Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan Infection


  • Please log in to reply
21 replies to this topic

#1 mr.weathers

mr.weathers

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:08:19 PM

Posted 08 February 2008 - 03:39 PM

i get like 5 runDLL errors everytime i boot up
spybot detected 2 traces of virtumonde, and it says it was removed
but i think its still here
sometimes i get popups for malware alarm, and windows explorer restarts alot


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:37:31 PM, on 2/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
Z:\program files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
Z:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
Z:\program files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
Z:\OLD SECRET FOLDER\Programs\YODM\Yodm3D.exe
Z:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Z:\program files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
Z:\program files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PWRISOVM.EXE] Z:\program files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NBKeyScan] "Z:\program files\Nero\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "Z:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Aim6] :"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Yodm3D] Z:\OLD SECRET FOLDER\Programs\YODM\Yodm3D.exe
O4 - HKCU\..\Run: [Microsoft SpA Service] hatred.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\storm\AppData\Local\Temp\mljjg.dll,#1
O4 - HKCU\..\Run: [AlcoholAutomount] "Z:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\storm\AppData\Local\Temp\rqrqr.dll,c
O4 - HKCU\..\Run: [MS Juan] rundll32 "C:\Users\storm\AppData\Local\Temp\dvpblhne.dll",run
O4 - HKCU\..\Run: [c8880be6] rundll32.exe "C:\Users\storm\AppData\Local\Temp\hfmgfhvt.dll",b
O4 - HKCU\..\Run: [SUPERAntiSpyware] Z:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] Z:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = Z:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Append to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://Z:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Z:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{41B1E71E-A382-4683-A1AA-CCBD797DA643}: NameServer = 4.2.2.2,4.2.2.3
O20 - Winlogon Notify: !SASWinLogon - Z:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - Z:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - Z:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - Z:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - Z:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - Z:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)

--
End of file - 12220 bytes

BC AdBot (Login to Remove)

 


#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 16 February 2008 - 04:08 AM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum.
My name is Richie and i'll be helping you to fix your problems.

Apologies for the late response,as i'm sure you can appreciate we are extremely busy.

If you've already recieved help at another forum and your issues have been resolved,or you're presently recieving help elsewhere then please let us know.

If you have not followed the info in the link below prior to posting your log then please do so now:
Preparation Guide for use before posting a HijackThis Log:
http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/

If you still require help,please post a new Hijackthis log into this topic in your next reply.

Also post a detailed description of the issues you're experiencing.

*Note*
Post all reports/logs directly into this topic,not as attachments,thanks.
Posted Image
Posted Image

#3 mr.weathers

mr.weathers
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:08:19 PM

Posted 21 February 2008 - 09:28 PM

Everytime i boot up my compputer, i get 5 RunDll errors
a couple weeks ago, McAfee detected one trace of virtumonde virus, and said that it successfully removed it,
but i still get the errors, and once evry few days i get a Blue screen that says "dumping physical memory" then reboots the computer
my computer is also running very slow
also, when i am on IE occasionally i get weird popups,
they are not advertisments, they are websites that i recently visited, that keep opening in new windows when i do not click anything
for example, i will get "google.com" open 5 times in 5 separate windows
and onetime it wouldnt stop so i had to restart my computer
any advice?

Scan saved at 9:23:37 PM, on 2/21/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Windows\RtHDVCpl.exe
Z:\program files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
Z:\program files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
Z:\program files\MagicDisc\MagicDisc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
Z:\program files\iTunes\iTunes.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Windows\explorer.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
E:\OLD SECRET FOLDER\Programs\Xpadder2008-02\Xpadder.exe
C:\Windows\system32\taskeng.exe
Z:\program files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PWRISOVM.EXE] Z:\program files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NBKeyScan] "Z:\program files\Nero\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "Z:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Aim6] :"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Microsoft SpA Service] hatred.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\storm\AppData\Local\Temp\mljjg.dll,#1
O4 - HKCU\..\Run: [AlcoholAutomount] "Z:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\storm\AppData\Local\Temp\rqrqr.dll,c
O4 - HKCU\..\Run: [MS Juan] rundll32 "C:\Users\storm\AppData\Local\Temp\dvpblhne.dll",run
O4 - HKCU\..\Run: [c8880be6] rundll32.exe "C:\Users\storm\AppData\Local\Temp\hfmgfhvt.dll",b
O4 - HKCU\..\Run: [SUPERAntiSpyware] Z:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] Z:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = Z:\program files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = Z:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Append to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://Z:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Z:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{41B1E71E-A382-4683-A1AA-CCBD797DA643}: NameServer = 4.2.2.2,4.2.2.3
O20 - Winlogon Notify: !SASWinLogon - Z:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - Z:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - Z:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - Z:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - Z:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - Z:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)

--
End of file - 12411 bytes

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 22 February 2008 - 06:51 AM

Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older versions of Sun Java,and then update.
1. Download the latest version of Java Runtime Environment (JRE)
2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u4'.
3. Click the "Download" button to the right.
4. Check the box that says: "Accept License Agreement".
5. The page will refresh.
6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.
7. Close any programs you may have running - especially your web browser.
8. Click Start and choose Control Panel:
- In Control Panel double click on the "Programs and Features" icon.
- Here you can find all the programs and items which are installed in Windows Vista.
- Now remove all older versions of Sun Java.
9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.
10. Click the Change/Remove button.
11. Repeat as many times as necessary to remove each Java versions.
12. Reboot your computer once all Java components are removed.
13. Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.


Please disable UAC [User Account Control].
1. Click Start and then click the picture at the top of the right column on the Start menu,this opens the User Accounts Control Panel.
2. Click Turn User Account Control on or off,you will have to respond to a UAC prompt to complete this action.
3. Clear the Use User Account Control (UAC) to help protect your computer check box and click OK.
4. Click Restart Now when prompted,after your computer restarts,UAC will be off.
You can repeat these steps to re-enable UAC,just click to select the check box in Step 3 when we've finished.


If you have previously downloaded ComboFix,please delete that version now.
Download Combofix by sUBs and save to your desktop.
Alternative Combofix download link HERE.
Note
It is important that it is saved directly to your desktop


Now close any open browsers.
Double click on Combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.
Note
Do not mouseclick combofix's window or do anything else on your pc while it's running.
That may cause the program/system to freeze/hang.

Do NOT post the ComboFix-quarantined-files.txt unless I ask.
Note
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Also post a new Hijackthis log please.
Posted Image
Posted Image

#5 mr.weathers

mr.weathers
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:08:19 PM

Posted 22 February 2008 - 05:18 PM

thanx for replying so fast




ComboFix 08-02-23 - storm 2008-02-22 17:05:48.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1066 [GMT -5:00]
Running from: C:\Users\storm\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat

----- BITS: Possible infected sites -----

hxxp://au.do
.
((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
.

2008-02-22 16:46 . 2008-02-22 16:46 <DIR> d----c--- C:\Program Files\Common Files\Java
2008-02-22 16:42 . 2008-02-22 16:42 54,156 --ah-c--- C:\Windows\QTFont.qfn
2008-02-22 16:42 . 2008-02-22 16:42 1,409 --a--c--- C:\Windows\QTFont.for
2008-02-22 16:11 . 2008-02-22 16:11 <DIR> d----c--- C:\Program Files\Sun
2008-02-20 18:01 . 2008-02-20 18:02 <DIR> d----c--- C:\Program Files\QuickTime
2008-02-19 16:34 . 2004-12-18 20:32 38,229 -----c--- C:\Windows\System32\drivers\StMp3Rec.sys
2008-02-19 16:33 . 2008-02-19 16:33 <DIR> d----c--- C:\Windows\Downloaded Installations
2008-02-18 19:03 . 2008-02-18 19:08 <DIR> d----c--- C:\New
2008-02-18 08:28 . 2008-02-18 08:28 <DIR> d----c--- C:\Program Files\NCH Software
2008-02-17 10:20 . 2008-02-20 16:47 <DIR> d----c--- C:\SHARED DOCUMENTS
2008-02-16 18:32 . 2008-02-16 18:32 <DIR> d----c--- C:\Windows\System32\RTCOM
2008-02-16 18:31 . 2008-02-16 18:31 <DIR> d----c--- C:\Program Files\Realtek
2008-02-16 11:32 . 2008-02-11 23:36 92,544 --a--c--- C:\Windows\System32\drivers\mcdbus.sys
2008-02-16 11:28 . 2008-02-16 11:28 <DIR> d----c--- C:\Program Files\Blast! Software
2008-02-16 11:28 . 1998-10-02 19:00 327,168 --a--c--- C:\Windows\IsUninst.exe
2008-02-16 11:28 . 2008-02-16 11:28 172 --a--c--- C:\Windows\PowerReg.dat
2008-02-16 09:33 . 2008-02-16 09:45 <DIR> d----c--- C:\Users\storm\AppData\Roaming\fretsonfire
2008-02-15 16:39 . 2008-02-15 16:39 1,244,672 --a------ C:\Windows\System32\mcmde.dll
2008-02-14 06:56 . 2008-02-14 06:56 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-14 06:56 . 2008-02-14 06:56 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 06:50 . 2008-02-14 06:50 3,504,696 --a------ C:\Windows\System32\ntkrnlpa.exe
2008-02-14 06:49 . 2008-02-14 06:49 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 06:49 . 2008-02-14 06:49 1,686,528 --a------ C:\Windows\System32\gameux.dll
2008-02-14 06:46 . 2008-02-14 06:46 1,831,424 --a------ C:\Windows\System32\inetcpl.cpl
2008-02-14 06:46 . 2008-02-14 06:46 56,320 --a------ C:\Windows\System32\iesetup.dll
2008-02-14 06:46 . 2008-02-14 06:46 26,624 --a------ C:\Windows\System32\ieUnatt.exe
2008-02-10 20:50 . 2008-02-11 19:53 <DIR> d----c--- C:\Users\storm\AppData\Roaming\gtk-2.0
2008-02-09 10:52 . 2008-02-09 10:52 <DIR> d----c--- C:\Windows\lhsp
2008-02-09 09:24 . 2008-02-17 08:43 223,238,449 --a--c--- C:\Windows\MEMORY.DMP
2008-02-08 23:04 . 2008-02-18 19:09 <DIR> d----c--- C:\loader2
2008-02-08 22:49 . 2008-02-14 16:23 <DIR> d----c--- C:\Users\storm\AppData\Roaming\.purple
2008-02-07 21:17 . 2008-02-07 21:18 <DIR> d----c--- C:\Program Files\Java
2008-02-07 18:27 . 2008-02-07 18:28 <DIR> d----c--- C:\Users\All Users\Lavasoft
2008-02-07 18:27 . 2008-02-07 18:28 <DIR> d----c--- C:\ProgramData\Lavasoft
2008-02-07 18:23 . 2008-02-08 06:14 <DIR> d----c--- C:\Users\All Users\Spybot - Search & Destroy
2008-02-07 18:23 . 2008-02-08 06:14 <DIR> d----c--- C:\ProgramData\Spybot - Search & Destroy
2008-02-05 21:09 . 2008-02-05 21:09 <DIR> d----c--- C:\Users\storm\AppData\Roaming\SUPERAntiSpyware.com
2008-02-05 21:09 . 2008-02-05 21:09 <DIR> d----c--- C:\Users\All Users\SUPERAntiSpyware.com
2008-02-05 21:09 . 2008-02-05 21:09 <DIR> d----c--- C:\ProgramData\SUPERAntiSpyware.com
2008-02-03 11:40 . 2008-02-03 11:40 579,584 --a------ C:\Windows\System32\icardagt.exe
2008-02-03 11:40 . 2008-02-03 11:40 88,576 --a------ C:\Windows\System32\infocardapi.dll
2008-02-03 11:40 . 2008-02-03 11:40 28,160 --a------ C:\Windows\System32\infocardcpl.cpl
2008-02-03 11:40 . 2008-02-03 11:40 11,776 --a------ C:\Windows\System32\icardres.dll
2008-02-03 11:39 . 2008-02-03 11:39 779,800 --a------ C:\Windows\System32\PresentationNative_v0300.dll
2008-02-03 11:39 . 2008-02-03 11:39 350,744 --a------ C:\Windows\System32\PresentationHost.exe
2008-02-03 11:39 . 2008-02-03 11:39 106,520 --a------ C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
2008-02-03 11:39 . 2008-02-03 11:39 33,304 --a------ C:\Windows\System32\PresentationHostProxy.dll
2008-02-03 11:31 . 2008-02-03 11:31 282,112 --a------ C:\Windows\System32\mscoree.dll
2008-02-03 11:31 . 2008-02-03 11:31 158,720 --a------ C:\Windows\System32\mscorier.dll
2008-02-03 11:31 . 2008-02-03 11:31 96,760 --a------ C:\Windows\System32\dfshim.dll
2008-02-03 11:31 . 2008-02-03 11:31 84,480 --a------ C:\Windows\System32\mscories.dll
2008-02-03 11:31 . 2008-02-03 11:31 41,984 --a------ C:\Windows\System32\netfxperf.dll
2008-02-02 23:28 . 2006-11-02 05:23 <DIR> dr------- C:\Users\LogMeInRemoteUser\Videos
2008-02-02 23:28 . 2006-11-02 05:23 <DIR> d-------- C:\Users\LogMeInRemoteUser\Saved Games
2008-02-02 23:28 . 2006-11-02 05:23 <DIR> dr------- C:\Users\LogMeInRemoteUser\Pictures
2008-02-02 23:28 . 2006-11-02 05:23 <DIR> dr------- C:\Users\LogMeInRemoteUser\Music
2008-02-02 23:28 . 2006-11-02 05:23 <DIR> dr------- C:\Users\LogMeInRemoteUser\Links
2008-02-02 23:28 . 2006-11-02 05:23 <DIR> dr------- C:\Users\LogMeInRemoteUser\Downloads
2008-02-02 23:28 . 2008-02-02 23:28 <DIR> dr------- C:\Users\LogMeInRemoteUser\Documents
2008-02-02 23:28 . 2006-11-02 06:18 <DIR> d--h----- C:\Users\LogMeInRemoteUser\AppData
2008-02-02 23:26 . 2008-02-02 23:26 1,024 --a--c--- C:\.rnd
2008-01-31 23:13 . 2008-01-31 23:13 90,112 --a--c--- C:\Windows\System32\QuickTimeVR.qtx
2008-01-31 23:13 . 2008-01-31 23:13 57,344 --a--c--- C:\Windows\System32\QuickTime.qts
2008-01-26 11:50 . 2008-02-22 16:44 13,244 --a--c--- C:\Windows\System32\Config.MPF
2008-01-26 11:49 . 2006-03-03 11:07 143,360 --a------ C:\Windows\System32\dunzip32.dll
2008-01-26 11:48 . 2007-06-25 10:57 171,240 --a--c--- C:\Windows\System32\drivers\mfehidk.sys
2008-01-26 11:48 . 2007-03-02 14:17 120,360 --a--c--- C:\Windows\System32\drivers\Mpfp.sys
2008-01-26 11:48 . 2007-06-25 14:54 71,496 --a--c--- C:\Windows\System32\drivers\mfeavfk.sys
2008-01-26 11:48 . 2007-06-25 10:57 37,480 --a--c--- C:\Windows\System32\drivers\mfesmfk.sys
2008-01-26 11:48 . 2007-06-25 10:57 34,184 --a--c--- C:\Windows\System32\drivers\mfebopk.sys
2008-01-26 11:48 . 2007-06-25 10:57 32,008 --a--c--- C:\Windows\System32\drivers\mferkdk.sys
2008-01-26 11:47 . 2008-01-26 11:47 <DIR> d----c--- C:\Program Files\McAfee.com
2008-01-26 11:47 . 2008-01-26 17:23 <DIR> d----c--- C:\Program Files\McAfee
2008-01-26 11:47 . 2008-01-26 11:49 <DIR> d----c--- C:\Program Files\Common Files\McAfee
2008-01-26 11:40 . 2008-01-26 11:50 <DIR> d----c--- C:\Users\All Users\McAfee
2008-01-26 11:40 . 2008-01-26 11:50 <DIR> d----c--- C:\ProgramData\McAfee
2008-01-25 23:31 . 2008-02-20 18:05 <DIR> d----c--- C:\Program Files\iPod
2008-01-25 23:01 . 2008-02-20 21:26 <DIR> d----c--- C:\Users\storm\AppData\Roaming\DVD Flick
2008-01-25 23:01 . 2004-03-09 00:00 212,240 --a--c--- C:\Windows\System32\richtx32.ocx
2008-01-25 23:01 . 2000-05-19 17:56 81,920 --a--c--- C:\Windows\System32\mbmouse.ocx
2008-01-25 23:01 . 2000-11-05 15:27 36,864 --a--c--- C:\Windows\System32\trayicon.ocx
2008-01-25 15:52 . 2004-03-22 15:17 24,816 --a------ C:\Windows\System32\mdimon.dll
2008-01-25 15:52 . 2008-01-25 15:52 376 --a--c--- C:\Windows\ODBC.INI
2008-01-25 15:50 . 2008-01-25 15:50 <DIR> d----c--- C:\Program Files\Microsoft ActiveSync
2008-01-25 15:50 . 2008-01-25 15:50 <DIR> d----c--- C:\Program Files\Common Files\L&H
2008-01-25 15:49 . 2008-01-25 15:54 <DIR> d----c--- C:\Program Files\Microsoft Works
2008-01-25 15:48 . 2008-01-25 15:48 <DIR> d----c--- C:\Windows\PCHEALTH
2008-01-25 15:48 . 2008-01-25 15:48 <DIR> d----c--- C:\Program Files\Microsoft.NET
2008-01-24 16:41 . 2008-01-24 16:41 49 --a--c--- C:\Windows\NeroDigital.ini
2008-01-24 16:40 . 2004-05-26 21:37 719,872 --a--c--- C:\Windows\System32\devil.dll
2008-01-24 16:40 . 2003-03-19 11:03 544,768 --a--c--- C:\Windows\System32\msvcr71d.dll
2008-01-24 16:40 . 2002-01-05 14:37 344,064 --a--c--- C:\Windows\System32\msvcr70.dll
2008-01-24 16:40 . 2006-09-16 19:44 314,368 --a--c--- C:\Windows\System32\avisynth.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 22:04 6,736 -c--a-w C:\Windows\system32\drivers\PROCEXP90.SYS
2008-02-21 22:43 --------- dc----w C:\ProgramData\Google Updater
2008-02-19 21:34 --------- dc-h--w C:\Program Files\InstallShield Installation Information
2008-02-16 23:31 319,456 -c--a-w C:\Windows\DIFxAPI.dll
2008-02-16 23:31 315,392 -c--a-w C:\Windows\HideWin.exe
2008-02-16 20:21 --------- dc----w C:\ProgramData\FLEXnet
2008-02-14 21:23 --------- dc----w C:\Users\storm\AppData\Roaming\.purple
2008-02-14 11:50 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-14 11:50 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-14 11:50 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 11:50 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 11:50 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 11:50 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-14 11:50 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-14 11:50 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 11:50 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-14 11:50 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-02-14 11:50 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-14 11:49 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 11:49 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 11:49 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 11:49 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 11:47 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 11:46 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-07 23:26 --------- dc----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-30 19:24 715,248 ----a-w C:\Windows\system32\drivers\sptd.sys
2008-01-26 16:51 --------- dc--a-w C:\ProgramData\TEMP
2008-01-26 15:27 --------- dc----w C:\Program Files\Common Files\Symantec Shared
2008-01-26 04:29 --------- dc----w C:\Program Files\Bonjour
2008-01-22 19:59 --------- dc----w C:\ProgramData\Symantec
2008-01-22 19:56 --------- dc----w C:\Program Files\AGEIA Technologies
2008-01-22 17:46 --------- dc----w C:\Users\storm\AppData\Roaming\InstallShield Installation Information
2008-01-22 16:41 --------- dc----w C:\Program Files\Google
2008-01-21 23:03 22,328 -c--a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-01-21 23:03 103,736 -c--a-w C:\Windows\System32\PnkBstrB.exe
2008-01-20 21:04 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-01-14 20:51 22,328 -c--a-w C:\Users\storm\AppData\Roaming\PnkBstrK.sys
2008-01-13 19:23 219 -c--a-w C:\data1.bin
2008-01-13 16:03 --------- dc----w C:\ProgramData\Roxio
2008-01-13 16:03 --------- dc----w C:\Program Files\Common Files\Roxio Shared
2008-01-13 15:52 --------- dc----w C:\ProgramData\F-Secure
2008-01-13 15:44 --------- dc----w C:\Users\storm\AppData\Roaming\F-Secure
2008-01-13 15:29 --------- dc----w C:\ProgramData\fssg
2008-01-10 23:06 --------- dc----w C:\Program Files\NCH Swift Sound
2008-01-10 21:06 98,304 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-01-10 21:01 --------- dc----w C:\Program Files\Common Files\InstallShield
2008-01-09 08:05 --------- dc----w C:\Program Files\Windows Sidebar
2008-01-09 08:05 --------- dc----w C:\Program Files\Windows Mail
2008-01-09 00:05 --------- dc----w C:\Program Files\Common Files\Adobe
2008-01-08 20:41 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-01-08 20:41 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-08 20:41 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-01-08 00:36 --------- dc----w C:\Users\storm\AppData\Roaming\Ahead
2008-01-08 00:35 --------- dc----w C:\Program Files\Ahead
2008-01-08 00:33 --------- dc----w C:\ProgramData\Ahead
2008-01-08 00:33 --------- dc----w C:\Program Files\Common Files\Ahead
2008-01-08 00:16 --------- dc----w C:\Users\storm\AppData\Roaming\Roxio
2008-01-08 00:08 --------- dc----w C:\ProgramData\Sonic
2008-01-08 00:07 --------- dc----w C:\ProgramData\InstallShield
2008-01-07 23:54 --------- dc----w C:\ProgramData\Nero
2008-01-07 23:54 --------- dc----w C:\Program Files\Common Files\Nero
2008-01-07 23:40 --------- dc----w C:\ProgramData\Avg7
2008-01-07 00:10 --------- dc----w C:\Users\storm\AppData\Roaming\SoundSpectrum
2008-01-07 00:08 --------- dc----w C:\Program Files\SoundSpectrum
2008-01-06 20:55 --------- dc----w C:\ProgramData\AOL OCP
2008-01-06 20:55 --------- dc----w C:\Program Files\Windows Defender
2008-01-06 20:55 --------- dc----w C:\Program Files\Windows Calendar
2008-01-06 20:54 --------- dc----w C:\Users\storm\AppData\Roaming\acccore
2008-01-06 20:54 --------- dc----w C:\ProgramData\AOL
2008-01-06 20:54 --------- dc----w C:\Program Files\AIM6
2008-01-06 20:52 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-01-06 20:51 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-01-06 20:51 376,320 ----a-w C:\Windows\System32\winsrv.dll
2008-01-06 20:49 229,888 ----a-w C:\Windows\System32\msshsq.dll
2008-01-06 20:49 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2008-01-06 20:49 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-01-06 20:48 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-01-06 20:46 --------- dc----w C:\Program Files\ATI Technologies
2008-01-06 20:28 174 --sha-w C:\Program Files\desktop.ini
2008-01-06 18:50 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-01-06 18:50 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2008-01-06 18:50 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2008-01-06 18:50 39,936 ----a-w C:\Windows\System32\slcinst.dll
2008-01-06 18:50 351,232 ----a-w C:\Windows\System32\SLUI.exe
2008-01-06 18:50 33,280 ----a-w C:\Windows\System32\slwmi.dll
2008-01-06 18:50 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2008-01-06 18:50 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-01-06 18:50 223,232 ----a-w C:\Windows\System32\SLC.dll
2008-01-06 18:50 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2008-01-06 18:50 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2008-01-06 18:49 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2008-01-06 18:47 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-01-06 18:46 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-01-06 18:46 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2008-01-06 18:46 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-01-06 18:46 5,120 ----a-w C:\Windows\System32\wmi.dll
2008-01-06 18:46 152,576 ----a-w C:\Windows\System32\imagehlp.dll
2008-01-06 18:46 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-01-06 18:46 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 07:35 125440]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [ ]
"Aim6"=":C:\Program Files\AIM6\aim6.exe" [ ]
"Microsoft SpA Service"="hatred.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-22 11:30 68856]
"MSServer"="C:\Users\storm\AppData\Local\Temp\mljjg.dll" [ ]
"AlcoholAutomount"="Z:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-12-22 02:23 221568]
"cmds"="C:\Users\storm\AppData\Local\Temp\rqrqr.dll" [ ]
"MS Juan"="C:\Users\storm\AppData\Local\Temp\dvpblhne.dll" [ ]
"c8880be6"="C:\Users\storm\AppData\Local\Temp\hfmgfhvt.dll" [ ]
"SUPERAntiSpyware"="Z:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
"SpybotSD TeaTimer"="Z:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-06 15:51 1006264]
"PWRISOVM.EXE"="Z:\program files\PowerISO\PWRISOVM.EXE" [2007-08-06 19:05 200704]
"NBKeyScan"="Z:\program files\Nero\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]
"NeroFilterCheck"="C:\Windows\system32\NeroCheck.exe" [2001-07-09 05:50 155648]
"Acrobat Assistant 8.0"="Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 23:24 620152]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-14 15:50 4399104 C:\Windows\RtHDVCpl.exe]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="Z:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 14:18 267048]
"SunJavaUpdateSched"="Z:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]

C:\Users\storm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - Z:\program files\MagicDisc\MagicDisc.exe [2008-02-16 11:32:50 546816]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2008-01-08 19:08:42 295606]
Adobe Acrobat Synchronizer.lnk - Z:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-01-22 11:30:20 124400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= Z:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
Z:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 Z:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=0 (0x0)

R0 hotcore3;hotcore3;C:\Windows\system32\drivers\hotcore3.sys [2007-03-07 13:27]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-09-29 03:13]
R3 netr73;Linksys Compact Wireless-G USB Adapter Driver for Vista;C:\Windows\system32\DRIVERS\WUSB54GCx86.sys [2007-03-12 10:12]
R3 VST_DPV;VST_DPV;C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 02:41]
R3 VSTHWBS2;VSTHWBS2;C:\Windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 02:41]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a47fe32-d8e0-11dc-b4f4-001aa080f942}]
\shell\AutoRun\command - H:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2008-02-15 07:05:11 C:\Windows\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-01-26 22:23:36 C:\Windows\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-02-23 22:10:02 C:\Windows\Tasks\User_Feed_Synchronization-{D4218DA1-4F22-4B40-928D-2E0E6CA3AF18}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 17:10:29
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-23 17:11:19
ComboFix-quarantined-files.txt 2008-02-23 22:11:16
.
2008-02-15 23:02:54 --- E O F ---





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:16:41 PM, on 2/23/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
Z:\program files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
Z:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Windows\RtHDVCpl.exe
Z:\program files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
Z:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\ehome\ehmsas.exe
Z:\Program Files\iTunes\iTunes.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\AIM6\aim6.exe
E:\OLD SECRET FOLDER\Programs\Xpadder2008-02\Xpadder.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\AIM6\aolsoftware.exe
Z:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
Z:\program files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - Z:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PWRISOVM.EXE] Z:\program files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NBKeyScan] "Z:\program files\Nero\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "Z:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "Z:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Aim6] :"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Microsoft SpA Service] hatred.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "Z:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SUPERAntiSpyware] Z:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] Z:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = Z:\program files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = Z:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Append to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://Z:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Z:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Z:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Z:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{41B1E71E-A382-4683-A1AA-CCBD797DA643}: NameServer = 4.2.2.2,4.2.2.3
O20 - Winlogon Notify: !SASWinLogon - Z:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - Z:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - Z:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - Z:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - Z:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - Z:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)

--
End of file - 115

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 22 February 2008 - 05:33 PM

Disable Windows Defender's real-time protection,as it may interfere.
* Open Microsoft Windows Defender. Click Start>All Programs>Windows Defender.
* Click on 'Tools'>'Options'.
* Under 'Real-time protection options', unselect the 'Turn on real-time protection' check box
* Click 'Save'.

Please disable Spybot S&D’s protection,or it will interfere.
You can enable it after you're clean.

Open Spybot and click on 'Mode' and check 'Advanced Mode'.
Click on 'Tools' in bottom left hand corner.
Click on the 'System Startup' icon.
Uncheck 'Teatimer' box and/or uncheck 'Resident'.
Click the 'Allow Change' box.
Then, check next to the computer clock to see if the icon for Spybot is still there.
If it is, right click it and choose 'exit Spybot-S&D Resident'.
Restart the computer.
If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:
http://www.russelltexas.com/malware/teatimer.htm


Copy and paste ALL the following text in the code box below into Notepad.
Click on Start/All Programs/Accessories/Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fix.reg to your desktop.
Then double click on the fix.reg file on your desktopPosted Imageand agree to merge the information into the registry,then restart your pc.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cmds"=-
"MS Juan"=-
"c8880be6"=-


Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)


Restart your pc.
post a new Hijackthis log,let me know how your pc is running now please.
Posted Image
Posted Image

#7 mr.weathers

mr.weathers
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:08:19 PM

Posted 23 February 2008 - 09:23 AM

The DLL errors stopped, so i guess thats progress
but whenever i open IE i get an "invalid address" box but when i close it, IE opens normally

as soon as i did the fix.reg things, my internet wont work
i can connect to the local network, but not to the internet
did i do something wrong?

heres the hi-jack this log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:59 AM, on 2/24/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
Z:\program files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
Z:\program files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe
C:\Windows\RtHDVCpl.exe
Z:\program files\iTunes\iTunesHelper.exe
Z:\program files\Java\jre1.6.0_04\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
Z:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
Z:\program files\MagicDisc\MagicDisc.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
Z:\Program Files\iTunes\iTunes.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Windows\system32\wbem\unsecapp.exe
Z:\program files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - Z:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PWRISOVM.EXE] Z:\program files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NBKeyScan] "Z:\program files\Nero\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "Z:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "Z:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Aim6] :"C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Microsoft SpA Service] hatred.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "Z:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SUPERAntiSpyware] Z:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = Z:\program files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = Z:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Append to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://Z:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://Z:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Z:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Z:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - Z:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - Z:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{41B1E71E-A382-4683-A1AA-CCBD797DA643}: NameServer = 4.2.2.2,4.2.2.3
O20 - Winlogon Notify: !SASWinLogon - Z:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - Z:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - Z:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - Z:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - Z:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - Z:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)

--
End of file - 10955 bytes

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 23 February 2008 - 09:50 AM

That's odd,that certainly should not have happened.
First try temporarily disabling McAfee Personal Firewall.

If you still can't connect to the internet,try this:
Click on Start/All Programs/Accessories/Run,type CMD then press Ok.
At the command prompt copy and paste NETSH WINSOCK RESET then press Enter.
At the command prompt copy and paste IPCONFIG /FLUSHDNS then press Enter.
At the command prompt copy and paste NETSH WINSOCK RESET CATALOG then press Enter.
Type EXIT press Enter again,restart your pc.
Now try connecting to the internet.

If still no joy try the following,make sure you read the info before making a start.
Reset Internet Explorer settings [RIES]:
http://windowshelp.microsoft.com/Windows/e...7fe1771033.mspx

Edited by RichieUK, 23 February 2008 - 09:51 AM.

Posted Image
Posted Image

#9 mr.weathers

mr.weathers
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:08:19 PM

Posted 23 February 2008 - 10:26 AM

still not working
i noticed that the regedit you gave me
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cmds"=-
"MS Juan"=-
"c8880be6"=-


says CMDS, is that possibly a typo?
im saying this, not to doubt you, just because the internet problems occured right after doing merging the values to my registry

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 23 February 2008 - 10:58 AM

says CMDS, is that possibly a typo?
im saying this, not to doubt you, just because the internet problems occured right after doing merging the values to my registry

Nope,its not a typo?

I missed this one:
Copy and paste ALL the following text in the code box below into Notepad.
Click on Start/All Programs/Accessories/Notepad.
Click on File(in the menu at the top)>Save as../Save as Type: 'All Files' /File name: fixA.reg to your desktop.
Then double click on the fixA.reg file on your desktopPosted Imageand agree to merge the information into the registry,then restart your pc.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSServer"=-

If still no joy,try restoring your system back to when your internet worked using System Restore.
Using Windows Vista System Restore:
http://www.howtogeek.com/howto/windows-vis...system-restore/
Scroll down to 'Restore system files and settings'.
Posted Image
Posted Image

#11 mr.weathers

mr.weathers
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:08:19 PM

Posted 23 February 2008 - 12:26 PM

tht didnt work either
i think combofix made a restore point, but i dont see it in the system restore window
other than that i dont have any restore points,
so is there a way i can undo the registry changes i added?

Edited by mr.weathers, 23 February 2008 - 12:35 PM.


#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 23 February 2008 - 03:19 PM

so is there a way i can undo the registry changes i added?

I cannot see how restoring malware entries to the registry will help.

See if the following helps:

Repair Your Internet Connection With Diagnose And Repair In Windows Vista:
http://www.adamsdvds.co.uk/tutorials/vista...ernet/index.php
http://vistarewired.com/2007/07/02/repairi...net-connection/

Reinstall and Reset TCP/IP (Internet Protocol) in Windows Vista, 2003 and XP:
http://www.mydigitallife.info/2007/06/19/r...ta-2003-and-xp/
Posted Image
Posted Image

#13 mr.weathers

mr.weathers
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:08:19 PM

Posted 23 February 2008 - 05:24 PM

those things didnt work either,
it seems those are problems related to not being able to connect to a network,
i AM connected
it show my computer on the web UI of the router, and and i can transfer files inside the network

i just cannot connect to the internet
is there a way to acces the system restore point created by combofix?

#14 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:01:19 AM

Posted 23 February 2008 - 06:15 PM

While Combofix was running,it may have backed up the registry.
Look in C:\WINDOWS for a folder named ERDNT,open that folder and look for ERDNT.EXE
If its present double click on ERDNT.EXE and follow the prompts.
Posted Image
Posted Image

#15 mr.weathers

mr.weathers
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:08:19 PM

Posted 23 February 2008 - 06:29 PM

there is, i will do this when i come home, but i have to leave right now


thank you, iwould have never found that
i will repost as soon as i try it



OK i did the restore thing, and now my internet is working, and i will create a restore point...
but i get the RunDLL errors agin,
is this something i should just learn to live with?

Edited by mr.weathers, 23 February 2008 - 11:42 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users