\DOCUMENTS AND SETTINGS\SUMMARAH HAMPTON\LOCAL SETTINGS\TEMP\ICO47.TMP
C:\DOCUMENTS AND SETTINGS\SUMMARAH HAMPTON\LOCAL SETTINGS\TEMP\ICO48.TMP
C:\DOCUMENTS AND SETTINGS\SUMMARAH HAMPTON\LOCAL SETTINGS\TEMP\ICO49.TMP
C:\DOCUMENTS AND SETTINGS\SUMMARAH HAMPTON\LOCAL SETTINGS\TEMP\ICO4A.TMP
C:\DOCUMENTS AND SETTINGS\SUMMARAH HAMPTON\LOCAL SETTINGS\TEMP\ICO4B.TMP

Trace.Known Threat Sources
C:\Documents and Settings\Keith Hampton\Local Settings\Temporary Internet Files\Content.IE5\9GPS1ZYM\data[1].htm
C:\Documents and Settings\Keith Hampton\Local Settings\Temporary Internet Files\Content.IE5\25WN218D\ajax[1].htm
C:\Documents and Settings\Keith Hampton\Local Settings\Temporary Internet Files\Content.IE5\PWFBB9GK\errorhandler[1].htm



MOVEIT LOG:
File/Folder C:\WINDOWS\system32\xdsbsvfh.dll not found.
File/Folder C:\WINDOWS\system32\pawdcfar.dll not found.

Created on 10/30/2007 16:02:23



HIJACKTHIS! LOG #2:

Logfile of HijackThis v1.99.1
Scan saved at 4:04:31 PM, on 10/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\Program Files\Dell\RAID Storage Manager\StorServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~1.DLL
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fbbfd91b06754b1eb0ad955642dae019
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fbbfd91b06754b1eb0ad955642dae019
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp...oads/msxml4.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...147/mcfscan.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: hggfgff - hggfgff.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: xdsbsvfh - xdsbsvfh.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - c:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RAID Storage Manager Agent (RAIDStorAgent) - Dell - c:\Program Files\Dell\RAID Storage Manager\StorServ.exe

#12 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 30 October 2007 - 07:09 PM

I am assuming that the computer is working properly now any more boot up issues any beeps?
=========================================================
Please reopen Hijackthis and place a check mark next to these entries:

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - Winlogon Notify: hggfgff - hggfgff.dll (file missing)
O20 - Winlogon Notify: xdsbsvfh - xdsbsvfh.dll (file missing)


Now click on Fix Checked and then close Hijackthis.
=====================================
After that go to Start>Control Panel >add\remove programs.
Uninstall these two programs below.

Crawler
Superantispyware


Then close the Control Panel.
====================
After that please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT

  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      Extended (if available otherwise Standard)
    • Scan Options:
      Scan Archives
      Scan Mail Bases

  • Click OK
  • Now under select a target to scan:
      Select My Computer

  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:

  • Save the file to your desktop.
  • Copy and paste that information in your next post.
==========================
Please post back with these logs:
Kaspersky log
New Hijackthis log


#13 shampton2

  • Group: Member
  • Posts: 29
  • Joined: 08-June 05

Posted 30 October 2007 - 09:47 PM

Well ... I got it started again, so I ran the 3 programs that you asked, and then after I removed those 2 programs, it asked me to reboot again. So I did, and now it's stuck again.

#14 kahdah

  • Group: GeekU Moderator
  • Posts: 15,822
  • Joined: 13-April 06

Posted 31 October 2007 - 03:40 AM

It sounds as if you have some sort of hardware issue.
IF you want you can try to open up the case and remove any PCI cards or cards inside the white slots

Pull out all of them except for your Ethernet card and see if that helps.
Also try to reseat the ram inside.
To do that please make sure it is securely set in it's holder and then take it out of it's holder and put it back in.
See if any of that helps.

If it does please do the online scan if you can.

#15 shampton2

  • Group: Member
  • Posts: 29
  • Joined: 08-June 05

Posted 31 October 2007 - 09:11 AM

I think it's the hardware too, because it came back on this morning. Guess I need to contact the manufacturer to get it fixed. I don't want to open that monster! Thanks for your advice. And I'll do the online scan and post the results in a few.

Share this topic:


  • 2 Pages +
  • 1
  • 2