Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Chasing tail trying to remove virus; plz help!


  • Please log in to reply

#1
ElGuapoTLH

ElGuapoTLH

    New Member

  • Member
  • Pip
  • 2 posts
A week ago my wife's computer began acting up: intermittently losing internet connection, terribly slow at power up and power down. I scanned for viruses and found newdotnet uninstall files but no entry in Add/Remove Programs. I removed these with AVG but still had problems with the connection -- which don't appear to be due to LSP problems (I've run LSPfix). After consulting the sticky on this forum, I installed SuperAntiSpyware and ran MalwareBytes' Anti-Malware, and I have SpyBot SD Resident running. These didn't fix the problem either. Then I ran Panda's ActiveScan and removed the things that it would for free -- but now Panda's ActiveScan won't run again. Finally, I ran a scan at Kaspersky and it found an email worm that seems to have slipped under the radar of the other programs. But, by now I've lost my confidence as to what to fix and how to fix it, and thus appeal to your help. Below, I've pasted the main.txt from Deckard's System Scanner; I've also attached extra.txt plus the Kaspersky report and the report from the last time I was able to run Panda's ActiveScan.

Any help MUCH appreciated.

Deckard's System Scanner v20071014.68
Run by Susan Stelzmann on 2008-06-19 21:46:03
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Susan Stelzmann.exe) -------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:46:05 PM, on 6/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
E:\LOGITECH\MouseWare\system\em_exec.exe
E:\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe
E:\Norton Ghost\Agent\PQV2iSvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Microsoft Windows Feedback Panel\WFPService.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Microsoft Windows Feedback Panel\wfpuser.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Microsoft Windows Feedback Panel\wfpasieve.exe
C:\Program Files\Microsoft Windows Feedback Panel\wfpcore.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Documents and Settings\Susan Stelzmann\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\SUSANS~1.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [zBrowser Launcher] E:\LOGITECH\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Norton Ghost 9.0] E:\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "E:\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\LOGITECH\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WFPUser.lnk = C:\Program Files\Microsoft Windows Feedback Panel\wfpuser.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoft...s/as2stubie.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1168138311812
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton Ghost - Symantec Corporation - E:\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - e:\SiSoftSandra\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - e:\SiSoftSandra\RpcSandraSrv.exe

--
End of file - 10547 bytes

-- Process Modules -------------------------------------------------------------

C:\WINDOWS\system32\winlogon.exe (pid 1164)
2007-04-19 13:41:36 294912 --a------ C:\Program Files\SUPERAntiSpyware\SASWINLO.dll <Not Verified; SUPERAntiSpyware.com; SUPERAntiSpyware WinLogon Processor>

C:\WINDOWS\explorer.exe (pid 548)
2006-10-30 10:36:36 43008 --a------ C:\Program Files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll <Not Verified; Apple Computer, Inc.; iTunes>
2006-10-30 10:36:36 129536 --a------ C:\Program Files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll <Not Verified; Apple Computer, Inc.; iTunes>
2007-04-23 04:56:48 9216 --a------ C:\Program Files\Altap Salamander 2.5\plugins\salamext.dll <Not Verified; ALTAP; SALAMEXT>
2006-08-16 07:56:09 9216 --a------ E:\Servant Salamander 2.5 RC2\plugins\salamext.dll <Not Verified; ALTAP, Ltd.; SALAMEXT>
2003-12-18 09:50:00 24064 --a------ C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL <Not Verified; Logitech Inc.; Productivity Software Common Files>
2003-12-18 09:50:00 6144 --a------ E:\LOGITECH\MouseWare\system\LgWndHk.dll <Not Verified; Logitech Inc.; MouseWare>
2008-05-13 10:13:36 77824 --a------ C:\Program Files\SUPERAntiSpyware\SASSEH.DLL <Not Verified; SuperAdBlocker.com; SuperAntiSpyware>
2003-02-11 08:10:00 20552 --a------ E:\WINZIP\WZSHLSTB.DLL <Not Verified; WinZip Computing, Inc.; WinZip>
2007-02-27 12:39:26 61440 --a------ C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL <Not Verified; SUPERAntiSpyware.com; SUPERAntiSpyware Context Menu Extension>
2006-01-12 20:49:01 581632 --a------ C:\Program Files\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll <Not Verified; Adobe Systems Inc.; Adobe Acrobat Elements>
2005-09-21 05:32:58 98304 --a------ C:\Program Files\Creative\Shared Files\CtCmeCtx.dll <Not Verified; Creative Technology Ltd; Creative Media Explorer>
2006-02-17 23:29:21 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
2005-12-08 13:26:58 704512 --a------ E:\creative\ShCtMtp.dll <Not Verified; Creative Technology Ltd; Zen Media Explorer (MTP)>

C:\WINDOWS\system32\rundll32.exe (pid 2552)
2003-12-18 09:50:00 6144 --a------ E:\LOGITECH\MouseWare\system\LgWndHk.dll <Not Verified; Logitech Inc.; MouseWare>
2003-12-18 09:50:00 24064 --a------ C:\Program Files\Common Files\Logitech\Scrolling\LGMSGHK.DLL <Not Verified; Logitech Inc.; Productivity Software Common Files>


-- Files created between 2008-05-19 and 2008-06-19 -----------------------------

2008-06-18 11:55:44 0 d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-06-18 11:55:36 0 d-------- C:\Program Files\Security Task Manager
2008-06-18 09:44:17 0 d-------- C:\Program Files\Trend Micro
2008-06-16 12:30:11 0 d-------- C:\WINDOWS\Prefetch
2008-06-16 12:22:16 0 d-------- C:\WINDOWS\system32\scripting
2008-06-16 12:22:14 0 d-------- C:\WINDOWS\l2schemas
2008-06-16 12:22:13 0 d-------- C:\WINDOWS\system32\en
2008-06-15 22:47:01 0 d-------- C:\Program Files\Panda Security
2008-06-15 21:12:21 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-06-15 21:12:18 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-06-15 21:12:18 0 d-------- C:\Documents and Settings\Susan Stelzmann\Application Data\SUPERAntiSpyware.com
2008-06-15 21:11:56 0 d-------- C:\Documents and Settings\Susan Stelzmann\Application Data\Malwarebytes
2008-06-15 21:11:54 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-15 21:11:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-11 20:18:07 0 d--h----- C:\$AVG8.VAULT$
2008-06-11 17:31:26 0 d-------- C:\Program Files\Bookworm Adventures Deluxe
2008-06-11 17:31:11 0 d-------- C:\Program Files\ReflexiveArcade
2008-06-11 17:27:45 691545 --a------ C:\WINDOWS\unins000.exe
2008-06-11 17:27:45 2550 --a------ C:\WINDOWS\unins000.dat
2008-06-11 17:21:42 0 d-------- C:\WINDOWS\system32\drivers\Avg
2008-06-11 17:21:38 0 d-------- C:\Program Files\AVG
2008-06-11 17:21:37 0 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-06-10 19:57:45 0 d-------- C:\Documents and Settings\Susan Stelzmann\Application Data\PlayFirst
2008-06-10 19:03:36 23 --a------ C:\WINDOWS\popcinfot.dat
2008-06-09 20:41:58 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-09 20:01:36 0 d-------- C:\WINDOWS\Logs
2008-06-09 18:32:05 409600 --a------ C:\WINDOWS\system32\wrap_oal.dll <Not Verified; Creative Labs; Creative Labs OpenAL32>
2008-06-09 18:32:05 86016 --a------ C:\WINDOWS\system32\OpenAL32.dll <Not Verified; Portions © Creative Labs Inc. and NVIDIA Corp.; Standard OpenAL™ Library>
2008-06-09 18:32:05 0 d-------- C:\Program Files\OpenAL
2008-06-09 18:24:25 0 d-------- C:\Program Files\Steam


-- Find3M Report ---------------------------------------------------------------

2008-06-19 21:30:36 0 d-------- C:\Documents and Settings\Susan Stelzmann\Application Data\Skype
2008-06-18 12:09:15 0 d-------- C:\Program Files\Creative
2008-06-18 09:48:14 0 d-------- C:\Program Files\Yahoo!
2008-06-16 12:22:37 0 d-------- C:\Program Files\Messenger
2008-06-16 12:22:13 0 d-------- C:\Program Files\Movie Maker
2008-06-16 12:17:58 0 d-------- C:\Program Files\Windows NT
2008-06-15 21:12:05 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-11 11:13:50 0 d-------- C:\Program Files\Symantec
2008-06-11 11:00:32 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-10 20:49:21 0 d-------- C:\Program Files\Shockwave.com
2008-06-10 19:57:56 0 d-------- C:\Documents and Settings\Susan Stelzmann\Application Data\Macromedia
2008-06-01 20:12:17 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-20 10:24:51 0 d-------- C:\Program Files\Microsoft Silverlight
2008-05-12 14:25:20 0 d-------- C:\Program Files\Yahoo SiteBuilder
2008-05-10 16:34:56 0 d-------- C:\Program Files\Picasa2
2008-05-09 20:25:43 0 d-------- C:\Program Files\Google
2008-05-09 14:38:52 10390 --a------ C:\WINDOWS\mozver.dat
2008-05-09 14:38:51 0 d-------- C:\Program Files\Virtools


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/04/2004 01:31 AM]
"zBrowser Launcher"="E:\LOGITECH\iTouch\iTouch.exe" [11/23/2002 02:15 AM]
"Logitech Utility"="Logi_MwX.Exe" [12/11/2003 05:50 AM C:\WINDOWS\LOGI_MWX.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"Norton Ghost 9.0"="E:\Norton Ghost\Agent\GhostTray.exe" [11/22/2004 05:20 PM]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [01/12/2006 08:52 PM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [10/22/2006 01:22 PM]
"nwiz"="nwiz.exe" [10/22/2006 01:22 PM C:\WINDOWS\system32\nwiz.exe]
"QuickTime Task"="E:\quicktime\qttask.exe" [10/25/2006 07:58 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [10/30/2006 10:36 AM]
"@"="" []
"SoundMan"="SOUNDMAN.EXE" [12/01/2004 03:54 PM C:\WINDOWS\SOUNDMAN.EXE]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [10/22/2006 01:22 PM]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe" [08/30/2007 07:32 AM]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [06/11/2008 05:21 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 08:12 PM]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [03/30/2006 04:45 PM]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [05/28/2007 02:52 PM]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [03/05/2007 05:57 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [05/09/2008 08:24 PM]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [05/28/2008 10:33 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
"tscuninstall"=%systemroot%\system32\tscupgrd.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [9/18/2006 10:23:21 PM]
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [5/24/2005 10:04:08 PM]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [5/9/2008 8:24:53 PM]
Logitech Desktop Messenger.lnk - E:\LOGITECH\Desktop Messenger\8876480\Program\LDMConf.exe [5/20/2005 8:16:58 PM]
Microsoft Office.lnk - E:\Microsoft Office\Office\OSA9.EXE [1/21/2000 4:15:54 AM]
WFPUser.lnk - C:\Program Files\Microsoft Windows Feedback Panel\wfpuser.exe [6/13/2006 5:43:38 PM]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/13/2008 10:13 AM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc




-- End of Deckard's System Scanner: finished at 2008-06-19 21:48:13 ------------

Attached Files


  • 0

Advertisements


#2
ElGuapoTLH

ElGuapoTLH

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
Quick follow-up with more evidence:

Today my wife used Internet Explorer, searched for something on Ebay, and got (re)directed to a fake page phishing for ATM, SSN, etc.

Further Googling based on this led me to remove this BHO that Hijack This spotted:
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

However, after rebooting we get the same issue -- search at Ebay directs us to the phishing page. So, seems this one is integrated w/ IE and further explains why I never had a problem since I'm a Firefox user.

Thanks again for any help on this.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP