Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Jul 5th, 2008, 6:27pm
   Mischel Internet Security Forum
   TrojanHunter
   TrojanHunter Scanner
(Moderators: Helena, Gavin_Coe, Magnus)
   same problem for weeks now,
« Previous topic | Next topic »
Pages: 1 2  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: same problem for weeks now,  (Read 506 times)
PcMac
Newbie
*





   


Posts: 16
same problem for weeks now,
« on: Mar 30th, 2008, 5:47am »
Quote Quote  Modify Modify

having same problem for weeks now,have url link for this below
here is screen shot
http://farm3.static.flickr.com/2108/2369339109_c9e639ce43_m.jpg
 
 recently I started getting this annoying alert window,how do I get rid of it?
 
"alert wrong log in or password !"
possible cause is several PCs on same Linksys router LAN  
using Network magic software
 
have looked everywhere on these programs,(firefox,network magic etc)
 but cannot find preference/option to cancel it  
 
having same result,but trojan hunter/or NEVER spybot removes it?
 
TROJAN HUNTER SAYS =”Vundo.897”
Found trojan file: C:\WINDOWS\system32\opnljjj.dll (Vundo.897)
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: same problem for weeks now,
« Reply #1 on: Mar 30th, 2008, 6:22am »
Quote Quote  Modify Modify

Yes, you have been infected.  Please do the following.  
 
1.  Download/install program Hijackthis per the instructions in the link below.  
 
http://www.misec.net/forum/board/FAQ/1163329424  
 
2.  Go to the link below and download program Combofix.exe and save it on your desktop.  
 
http://download.bleepingcomputer.com/sUBs/ComboFix.exe  
 
3.  Temporarily de-Activate all your security programs EXCEPT your software firewall.  
 
4.  Close down as many programs as you can (programs in the Notification Tray-  next to the clock).  
 
5.  Close your browser.  
 
6.  Double click on Combofix.exe to execute it and follow the instructions.  
 
Please note, that once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.  
 
-  When Combofix.exe is finished, it will save a log on your system.    
 
7.  Post the Combofix log back here  
 
8.  Run Hijackthis and post a HiJackthis scan log back here.  DO NOT fix anything with HJT...just post the scan log.
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
PcMac
Newbie
*





   


Posts: 16
Re: same problem for weeks now,
« Reply #2 on: Mar 30th, 2008, 7:28am »
Quote Quote  Modify Modify

ComboFix 08-03-30.2 - DJ 2008-03-30 10:10:32.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.474 [GMT -3:00]
Running from: C:\Documents and Settings\DJ\My Documents\DOWNLOADS\ComboFix.exe
 * Created a new restore point
 
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
 
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
C:\WINDOWS\BM9fe05f1b.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\bmqetfay.dll
C:\WINDOWS\system32\brncxvyg.dll
C:\WINDOWS\system32\cmeftrjd.dll
C:\WINDOWS\system32\cvixhqmg.ini
C:\WINDOWS\system32\ddayx.dll
C:\WINDOWS\system32\diwexhxq.dll
C:\WINDOWS\system32\gjpbkeqm.dll
C:\WINDOWS\system32\gmqhxivc.dll
C:\WINDOWS\system32\kpllquec.dll
C:\WINDOWS\system32\mfawisyo.dll
C:\WINDOWS\system32\mgxqpgvk.dll
C:\WINDOWS\system32\ncamcimt.dll
C:\WINDOWS\system32\opnljjj.dll
C:\WINDOWS\system32\smgtfstw.dll
C:\WINDOWS\system32\tmicmacn.ini
C:\WINDOWS\system32\todipwly.dll
C:\WINDOWS\system32\tumidpdf.dll
C:\WINDOWS\system32\vvvwa.ini
C:\WINDOWS\system32\vvvwa.ini2
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\system32\wtsftgms.ini
C:\WINDOWS\system32\xyadd.ini
C:\WINDOWS\system32\xyadd.ini2
G:\Autorun.inf
 
.
(((((((((((((((((((((((((   Files Created from 2008-02-28 to 2008-03-30  )))))))))))))))))))))))))))))))
.
 
2008-03-30 09:56 . 2008-03-30 09:56
<DIR>
d--------
C:\Program Files\Trend Micro
2008-03-29 08:22 . 2007-01-18 09:00
3,968
--a------
C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-03-27 15:39 . 2008-03-28 15:39
774
---hs----
C:\WINDOWS\system32\bahcsxws.ini
2008-03-26 15:38 . 2008-03-27 04:09
714
---hs----
C:\WINDOWS\system32\cjfdajba.ini
2008-03-25 22:10 . 2008-03-30 10:19
54,156
--ah-----
C:\WINDOWS\QTFont.qfn
2008-03-25 22:10 . 2008-03-25 22:10
1,409
--a------
C:\WINDOWS\QTFont.for
2008-03-25 15:41 . 2008-03-29 08:40
894
---hs----
C:\WINDOWS\system32\bomhqhio.ini
2008-03-24 15:38 . 2008-03-25 15:38
414
---hs----
C:\WINDOWS\system32\yqbrwjfc.ini
2008-03-23 10:53 . 2004-08-03 22:58
14,848
--a------
C:\WINDOWS\system32\drivers\kbdhid.sys
2008-03-23 10:53 . 2004-08-03 22:58
14,848
--a--c---
C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-03-22 23:12 . 2006-11-13 03:02
288,768
---------
C:\WINDOWS\system32\rhttpaa.dll
2008-03-22 23:12 . 2006-11-13 03:02
116,736
---------
C:\WINDOWS\system32\aaclient.dll
2008-03-22 23:12 . 2006-11-13 03:02
36,352
---------
C:\WINDOWS\system32\tsgqec.dll
2008-03-22 20:15 . 2008-03-22 20:15
<DIR>
d--------
C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-03-22 15:38 . 2008-03-22 15:38
534
---hs----
C:\WINDOWS\system32\gjhptnhu.ini
2008-03-22 09:14 . 2008-03-22 09:14
474
---hs----
C:\WINDOWS\system32\htfgbbhr.ini
2008-03-22 06:10 . 2008-03-22 21:31
534
---hs----
C:\WINDOWS\system32\yosrqihw.ini
2008-03-21 06:07 . 2008-03-21 06:07
534
---hs----
C:\WINDOWS\system32\yuoybufy.ini
2008-03-20 19:40 . 2008-03-21 06:11
534
---hs----
C:\WINDOWS\system32\knlycdla.ini
2008-03-20 19:40 . 2008-03-22 02:12
0
--a------
C:\WINDOWS\system32\pyfsnvud.dll
2008-03-19 19:37 . 2008-03-20 19:37
354
---hs----
C:\WINDOWS\system32\wtufprkk.ini
2008-03-19 19:37 . 2008-03-22 02:11
0
--a------
C:\WINDOWS\system32\lnlqhtmu.dll
2008-03-18 19:38 . 2008-03-18 19:38
294
---hs----
C:\WINDOWS\system32\lypkbmix.ini
2008-03-18 19:37 . 2008-03-22 02:11
0
--a------
C:\WINDOWS\system32\fsvrfrsr.dll
2008-03-17 19:38 . 2008-03-17 19:38
534
---hs----
C:\WINDOWS\system32\fnekkvtc.ini
2008-03-17 19:38 . 2008-03-22 02:10
0
--a------
C:\WINDOWS\system32\ctvkkenf.dll
2008-03-17 09:26 . 2008-03-17 09:26
<DIR>
d---s----
C:\Documents and Settings\LocalService\UserData
2008-03-16 19:35 . 2008-03-17 15:20
474
---hs----
C:\WINDOWS\system32\ojtgskjw.ini
2008-03-16 19:35 . 2008-03-22 02:11
0
--a------
C:\WINDOWS\system32\lpdnjayc.dll
2008-03-16 19:33 . 2008-03-16 19:33
63
--a------
C:\WINDOWS\system32\9cd37e09
2008-03-16 19:31 . 2008-03-17 11:52
<DIR>
d--------
C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-16 19:29 . 2008-03-22 20:30
<DIR>
d--------
C:\Program Files\Bat
2008-03-15 22:56 . 2008-03-15 22:56
<DIR>
d--------
C:\Program Files\Common Files\xing shared
2008-03-15 22:55 . 2008-03-15 22:56
<DIR>
d--------
C:\Program Files\Real
2008-03-15 22:55 . 2008-03-15 22:55
<DIR>
d--------
C:\Program Files\Common Files\Real
2008-02-24 07:59 . 2008-02-24 07:59
<DIR>
d--------
C:\Program Files\Windows Media Connect 2
2008-02-24 07:58 . 2008-02-24 07:58
<DIR>
d--------
C:\WINDOWS\system32\LogFiles
2008-02-18 08:43 . 2008-02-18 08:43
<DIR>
d--------
C:\Program Files\MagicISO
2008-02-15 09:27 . 2008-02-15 09:27
<DIR>
d--------
C:\Documents and Settings\DJ\Application Data\Maxprog
2008-02-15 09:26 . 2008-02-15 09:29
<DIR>
d--------
C:\Program Files\iCash
2008-02-12 13:25 . 2008-02-12 13:25
<DIR>
d--------
C:\Program Files\Morpheus Photo Morpher
2008-02-12 13:25 . 2008-02-12 13:25
<DIR>
d--------
C:\Documents and Settings\DJ\Application Data\Morpheus Software
2008-02-11 08:51 . 2008-03-02 21:40
<DIR>
d--------
C:\Program Files\Podmaxx 2008
2008-02-11 08:51 . 2008-02-11 08:51
<DIR>
d--------
C:\Program Files\AviSynth 2.5
2008-02-11 08:51 . 2008-02-11 08:51
<DIR>
d--------
C:\Documents and Settings\DJ\Application Data\Bling Software
2008-02-10 23:27 . 2008-02-10 23:27
<DIR>
d--------
C:\Program Files\Real Alternative
2008-02-10 17:17 . 2008-02-10 17:17
<DIR>
d--------
C:\Program Files\Common Files\eSellerate
2008-02-10 17:14 . 2008-02-10 17:15
<DIR>
d--------
C:\Program Files\iPod Access for Windows
2008-02-10 17:14 . 2008-02-10 17:14
<DIR>
d--------
C:\Documents and Settings\All Users\Application Data\Findley Designs
2008-02-06 09:51 . 2008-02-06 09:51
<DIR>
d--------
C:\Documents and Settings\DJ\Application Data\AutoSync for Yahoo
2008-02-06 09:12 . 2008-02-06 09:12
<DIR>
d--------
C:\Program Files\Common Files\Intellisync
2008-02-06 08:57 . 2008-02-06 08:57
<DIR>
d--------
C:\Documents and Settings\DJ\Application Data\XemiComputers
2008-02-06 08:57 . 2008-02-06 08:57
<DIR>
d--------
C:\Documents and Settings\All Users\Application Data\XemiComputers
2008-02-06 08:55 . 2008-02-06 08:55
<DIR>
d--------
C:\Program Files\XemiComputers
2008-02-03 18:51 . 2008-02-03 19:30
<DIR>
d--------
C:\Program Files\VstPlugins
2008-02-03 18:51 . 2002-07-07 19:14
1,294,336
--a------
C:\WINDOWS\system32\vorbis.acm
2008-02-03 18:51 . 2006-06-20 05:56
225,280
--a------
C:\WINDOWS\system32\rewire.dll
2008-02-03 18:50 . 2008-02-03 19:30
<DIR>
d--------
C:\Program Files\Image-Line
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-30 13:19
---------
d-----w
C:\Program Files\Symantec AntiVirus
2008-03-30 13:05
---------
d-----w
C:\Documents and Settings\DJ\Application Data\uTorrent
2008-03-29 23:22
---------
d-----w
C:\Program Files\Sticky Password
2008-03-29 22:10
---------
d-----w
C:\Documents and Settings\DJ\Application Data\OpenOffice.org2
2008-03-24 07:58
---------
d-----w
C:\Program Files\uTorrent
2008-03-23 19:37
---------
d-----w
C:\Program Files\PowerArchiver
2008-03-23 13:31
---------
d-----w
C:\Program Files\MP3 Splitter & Joiner
2008-02-26 16:20
---------
d-----w
C:\Documents and Settings\All Users\Application Data\Dell
2008-02-17 05:14
---------
d-----w
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-17 05:11
---------
d-----w
C:\Program Files\Spybot - Search & Destroy
2008-02-17 04:57
691,545
----a-w
C:\WINDOWS\unins000.exe
2008-02-11 01:35
---------
d-----w
C:\Program Files\DivX
2008-02-06 12:12
---------
d-----w
C:\Program Files\Yahoo!
2008-01-31 04:48
---------
d-----w
C:\Program Files\iTunes
2008-01-31 04:48
---------
d-----w
C:\Program Files\iPod
2008-01-31 04:46
---------
d-----w
C:\Program Files\QuickTime
2007-09-13 17:44
54,266
-c--a-w
C:\Documents and Settings\DJ\Application Data\unins000.dat
2007-09-13 17:43
683,801
----a-w
C:\Documents and Settings\DJ\Application Data\unins000.exe
2007-09-24 14:06
56
--sh--r
C:\WINDOWS\system32\E03E99BDB9.sys
2007-12-03 00:12
10,856
--sha-w
C:\WINDOWS\system32\KGyGaAvL.sys
.
 
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown  
REGEDIT4
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{144C8C31-035B-4A12-B56F-BF3B7C69692B}]
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E906942-51F3-4789-8DC8-86D2C50AD829}]
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{609B3F42-D7DD-47F7-8376-D940FBEDB7E7}]
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61ab0961-ca3a-4cf0-9e7c-5e55bdacd454}]
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79A96D3A-50D3-45C6-8A8A-441F53899559}]
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7822D3F-8F22-4DBF-8EE2-A0A5AE7938F8}]
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D1F63132-2163-4A36-AE50-EC0F99327371}]
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E9383002-FC55-4330-B9C9-67E03BC5C840}]
 
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F86182B1-AE6C-465C-A70F-6675E763E44F}]
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
"PowerArchiver Tray"="C:\Program Files\PowerArchiver\PASTARTER.EXE" [2007-11-30 12:08 140328]
"Active Desktop Calendar"="C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe" [2008-02-06 08:53 1171968]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-09 22:05 344064]
"DiskeeperSystray"="C:\Program Files\Executive Software\Diskeeper\DkIcon.exe" [2004-10-04 20:53 176216]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-10-04 13:42 48752]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-11-15 14:28 85744]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 20:20 866584]
"THGuard"="C:\Program Files\TrojanHunter 5.0\THGuard.exe" [2007-09-09 10:31 1046688]
"nmapp"="C:\Program Files\Pure Networks\Network Magic\nmapp.exe" [2007-03-14 16:42 321088]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 15:42 1404928]
"WinUtilities Memory Optimizer"="C:\Program Files\WinUtilities\ToolMemoryOptimizer.exe" [2007-11-20 06:09 409600]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 14:19 15872]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]
"1cla.exe"="c:\progra~1\1click~1\1cla.exe" [2006-05-25 17:26 655360]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 13:30 139264]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
"9cd36c87"="C:\WINDOWS\system32\oihqhmob.dll" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-15 22:55 185896]
"BM9fe05f1b"="C:\WINDOWS\system32\mgxqpgvk.dll" [ ]
 
C:\Documents and Settings\DJ\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 22:57:56 393216]
 
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-09-12 22:43:41 118784]
Yahoo! Autosync.lnk - C:\Program Files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe [2007-08-21 15:28:52 391680]
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableChangePassword"= 0 (0x0)
"DisableLockWorkstation"= 0 (0x0)
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnljjj]
opnljjj.dll
 
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\progra~1\1click~1\1cla.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Java\\jre1.6.0_03\\launch4j-tmp\\Efigio.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"137:TCP"= 137:TCP:SMB  
"138:TCP"= 138:TCP:SMB  
"67:UDP"= 67:UDPCheesyHCP Discovery Service
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
 
R0 ppa;Iomega Parallel Port Filter Driver;C:\WINDOWS\system32\DRIVERS\ppa.sys [2001-08-17 10:53]
R1 HFSYS;HFSYS;C:\WINDOWS\system32\drivers\HFSYS.SYS [2004-01-12 01:34]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
S3 cmudau;Audio Advantage Roadie Interface;C:\WINDOWS\system32\drivers\cmudau.sys [2005-10-03 10:07]
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d40762bc-8a02-11dc-81cc-00111182a29c}]
\Shell\AutoRun\command - Sticky~1.exe
\Shell\open\command - Sticky~1.exe
 
.
Contents of the 'Scheduled Tasks' folder
"2008-03-30 13:19:57 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-03-24 08:05:10 C:\WINDOWS\Tasks\Spybot - Search & Destroy -  Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
************************************************************************ **
 
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-30 10:19:37
Windows 5.1.2600 Service Pack 2 NTFS
 
scanning hidden processes ...  
 
scanning hidden autostart entries ...
 
scanning hidden files ...  
 
scan completed successfully  
hidden files: 0  
 
************************************************************************ **
.
--------------------- DLLs Loaded Under Running Processes ---------------------
 
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
-> C:\Program Files\XemiComputers\Active Desktop Calendar\MouseHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Executive Software\Diskeeper\DfrgFat.exe
.
************************************************************************ **
.
Completion time: 2008-03-30 10:24:17 - machine was rebooted
ComboFix-quarantined-files.txt  2008-03-30 13:24:14
Pre-Run: 631,389,581,312 bytes free
Post-Run: 631,357,718,528 bytes free
.
2008-03-12 11:03:24
--- E O F ---  
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: same problem for weeks now,
« Reply #3 on: Mar 30th, 2008, 7:32am »
Quote Quote  Modify Modify

Your system was heavily infected.
 
Please post the Hijackthis log  Wink
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
PcMac
Newbie
*





   


Posts: 16
Re: same problem for weeks now,
« Reply #4 on: Mar 30th, 2008, 7:40am »
Quote Quote  Modify Modify

StartupList report, 3/30/2008, 10:03:24 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================
 
Running processes:
 
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\PROGRA~1\1CLICK~1\1cla.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\WinUtilities\ToolMemoryOptimizer.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Sticky Password\stpass.exe
C:\Documents and Settings\DJ\My Documents\UTILITIES\XFilesDialog\XFilesDialog.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\FileMaker\FileMaker Pro 5\FileMaker Pro.exe
C:\Program Files\TrojanHunter 5.0\TrojanHunter.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
C:\Program Files\TechSmith\SnagIt 7\TSCHelp.exe
C:\Program Files\textSOAP\textsoap.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
--------------------------------------------------
 
Listing of startup folders:
 
Shell folders Startup:
[C:\Documents and Settings\DJ\Start Menu\Programs\Startup]
OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
 
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
Yahoo! Autosync.lnk = C:\Program Files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe
 
--------------------------------------------------
 
Checking Windows NT UserInit:
 
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe
 
--------------------------------------------------
 
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
 
ATIPTA = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
DiskeeperSystray = "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
vptray = C:\PROGRA~1\SYMANT~1\VPTray.exe
Windows Defender = "C:\Program Files\Windows Defender\MSASCui.exe" -hide
THGuard = "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
nmapp = "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun
SoundMAXPnP = C:\Program Files\Analog Devices\Core\smax4pnp.exe
WinUtilities Memory Optimizer = C:\Program Files\WinUtilities\ToolMemoryOptimizer.exe -hide
UnlockerAssistant = "C:\Program Files\Unlocker\UnlockerAssistant.exe"
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
1cla.exe = c:\progra~1\1click~1\1cla.exe
IAAnotif = C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
dscactivate = "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
9cd36c87 = rundll32.exe "C:\WINDOWS\system32\oihqhmob.dll",b
BM9fe05f1b = Rundll32.exe "C:\WINDOWS\system32\mgxqpgvk.dll",s
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 
--------------------------------------------------
 
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
 
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
DellSupportCenter = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
PowerArchiver Tray = C:\Program Files\PowerArchiver\PASTARTER.EXE
Active Desktop Calendar = C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
 
--------------------------------------------------
 
Load/Run keys from C:\WINDOWS\WIN.INI:
 
load=*INI section not found*
run=*INI section not found*
 
Load/Run keys from Registry:
 
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=C:\PROGRA~1\1CLICK~1\1cla.exe
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=*Registry value not found*
 
--------------------------------------------------
 
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
 
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
 
Shell & screensaver key from Registry:
 
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\ssmarque.scr
drivers=*Registry value not found*
 
Policies Shell key:
 
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
 
--------------------------------------------------
 
 
Enumerating Task Scheduler jobs:
 
MP Scheduled Scan.job
Spybot - Search & Destroy -  Scheduled Task.job
 
--------------------------------------------------
 
Enumerating Download Program Files:
 
[WUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\wuweb.dll
CODEBASE = http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/clien t/wuweb_site.cab?1189706079109
 
--------------------------------------------------
 
Enumerating ShellServiceObjectDelayLoad items:
 
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll
 
--------------------------------------------------
End of report, 8,925 bytes
Report generated in 0.093 seconds
 
Command line options:
   /verbose  - to add additional info on each section
   /complete - to include empty sections and unsuspicious data
   /full     - to include several rarely-important sections
   /force9x  - to include Win9x-only startups even if running on WinNT
   /forcent  - to include WinNT-only startups even if running on Win9x
   /forceall - to include all Win9x and WinNT startups, regardless of platform
   /history  - to list version history only
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: same problem for weeks now,
« Reply #5 on: Mar 30th, 2008, 7:47am »
Quote Quote  Modify Modify

I'm a bit confused about the 2nd log you submitted.  It is not a Hijackthis V2.0.2 log.  Did you install Hijackthis from the link below?  
 
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis
 
A Hijackthis log looks like this:
 
Quote:
Logfile of Trend Micro HijackThis v2.0.2  
Scan saved at 12:34:15 AM, on 3/29/2008  
Platform: Windows XP SP2 (WinNT 5.01.2600)  
MSIE: Internet Explorer v7.00 (7.00.6000.1660  
Boot mode: Normal  
 
Running processes:  
C:\WINDOWS\System32\smss.exe  
C:\WINDOWS\system32\csrss.exe  
C:\WINDOWS\system32\winlogon.exe  
C:\WINDOWS\system32\services.exe  
C:\WINDOWS\system32\lsass.exe  
C:\WINDOWS\system32\svchost.exe  
C:\WINDOWS\system32\svchost.exe  
C:\WINDOWS\System32\svchost.exe  
D:\Blink\blinksvc.exe  
C:\WINDOWS\system32\svchost.exe  
D:\Blink\blinkrm.exe  
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe  
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe  
D:\Ad-Aware 2007\aawservice.exe  
C:\WINDOWS\system32\spoolsv.exe  
C:\WINDOWS\Explorer.EXE  
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe  
C:\WINDOWS\system32\svchost.exe  
C:\Program Files\Bonjour\mDNSResponder.exe  
D:\Comodo\Firewall\cmdagent.exe  
C:\Program Files\Symantec AntiVirus\DefWatch.exe  
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe  
D:\Raxco\PerfectDisk\PDAgent.exe  
C:\WINDOWS\SOUNDMAN.EXE  
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe  
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe  
D:\WinPatrol\winpatrol.exe  
D:\TrueImageHome\TrueImageMonitor.exe  
D:\CounterSpy\SBCSSvc.exe  
D:\TrueImageHome\TimounterMonitor.exe  
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe  
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe  
C:\Program Files\Common Files\Symantec Shared\ccApp.exe  
C:\Program Files\Common Files\eEye Digital Security\Application Bus\eeyeevnt.exe  
D:\Blink\BLINK.EXE  
D:\FileBX\FileBX.exe  
C:\Program Files\Google\Google Updater\GoogleUpdater.exe  
D:\Raxco\PerfectDisk\PDEngine.exe  
C:\WINDOWS\System32\alg.exe  
C:\WINDOWS\system32\wbem\wmiprvse.exe  
D:\GhostSurf Platinum\Proxy.exe  
E:\Downloads\HiJackThis\HijackThis.exe  
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896  
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896  
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157  
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212  
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll  
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll  
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll  
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE  
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"  
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM  
O4 - HKLM\..\Run: [GhostSurf Reminder] "D:\GhostSurf Platinum\Privacy Control Center.exe" reminder  
O4 - HKLM\..\Run: [WinPatrol] d:\WinPatrol\winpatrol.exe -expressboot  
O4 - HKLM\..\Run: [COMODO Firewall Pro] "D:\Comodo\Firewall\cfp.exe" -h  
O4 - HKLM\..\Run: [TrueImageMonitor.exe] D:\TrueImageHome\TrueImageMonitor.exe  
O4 - HKLM\..\Run: [AcronisTimounterMonitor] D:\TrueImageHome\TimounterMonitor.exe  
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"  
O4 - HKLM\..\Run: [THGuard] "D:\TrojanHunter 5.0\THGuard.exe"  
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe  
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"  
O4 - Startup: AutorunsDisabled  
O4 - Startup: ERUNT AutoBackup.lnk = D:\ERUNT\AUTOBACK.EXE  
O4 - Global Startup: Blink.lnk = D:\Blink\BLINK.EXE  
O4 - Global Startup: FileBox eXtender.lnk = D:\FileBX\FileBX.exe  
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe  
O8 - Extra context menu item: Add to Evernote - res://d:\Evernote3\enbar.dll/2000  
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll  
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll  
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL  
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll  
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll  
O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - d:\Evernote3\enbar.dll  
O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - d:\Evernote3\enbar.dll  
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe  
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe  
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab  
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab  
O17 - HKLM\System\CCS\Services\Tcpip\..\{3B6B3180-3D93-4F3D-A01F-79219E005249}  : NameServer = 64.56.143.163,64.56.143.165  
O18 - Filter hijack: text/html - {72D50253-BE71-4c85-9B38-6331E5AD1499} - D:\Blink\IEMimeFilter.dll  
O20 - AppInit_DLLs: secuload.dll,c:\windows\system32\guard32.dll  
O20 - Winlogon Notify: !SASWinLogon - D:\SUPERAntiSpyware\SASWINLO.dll  
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\Ad-Aware 2007\aawservice.exe  
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe  
O23 - Service: eEye Blink Engine (blinksvc) - eEye Digital Security - D:\Blink\blinksvc.exe  
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe  
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe  
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe  
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe  
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - D:\Comodo\Firewall\cmdagent.exe  
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe  
O23 - Service: eEye Application Bus (eeyeevnt) - eEye Digital Security - C:\Program Files\Common Files\eEye Digital Security\Application Bus\eeyeevnt.exe  
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe  
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe  
O23 - Service: PDAgent - Raxco Software, Inc. - D:\Raxco\PerfectDisk\PDAgent.exe  
O23 - Service: PDEngine - Raxco Software, Inc. - D:\Raxco\PerfectDisk\PDEngine.exe  
O23 - Service: PDExchange - Raxco Software, Inc. - D:\Raxco\PerfectDisk\PDExchange.exe  
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe  
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - D:\CounterSpy\SBCSSvc.exe  
O23 - Service: SBO - Sysinternals www.sysinternals.com - C:\DOCUME~1\gregg\LOCALS~1\Temp\SBO.exe  
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe  
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe  
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe  
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe  
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe  
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe  
O23 - Service: WMPTSZMM - Sysinternals www.sysinternals.com - C:\DOCUME~1\gregg\LOCALS~1\Temp\WMPTSZMM.exe  
O24 - Desktop Component 0: (no name) - (no file)  
O24 - Desktop Component 1: (no name) - (no file)  
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: same problem for weeks now,
« Reply #6 on: Mar 30th, 2008, 7:49am »
Quote Quote  Modify Modify

Oh I see what you did.  Wrong HJT option.
 
On the Main Menu of HJT, click on "Do a system scan and save a logfile".
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
PcMac
Newbie
*





   


Posts: 16
Re: same problem for weeks now,
« Reply #7 on: Mar 30th, 2008, 7:53am »
Quote Quote  Modify Modify

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52:47 AM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\WinUtilities\ToolMemoryOptimizer.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\progra~1\1click~1\1cla.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Apple Software Update\SoftwareUpdate.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\Executive Software\Diskeeper\DfrgFat.exe
C:\Program Files\Executive Software\Diskeeper\DkIcon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =  
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Network Magic Browser Helper - {07D7F044-2F5F-41B2-BAA5-936814AF0163} - C:\Program Files\Pure Networks\Network Magic\nmbrhlp2.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [WinUtilities Memory Optimizer] C:\Program Files\WinUtilities\ToolMemoryOptimizer.exe -hide
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [1cla.exe] c:\progra~1\1click~1\1cla.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [9cd36c87] rundll32.exe "C:\WINDOWS\system32\oihqhmob.dll",b
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Yahoo! Autosync.lnk = C:\Program Files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/clien t/wuweb_site.cab?1189706079109
O20 - Winlogon Notify: opnljjj - opnljjj.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
 
--
End of file - 9777 bytes
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: same problem for weeks now,
« Reply #8 on: Mar 30th, 2008, 8:04am »
Quote Quote  Modify Modify

Okay, ComboFix did a great job of removing a lot of the infections; however, there are still more on your system.  
 
First of all, please do this:
 
Go to the link below and run a scan on the following two files.  Please report back here what these combination of several scan programs report on these two files.
 
oihqhmob.dll     (located in C:\Windows\System32)
1cla.exe    (located in C:\Program Files\1click~)

 
http://virusscan.jotti.org/
 
While you are having these analyzed, I'll type up another instruction post.
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
PcMac
Newbie
*





   


Posts: 16
Re: same problem for weeks now,
« Reply #9 on: Mar 30th, 2008, 8:16am »
Quote Quote  Modify Modify

cannot find either file!!
 
oihqhmob.dll (located in C:\Windows\System32)
 
 1cla.exe (located in C:\Program Files\1click~)
 
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: same problem for weeks now,
« Reply #10 on: Mar 30th, 2008, 8:28am »
Quote Quote  Modify Modify

Oops, you probably need to make all your files and folders visible per the instructions in the link below.  
 
http://www.misec.net/forum/board/FAQ/1139610900
 
Now can you find these files ?
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
PcMac
Newbie
*





   


Posts: 16
Re: same problem for weeks now,
« Reply #11 on: Mar 30th, 2008, 8:40am »
Quote Quote  Modify Modify

No threat detected  
: 1cl.exe  
 
oihqhmob.dll
not found
 
this is looking like I have to wipe HD and reinstall XP?
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: same problem for weeks now,
« Reply #12 on: Mar 30th, 2008, 8:43am »
Quote Quote  Modify Modify

No...definitely not necessary to reformat your disk.  I'll post further instructions in just a minute or so.   Wink
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: same problem for weeks now,
« Reply #13 on: Mar 30th, 2008, 8:52am »
Quote Quote  Modify Modify

1.  Please submit the following folder to Mischel Internet Security  
 
-  Submit the Combofix Quarantine folder to Mischel Internet Security.
 
-  The Quarantine folder is folder Qoobox located at C:\Qoobox
 
-  Right click on folder Qoobox and select "Send to>Compressed (zipped) folder"
 
-  Windows Explorer will tell you that it wants to zip this folder and place it on your desktop.  Let it place it on your desktop.
 
-  Then attach the zipped folder to an e-mail to submit@misec.net and send it off.
 
NOTE:  If this folder is too big for your e-mail client, just proceed to the next step.
 
2.  Delete the following from your system:
 
-  The folder Qoobox from C:\
-  The folder Qoobox from your desktop
-  Combofix.exe from your desktop (or whereever you stored it)
-  The combofix.txt log  
-  The e-mail with Qoobox zipped folder to misec.net so that this attachment is no longer in your e-mail client.
 
3.  Run another Hijackthis scan.
 
4.  When the scan is completed, place a checkmark in the box next to the following items.  BE SURE that these are the only items checked.
 

O4 - HKLM\..\Run: [9cd36c87] rundll32.exe "C:\WINDOWS\system32\oihqhmob.dll",b
 
O20 - Winlogon Notify: opnljjj - opnljjj.dll (file missing)

 
5.  Click on Fix Checked at the lower left of the Hijackthis window.  Confirm that you want HJT to fix these items and let it fix them.
 
6.  Close your HJT window and REBOOT.
 
7.  Run another HJT scan and post the log back here.
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
PcMac
Newbie
*





   


Posts: 16
Re: same problem for weeks now,
« Reply #14 on: Mar 30th, 2008, 9:17am »
Quote Quote  Modify Modify

cannot email log,as scans as virus
 
rebooted, heres newest scan  
 
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:14:48 PM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\iPod Access for Windows\iPAHelper.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\progra~1\1click~1\1cla.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TrojanHunter 5.0\THGuard.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\WinUtilities\ToolMemoryOptimizer.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Executive Software\Diskeeper\DfrgNTFS.exe
 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =  
F3 - REG:win.ini: load=C:\progra~1\1click~1\1cla.exe
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Network Magic Browser Helper - {07D7F044-2F5F-41B2-BAA5-936814AF0163} - C:\Program Files\Pure Networks\Network Magic\nmbrhlp2.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [WinUtilities Memory Optimizer] C:\Program Files\WinUtilities\ToolMemoryOptimizer.exe -hide
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [1cla.exe] c:\progra~1\1click~1\1cla.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Yahoo! Autosync.lnk = C:\Program Files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/clien t/wuweb_site.cab?1189706079109
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
 
--
End of file - 9595 bytes
IP Logged
Pages: 1 2  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print