Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Worm. Need Help! Dss Log Included


  • This topic is locked This topic is locked
2 replies to this topic

#1 P1Armydg

P1Armydg

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:55 AM

Posted 15 April 2008 - 08:01 PM

Deckard's System Scanner v20071014.68
Run by Owner on 2008-04-15 16:48:13
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
62: 2008-04-16 00:48:26 UTC - RP795 - Deckard's System Scanner Restore Point
61: 2008-04-16 00:29:48 UTC - RP794 - Removed Panda Internet Security 2008
60: 2008-04-15 01:17:43 UTC - RP793 - Installed Panda Internet Security 2008
59: 2008-04-15 00:35:41 UTC - RP792 - Software Distribution Service 3.0
58: 2008-04-15 00:09:20 UTC - RP791 - Last known good configuration


-- First Restore Point --
1: 2008-04-15 00:08:41 UTC - RP734 - Installed Scrabble Complete


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 84% (more than 75%).
Total Physical Memory: 448 MiB (512 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-04-15 16:54:18
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\itqzonwh\krmfivaz.exe
C:\WINDOWS\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon05.exe
C:\hp\KBD\kbd.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\ltmsg.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\obonmhaj.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\Runservice.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\interMute\SpamSubtract\SpamSub.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Documents and Settings\Owner\Desktop\dss.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.search.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Cox High Speed Internet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spy Class - {1DBB09FF-5697-4E4A-B138-1428E2DB5B20} - C:\WINDOWS\system32\ietbr.dll
O2 - BHO: (no name) - {36FEC1A7-01EC-43D1-95BA-2572A78626C9} - C:\WINDOWS\system32\awtsSihg.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DVA Storm - {5B434315-59C8-4480-8E72-058282FAAF1E} - C:\WINDOWS\lgmxvpatqgl.dll
O2 - BHO: (no name) - {C14E6230-757D-4246-81CE-B34E2940C722} - C:\WINDOWS\system32\jkkHAtst.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: {B5AB638F-D76C-415B-A8F2-F3CEAC502212} - - (no file)
O3 - Toolbar: PopUp Blocker and Web Privacy Manager - {BC97B254-B2B9-4D40-971D-78E0978F5F26}} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: qtvglped - {C130E860-7C1C-44F0-996C-1F995C10B61E} - C:\WINDOWS\qtvglped.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
O4 - HKLM\..\Run: [SpamExtract] C:\PROGRA~1\SPAMEX~1\oeSpamExtractLdr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [5c15cdd3] rundll32.exe "C:\WINDOWS\system32\kgoxkqcn.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [dzutwtcx] C:\WINDOWS\system32\obonmhaj.exe
O4 - HKLM\..\Policies\Explorer\Run: [Loo1lf7k4p] C:\Documents and Settings\All Users\Application Data\itqzonwh\krmfivaz.exe
O4 - Startup: FriendFinder Messenger.lnk = ?
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {CB97291A-6603-466A-AA11-80C2EB74CB10} (CoxSelfInstallAx10 Control) - https://install.cox.net/CoxSelfInstall/CoxS...InstallAx10.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://l.yimg.com/jh/games/web_games/popca...aploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} () - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O20 - AppInit_DLLs: NVDESK32.DLL
O20 - Winlogon Notify: jkkHAtst - C:\WINDOWS\system32\jkkHAtst.dll
O21 - SSODL: pmsoarbf - {5705DBA7-757F-4331-8E77-71A93A307CA7} - C:\WINDOWS\pmsoarbf.dll
O21 - SSODL: omlbpkaw - {1A0381CF-6405-4965-9AA6-A4A76669B5F7} - C:\WINDOWS\omlbpkaw.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\Runservice.exe
O23 - Service: NNServ - Unknown owner - C:\Program Files\NewDotNet\nnrun.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 11358 bytes

-- File Associations -----------------------------------------------------------

.scr - AutoCADScriptFile - shell\open\command - "C:\WINDOWS\system32\notepad.exe" "%1"


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

All drivers whitelisted.


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour>
R2 LicCtrlService (LicCtrl Service) - c:\windows\runservice.exe
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>

S2 NNServ - "c:\program files\newdotnet\nnrun.exe" "c:\program files\newdotnet\nncore.dll" servicestart (file missing)


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2008-04-15 16:51:01 366 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
2008-04-04 17:28:19 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


-- Files created between 2008-03-15 and 2008-04-15 -----------------------------

2008-04-15 16:32:46 0 d-------- C:\WINDOWS\privacy_danger
2008-04-14 17:31:00 0 d-------- C:\Documents and Settings\Owner\Application Data\TmpRecentIcons
2008-04-14 17:26:09 0 d-------- C:\Documents and Settings\All Users\Application Data\sentinel
2008-04-14 17:19:29 0 d-------- C:\Documents and Settings\All Users\Application Data\Backup
2008-04-14 17:14:20 0 d-------- C:\Program Files\Common Files\Panda Software
2008-04-14 16:11:30 85056 --a------ C:\WINDOWS\system32\kgoxkqcn.dll
2008-04-14 16:10:04 3648 --a------ C:\WINDOWS\system32\thcjdxhe.dll
2008-04-14 16:08:29 197124 --ahs---- C:\WINDOWS\system32\ghiSstwa.ini2
2008-04-14 16:08:22 273408 --a------ C:\WINDOWS\system32\awtsSihg.dll
2008-04-14 16:02:07 98304 --a------ C:\WINDOWS\rtqmekwg.exe
2008-04-14 16:02:07 200704 --a------ C:\WINDOWS\qtvglped.dll
2008-04-14 16:02:07 188416 --a------ C:\WINDOWS\pmsoarbf.dll
2008-04-14 16:02:07 217088 --a------ C:\WINDOWS\omlbpkaw.dll
2008-04-14 16:02:07 94208 --a------ C:\WINDOWS\npqtsrak.exe
2008-04-14 16:02:07 245760 --a------ C:\WINDOWS\lgmxvpatqgl.dll
2008-04-14 16:01:52 0 d-------- C:\Documents and Settings\All Users\Application Data\itqzonwh
2008-04-14 16:01:51 94208 --a------ C:\WINDOWS\system32\obonmhaj.exe
2008-04-14 16:01:51 40448 --a------ C:\WINDOWS\system32\hgGxWnLb.dll
2008-04-14 16:01:40 40448 --a------ C:\WINDOWS\system32\qoMfcYsp.dll
2008-04-14 16:01:24 40448 --a------ C:\WINDOWS\system32\jkkHAtst.dll
2008-04-06 10:48:10 0 d-------- C:\Documents and Settings\LocalService\Application Data\Mozilla
2008-04-05 18:25:46 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-04-04 17:49:18 0 d-------- C:\Program Files\Icy Spell
2008-04-04 17:48:58 0 d-------- C:\Program Files\ReflexiveArcade
2008-04-03 19:14:50 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-02 19:19:28 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-02 19:16:58 0 d-------- C:\WINDOWS\system32\LogFiles
2008-04-02 19:16:58 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-04-02 19:15:15 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-04-02 19:13:25 0 d-------- C:\Program Files\Netflix
2008-03-22 12:21:07 0 d-------- C:\Program Files\iTunes
2008-03-22 12:20:11 0 d-------- C:\Program Files\Bonjour
2008-03-22 12:15:41 0 d-------- C:\Program Files\Apple Software Update
2008-03-22 12:15:26 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-03-22 12:14:59 0 d-------- C:\Program Files\Common Files\Apple
2008-03-22 12:14:57 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple


-- Find3M Report ---------------------------------------------------------------

2008-04-15 16:34:40 0 d-------- C:\Documents and Settings\Owner\Application Data\LimeWire
2008-04-15 16:32:17 1129 --ahs---- C:\WINDOWS\system32\mmf.sys
2008-04-15 16:31:28 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-04-14 19:42:03 0 d-------- C:\Documents and Settings\Owner\Application Data\interMute
2008-04-14 19:39:58 0 d-------- C:\Program Files\PokerStars.NET
2008-04-14 17:30:31 0 d-------- C:\Program Files\Common Files
2008-04-14 16:35:54 0 d-------- C:\Documents and Settings\Owner\Application Data\Lavasoft
2008-04-14 16:07:49 0 d-------- C:\Program Files\Gluz
2008-04-12 11:32:20 0 d-------- C:\Program Files\Starcraft
2008-04-03 19:14:50 0 d-------- C:\Documents and Settings\Owner\Application Data\Yahoo!
2008-04-03 17:47:07 0 d-------- C:\Program Files\Yahoo! Games
2008-03-22 12:21:28 0 d-------- C:\Program Files\iPod
2008-03-22 12:19:00 0 d-------- C:\Program Files\QuickTime
2008-03-13 16:50:39 0 d-------- C:\Program Files\LimeWire
2008-03-13 16:48:26 0 d-------- C:\Program Files\Setup NetZero
2008-02-27 18:16:24 0 d-------- C:\Program Files\PacificPoker4
2008-02-26 21:01:27 0 d-------- C:\Documents and Settings\Owner\Application Data\Autodesk
2008-02-26 20:59:35 0 d-------- C:\Program Files\Common Files\Autodesk Shared
2008-02-26 20:56:30 0 d-------- C:\Program Files\AnswerWorks 4.0
2008-02-26 20:54:45 0 d-------- C:\Program Files\Autodesk
2008-02-26 18:51:55 0 d-------- C:\Program Files\Game House
2008-02-26 18:41:18 0 d-------- C:\Documents and Settings\Owner\Application Data\Creative
2008-02-26 18:07:16 14 --a----c- C:\WINDOWS\popcinfo.dat
2008-02-26 17:57:12 0 d-------- C:\Program Files\Yahoo!
2008-02-23 22:16:55 0 d-------- C:\Program Files\Oberon Media
2008-02-16 18:17:22 0 d-------- C:\Documents and Settings\Owner\Application Data\IBMERS
2008-02-13 17:16:19 967 --a------ C:\WINDOWS\ScUnin.pif
2008-02-13 17:16:19 94208 --a------ C:\WINDOWS\ScUnin.exe <Not Verified; Blizzard Entertainment; Starcraft Uninstaller>
2008-02-13 17:16:19 13044 --a------ C:\WINDOWS\scunin.dat


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1DBB09FF-5697-4E4A-B138-1428E2DB5B20}]
06/18/2004 06:14 PM 98304 --a------ C:\WINDOWS\system32\ietbr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36FEC1A7-01EC-43D1-95BA-2572A78626C9}]
04/14/2008 04:08 PM 273408 --a------ C:\WINDOWS\system32\awtsSihg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5B434315-59C8-4480-8E72-058282FAAF1E}]
04/14/2008 11:11 AM 245760 --a------ C:\WINDOWS\lgmxvpatqgl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C14E6230-757D-4246-81CE-B34E2940C722}]
04/14/2008 04:01 PM 40448 --a------ C:\WINDOWS\system32\jkkHAtst.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 04:04 PM]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [08/21/2003 03:23 AM]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [08/21/2003 03:15 AM]
"KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 07:02 PM]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [08/19/2003 08:01 AM]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [11/03/2003 04:50 PM]
"VTTimer"="VTTimer.exe" [10/22/2004 11:53 AM C:\WINDOWS\system32\VTTimer.exe]
"LTMSG"="LTMSG.exe" [07/14/2003 05:52 PM C:\WINDOWS\ltmsg.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [10/16/2002 03:57 PM]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [03/12/2003 04:23 AM]
"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 01:47 PM C:\WINDOWS\ALCXMNTR.EXE]
"gah95on6"="C:\WINDOWS\system32\gah95on6.exe" []
"SpamExtract"="C:\PROGRA~1\SPAMEX~1\oeSpamExtractLdr.exe" [01/11/2005 05:41 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" [03/04/2005 03:36 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [01/31/2008 11:13 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [02/19/2008 01:10 PM]
"5c15cdd3"="C:\WINDOWS\system32\kgoxkqcn.dll" [04/14/2008 04:11 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" []
"Registry Cleaner"="C:\Program Files\Registry Cleaner\RegClean.exe" []
"BackupNotify"="c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [01/09/2004 01:34 AM]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [09/28/2006 08:09 PM]
"dzutwtcx"="C:\WINDOWS\system32\obonmhaj.exe" [04/14/2008 04:01 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
"Loo1lf7k4p"=C:\Documents and Settings\All Users\Application Data\itqzonwh\krmfivaz.exe

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{C14E6230-757D-4246-81CE-B34E2940C722}"= C:\WINDOWS\system32\jkkHAtst.dll [04/14/2008 04:01 PM 40448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"pmsoarbf"= {5705DBA7-757F-4331-8E77-71A93A307CA7} - C:\WINDOWS\pmsoarbf.dll [04/14/2008 11:11 AM 188416]
"omlbpkaw"= {1A0381CF-6405-4965-9AA6-A4A76669B5F7} - C:\WINDOWS\omlbpkaw.dll [04/14/2008 11:11 AM 217088]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkHAtst]
jkkHAtst.dll 04/14/2008 04:01 PM 40448 C:\WINDOWS\system32\jkkHAtst.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=NVDESK32.DLL

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\awtsSihg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-04-15 16:56:07 ------------

BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:02:55 AM

Posted 27 April 2008 - 12:44 PM

Hello P1Armydg,

Welcome to Bleeping Computer :blink:

Sorry about the delay.:thumbsup: If you still need help, please post a new HijackThis log to make sure nothing has changed, and I'll be happy to look at it for you.

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:02:55 AM

Posted 07 May 2008 - 09:36 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users