Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojon Virus Virtumonde Help!


  • Please log in to reply

#1
Kriegster

Kriegster

    Member

  • Member
  • PipPip
  • 14 posts
I have no clue how i got this but its on my computer and its p****** me off. All i need is to know how to remove this, as my virus scanner has blocked all the trojans it tried downloading to my computer.

The Following Trojans have been downloaded to my computer but caught while on entry:
Both Which i have found to be the strain of Vundo.
These pop up 1-3 times a day over and over again... its annoying. :)

I did run spybot search and destory and it found two reg entryies but once removed on the next reboot they just come back.

Trojan.Vundo
Trojan.Metajuan

heres my log file for hijackthis.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:59:23 AM, on 7/18/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Steam\Steam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Symantec Shared\SecurityHistory\mcui32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
///Virus?/// O2 - BHO: (no name) - {AF2FD6C4-C771-4970-B62E-C4281707AF84} - C:\Windows\system32\vtUkjIAP.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplane...C_2.3.6.108.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O21 - SSODL: SetDriveStat - {71660196-855f-4cd2-b4c4-d34b79637b5e} - C:\Windows\Resources\SetDriveStat.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 7673 bytes


thanks


UPDATE:

Hmm... it seems to start running when i open internet explorer...... im using firefox and i think thats why it hasnt been running in the past couple hours..
RESCAN



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:13:39 AM, on 7/18/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Steam\Steam.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: (no name) - {E01B548F-5988-44D5-B4AE-46299EFEE29E} - C:\Windows\system32\vtUkjIAP.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
//Virus?//O4 - HKLM\..\Run: [82a83da7] rundll32.exe "C:\Windows\system32\oqlaqpeu.dll",b
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplane...C_2.3.6.108.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O21 - SSODL: SetDriveStat - {71660196-855f-4cd2-b4c4-d34b79637b5e} - C:\Windows\Resources\SetDriveStat.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 8179 bytes

Edited by kahdah, 18 July 2008 - 10:28 AM.

  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Kriegster

Welcome to G2Go. :)
=====================

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

  • 0

#3
Kriegster

Kriegster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
okay here ya go:

Deckard's System Scanner v20071014.68
Run by Hunter on 2008-07-18 11:34:32
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
6: 2008-07-18 14:18:23 UTC - RP65 - Installed Windows Media Player Firefox Plugin
5: 2008-07-12 18:44:44 UTC - RP64 - Scheduled Checkpoint
4: 2008-07-12 06:35:05 UTC - RP63 - Scheduled Checkpoint
3: 2008-07-11 17:56:43 UTC - RP62 - Installed iTunes
2: 2008-07-11 17:55:34 UTC - RP61 - Device Driver Package Install: Apple, Inc. Universal Serial Bus controllers


-- First Restore Point --
1: 2008-07-11 17:54:34 UTC - RP60 - Last known good configuration


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Hunter.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:35:40 AM, on 7/18/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Steam\Steam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Hunter\Downloads\dss.exe
C:\Windows\system32\SearchFilterHost.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Hunter.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: (no name) - {E01B548F-5988-44D5-B4AE-46299EFEE29E} - C:\Windows\system32\vtUkjIAP.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [82a83da7] rundll32.exe "C:\Windows\system32\oqlaqpeu.dll",b
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O13 - Gopher Prefix:
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplane...C_2.3.6.108.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O21 - SSODL: SetDriveStat - {71660196-855f-4cd2-b4c4-d34b79637b5e} - C:\Windows\Resources\SetDriveStat.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 7992 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080712-125504-189 O4 - HKLM\..\Run: [82a83da7] rundll32.exe "C:\Windows\system32\rsmxvuqy.dll",b
backup-20080712-125504-619 O2 - BHO: (no name) - {A353F2AB-0FA3-4FDC-A084-9C8322828D9D} - C:\Windows\system32\vtUkjIAP.dll
backup-20080712-125642-260 O2 - BHO: (no name) - {A353F2AB-0FA3-4FDC-A084-9C8322828D9D} - C:\Windows\system32\vtUkjIAP.dll

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>

S3 DSproct - \??\c:\program files\dellsupport\gtaction\triggers\dsproct.sys


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>

S3 DSBrokerService - "c:\program files\dellsupport\brkrsvc.exe" <Not Verified; ; Gteko BrkrSvc Application>
S3 stllssvr - "c:\program files\common files\surething shared\stllssvr.exe" <Not Verified; MicroVision Development, Inc.; SureThing CD Labeler>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {997b5d8d-c442-4f2e-baf3-9c8e671e9e21}
Description: Logitech GamePanel Devices
Device ID: ROOT\SIDESHOW\0000
Manufacturer: Logitech Inc
Name: Logitech GamePanel Devices
PNP Device ID: ROOT\SIDESHOW\0000
Service: WUDFRd


-- Scheduled Tasks -------------------------------------------------------------

2008-07-07 20:28:22 548 --a------ C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Hunter.job


-- Files created between 2008-06-18 and 2008-07-18 -----------------------------

2008-07-18 09:30:49 116864 --a------ C:\Windows\system32\wwrdcv.dll
2008-07-18 09:30:48 116864 --a------ C:\Windows\system32\rsmhdswq.dll
2008-07-18 09:28:29 92672 --a------ C:\Windows\system32\oqlaqpeu.dll
2008-07-12 12:43:10 0 d-------- C:\VundoFix Backups
2008-07-11 21:51:47 0 d-------- C:\Program Files\Trend Micro
2008-07-11 21:51:39 0 d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-07-11 21:24:50 109500 --a------ C:\Windows\system32\hvlefnyw.exe
2008-07-11 21:21:48 0 --a------ C:\Windows\system32\rsmxvuqy.dll
2008-07-11 19:42:16 0 d-------- C:\Program Files\Red Kawa
2008-07-11 12:58:46 0 d-------- C:\Program Files\iPod
2008-07-11 12:58:42 0 d-------- C:\Program Files\iTunes
2008-07-11 12:56:32 0 d-------- C:\Program Files\Apple Software Update
2008-07-10 23:19:41 0 d-------- C:\Program Files\FileZilla FTP Client
2008-07-10 20:41:56 0 d-------- C:\Program Files\Lavasoft
2008-07-10 20:41:51 0 d-------- C:\Users\All Users\Lavasoft
2008-07-10 15:50:39 0 --a------ C:\Windows\nsreg.dat
2008-07-10 10:42:00 0 --a------ C:\z3g45.bat
2008-07-10 10:40:59 29568 --a------ C:\Windows\system32\ssqNEuvw.dll
2008-07-09 22:13:23 0 d-------- C:\Fraps
2008-07-09 22:02:45 623592 --ahs---- C:\Windows\system32\PAIjkUtv.ini2 <PAIJKU~1.INI>
2008-07-09 22:02:37 318208 -----n--- C:\Windows\system32\vtUkjIAP.dll
2008-07-09 21:57:31 29568 --a------ C:\Windows\system32\awtqrrOH.dll
2008-07-09 21:53:54 0 d-------- C:\Windows\WinAVI Video Converter 9.0
2008-07-07 23:40:45 0 d-a------ C:\Users\All Users\TEMP
2008-07-07 23:40:39 0 d-------- C:\Program Files\Skype Recorder
2008-07-03 23:36:44 0 d-------- C:\Users\All Users\Media Center Programs
2008-07-03 23:36:43 0 d-------- C:\Program Files\Guild Wars
2008-07-03 19:45:26 0 d-------- C:\Program Files\AutoHotkey
2008-07-03 14:50:41 0 d-------- C:\Program Files\WinSCP
2008-06-30 21:06:14 0 d-------- C:\Program Files\QAvimator
2008-06-29 12:10:12 0 d-------- C:\Program Files\Obsidium Software Protection System
2008-06-28 23:51:20 0 d-------- C:\Program Files\SecondLife
2008-06-27 15:13:12 0 d-------- C:\Program Files\Common Files\INCA Shared
2008-06-27 15:13:05 4682 --a------ C:\Windows\system32\npptNT2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT>
2008-06-26 21:34:52 0 d-------- C:\Program Files\MAIET
2008-06-26 21:32:22 0 d-------- C:\ijji
2008-06-26 21:30:35 0 d-------- C:\Program Files\NHN USA
2008-06-25 17:26:24 0 d-------- C:\Program Files\Xilisoft
2008-06-25 10:36:17 0 d-------- C:\Program Files\Activision
2008-06-24 17:17:06 0 d-------- C:\Users\All Users\Electronic Arts
2008-06-24 17:16:48 2534 --a------ C:\Windows\system32\ealregsnapshot1.reg <EALREG~1.REG>
2008-06-24 16:56:01 0 d-------- C:\Windows\.jagex_cache_32
2008-06-24 16:55:54 0 d-------- C:\Windows\Sun
2008-06-23 13:10:31 0 d-------- C:\Program Files\Rockstar Games
2008-06-22 10:37:24 0 d-------- C:\Program Files\EA GAMES
2008-06-22 10:37:23 442368 -ra------ C:\Windows\system32\vp6vfw.dll <Not Verified; On2.com; On2_VP6>
2008-06-20 16:42:08 0 d-------- C:\Program Files\Electronic Arts
2008-06-20 16:36:36 0 d-------- C:\Program Files\PowerISO
2008-06-20 15:49:32 0 d-------- C:\Program Files\Download Manager
2008-06-20 15:21:20 0 d-------- C:\Users\All Users\Xfire
2008-06-20 15:21:20 0 d-------- C:\Program Files\Xfire
2008-06-20 14:07:42 36104 --a------ C:\Windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat <SPOONU~1.DAT>
2008-06-20 14:07:42 131072 --a------ C:\Windows\system32\SpoonUninstall.exe <SPOONU~1.EXE>
2008-06-20 14:07:28 0 d-------- C:\Program Files\Illustrate
2008-06-19 22:47:37 0 d-------- C:\HammerAutosave
2008-06-18 20:47:09 0 d-------- C:\I_ROBOT_16X9
2008-06-18 13:43:05 0 d-------- C:\Program Files\PeerGuardian2
2008-06-18 11:27:39 0 d-------- C:\Users\All Users\Viewpoint
2008-06-18 11:27:34 0 d-------- C:\Users\All Users\acccore
2008-06-18 11:27:34 0 d-------- C:\Program Files\Viewpoint
2008-06-18 11:27:26 0 d-------- C:\Users\All Users\AOL
2008-06-18 11:27:26 0 d-------- C:\Users\All Users\AOL OCP
2008-06-18 11:27:09 0 d-------- C:\Program Files\Common Files\AOL
2008-06-18 11:26:57 0 d-------- C:\Program Files\AIM6


-- Find3M Report ---------------------------------------------------------------

2008-07-18 09:26:46 0 d-------- C:\Program Files\Common Files\Steam
2008-07-18 09:26:44 0 d-------- C:\Program Files\Steam
2008-07-11 21:54:30 0 d-------- C:\Users\Hunter\AppData\Roaming\uTorrent
2008-07-11 12:04:28 0 d-------- C:\Users\Hunter\AppData\Roaming\Apple Computer
2008-07-10 23:29:55 0 d-------- C:\Users\Hunter\AppData\Roaming\FileZilla
2008-07-10 20:37:07 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-10 16:41:45 0 d-------- C:\Users\Hunter\AppData\Roaming\Xfire
2008-07-10 15:50:36 0 d-------- C:\Users\Hunter\AppData\Roaming\Mozilla
2008-07-10 15:41:28 0 d-------- C:\Users\Hunter\AppData\Roaming\LimeWire
2008-07-10 11:20:06 0 d-------- C:\Users\Hunter\AppData\Roaming\HLSW
2008-07-08 00:29:29 0 d-------- C:\Users\Hunter\AppData\Roaming\Skype
2008-07-08 00:04:53 0 d-------- C:\Users\Hunter\AppData\Roaming\skypePM
2008-07-03 18:07:49 600 --a------ C:\Users\Hunter\AppData\Roaming\winscp.rnd
2008-06-28 23:52:52 0 d-------- C:\Users\Hunter\AppData\Roaming\SecondLife
2008-06-28 20:57:59 0 d-------- C:\Users\Hunter\AppData\Roaming\IGN_DLM
2008-06-27 15:41:33 0 d-------- C:\Users\Hunter\AppData\Roaming\SPORE Creature Creator
2008-06-27 15:13:12 0 d-------- C:\Program Files\Common Files
2008-06-27 15:04:05 0 d--h----- C:\Users\Hunter\AppData\Roaming\ijjigame
2008-06-26 21:30:35 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-20 20:04:52 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-20 14:05:30 563 --a------ C:\Users\Hunter\AppData\Roaming\AutoGK.ini
2008-06-18 11:30:59 0 d-------- C:\Users\Hunter\AppData\Roaming\acccore
2008-06-18 11:10:07 0 d-------- C:\Users\Hunter\AppData\Roaming\Ventrilo
2008-06-17 20:17:04 0 d-------- C:\Program Files\LimeWire
2008-06-17 14:40:08 0 d-------- C:\Program Files\BitComet
2008-06-17 10:57:56 0 d-------- C:\Program Files\AutoGK
2008-06-17 10:57:54 43698 --a------ C:\Windows\system32\xvid-uninstall.exe <XVID-U~1.EXE>
2008-06-17 10:57:48 0 d-------- C:\Program Files\AviSynth 2.5
2008-06-17 10:57:39 0 d-------- C:\Program Files\Gabest
2008-06-17 10:39:55 0 d-------- C:\Program Files\DVD Decrypter
2008-06-17 00:14:35 56 --ah----- C:\Windows\system32\ezsidmv.dat
2008-06-17 00:13:45 0 d-------- C:\Program Files\Skype
2008-06-17 00:13:42 0 d-------- C:\Program Files\Common Files\Skype
2008-06-14 23:29:26 0 d---s---- C:\Program Files\HLSW
2008-06-14 23:10:36 0 d-------- C:\Program Files\Bonjour
2008-06-14 23:10:26 0 d-------- C:\Program Files\QuickTime
2008-06-14 23:07:36 0 d-------- C:\Program Files\Common Files\Apple
2008-06-14 23:04:19 0 d-------- C:\Program Files\iDump
2008-06-14 22:28:56 0 d-------- C:\Program Files\Xvid
2008-06-14 22:26:27 0 d-------- C:\Users\Hunter\AppData\Roaming\DivX
2008-06-14 18:32:58 0 d-------- C:\Program Files\DivX
2008-06-14 18:16:04 0 d-------- C:\Users\Hunter\AppData\Roaming\WinRAR
2008-06-14 17:05:05 174 --ahs---- C:\Program Files\desktop.ini
2008-06-14 16:57:12 0 d-------- C:\Program Files\Windows Sidebar
2008-06-14 16:57:12 0 d-------- C:\Program Files\Windows Calendar
2008-06-14 16:57:12 0 d-------- C:\Program Files\Movie Maker
2008-06-14 16:57:11 0 d-------- C:\Program Files\Windows Mail
2008-06-14 16:57:10 0 d-------- C:\Program Files\Windows Photo Gallery
2008-06-14 16:57:10 0 d-------- C:\Program Files\Windows Journal
2008-06-14 16:57:10 0 d-------- C:\Program Files\Windows Collaboration
2008-06-14 16:57:06 0 d-------- C:\Program Files\Windows Defender
2008-06-14 16:13:55 0 d-------- C:\Program Files\Norton Internet Security
2008-06-14 16:08:30 0 d-------- C:\Program Files\Logitech
2008-06-14 16:04:56 0 d-------- C:\Program Files\Symantec
2008-06-14 16:02:53 0 d-------- C:\Users\Hunter\AppData\Roaming\Logitech
2008-06-14 15:59:03 0 d-------- C:\Program Files\Common Files\Logishrd
2008-06-14 15:58:22 0 d-------- C:\Users\Hunter\AppData\Roaming\InstallShield
2008-06-14 15:52:45 0 d-------- C:\Users\Hunter\AppData\Roaming\Symantec
2008-06-14 15:06:37 0 d-------- C:\Users\Hunter\AppData\Roaming\Adobe
2008-06-14 14:50:56 0 d-------- C:\Program Files\Ventrilo
2008-06-14 14:40:55 0 d-------- C:\Program Files\uTorrent
2008-06-14 14:20:17 0 d-------- C:\Users\Hunter\AppData\Roaming\Google
2008-06-14 14:15:09 0 d-------- C:\Program Files\Common Files\InstallShield
2008-06-14 14:11:19 0 d-------- C:\Users\Hunter\AppData\Roaming\Macromedia
2008-06-14 14:08:15 0 d--h----- C:\Users\Hunter\AppData\Roaming\GTek
2008-06-14 14:07:16 0 d-------- C:\Users\Hunter\AppData\Roaming\Identities
2008-05-30 18:22:48 802816 --a------ C:\Windows\system32\divx_xx11.dll <DIVX_X~3.DLL> <Not Verified; DivX, Inc.; DivX?>
2008-05-30 18:22:48 823296 --a------ C:\Windows\system32\divx_xx0c.dll <DIVX_X~1.DLL> <Not Verified; DivX, Inc.; DivX®>
2008-05-30 18:22:48 823296 --a------ C:\Windows\system32\divx_xx07.dll <DIVX_X~2.DLL> <Not Verified; DivX, Inc.; DivX®>
2008-05-30 18:22:46 815104 --a------ C:\Windows\system32\divx_xx0a.dll <DIVX_X~4.DLL> <Not Verified; DivX, Inc.; DivX®>
2008-05-30 18:22:46 683520 --a------ C:\Windows\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-22 17:22:18 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2008-05-22 17:19:46 196608 --a------ C:\Windows\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-05-22 17:19:46 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-05-22 17:18:54 12288 --a------ C:\Windows\system32\DivXWMPExtType.dll <DIVXWM~1.DLL>
2008-04-27 10:35:28 180224 --a------ C:\Windows\system32\xvidvfw.dll
2008-04-27 10:33:36 765952 --a------ C:\Windows\system32\xvidcore.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
08/24/2007 10:51 PM 316784 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
06/14/2008 04:03 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E01B548F-5988-44D5-B4AE-46299EFEE29E}]
07/09/2008 10:02 PM 318208 --------- C:\Windows\system32\vtUkjIAP.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [08/24/2007 10:51 PM 316784]

[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/14/2008 11:01 AM]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [07/10/2008 09:47 AM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [07/10/2008 10:51 AM]
"82a83da7"="C:\Windows\system32\oqlaqpeu.dll" [07/18/2008 09:28 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [01/19/2008 02:33 AM]
"Aim6"="" []
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [03/05/2007 04:57 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [01/19/2008 02:33 AM]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [6/14/2008 3:58:50 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"=0 (0x0)
"EnableLUA"=0 (0x0)
"EnableUIADesktopToggle"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}"= C:\Windows\system32\ssqNEuvw.dll [07/09/2008 09:57 PM 29568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SetDriveStat"= {71660196-855f-4cd2-b4c4-d34b79637b5e} - C:\Windows\Resources\SetDriveStat.dll [07/10/2008 10:41 AM 22566]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\Windows\system32\vtUkjIAP

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- Hosts -----------------------------------------------------------------------

127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com

8784 more entries in hosts file.


-- End of Deckard's System Scanner: finished at 2008-07-18 11:37:03 ------------















Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft® Windows Vista™ Home Premium (build 6001) SP 1.0
Architecture: X86; Language: English

CPU 0: Intel® Core™2 Duo CPU E4500 @ 2.20GHz
Percentage of Memory in Use: 45%
Physical Memory (total/avail): 2045.45 MiB / 1109.83 MiB
Pagefile Memory (total/avail): 4328.19 MiB / 3082.4 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1882.49 MiB

C: is Fixed (NTFS) - 288.04 GiB total, 144.53 GiB free.
D: is Fixed (NTFS) - 10 GiB total, 6.23 GiB free.
E: is CDROM (No Media)
F: is CDROM (CDFS)

\\.\PHYSICALDRIVE0 - ST3320620AS ATA Device - 298.09 GiB - 3 partitions
\PARTITION0 - Unknown - 47.03 MiB
\PARTITION1 - Installable File System - 10 GiB - D:
\PARTITION2 (bootable) - Installable File System - 288.04 GiB - C:



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is disabled.

FW: Norton Internet Security v15.0.0.60 (Symantec Corporation)
AV: Norton Internet Security v15.0.0.60 (Symantec Corporation)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation) Disabled
AS: Norton Internet Security v15.0.0.60 (Symantec Corporation)

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Hunter\AppData\Roaming
CLASSPATH=.;C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=HUNTER-PC
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Hunter
LOCALAPPDATA=C:\Users\Hunter\AppData\Local
LOGONSERVER=\\HUNTER-PC
MOZ_CRASHREPORTER_DATA_DIRECTORY=C:\Users\Hunter\AppData\Roaming\Mozilla\Firefox\Crash Reports
MOZ_CRASHREPORTER_RESTART_ARG_0=C:\Program Files\Mozilla Firefox\firefox.exe
MOZ_CRASHREPORTER_STRINGS_OVERRIDE=C:\Program Files\Mozilla Firefox\crashreporter-override.ini
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\;C:\PROGRA~1\Google\GOOGLE~2;C:\PROGRA~1\Google\GOOGLE~2;C:\PROGRA~1\Google\GOOGLE~2
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 13, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f0d
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
RoxioCentral=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
SESSIONNAME=Console
sourcesdk=c:\program files\steam\steamapps\kriegster108\sourcesdk
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Hunter\AppData\Local\Temp
TMP=C:\Users\Hunter\AppData\Local\Temp
USERDOMAIN=Hunter-PC
USERNAME=Hunter
USERPROFILE=C:\Users\Hunter
VProject=c:\program files\steam\steamapps\kriegster108\counter-strike source\cstrike
windir=C:\Windows
__APPCOMPAT_MANIFEST=
__COMPAT_LAYER=VistaSetUp


-- User Profiles ---------------------------------------------------------------

Hunter (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
--> MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
µTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALL
Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player 9 ActiveX --> C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX --> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin --> C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 7.0.8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
AIM 6 --> C:\Program Files\AIM6\uninst.exe
AOL Install --> MsiExec.exe /I{2357B8BC-88C9-4A72-818C-050CC4EB0778}
AppCore --> MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B}
Apple Mobile Device Support --> MsiExec.exe /I{35B91753-5789-4517-9CF1-2CCE3A8CF4F1}
Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
Audiosurf --> "C:\Program Files\Steam\steam.exe" steam://uninstall/12900
Auto Gordian Knot 2.45 --> C:\Program Files\AutoGK\uninst.exe
AutoHotkey 1.0.47.06 --> C:\Program Files\AutoHotkey\uninst.exe
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
Call of Duty® 4 - Modern Warfare™ --> "C:\Program Files\InstallShield Installation Information\{F82C1FF3-4B7A-49B2-ACF7-5AE402C4C0CB}\setup.exe" -runfromtemp -l0x0409 -removeonly
Call of Duty® 4 - Modern Warfare™ --> MsiExec.exe /X{F82C1FF3-4B7A-49B2-ACF7-5AE402C4C0CB}
ccCommon --> MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118}
CDDRV_Installer --> MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
Component Framework --> MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09}
Counter-Strike --> "C:\Program Files\Steam\steam.exe" steam://uninstall/10
Counter-Strike: Source --> "C:\Program Files\Steam\steam.exe" steam://uninstall/240
dBpowerAMP Music Converter --> "C:\Windows\system32\SpoonUninstall.exe" <uninstall>C:\Windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
Dell DataSafe Online --> MsiExec.exe /I{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}
Dell Support Center --> MsiExec.exe /I{B8C54AB1-7E1A-40E8-B794-EDB6E8921F3A}
Dell System Customization Wizard --> MsiExec.exe /I{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}
DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
Download Manager 2.3.6 --> C:\Program Files\Download Manager\uninst.exe
DVD Decrypter (Remove Only) --> "C:\Program Files\DVD Decrypter\uninstall.exe"
EA Download Manager --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{EF7E931D-DC84-471B-8DB6-A83358095474} /l1033
EarthLink Setup Files --> MsiExec.exe /X{5E68BB65-4059-4FE5-AAC4-0CD1D79BBDE2}
FileZilla Client 3.0.11 --> C:\Program Files\FileZilla FTP Client\uninstall.exe
Fraps (remove only) --> "C:\Fraps\uninstall.exe"
Games, Music, & Photos Launcher --> MsiExec.exe /I{3E25E350-949F-4DB7-8288-2A60E018B4C1}
Garry's Mod --> "C:\Program Files\Steam\steam.exe" steam://uninstall/4000
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
Grand Theft Auto Vice City --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4B35F00C-E63D-40DC-9839-DF15A33EAC46}\setup.exe" -l0x9
Guild Wars --> "C:\Program Files\Guild Wars\Gw.exe" -uninstall
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HLSW v1.2.1.2 --> "C:\Program Files\HLSW\unins000.exe"
iDump (Backing up your iPod) --> C:\Program Files\iDump\uninstall.exe
ijji --> C:\ijji\ENGLISH\ijjiUninstall.exe
ijji - Gunz --> C:\ijji\ENGLISH\Gunz\Uninstall.exe
ijji Auto Installer --> "C:\Program Files\InstallShield Installation Information\{1DCC7418-2089-4BDD-B321-3771956160FC}\setup.exe" -runfromtemp -l0x0009 -removeonly
Intel® PRO Network Connections 12.1.11.0 --> MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
Intel® PRO Network Connections 12.1.11.0 --> MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
Internet Service Offers Launcher --> MsiExec.exe /I{CCFF1E13-77A2-4032-8B12-7566982A27DF}
iTunes --> MsiExec.exe /I{EF6C4600-306D-4F6A-A119-C2A877D25B4A}
Java™ SE Runtime Environment 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
KhalInstallWrapper --> MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
LimeWire PRO 4.18.2 --> "C:\Program Files\LimeWire\uninstall.exe"
LiveUpdate (Symantec Corporation) --> MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\ProgramData\LuUninstall.LiveUpdate"
LiveUpdate (Symantec Corporation) --> MsiExec.exe /X{E80F62FF-5D3C-4A19-8409-9721F2928206}
Logitech GamePanel Software 2.02 --> MsiExec.exe /X{0523EAF4-402C-4435-A0DA-13C40193D811}
Logitech SetPoint --> C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x0009 -removeonly
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works --> MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
Mozilla Firefox (3.0.1) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833) --> MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
Norton AntiVirus --> MsiExec.exe /X{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}
Norton AntiVirus Help --> MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
Norton Confidential Core --> MsiExec.exe /I{55A6283C-638A-4EE0-B491-51118554BDA2}
Norton Internet Security --> MsiExec.exe /I{3672B097-EA69-4BFE-B92F-29AE6D9D2B34}
Norton Internet Security --> MsiExec.exe /I{C1C185CA-C531-49F5-A6FA-B838405A049D}
Norton Internet Security (Symantec Corporation) --> "C:\Program Files\Common Files\Symantec Shared\SymSetup\{C1C185CA-C531-49F5-A6FA-B838405A049D}_15_0_0_60\Setup.exe" /X
Norton Protection Center --> MsiExec.exe /I{62120008-8E1E-4807-860D-A8B48F8552DB}
NVIDIA Drivers --> C:\Windows\system32\NVUNINST.EXE UninstallGUI
Obsidium 1.3 --> C:\Program Files\Obsidium Software Protection System\Uninstall.exe
PeerGuardian 2.0 --> "C:\Program Files\PeerGuardian2\unins000.exe"
Portal --> "C:\Program Files\Steam\steam.exe" steam://uninstall/400
PowerISO --> "C:\Program Files\PowerISO\uninstall.exe"
Product Documentation Launcher --> MsiExec.exe /I{89CEAE14-DD0F-448E-9554-15781EC9DB24}
QuickTime --> MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
Realtek High Definition Audio Driver --> RtlUpd.exe -r -m
Roxio Creator Audio --> MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
Roxio Creator BDAV Plugin --> MsiExec.exe /I{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}
Roxio Creator Copy --> MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
Roxio Creator Data --> MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
Roxio Creator DE --> MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Tools --> MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
Roxio Express Labeler --> MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio MyDVD DE --> MsiExec.exe /I{D639085F-4B6E-4105-9F37-A0DBB023E2FB}
Roxio Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
SecondLife (remove only) --> "C:\Program Files\SecondLife\uninst.exe" /P="SecondLife"
Skype™ 3.8 --> MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Sonic Activation Module --> MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
Source SDK Base --> "C:\Program Files\Steam\steam.exe" steam://uninstall/215
SPBBC 32bit --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
SPORE™ Creature Creator --> "C:\Program Files\InstallShield Installation Information\{8CC42289-E228-4A35-B8A9-015242283BB2}\SCCSetup.exe" -runfromtemp -l0x0009 -removeonly
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steam --> MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Team Fortress 2 --> "C:\Program Files\Steam\steam.exe" steam://uninstall/440
The Sims 2 --> C:\Program Files\EA GAMES\The Sims 2\EAUninstall.exe
The Sims 2 University --> C:\Program Files\EA GAMES\The Sims 2 University\EAUninstall.exe
URL Assistant --> regsvr32 /u /s "C:\Program Files\BAE\BAE.dll"
User's Guides --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.exe"
Ventrilo Client --> MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Videora iPhone Converter 3.08 --> C:\Program Files\Red Kawa\Video Converter 3\uninstaller.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u
VobSub v2.23 (Remove Only) --> "C:\Program Files\Gabest\VobSub\uninstall.exe"
Windows Media Player Firefox Plugin --> MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
WinSCP 4.1.4 beta --> "C:\Program Files\WinSCP\unins000.exe"
Xfire (remove only) --> "C:\Program Files\Xfire\uninst.exe"
Xilisoft DVD Creator --> C:\Program Files\Xilisoft\DVD Creator3\Uninstall.exe
Xvid 1.1.3 final uninstall --> "C:\Program Files\Xvid\unins000.exe"
XviD MPEG4 Video Codec (remove only) --> "C:\Windows\system32\xvid-uninstall.exe"


-- Application Event Log -------------------------------------------------------

Event Record #/Type6002 / Error
Event Submitted/Written: 07/18/2008 11:09:02 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application Explorer.EXE, version 6.0.6001.18000, time stamp 0x47918e5d, faulting module ntdll.dll, version 6.0.6001.18000, time stamp 0x4791a7a6, exception code 0xc0000374, fault offset 0x000b015d,
process id 0xccc, application start time 0xExplorer.EXE0.

Event Record #/Type5996 / Error
Event Submitted/Written: 07/18/2008 09:55:41 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application Explorer.EXE, version 6.0.6001.18000, time stamp 0x47918e5d, faulting module oqlaqpeu.dll, version 0.0.0.0, time stamp 0x486b4ed7, exception code 0xc0000005, fault offset 0x000013ac,
process id 0xccc, application start time 0xExplorer.EXE0.

Event Record #/Type5988 / Error
Event Submitted/Written: 07/18/2008 09:30:50 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application rundll32.exe, version 6.0.6000.16386, time stamp 0x4549b0e1, faulting module kernel32.dll, version 6.0.6001.18000, time stamp 0x4791a76d, exception code 0xe06d7363, fault offset 0x000442eb,
process id 0x1360, application start time 0xrundll32.exe0.

Event Record #/Type5969 / Success
Event Submitted/Written: 07/18/2008 09:24:53 AM
Event ID/Source: 5617 / WinMgmt
Event Description:


Event Record #/Type5968 / Success
Event Submitted/Written: 07/18/2008 09:24:52 AM
Event ID/Source: 5615 / WinMgmt
Event Description:




-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type23222 / Error
Event Submitted/Written: 07/18/2008 09:33:28 AM
Event ID/Source: 10010 / DCOM
Event Description:
{0002DF01-0000-0000-C000-000000000046}

Event Record #/Type23131 / Error
Event Submitted/Written: 07/18/2008 09:24:42 AM
Event ID/Source: 15016 / HTTP
Event Description:
\Device\Http\ReqQueueKerberos

Event Record #/Type23092 / Warning
Event Submitted/Written: 07/18/2008 09:18:12 AM
Event ID/Source: 8005 / bowser
Event Description:
The browser has received a server announcement indicating that the computer HUNTER-PC
is a master browser, but this computer is not a master browser.

Event Record #/Type23091 / Error
Event Submitted/Written: 07/18/2008 09:18:12 AM
Event ID/Source: 8003 / bowser
Event Description:
The master browser has received a server announcement from the computer D81KTJ71
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{CD183CC7-6475-43EF-A5AB-D848E95FC.
The master browser is stopping or an election is being forced.

Event Record #/Type23085 / Error
Event Submitted/Written: 07/18/2008 08:43:18 AM
Event ID/Source: 7000 / Service Control Manager
Event Description:
Steam Client Service%%1053



-- End of Deckard's System Scanner: finished at 2008-07-18 11:37:03 ------------
  • 0

#4
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please visit this web page for instructions for downloading and running Combofix >ComboFix Instructions
We now suggest that you install the Windows Recovery Console.
The Windows recovery console will allow you to boot up into a special recovery mode that allows us to help you in the case that your computer has a problem after an attempted removal of malware.

Post the log from ComboFix when you've accomplished all of that, along with a new HijackThis log.
  • 0

#5
Kriegster

Kriegster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
yay! it found all the randomly generated dll files ive tried to remove!! thanks alot!! i hope is completely gone now.

Also by the wayy.... couple days ago when i turned on my computer,it seemed that the virus wasnt running on my system when i did the hijackthis scan (the DLLs didnt show up.) but i had to get on internet explorer (i use firefox) to use FTP when i noticed it had begun to run again in my processes. i redid the scan just right after that and the Vundo DLLs popped back up in the log. just to let you know if this might help if there might still be a problem.



ComboFix LOG:


ComboFix 08-07-17.4 - Hunter 2008-07-18 18:45:35.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.925 [GMT -5:00]
Running from: C:\Users\Hunter\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Users\Hunter\AppData\Local\Microsoft\Windows\Temporary Internet Files\ijjistarter_verinfo.dat
C:\Users\Hunter\AppData\Local\Microsoft\Windows\Temporary Internet Files\ijjistarter2.exe
C:\Windows\system32\acyukbun.ini
C:\Windows\system32\awtqrrOH.dll
C:\Windows\system32\ippfssty.ini
C:\Windows\system32\oqlaqpeu.dll
C:\Windows\System32\PAIjkUtv.ini
C:\Windows\System32\PAIjkUtv.ini2
C:\Windows\system32\qnusapdq.ini
C:\Windows\system32\rsmhdswq.dll
C:\Windows\system32\ssqNEuvw.dll
C:\Windows\system32\uepqalqo.ini
C:\Windows\system32\vtUkjIAP.dll
C:\Windows\system32\wsbeflvv.ini
C:\Windows\system32\wwrdcv.dll
C:\Windows\system32\yquvxmsr.ini

.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.

2008-07-18 11:34 . 2008-07-18 11:34 <DIR> d-------- C:\Deckard
2008-07-12 12:43 . 2008-07-12 12:43 <DIR> d-------- C:\VundoFix Backups
2008-07-11 21:51 . 2008-07-12 00:32 <DIR> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-07-11 21:51 . 2008-07-12 00:32 <DIR> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-07-11 21:51 . 2008-07-11 21:51 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-11 21:51 . 2008-07-11 21:51 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-11 21:24 . 2008-07-11 21:24 109,500 --a------ C:\Windows\System32\hvlefnyw.exe
2008-07-11 19:42 . 2008-07-11 19:42 <DIR> d-------- C:\Program Files\Red Kawa
2008-07-11 12:58 . 2008-07-11 12:59 <DIR> d-------- C:\Program Files\iTunes
2008-07-11 12:58 . 2008-07-11 12:58 <DIR> d-------- C:\Program Files\iPod
2008-07-11 12:56 . 2008-07-11 12:56 <DIR> d-------- C:\Program Files\Apple Software Update
2008-07-10 23:20 . 2008-07-10 23:29 <DIR> d-------- C:\Users\Hunter\AppData\Roaming\FileZilla
2008-07-10 23:19 . 2008-07-10 23:19 <DIR> d-------- C:\Program Files\FileZilla FTP Client
2008-07-10 20:41 . 2008-07-10 20:44 <DIR> d-------- C:\Users\All Users\Lavasoft
2008-07-10 20:41 . 2008-07-10 20:44 <DIR> d-------- C:\ProgramData\Lavasoft
2008-07-10 20:41 . 2008-07-10 20:41 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-10 15:50 . 2008-07-10 15:50 0 --a------ C:\Windows\nsreg.dat
2008-07-10 10:42 . 2008-07-10 10:42 0 --a------ C:\z3g45.bat
2008-07-10 09:35 . 2008-07-10 09:35 32,000 --a------ C:\Windows\System32\drivers\usbaapl.sys
2008-07-09 22:13 . 2008-07-10 23:05 <DIR> d-------- C:\Fraps
2008-07-09 21:53 . 2008-07-09 21:53 <DIR> d-------- C:\Windows\WinAVI Video Converter 9.0
2008-07-07 23:40 . 2008-07-10 23:05 <DIR> d-a------ C:\Users\All Users\TEMP
2008-07-07 23:40 . 2008-07-10 23:05 <DIR> d-a------ C:\ProgramData\TEMP
2008-07-07 23:40 . 2008-07-07 23:43 <DIR> d-------- C:\Program Files\Skype Recorder
2008-07-07 16:57 . 2008-07-07 16:57 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-07-03 23:36 . 2008-07-03 23:36 <DIR> d-------- C:\Users\All Users\Media Center Programs
2008-07-03 23:36 . 2008-07-03 23:36 <DIR> d-------- C:\ProgramData\Media Center Programs
2008-07-03 23:36 . 2008-07-03 23:36 <DIR> d-------- C:\Program Files\Guild Wars
2008-07-03 19:45 . 2008-07-03 19:45 <DIR> d-------- C:\Program Files\AutoHotkey
2008-07-03 17:02 . 2008-07-03 17:03 269,220,493 --a------ C:\Windows\MEMORY.DMP
2008-07-03 14:50 . 2008-07-03 14:50 <DIR> d-------- C:\Program Files\WinSCP
2008-06-30 21:06 . 2008-06-30 21:06 <DIR> d-------- C:\Program Files\QAvimator
2008-06-29 12:10 . 2008-06-29 12:10 <DIR> d-------- C:\Program Files\Obsidium Software Protection System
2008-06-28 23:52 . 2008-06-28 23:52 <DIR> d-------- C:\Users\Hunter\AppData\Roaming\SecondLife
2008-06-28 23:51 . 2008-06-28 23:53 <DIR> d-------- C:\Program Files\SecondLife
2008-06-27 15:13 . 2008-06-27 15:13 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-06-27 15:13 . 2003-07-17 13:17 5,174 --a------ C:\Windows\System32\nppt9x.vxd
2008-06-27 15:13 . 2005-01-01 04:43 4,682 --a------ C:\Windows\System32\npptNT2.sys
2008-06-26 21:36 . 2008-07-03 18:53 52 --a------ C:\Windows\GunzLauncher.INI
2008-06-26 21:34 . 2008-06-26 21:34 <DIR> d-------- C:\Program Files\MAIET
2008-06-26 21:32 . 2008-06-27 15:04 <DIR> d--h----- C:\Users\Hunter\AppData\Roaming\ijjigame
2008-06-26 21:32 . 2008-06-26 21:32 <DIR> d-------- C:\ijji
2008-06-26 21:30 . 2008-06-26 21:30 <DIR> d-------- C:\Program Files\NHN USA
2008-06-26 21:30 . 2008-06-17 19:28 710,064 --a------ C:\Windows\System32\ijjiSetup.exe
2008-06-26 21:30 . 2008-06-11 23:01 58,800 --a------ C:\Windows\System32\ijjiPlugin2.dll
2008-06-26 15:10 . 2008-06-26 15:10 42,320 --a------ C:\Windows\System32\xfcodec.dll
2008-06-25 17:26 . 2008-07-10 21:52 <DIR> d-------- C:\Program Files\Xilisoft
2008-06-25 10:57 . 2008-07-10 16:39 136,888 --a------ C:\Windows\System32\drivers\PnkBstrK.sys
2008-06-25 10:57 . 2008-07-10 16:39 111,928 --a------ C:\Windows\System32\PnkBstrB.exe
2008-06-25 10:57 . 2008-06-25 11:02 66,872 --a------ C:\Windows\System32\PnkBstrA.exe
2008-06-25 10:57 . 2008-06-25 10:57 22,328 --a------ C:\Users\Hunter\AppData\Roaming\PnkBstrK.sys
2008-06-25 10:57 . 2008-06-25 10:57 321 --a------ C:\Windows\game.ini
2008-06-25 10:36 . 2008-06-25 10:36 <DIR> d-------- C:\Program Files\Activision
2008-06-24 17:17 . 2008-06-24 17:17 <DIR> d-------- C:\Users\All Users\Electronic Arts
2008-06-24 17:17 . 2008-06-24 17:17 <DIR> d-------- C:\ProgramData\Electronic Arts
2008-06-24 17:16 . 2008-06-24 17:16 <DIR> dr------- C:\Windows\System32\config\systemprofile\Videos
2008-06-24 17:16 . 2008-06-24 17:16 <DIR> dr------- C:\Windows\System32\config\systemprofile\Searches
2008-06-24 17:16 . 2008-06-24 17:16 <DIR> dr------- C:\Windows\System32\config\systemprofile\Saved Games
2008-06-24 17:16 . 2008-06-24 17:16 <DIR> dr------- C:\Windows\System32\config\systemprofile\Pictures
2008-06-24 17:16 . 2008-06-24 17:16 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-06-24 17:16 . 2008-06-24 17:16 <DIR> dr------- C:\Windows\System32\config\systemprofile\Links
2008-06-24 17:16 . 2008-06-24 17:16 <DIR> dr------- C:\Windows\System32\config\systemprofile\Downloads
2008-06-24 17:16 . 2008-06-24 17:16 <DIR> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-06-24 17:16 . 2008-06-24 17:16 2,534 --a------ C:\Windows\System32\ealregsnapshot1.reg
2008-06-24 16:56 . 2008-06-24 16:56 <DIR> d-------- C:\Windows\.jagex_cache_32
2008-06-24 16:55 . 2008-06-24 16:55 <DIR> d-------- C:\Windows\Sun
2008-06-23 13:10 . 2008-06-23 13:10 <DIR> d-------- C:\Program Files\Rockstar Games
2008-06-22 10:37 . 2008-06-22 18:58 <DIR> d-------- C:\Program Files\EA GAMES
2008-06-22 10:37 . 2004-08-18 03:34 442,368 -ra------ C:\Windows\System32\vp6vfw.dll
2008-06-20 16:46 . 2008-06-27 15:41 <DIR> d-------- C:\Users\Hunter\AppData\Roaming\SPORE Creature Creator
2008-06-20 16:46 . 2008-06-20 16:46 107,888 --a------ C:\Windows\System32\CmdLineExt.dll
2008-06-20 16:42 . 2008-06-24 17:17 <DIR> d-------- C:\Program Files\Electronic Arts
2008-06-20 16:36 . 2008-06-20 16:36 <DIR> d-------- C:\Program Files\PowerISO
2008-06-20 15:49 . 2008-06-28 20:57 <DIR> d-------- C:\Users\Hunter\AppData\Roaming\IGN_DLM
2008-06-20 15:49 . 2008-06-20 15:49 <DIR> d-------- C:\Program Files\Download Manager
2008-06-20 15:21 . 2008-07-10 16:41 <DIR> d-------- C:\Users\Hunter\AppData\Roaming\Xfire
2008-06-20 15:21 . 2008-07-10 15:14 <DIR> d-------- C:\Users\All Users\Xfire
2008-06-20 15:21 . 2008-07-10 15:14 <DIR> d-------- C:\ProgramData\Xfire
2008-06-20 15:21 . 2008-07-01 10:49 <DIR> d-------- C:\Program Files\Xfire
2008-06-20 14:07 . 2008-06-20 14:07 <DIR> d-------- C:\Program Files\Illustrate
2008-06-20 14:07 . 2008-06-20 14:07 131,072 --a------ C:\Windows\System32\SpoonUninstall.exe
2008-06-20 14:07 . 2008-06-20 14:07 36,104 --a------ C:\Windows\System32\SpoonUninstall-dBpowerAMP Music Converter.dat
2008-06-20 14:07 . 2008-06-20 14:07 33,846 --a------ C:\Windows\System32\SpoonUninstall-dBpowerAMP Music Converter.bmp
2008-06-19 22:47 . 2008-06-20 11:18 <DIR> d-------- C:\HammerAutosave
2008-06-18 20:47 . 2008-07-07 16:50 <DIR> d-------- C:\I_ROBOT_16X9
2008-06-18 13:43 . 2008-06-18 13:43 <DIR> d-------- C:\Program Files\PeerGuardian2
2008-06-18 11:30 . 2008-06-18 11:30 <DIR> d-------- C:\Users\Hunter\AppData\Roaming\acccore
2008-06-18 11:27 . 2008-06-18 11:27 <DIR> d-------- C:\Users\All Users\Viewpoint
2008-06-18 11:27 . 2008-06-18 11:31 <DIR> d-------- C:\Users\All Users\AOL OCP
2008-06-18 11:27 . 2008-06-18 11:27 <DIR> d-------- C:\Users\All Users\AOL
2008-06-18 11:27 . 2008-06-18 11:27 <DIR> d-------- C:\Users\All Users\acccore
2008-06-18 11:27 . 2008-06-18 11:27 <DIR> d-------- C:\ProgramData\Viewpoint
2008-06-18 11:27 . 2008-06-18 11:31 <DIR> d-------- C:\ProgramData\AOL OCP
2008-06-18 11:27 . 2008-06-18 11:27 <DIR> d-------- C:\ProgramData\AOL
2008-06-18 11:27 . 2008-06-18 11:27 <DIR> d-------- C:\ProgramData\acccore
2008-06-18 11:27 . 2008-06-18 11:27 <DIR> d-------- C:\Program Files\Viewpoint
2008-06-18 11:27 . 2008-06-18 11:27 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-06-18 11:26 . 2008-06-18 11:30 <DIR> d-------- C:\Program Files\AIM6
2008-06-18 11:26 . 2008-06-18 11:30 366 --ah----- C:\IPH.PH

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 21:12 --------- d-----w C:\Program Files\Steam
2008-07-18 20:41 --------- d-----w C:\ProgramData\Symantec
2008-07-18 14:26 --------- d-----w C:\Program Files\Common Files\Steam
2008-07-12 02:54 --------- d-----w C:\Users\Hunter\AppData\Roaming\uTorrent
2008-07-11 17:04 --------- d-----w C:\Users\Hunter\AppData\Roaming\Apple Computer
2008-07-11 01:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-10 20:41 --------- d-----w C:\Users\Hunter\AppData\Roaming\LimeWire
2008-07-10 16:20 --------- d-----w C:\Users\Hunter\AppData\Roaming\HLSW
2008-07-08 05:29 --------- d-----w C:\Users\Hunter\AppData\Roaming\Skype
2008-07-08 05:04 --------- d-----w C:\Users\Hunter\AppData\Roaming\skypePM
2008-06-27 02:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-21 01:04 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-18 16:10 --------- d-----w C:\Users\Hunter\AppData\Roaming\Ventrilo
2008-06-18 01:17 --------- d-----w C:\Program Files\LimeWire
2008-06-17 19:40 --------- d-----w C:\Program Files\BitComet
2008-06-17 15:57 --------- d-----w C:\Program Files\Gabest
2008-06-17 15:57 --------- d-----w C:\Program Files\AviSynth 2.5
2008-06-17 15:57 --------- d-----w C:\Program Files\AutoGK
2008-06-17 15:39 --------- d-----w C:\Program Files\DVD Decrypter
2008-06-17 05:13 --------- d-----w C:\ProgramData\Skype
2008-06-17 05:13 --------- d-----w C:\Program Files\Skype
2008-06-17 05:13 --------- d-----w C:\Program Files\Common Files\Skype
2008-06-15 06:47 891,448 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-06-15 04:29 --------- d-s---w C:\Program Files\HLSW
2008-06-15 04:11 --------- d-----w C:\ProgramData\Apple Computer
2008-06-15 04:10 --------- d-----w C:\Program Files\QuickTime
2008-06-15 04:10 --------- d-----w C:\Program Files\Bonjour
2008-06-15 04:07 --------- d-----w C:\ProgramData\Apple
2008-06-15 04:07 --------- d-----w C:\Program Files\Common Files\Apple
2008-06-15 04:04 --------- d-----w C:\Program Files\iDump
2008-06-15 04:02 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-06-15 03:28 --------- d-----w C:\Program Files\Xvid
2008-06-15 03:26 --------- d-----w C:\Users\Hunter\AppData\Roaming\DivX
2008-06-14 23:32 --------- d-----w C:\Program Files\DivX
2008-06-14 22:05 174 --sha-w C:\Program Files\desktop.ini
2008-06-14 21:57 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-14 21:57 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-06-14 21:57 --------- d-----w C:\Program Files\Windows Mail
2008-06-14 21:57 --------- d-----w C:\Program Files\Windows Journal
2008-06-14 21:57 --------- d-----w C:\Program Files\Windows Defender
2008-06-14 21:57 --------- d-----w C:\Program Files\Windows Collaboration
2008-06-14 21:57 --------- d-----w C:\Program Files\Windows Calendar
2008-06-14 21:13 --------- d-----w C:\Program Files\Norton Internet Security
2008-06-14 21:08 --------- d-----w C:\Program Files\Logitech
2008-06-14 21:04 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2008-06-14 21:04 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2008-06-14 21:04 10,671 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2008-06-14 21:04 --------- d-----w C:\Program Files\Symantec
2008-06-14 21:03 --------- d-----w C:\ProgramData\LogiShrd
2008-06-14 21:02 --------- d-----w C:\Users\Hunter\AppData\Roaming\Logitech
2008-06-14 21:01 0 ---ha-w C:\Windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-06-14 20:59 --------- d-----w C:\Program Files\Common Files\Logishrd
2008-06-14 20:58 --------- d-----w C:\Users\Hunter\AppData\Roaming\InstallShield
2008-06-14 20:58 --------- d-----w C:\ProgramData\Logitech
2008-06-14 20:52 --------- d-----w C:\Users\Hunter\AppData\Roaming\Symantec
2008-06-14 19:50 --------- d-----w C:\Program Files\Ventrilo
2008-06-14 19:41 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-06-14 19:40 540,672 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-06-14 19:40 458,752 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-06-14 19:40 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-06-14 19:40 2,153,984 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-06-14 19:40 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-06-14 19:40 --------- d-----w C:\Program Files\uTorrent
2008-06-14 19:26 --------- d-----w C:\ProgramData\NVIDIA
2008-06-14 19:15 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-06-14 19:08 --------- d--h--w C:\Users\Hunter\AppData\Roaming\GTek
2008-06-14 18:58 --------- d-sh--w C:\ProgramData\Templates
2008-06-14 18:58 --------- d-sh--w C:\ProgramData\Start Menu
2008-06-14 18:58 --------- d-sh--w C:\ProgramData\Favorites
2008-06-14 18:58 --------- d-sh--w C:\ProgramData\Documents
2008-06-14 18:58 --------- d-sh--w C:\ProgramData\Desktop
2008-06-14 18:58 --------- d-sh--w C:\ProgramData\Application Data
2008-06-13 19:14 24,112 ----a-w C:\Windows\system32\drivers\SymIMV.sys
2008-06-13 19:14 13,093 ----a-w C:\Windows\system32\drivers\SymRedir.cat
2008-06-13 19:14 1,611 ----a-w C:\Windows\system32\drivers\SymRedir.inf
2008-06-13 19:13 96,432 ----a-w C:\Windows\system32\drivers\symfw.sys
2008-06-13 19:13 41,008 ----a-w C:\Windows\system32\drivers\symndisv.sys
2008-06-13 19:13 38,576 ----a-w C:\Windows\system32\drivers\symids.sys
2008-06-13 19:13 22,320 ----a-w C:\Windows\system32\drivers\symredrv.sys
2008-06-13 19:13 184,240 ----a-w C:\Windows\system32\drivers\symtdi.sys
2008-06-13 19:13 13,616 ----a-w C:\Windows\system32\drivers\symdns.sys
2008-06-12 06:28 56,108 ----a-w C:\Windows\system32\drivers\scdemu.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 02:33 125952]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 16:57 1103480]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 02:33 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 11:01 51048]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-06-14 15:58:50 805392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SetDriveStat"= {71660196-855f-4cd2-b4c4-d34b79637b5e} - C:\Windows\Resources\SetDriveStat.dll [2008-07-10 10:41 22566]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{B7831B47-19CA-448B-B849-E70182D9DADE}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{4006565D-6FA8-40A2-9AA1-8BB53D884C7A}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{7A0AE662-94E2-4B3D-B2A6-3F9232D4CD2D}C:\\program files\\steam\\steamapps\\kriegster108\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\kriegster108\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{5E4084BE-ECE1-41D5-9E7A-1472B7335E49}C:\\program files\\steam\\steamapps\\kriegster108\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\kriegster108\counter-strike\hl.exe:Half-Life Launcher
"{414971E8-10F7-4CDA-AD75-E9C2107212BE}"= UDP:23555:BitComet 23555 TCP
"{87F9AA45-5928-415D-96F5-BF27A9C8EAC1}"= TCP:23555:BitComet 23555 UDP
"{39722BFD-0657-461B-8D65-871B6F173B2A}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{E7208BA8-5A9A-4207-9129-5D403FF14C68}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{26D4D422-C561-4DAF-91C9-C84663DB8C49}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{CFD21904-B77A-4699-9776-6F8287BAA921}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{95ED392C-4E86-425A-8189-A3DE51584598}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{BECC518B-3135-49C7-82B3-A4B2C7F964B7}"= UDP:C:\Program Files\AIM6\aim6.exe:AIM
"{E45C7C0A-1068-445C-8D40-6463C71DC3C6}"= TCP:C:\Program Files\AIM6\aim6.exe:AIM
"{87C46062-1293-45F2-8726-B6DBD9F5CDC6}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{CDA34645-1317-42AC-8F26-050C802AFAEB}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{F767DCD3-A61D-4E0A-A4E0-6C19C603B4EF}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{A26FDE2F-BCFE-4831-B3E4-78DF0D536127}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{B88F11AD-309D-4921-A2B2-1D2F4C1569FC}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{9E520922-4757-45BD-B8A0-2102270B9B4A}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{39383272-43C2-416C-804E-8DF20E3707FD}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{64662540-C851-4D2D-83A1-41BD811CEEEF}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080718.003\IDSvix86.sys [2008-03-20 15:37]
R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-14 11:02]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-06-13 14:13]
S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-07-18 08:43]

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-07-08 01:28:22 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Hunter.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Aim6 - (no file)
HKLM-Run-82a83da7 - C:\Windows\system32\oqlaqpeu.dll
ShellExecuteHooks-{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286} - C:\Windows\system32\ssqNEuvw.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-18 18:51:56
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\Program Files\Common Files\Symantec Shared\SPBBC\2008-07-18-4bca.kc 295448 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\nvvsvc.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\PnkBstrA.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Completion time: 2008-07-18 18:58:40 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-18 23:58:22

Pre-Run: 151,844,974,592 bytes free
Post-Run: 151,988,867,072 bytes free

326 --- E O F --- 2008-06-25 21:01:11




HIJACKTHISLOG:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:01:48 PM, on 7/18/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplane...C_2.3.6.108.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O21 - SSODL: SetDriveStat - {71660196-855f-4cd2-b4c4-d34b79637b5e} - C:\Windows\Resources\SetDriveStat.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 7206 bytes

Edited by Kriegster, 18 July 2008 - 06:09 PM.

  • 0

#6
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please submit the following file to one of these online file scanners.
(All you have to do is copy and paste it in )

C:\Windows\Resources\SetDriveStat.dll

Jotti File Scan
VirusTotal File Scan

This will produce a report after the scan is complete, please copy and paste those results in your next post.
  • 0

#7
Kriegster

Kriegster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
ah niceee:

virusscan.jotti.org
File: SetDriveStat.dll
Status:
INFECTED/MALWARE
MD5: c517cc6d3372339fffbb8de1aa736393
Packers detected:
-
Scanner results
Scan taken on 19 Jul 2008 01:20:31 (GMT)
A-Squared
Found nothing
AntiVir
Found TR/Click.Small.ZJ
ArcaVir
Found nothing
Avast
Found Win32:Trojan-gen {Other}
AVG Antivirus
Found Clicker.OND
BitDefender
Found BehavesLike:Trojan.ShellObject (probable variant)
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found W32/Trojan2.AUDB
F-Secure Anti-Virus
Found Trojan-Clicker.Win32.Small.zj
Fortinet
Found nothing
Ikarus
Found Trojan-Clicker.Win32.Zirit.Y
Kaspersky Anti-Virus
Found Trojan-Clicker.Win32.Small.zj
NOD32
Found nothing
Norman Virus Control
Found W32/Smalltroj.FJBX
Panda Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
  • 0

#8
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\Windows\System32\hvlefnyw.exe
    C:\z3g45.bat
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SetDriveStat
    C:\Windows\Resources\SetDriveStat.dll
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • OTMoveit2 will create a log of moved files in the C:\_OTMoveIt\MovedFiles folder. The log's name will appear as the date and time it was created, with the format mmddyyyy_hhmmss.log. Open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
====================
Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley.
==============
Post those logs and a new dss log and let me know if all is normal again?
  • 0

#9
Kriegster

Kriegster

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
C:\Windows\System32\hvlefnyw.exe moved successfully.
C:\z3g45.bat moved successfully.
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SetDriveStat >
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SetDriveStat deleted successfully.
DllUnregisterServer procedure not found in C:\Windows\Resources\SetDriveStat.dll
C:\Windows\Resources\SetDriveStat.dll NOT unregistered.
C:\Windows\Resources\SetDriveStat.dll moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07182008_204739

Once it moved the files, the program crashed but it still has seemed to work.



Also the malware program i tried scanning with stops responding and i cant x out of it. I let it go for 5hrs and it still never responded so i gave up. There another program you can give me?

I can get a copy of spyware doctor and use that...?

Edited by Kriegster, 19 July 2008 - 12:22 PM.

  • 0

#10
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please download SUPERAntiSpyware Home Edition (free version).
–Install it and double-click the icon on your desktop to run it.
  • It will ask if you want to update the program definitions, click Yes.
  • Under Configuration and Preferences, click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked:
  • Close browsers before scanning
  • Scan for tracking cookies
  • Scan for Alternate Data streams
  • Terminate memory threats before quarantining.
  • Please leave the others unchecked.
  • Click the Close button to leave the control center screen.

b]Then run Superantispyware[/b].
  • Double click on the icon to start Superantispyware.
  • On the main screen, under Scan for Harmful Software click Scan your computer.
  • On the left check C:\Fixed Drive.
  • On the right, under Complete Scan, choose Perform Complete Scan.
  • Click Next to start the scan. Please be patient while it scans your computer.
  • After the scan is complete a summary box will appear. Click OK.
  • Make sure everything in the white box has a check next to it, then click Next.
  • It will quarantine what it found and if it asks if you want to reboot, click Yes.
1. To retrieve the removal information for me please do the following:
2. After reboot, double-click the SUPERAntispyware icon on your desktop.
3. Click Preferences. Click the Statistics/Logs tab.
4. Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
5. It will open in your default text editor (such as Notepad/Wordpad).
6. Please highlight everything in the notepad, then right-click and choose copy.
7. Click close and close again to exit the program.
Save the log information. If needed (still infected) paste this info along with your HijackThis log.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP