Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Please help with SpySheriff [RESOLVED]


  • This topic is locked This topic is locked

#1
strassle

strassle

    Member

  • Member
  • PipPip
  • 14 posts
This spysheriff is killing my computer. I delete it, and can't get it off permanently, it just keeps coming back. Please help, here is my Hijack this log. There is also a program called slotch bar I can't get off. Please help!!!


Logfile of HijackThis v1.99.1
Scan saved at 3:45:08 PM, on 6/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\windowsautomaticupdates.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DVD43\dvd43_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ProSiteFinder\prositefinder.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Creative\SB Wireless Music\Media Server\SBWMsvr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\temp\sahagent-cdt1004.exe
C:\Program Files\ProSiteFinder\prositefinderh.exe
C:\Program Files\ProSiteFinder\prositefinder.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\program files\internet explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.110\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {00000000-0000-4947-B331-0FD40965D7A7} - C:\Program Files\ProSiteFinder\ProSiteFinder.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DVD43] C:\Program Files\DVD43\dvd43_tray.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [3DNADesktop] "C:\Program Files\3DNA\Resources\3dnasys.exe" -open
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKLM\..\Run: [TKAy7M3eI] C:\WINDOWS\ryvsupel.exe
O4 - HKLM\..\Run: [Windows Shell] C:\WINDOWS\system32\shell32.exe
O4 - HKLM\..\Run: [I downloaded pirated Software I post my Hijack Log] C:\WINDOWS\system32\_.gof
O4 - HKLM\..\Run: [msxct] msxct.exe
O4 - HKLM\..\Run: [zqd] C:\WINDOWS\zqd.exe
O4 - HKLM\..\Run: [hYcFv1] C:\WINDOWS\sttnb.exe
O4 - HKLM\..\Run: [EcIVj7] C:\WINDOWS\dwdnqri.exe
O4 - HKLM\..\Run: [vwhef] C:\WINDOWS\vwhef.exe
O4 - HKLM\..\Run: [ProSiteFinder] C:\Program Files\ProSiteFinder\prositefinder.exe
O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\user\LOCALS~1\Temp\sahagent-cdt1004.exe run
O4 - HKLM\..\RunOnce: [XoftSpy] "C:\Program Files\XoftSpy\XoftSpy.exe" -b
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SB Wireless Music] C:\Program Files\Creative\SB Wireless Music\Media Server\SBWMsvr.exe startup
O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)
O23 - Service: Windows Automatic Updates - Stanford University - C:\WINDOWS\system32\windowsautomaticupdates.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
  • 0

Advertisements


#2
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Welcome to Geeks 2 Go. Sorry about the delay in getting to your post, we have been very busy.

Do you still require help or are your problems resolved.

Please let me know and if you still require assistance, please post a fresh HJT log.

Regards,

Usetobe
  • 0

#3
strassle

strassle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Yes, please, I do still require assisstance :tazz:

Thank you,
Ray
  • 0

#4
strassle

strassle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Logfile of HijackThis v1.99.1
Scan saved at 3:35:20 PM, on 6/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\windowsautomaticupdates.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DVD43\dvd43_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\DOCUME~1\user\LOCALS~1\Temp\sahagent-cdt1004.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Creative\SB Wireless Music\Media Server\SBWMsvr.exe
C:\program files\internet explorer\iexplore.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\180searchassistant\salm.exe
C:\Program Files\Adobe\Photoshop CS\Photoshop.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.156\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\program files\180searchassistant\salmhook.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DVD43] C:\Program Files\DVD43\dvd43_tray.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [3DNADesktop] "C:\Program Files\3DNA\Resources\3dnasys.exe" -open
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKLM\..\Run: [TKAy7M3eI] C:\WINDOWS\ryvsupel.exe
O4 - HKLM\..\Run: [Windows Shell] C:\WINDOWS\system32\shell32.exe
O4 - HKLM\..\Run: [I downloaded pirated Software I post my Hijack Log] C:\WINDOWS\system32\_.gof
O4 - HKLM\..\Run: [zqd] C:\WINDOWS\zqd.exe
O4 - HKLM\..\Run: [hYcFv1] C:\WINDOWS\sttnb.exe
O4 - HKLM\..\Run: [EcIVj7] C:\WINDOWS\dwdnqri.exe
O4 - HKLM\..\Run: [vwhef] C:\WINDOWS\vwhef.exe
O4 - HKLM\..\Run: [mnih] C:\WINDOWS\mnih.exe
O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\user\LOCALS~1\Temp\sahagent-cdt1004.exe run
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [salm] c:\program files\180searchassistant\salm.exe
O4 - HKLM\..\Run: [clatqrqx] C:\WINDOWS\clatqrqx.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SB Wireless Music] C:\Program Files\Creative\SB Wireless Music\Media Server\SBWMsvr.exe startup
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180search...com/180saax.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)
O23 - Service: Windows Automatic Updates - Stanford University - C:\WINDOWS\system32\windowsautomaticupdates.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
  • 0

#5
Guest_usetobe_*

Guest_usetobe_*
  • Guest
First, download and install CleanUp! but do not run it yet.
*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.

Download, install, and update Ewido Security Suite
  • Install ewido security suite
  • Launch ewido, there should be a big E icon on your desktop, double-click it.
  • The program will prompt you to update click the OK button
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
The update will start and a progress bar will show the updates being installed.
After the updates are installed, exit Ewido

Set up PC to show hidden files.(Click link if you do not know how)
Show hidden files

Reboot into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Once in Safe Mode, Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
  • Scan local drives for temporary files
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.

After Cleanup! is finished:
  • Run Ewido.
  • Click on scanner
  • Make sure the following boxes are checked before scanning:
    • Binder
    • Crypter
    • Archives
  • Click on Start Scan
  • Let the program scan the machine
While the scan is in progress you will be prompted to clean the first infected file it finds. Choose "clean", then put a check next to "Perform action on all infections" in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report
  • Save the report to your desktop
  • Exit Ewido
Reboot into normal mode.

Go to Start > Control Panel > Add or Remove Programs and remove the following:

SpySheriff
Spyware Cleaner
<<---Rogue software.

Exit Add or Remove Programs.

Using windows explorer, Delete the following, in bold, if found:

C:\Documents and Settings\user account\Start Menu\Programs\SpySheriff <-whole folder
C:\Documents and Settings\user account\Application Data\Install.dat
C:\Program Files\SpySheriff <-whole folder
C:\Windows\Desktop.html
C:\winstall.exe

*NOTE* user account is not the actual name of that folder. The name of that folder will be the name of your computer profile.

Make sure you are disconnected from the Internet and that all programs and windows are closed. Run HiJackThis. Place a check next to the following items, if found, and click FIX CHECKED:

O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\program files\180searchassistant\salmhook.dll
O4 - HKLM\..\Run: [TKAy7M3eI] C:\WINDOWS\ryvsupel.exe
O4 - HKLM\..\Run: [Windows Shell] C:\WINDOWS\system32\shell32.exe
O4 - HKLM\..\Run: [I downloaded pirated Software I post my Hijack Log] C:\WINDOWS\system32\_.gof
O4 - HKLM\..\Run: [zqd] C:\WINDOWS\zqd.exe
O4 - HKLM\..\Run: [hYcFv1] C:\WINDOWS\sttnb.exe
O4 - HKLM\..\Run: [EcIVj7] C:\WINDOWS\dwdnqri.exe
O4 - HKLM\..\Run: [vwhef] C:\WINDOWS\vwhef.exe
O4 - HKLM\..\Run: [mnih] C:\WINDOWS\mnih.exe
O4 - HKLM\..\Run: [SAHBundle] C:\DOCUME~1\user\LOCALS~1\Temp\sahagent-cdt1004.exe run
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [salm] c:\program files\180searchassistant\salm.exe
O4 - HKLM\..\Run: [clatqrqx] C:\WINDOWS\clatqrqx.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180search...com/180saax.cab
O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)

[/b]

Close HiJackThis.

Again using windows explorer locate and delete the following if found, PLEASE MAKE SURE THE FILES YOU DELETE ARE EXACTLY THE SAME AS BELOW.

C:\WINDOWS\ryvsupel.exe
C:\WINDOWS\system32\shell32.exe
C:\WINDOWS\system32\_.gof
C:\WINDOWS\zqd.exe
C:\WINDOWS\sttnb.exe
C:\WINDOWS\dwdnqri.exe
C:\WINDOWS\vwhef.exe
C:\WINDOWS\mnih.exe
C:\DOCUME~1\user\LOCALS~1\Temp\sahagent-cdt1004.exe run
C:\Program Files\Media Access\MediaAccK.exe
c:\program files\180searchassistant\salm.exe
C:\WINDOWS\clatqrqx.exe
C:\Program Files\Spyware Cleaner\SCService.exe


RIGHT-CLICK HERE and go to Save As (in IE it's "Save Target As") in order to download the smitfraud reg to your desktop.

Double-click smitfraud.reg on your desktop. When asked if you want to merge with the registry click YES.

After the merged successfully prompt, using Windows Explorer, navigate to the following folder:

C:\Windows\Prefetch

If there are any files inside the Prefetch folder, delete ALL of them. (Do NOT delete the folder. Just delete the files inside.)

Reboot your computer.

You should be able to change your desktop back to normal now if you had a problem with it.

Now Run this online virus scan: ActiveScan - Save the results from the scan!.

Post the report from Ewido Panda and a new HiJackThis log into this topic
  • 0

#6
strassle

strassle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Logfile of HijackThis v1.99.1
Scan saved at 2:27:51 AM, on 6/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DVD43\dvd43_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\program files\valve\steam\steam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Creative\SB Wireless Music\Media Server\SBWMsvr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\windowsautomaticupdates.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX00.328\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DVD43] C:\Program Files\DVD43\dvd43_tray.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [3DNADesktop] "C:\Program Files\3DNA\Resources\3dnasys.exe" -open
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SB Wireless Music] C:\Program Files\Creative\SB Wireless Music\Media Server\SBWMsvr.exe startup
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Windows Automatic Updates - Stanford University - C:\WINDOWS\system32\windowsautomaticupdates.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)


Panda:

Incident Status Location

Adware:Adware/SaveNow No disinfected Windows Registry
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\msxct1.ini
Adware:Adware/MyWay No disinfected C:\Program Files\MyWay
Adware:Adware/nCase No disinfected C:\WINDOWS\Downloaded Program Files\clientax.dll
Spyware:Spyware/Dyfuca No disinfected Windows Registry
Spyware:Spyware/ISTbar No disinfected C:\Program Files\Daily Weather Forecast
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\u6f6uftuc.exe
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Fun & Games\Betting.lnk
Adware:Adware/WinTools No disinfected Windows Registry
Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\a95kfrhe.ini
Adware:Adware/ExactSearch No disinfected Windows Registry
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-2fa9f21f-2d96b497.zip[GetAccess.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-2fa9f21f-2d96b497.zip[InsecureClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-2fa9f21f-2d96b497.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-2fa9f21f-2d96b497.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv429.jar-78d0a604-138efd62.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv429.jar-78d0a604-138efd62.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv429.jar-78d0a604-138efd62.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv429.jar-78d0a604-138efd62.zip[Parser.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv684.jar-6c93babb-7649782c.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv684.jar-6c93babb-7649782c.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv684.jar-6c93babb-7649782c.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv684.jar-6c93babb-7649782c.zip[Parser.class]
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Fun & Games\Betting.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Fun & Games\Casino Palace.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Fun & Games\Casino.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Fun & Games\Games.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Fun & Games\Horoscope.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Going Places\Air Tickets.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Going Places\Car Rentals.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Going Places\Hotel Deals.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Going Places\Luggage.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Going Places\Travel.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Living\Dating.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Living\Find a Degree.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Living\Find a job.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Living\Home.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Living\Insurance.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Auctions.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Books.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Computers.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Discount.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Flowers.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Golf.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Jewelry.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Movies.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Music.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Online Store.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Perfume.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Shop\Sleepwear.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Technology\Adware Remover.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Technology\Anti-Virus.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Technology\PC Cleaner.lnk
Adware:Adware/CWS No disinfected C:\Documents and Settings\user\Favorites\Technology\Tech & gadgets.lnk
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\user\My Documents\My Downloads\mirror_plugin.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Mafia no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Malice Mud Duck Productions crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Mario Pinball Land GBA Puzzle Nintendo crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Mario Tennis GC Nintendo crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Matrix Screensaver.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Max Payne 2 Fall Of Max Payne no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Max Payne 2 NO CD Crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Max Payne 2 The Fall of Max Payne NO CD crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\MaxPayne 2 The Fall Of Max Payne Crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\McFarlanes Evil Prophecy Konami crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Medal Of Honor - Allied Assault no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Medal Of Honor - Allied Assault BreakThrough no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Medal Of Honor - Allied Assault no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Medal of Honor Pacific Assault EA Games crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Medal of Honor- Allied Assault no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Medieval - Total War no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Mega Man Anniversary Collection GC Capcom crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Metal Gear Acid PSP Strategy Konami crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Metal Gear Solid 3 - Snake Eater Konami crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Microsoft Flight Simulator 2004 - A Century Of Flight no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Microsoft Office 2000 Regmaker.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Microsoft Office XP Activation Crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Microsoft Office XP Activation Killer.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Microsoft Office XP Professional Crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Microsoft Office XP Professional Serial.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Microsoft Office XP Universal Activator v1.0.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Midnight Club 3 - DUB Edition Rockstar Games crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\mirc 6.1x reg entries.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\mIRC 6.X crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Morpheus patch.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\MS Office XP Activation Crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\MS Zoo Tycoon no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\MSN advert remover.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\MSN Toolbar advert remover.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\MVP Baseball 2004 EA crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\NBA Live 2003 crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\NBA Live 2004 crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\NCAA Football 2005 EA crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Need For Speed 5 - no cd.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Need for Speed Hot Pursuit 2 CD KeyGenerator.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Need for speed underground - nocd.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Need for Speed Underground 2 crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Need for Speed Underground 2 Electronic Arts crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Need for Speed Underground 2 NO CD crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Need for Speed Underground NO CD crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Need for Speed4 - NOCD.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\NeedforspeedUnderground-nocd.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Nero Burning ROM v6.x crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Ninja Gaiden Tecmo crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Norton AntiVirus 2004 crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Onimusha 3 - Demon Siege Adventure Capcom crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Psi-Ops - The Mindgate Conspiracy Midway crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Purge Jihad Freeform Interactive LLC crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\RealPlayer crack (keygen).exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Red Dead Revolver Rockstar Games crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Resident Evil 4 GC Adventure Capcom crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Rise of Nations - Thrones & Patriots Strategy Microsoft crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\RoboForm crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Roller Coaster Tycoon no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\RYL crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Second Life Role-Playing Linden Lab crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Shadow Ops - Red Mercury Atari crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\ShellShock - Nam 67 Eidos Interactive crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Silent Storm - Sentinels Strategy _No Company crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Sim City 4 - Rush Hour no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Sim City 4 Deluxe no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Sim Theme Park World no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Singles - Flirt Up Your Life Strategy Eidos Interactive crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Snood crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Snowblind Eidos Interactive crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Soldier of Fortune II- Double Helix no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\SolSuite 2004 - Solitaire Card Games Suite crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Sonic the Hedgehog 3 crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Spider-Man 2 Activision crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Spider-Man 2 GC Activision crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Sponge Bob Square Pants - Operation Krabby Patty no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Spybot Search and Destroy.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Star Wars - Jedi Knight - Jedi Academy no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Star Wars - Knights of the Old Republic Role-Playing LucasArts crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Star Wars Galactic Battlegrounds- Clone Campaigns no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Star Wars Jedi Knight II - Jedi Outcast no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Star Wars Jedi Knight II- Jedi Outcast no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Star Wars Knights of the Old Republic II - The Sith Lords Role-Playing LucasArts crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\Starcraft - Battlechest no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Chronicles of Riddick - Escape From Butcher Bay VU Games crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Elder Scrolls III - Morrowind Game of the Year Edition Role-Playing Bethesda Softworks crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Legend of Zelda (working title) GC Nintendo crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Legend of Zelda - Four Swords Adventures GC Nintendo crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Legend of Zelda - The Minish Cap GBA Nintendo crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Lord of the Rings The Battle for Middle-earth Strategy EA Games crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Lord of the Rings The Return of The King crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims - Hot Date Expansion Pack no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims - Makin Magic Expansion Pack no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims - Superstar Expansion Pack no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims - Unleashed Expansion Pack no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims - Vacation Expansion Pack no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims - Hot Date Expansion Pack no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims - Vacation Expansion Pack no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims 2 crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims Deluxe no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims Deluxe no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims Double Deluxe no cd crack.exe
Virus:W32/Sndc.A.worm Disinfected C:\WINDOWS\Downloaded Installations\The Sims no cd crack.exe
  • 0

#7
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Hi Again,

I need you to copy all of the Killbox file paths below and paste them into Notepad.

C:\WINDOWS\msxct1.ini
C:\Program Files\MyWay
C:\WINDOWS\Downloaded Program Files\clientax.dll
C:\Program Files\Daily Weather Forecast
C:\WINDOWS\u6f6uftuc.exe
C:\Documents and Settings\user\Favorites\Fun & Games\Betting.lnk
C:\WINDOWS\system32\a95kfrhe.ini
C:\Documents and Settings\user\Favorites\Fun & Games\Betting.lnk
C:\Documents and Settings\user\Favorites\Fun & Games\Casino Palace.lnk
C:\Documents and Settings\user\Favorites\Fun & Games\Casino.lnk
C:\Documents and Settings\user\Favorites\Fun & Games\Games.lnk
C:\Documents and Settings\user\Favorites\Fun & Games\Horoscope.lnk
C:\Documents and Settings\user\Favorites\Going Places\Air Tickets.lnk
C:\Documents and Settings\user\Favorites\Going Places\Car Rentals.lnk
C:\Documents and Settings\user\Favorites\Going Places\Hotel Deals.lnk
C:\Documents and Settings\user\Favorites\Going Places\Luggage.lnk
C:\Documents and Settings\user\Favorites\Going Places\Travel.lnk
C:\Documents and Settings\user\Favorites\Living\Dating.lnk
C:\Documents and Settings\user\Favorites\Living\Find a Degree.lnk
C:\Documents and Settings\user\Favorites\Living\Find a job.lnk
C:\Documents and Settings\user\Favorites\Living\Home.lnk
C:\Documents and Settings\user\Favorites\Living\Insurance.lnk
C:\Documents and Settings\user\Favorites\Shop\Auctions.lnk
C:\Documents and Settings\user\Favorites\Shop\Books.lnk
C:\Documents and Settings\user\Favorites\Shop\Computers.lnk
C:\Documents and Settings\user\Favorites\Shop\Discount.lnk
C:\Documents and Settings\user\Favorites\Shop\Flowers.lnk
C:\Documents and Settings\user\Favorites\Shop\Golf.lnk
C:\Documents and Settings\user\Favorites\Shop\Jewelry.lnk
C:\Documents and Settings\user\Favorites\Shop\Movies.lnk
C:\Documents and Settings\user\Favorites\Shop\Music.lnk
C:\Documents and Settings\user\Favorites\Shop\Online Store.lnk
C:\Documents and Settings\user\Favorites\Shop\Perfume.lnk
C:\Documents and Settings\user\Favorites\Shop\Sleepwear.lnk
C:\Documents and Settings\user\Favorites\Technology\Adware Remover.lnk
C:\Documents and Settings\user\Favorites\Technology\Anti-Virus.lnk
C:\Documents and Settings\user\Favorites\Technology\PC Cleaner.lnk
C:\Documents and Settings\user\Favorites\Technology\Tech & gadgets.lnk
C:\Documents and Settings\user\My Documents\My Downloads\mirror_plugin.exe


* Please download the Killbox by Option^Explicit. *In the event you already have Killbox, this is a new version that I need you to download.
Unzip it to the desktop.

* Please run Killbox.

* Select "Delete on Reboot".

* Open the Notepad file where you saved the file paths earlier and copy the file paths below to the clipboard by highlighting them and pressing CTRL + C:

* Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

* Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

Cary out another ewido scan and save the report.

Rescan with HJT and post the log back with the ewido log
  • 0

#8
strassle

strassle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 6:15:51 AM, 6/27/2005
+ Report-Checksum: 5804651C

+ Date of database: 6/26/2005
+ Version of scan engine: v3.0

+ Duration: 13 min
+ Scanned Files: 82825
+ Speed: 99.59 Files/Second
+ Infected files: 4
+ Removed files: 4
+ Files put in quarantine: 4
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\Documents and Settings\user\Cookies\user@advertising[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\user\Cookies\user@atdmt[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\user\Cookies\user@servedby.advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\user\Local Settings\Temp\15574.exe -> TrojanDownloader.Small.alr -> Cleaned with backup


::Report End



Logfile of HijackThis v1.99.1
Scan saved at 6:16:17 AM, on 6/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\windowsautomaticupdates.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\DVD43\dvd43_tray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Creative\SB Wireless Music\Media Server\SBWMsvr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\user\LOCALS~1\Temp\Rar$EX01.032\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SB Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DVD43] C:\Program Files\DVD43\dvd43_tray.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [3DNADesktop] "C:\Program Files\3DNA\Resources\3dnasys.exe" -open
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SB Wireless Music] C:\Program Files\Creative\SB Wireless Music\Media Server\SBWMsvr.exe startup
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Windows Automatic Updates - Stanford University - C:\WINDOWS\system32\windowsautomaticupdates.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
  • 0

#9
Guest_usetobe_*

Guest_usetobe_*
  • Guest
From your log, I see nothing in the ways of trojans, nor any evil entities attempting to possess your computer, except for Windows but it's too late for that one. :tazz:

Congratulations your log now appears to be clean. ;)

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:

Detect and Remove Programs:
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
Prevention Programs:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
Other necessary Programs:
  • AntiVirus Program<= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kapersky, this is a must have.
  • Firewall<= A firewall is definatley a must have. Two good free versions are Sygate and ZoneLabs.
  • More Secure Browser<= Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
And also see TonyKlein's good advice
So how did I get infected in the first place? and AntiSpyware Net's spyware article: Spyware, Adware, Malware: What it is, how it got on my computer, how to get rid of it, and how to prevent it.
  • 0

#10
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP