Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bug, Trojans, Popups All Over The Place..help


  • This topic is locked This topic is locked
13 replies to this topic

#1 sportman32922

sportman32922

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 14 May 2008 - 03:48 PM

i am in desperate need of help..i have bugs , bugs and more bugs..i cant really anything my start up screen just glitches when i try to go to my computer or to the control panel. it also changes to red or blue. i also have pop ups galor when it was switching..help me please..ive tried deleting the user screen and it doesnt even let me do that either..helppp

BC AdBot (Login to Remove)

 


#2 sportman32922

sportman32922
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 14 May 2008 - 10:58 PM

helllppp

Deckard's System Scanner v20071014.68
Run by Administrator on 2008-05-14 22:46:26
Computer is in Safe Mode with Networking.
--------------------------------------------------------------------------------



-- HijackThis (run as Administrator.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:47:03 PM, on 5/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\wmsdkns.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\N8XCRF41\dss[1].exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrator.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wmsdkns.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {02834062-9DEA-45FA-909B-BBE101BF8AC2} - C:\WINDOWS\system32\iifggeEw.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: cpmsky browser optimizer - {1d4d4d8b-f882-9954-bd2c-90d13be73db5} - C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll
O2 - BHO: AddTask Class - {24F06550-65E3-4D1C-8CFE-839C296B5530} - C:\Program Files\eread7.0\IEeREAD.dll
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: AddTask Class - {6A19C29D-ED45-4483-8999-9F939C8161F2} - C:\Program Files\eread7.0\WebHook.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {9DDC3DD3-F637-F199-1594-D38F035178C2} - C:\WINDOWS\system32\wvgroye.dll
O2 - BHO: (no name) - {A7646A99-6448-42E5-9B9F-8D73E4C19086} - C:\WINDOWS\system32\ddcArRjh.dll
O2 - BHO: (no name) - {AAE34D58-ACF8-43F8-B99E-5327735CBB27} - C:\WINDOWS\system32\yayxWnkk.dll
O2 - BHO: (no name) - {B31BD6AE-F538-44E8-A7E3-7B733A16F748} - C:\WINDOWS\system32\jkkHAspP.dll
O2 - BHO: (no name) - {C6EE2ED9-3B65-493C-82AC-6E70AC6E11D7} - C:\WINDOWS\system32\cbXOEtro.dll
O2 - BHO: (no name) - {C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8} - C:\WINDOWS\system32\opnlMcbx.dll
O2 - BHO: (no name) - {CBDFB4FE-CC65-40B1-938B-45F317F592C8} - C:\WINDOWS\system32\awtqnopP.dll
O2 - BHO: {cee33c47-f06f-ca29-a0a4-acf63e7c29cc} - {cc92c7e3-6fca-4a0a-92ac-f60f74c33eec} - C:\WINDOWS\system32\dgjasoeq.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O2 - BHO: Microsoft copyright - {FFFFFFFF-BBBB-4146-86FD-A722E8AB3489} - sockins32.dll (file missing)
O3 - Toolbar: Yahoo! uC - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [spa_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll" DllInit
O4 - HKLM\..\Run: [{1dfb1062-f415-f018-f2cf-532f14b79614}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll" DllInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [7027473e] rundll32.exe "C:\WINDOWS\system32\bgslubpc.dll",b
O4 - HKLM\..\Run: [BM731474a2] Rundll32.exe "C:\WINDOWS\system32\fyqdydny.dll",s
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: opnlMcbx - C:\WINDOWS\SYSTEM32\opnlMcbx.dll
O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\b2new.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe

--
End of file - 9595 bytes

-- Files created between 2008-04-14 and 2008-05-14 -----------------------------

2008-05-14 22:46:45 0 d-------- C:\Program Files\Trend Micro
2008-05-14 22:45:38 19968 --a------ C:\WINDOWS\swin32.dll
2008-05-14 22:45:38 30208 --a------ C:\WINDOWS\stcloader.exe
2008-05-14 22:45:38 21248 --a------ C:\WINDOWS\bokja.exe
2008-05-14 22:45:37 22016 --a------ C:\WINDOWS\bjam.dll
2008-05-14 22:45:37 14080 --a------ C:\WINDOWS\2020search2.dll
2008-05-14 22:10:21 98928 --a------ C:\WINDOWS\system32\dgjasoeq.dll
2008-05-14 22:10:01 83152 --a------ C:\WINDOWS\system32\bgslubpc.dll
2008-05-14 22:04:47 2048 --a------ C:\WINDOWS\system32\xahskrxq.exe
2008-05-14 22:04:37 90208 --a------ C:\WINDOWS\system32\fyqdydny.dll
2008-05-14 22:03:56 1198371 --ahs---- C:\WINDOWS\system32\Pponqtwa.ini2
2008-05-14 22:03:51 314448 --a------ C:\WINDOWS\system32\awtqnopP.dll
2008-05-14 21:58:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-05-14 21:58:56 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-05-14 21:50:42 0 d-------- C:\Documents and Settings\th\Application Data\Macromedia
2008-05-14 21:50:36 0 d-------- C:\Documents and Settings\th\Application Data\Adobe
2008-05-14 21:50:30 0 d-------- C:\Documents and Settings\th\Application Data\Yahoo!
2008-05-14 21:48:49 0 d-------- C:\Documents and Settings\th\Application Data\Identities
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\Templates
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\Start Menu
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\SendTo
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\Recent
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\PrintHood
2008-05-14 21:48:05 524288 --ah----- C:\Documents and Settings\th\NTUSER.DAT
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\NetHood
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\My Documents
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\Local Settings
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\Favorites
2008-05-14 21:48:05 0 d-------- C:\Documents and Settings\th\Desktop
2008-05-14 21:48:05 0 d---s---- C:\Documents and Settings\th\Cookies
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\Application Data
2008-05-14 21:48:05 0 d---s---- C:\Documents and Settings\th\Application Data\Microsoft
2008-05-14 17:03:28 0 d-------- C:\Documents and Settings\th1\Application Data\Macromedia
2008-05-14 17:03:18 0 d-------- C:\Documents and Settings\th1\Application Data\Adobe
2008-05-14 17:03:12 0 d-------- C:\Documents and Settings\th1\Application Data\Yahoo!
2008-05-14 17:01:03 0 d-------- C:\Documents and Settings\th1\Application Data\Identities
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\Templates
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\Start Menu
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\SendTo
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\Recent
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\PrintHood
2008-05-14 17:00:12 786432 --ah----- C:\Documents and Settings\th1\NTUSER.DAT
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\NetHood
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\My Documents
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\Local Settings
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\Favorites
2008-05-14 17:00:12 0 d-------- C:\Documents and Settings\th1\Desktop
2008-05-14 17:00:12 0 d---s---- C:\Documents and Settings\th1\Cookies
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\Application Data
2008-05-14 17:00:12 0 d---s---- C:\Documents and Settings\th1\Application Data\Microsoft
2008-05-14 16:56:46 83152 --a------ C:\WINDOWS\system32\mabxljsa.dll
2008-05-14 16:56:40 98928 --a------ C:\WINDOWS\system32\xukubahs.dll
2008-05-14 16:54:21 2048 --a------ C:\WINDOWS\system32\tdpbfuhi.exe
2008-05-14 16:54:13 90208 --a------ C:\WINDOWS\system32\xcjnnugj.dll
2008-05-14 16:53:31 1195811 --ahs---- C:\WINDOWS\system32\hjRrAcdd.ini2
2008-05-14 16:53:27 314448 --a------ C:\WINDOWS\system32\ddcArRjh.dll
2008-05-11 22:33:10 316464 --a------ C:\WINDOWS\system32\hgGyxVMf.dll
2008-05-11 21:42:38 98912 --a------ C:\WINDOWS\system32\rwkjhvog.dll
2008-05-11 21:39:39 83024 --a------ C:\WINDOWS\system32\lqsglqft.dll
2008-05-11 21:39:38 2048 --a------ C:\WINDOWS\system32\xvtqberl.exe
2008-05-11 21:37:22 90208 --a------ C:\WINDOWS\system32\toojhugf.dll
2008-05-11 21:36:37 1036033 --ahs---- C:\WINDOWS\system32\kknWxyay.ini2
2008-05-11 21:36:33 316464 --a------ C:\WINDOWS\system32\yayxWnkk.dll
2008-05-11 20:39:04 98912 --a------ C:\WINDOWS\system32\amvbhila.dll
2008-05-11 20:39:01 83024 --a------ C:\WINDOWS\system32\ovaalwnt.dll
2008-05-11 20:36:56 2048 --a------ C:\WINDOWS\system32\pgefwynh.exe
2008-05-11 20:36:47 90208 --a------ C:\WINDOWS\system32\ortmnofc.dll
2008-05-11 20:36:00 1036155 --ahs---- C:\WINDOWS\system32\ortEOXbc.ini2
2008-05-11 20:35:56 316464 --a------ C:\WINDOWS\system32\cbXOEtro.dll
2008-05-11 18:47:08 98912 --a------ C:\WINDOWS\system32\dteyvyov.dll
2008-05-11 18:47:07 2048 --a------ C:\WINDOWS\system32\sqlnttso.exe
2008-05-11 18:44:58 83024 --a------ C:\WINDOWS\system32\xkqwjdki.dll
2008-05-11 18:44:51 90208 --a------ C:\WINDOWS\system32\yavsvcde.dll
2008-05-11 18:44:06 1036005 --ahs---- C:\WINDOWS\system32\PpsAHkkj.ini2
2008-05-11 18:44:02 316464 --a------ C:\WINDOWS\system32\jkkHAspP.dll
2008-05-11 18:40:21 0 d-------- C:\Documents and Settings\Administrator\Application Data\DivX
2008-05-11 18:35:04 16384 --a------ C:\WINDOWS\2020search.dll
2008-05-11 06:17:11 25728 --a------ C:\WINDOWS\system32\fccccCsQ.dll
2008-05-11 05:48:24 316464 --a------ C:\WINDOWS\system32\xxyabbCU.dll
2008-05-11 05:44:22 25728 --a------ C:\WINDOWS\system32\iifFuVMF.dll
2008-05-11 05:41:23 9216 --a------ C:\WINDOWS\cdsm32.dll
2008-05-10 23:04:25 6455 --ahs---- C:\WINDOWS\system32\wEeggfii.ini2
2008-05-10 23:04:20 316480 --a------ C:\WINDOWS\system32\iifggeEw.dll
2008-05-10 22:56:24 13568 --a------ C:\WINDOWS\voiceip.dll
2008-05-10 21:13:42 316480 --a------ C:\WINDOWS\system32\fccAsTKC.dll
2008-05-10 20:08:19 316480 --a------ C:\WINDOWS\system32\mlJCtQKa.dll
2008-05-10 19:27:39 19200 --a------ C:\WINDOWS\mssvr.exe
2008-05-10 19:27:39 20992 --a------ C:\WINDOWS\mspphe.dll
2008-05-10 19:27:35 32768 --a------ C:\WINDOWS\saiemod.dll
2008-05-10 19:27:34 17664 --a------ C:\WINDOWS\msapasrc.dll
2008-05-10 19:27:34 12288 --a------ C:\WINDOWS\msa64chk.dll
2008-05-10 19:27:33 13568 --a------ C:\WINDOWS\winsb.dll
2008-05-10 19:27:33 26112 --a------ C:\WINDOWS\shdocpl.dll
2008-05-10 19:27:33 16896 --a------ C:\WINDOWS\shdocpe.dll
2008-05-10 19:27:33 15360 --a------ C:\WINDOWS\ntnut.exe
2008-05-10 19:27:33 30720 --a------ C:\WINDOWS\browserad.dll
2008-05-10 19:27:32 12032 --a------ C:\WINDOWS\aviwrap32.dll
2008-05-10 19:27:32 27136 --a------ C:\WINDOWS\avisynthex32.dll
2008-05-10 19:27:32 30464 --a------ C:\WINDOWS\avifile32.dll
2008-05-10 19:27:32 9216 --a------ C:\WINDOWS\autodisc32.dll
2008-05-10 19:27:32 8960 --a------ C:\WINDOWS\audiosrv32.dll
2008-05-10 19:27:32 13824 --a------ C:\WINDOWS\ati2dvag32.dll
2008-05-10 19:27:32 17408 --a------ C:\WINDOWS\ati2dvaa32.dll
2008-05-10 19:27:32 23296 --a------ C:\WINDOWS\athprxy32.dll
2008-05-10 19:27:31 12800 --a------ C:\WINDOWS\changeurl_30.dll
2008-05-10 19:27:31 8960 --a------ C:\WINDOWS\asycfilt32.dll
2008-05-10 19:27:31 25088 --a------ C:\WINDOWS\asferror32.dll
2008-05-10 19:27:31 17408 --a------ C:\WINDOWS\apphelp32.dll
2008-05-10 19:07:01 60928 --a------ C:\WINDOWS\system32\wvgroye.dll
2008-05-10 19:06:07 0 d-------- C:\Program Files\Common Files\?ystem
2008-05-10 19:03:30 0 d-------- C:\Program Files\QdrPack
2008-05-10 19:03:10 25728 --a------ C:\WINDOWS\system32\opnlMcbx.dll
2008-05-10 19:03:06 0 d-------- C:\Program Files\QdrModule
2008-05-10 19:03:06 0 d-------- C:\Program Files\ISM
2008-05-10 19:02:15 32768 --a------ C:\WINDOWS\system32\sockins32.dll <Not Verified; ThinkPad; ThinkPad repl>
2008-05-10 19:01:54 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-05-10 19:01:52 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-05-10 19:01:40 0 d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-05-10 19:01:39 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-05-10 19:01:37 4 --a------ C:\WINDOWS\system32\winfrun32.bin
2008-05-10 19:01:35 91563 --a------ C:\WINDOWS\system32\wmsdkns.exe <Not Verified; Microsoft; XML Media>
2008-05-10 19:01:35 91563 --a------ C:\WINDOWS\lfn.exe <Not Verified; Microsoft; XML Media>
2008-05-10 19:01:30 25600 --a------ C:\WINDOWS\b2new.exe
2008-05-09 13:10:10 229514 --a------ C:\WINDOWS\system32\000080.exe
2008-05-08 05:27:22 0 d-------- C:\WINDOWS\pss
2008-05-05 07:16:50 331776 --a------ C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll
2008-05-03 12:48:00 270709 --a------ C:\WINDOWS\system32\000060.exe
2008-04-28 08:20:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-28 08:20:39 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 08:01:12 0 d-------- C:\Program Files\XoftSpySE
2008-04-22 22:36:27 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-20 16:08:59 6656 --a------ C:\WINDOWS\tions.dll
2008-04-19 22:18:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-19 22:04:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-19 21:59:19 0 d-------- C:\Program Files\Yahoo!


-- Find3M Report ---------------------------------------------------------------

2008-05-11 18:33:24 0 d-------- C:\Program Files\Common Files
2008-05-11 18:10:08 0 d-------- C:\Program Files\QdrDrive
2008-05-10 19:06:07 0 d-------- C:\Program Files\Common Files\?ystem
2008-05-07 07:45:18 0 d-------- C:\Program Files\Hp
2008-04-28 07:58:48 0 d-------- C:\Program Files\Ares
2008-04-11 17:46:22 0 d-------- C:\Program Files\Java
2008-04-07 10:00:07 0 d-------- C:\Program Files\eread7.0
2008-04-05 12:08:28 0 d-------- C:\Program Files\real
2008-04-04 17:22:46 0 d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-04 15:51:07 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-03 00:00:25 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-30 22:22:04 0 d-------- C:\Program Files\Lavasoft
2008-03-30 20:51:02 6656 --a------ C:\WINDOWS\ctions.dll
2008-03-30 15:37:45 0 d-------- C:\Program Files\FrostWire
2008-03-26 00:10:53 0 d-------- C:\Program Files\Windows Media Connect 2
2008-03-22 22:04:15 40713 --a------ C:\WINDOWS\system32\cpmsky-uninst.exe
2008-03-22 22:04:12 80121 --a------ C:\WINDOWS\system32\adzgalore-remove.exe
2008-03-15 16:56:59 0 d-------- C:\Program Files\DivX
2008-03-15 16:15:01 0 d-------- C:\Program Files\K-Lite Codec Pack
2008-03-06 11:27:53 281 --a------ C:\WINDOWS\system32\PavCPL.dat
2008-03-06 11:13:35 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-03-03 03:30:50 50 --a------ C:\AUTOEXEC.BAT
2008-02-27 02:47:08 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-02-27 02:39:32 0 -rahs---- C:\MSDOS.SYS
2008-02-27 02:39:32 0 -rahs---- C:\IO.SYS
2008-02-27 02:39:32 0 --a------ C:\CONFIG.SYS
2008-02-27 02:34:57 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-02-26 18:17:54 62 --ahs---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2008-02-20 22:05:44 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-02-20 22:04:16 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-02-20 22:04:16 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-02-20 22:04:04 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-02-20 22:04:04 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX>
2008-02-20 22:04:04 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX>
2008-02-20 22:04:04 682496 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX>
2008-02-20 22:03:24 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000250-0320-4dd4-be4f-7566d2314352}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02834062-9DEA-45FA-909B-BBE101BF8AC2}]
05/10/2008 11:04 PM 316480 --a------ C:\WINDOWS\system32\iifggeEw.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13197ace-6851-45c3-a7ff-c281324d5489}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15651c7c-e812-44a2-a9ac-b467a2233e7d}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1d4d4d8b-f882-9954-bd2c-90d13be73db5}]
05/05/2008 07:16 AM 331776 --a------ C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{24F06550-65E3-4D1C-8CFE-839C296B5530}]
06/28/2007 05:25 PM 57344 --------- C:\Program Files\eread7.0\IEeREAD.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5dafd089-24b1-4c5e-bd42-8ca72550717b}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5fa6752a-c4a0-4222-88c2-928ae5ab4966}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{622cc208-b014-4fe0-801b-874a5e5e403a}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A19C29D-ED45-4483-8999-9F939C8161F2}]
03/10/2008 12:08 PM 81920 --------- C:\Program Files\eread7.0\WebHook.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8674aea0-9d3d-11d9-99dc-00600f9a01f1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{965a592f-8efa-4250-8630-7960230792f1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9c5b2f29-1f46-4639-a6b4-828942301d3e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9DDC3DD3-F637-F199-1594-D38F035178C2}]
04/11/2008 01:51 PM 60928 --a------ C:\WINDOWS\system32\wvgroye.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A7646A99-6448-42E5-9B9F-8D73E4C19086}]
05/14/2008 04:53 PM 314448 --a------ C:\WINDOWS\system32\ddcArRjh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AAE34D58-ACF8-43F8-B99E-5327735CBB27}]
05/11/2008 09:36 PM 316464 --a------ C:\WINDOWS\system32\yayxWnkk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B31BD6AE-F538-44E8-A7E3-7B733A16F748}]
05/11/2008 06:44 PM 316464 --a------ C:\WINDOWS\system32\jkkHAspP.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6EE2ED9-3B65-493C-82AC-6E70AC6E11D7}]
05/11/2008 08:35 PM 316464 --a------ C:\WINDOWS\system32\cbXOEtro.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}]
05/10/2008 07:03 PM 25728 --a------ C:\WINDOWS\system32\opnlMcbx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CBDFB4FE-CC65-40B1-938B-45F317F592C8}]
05/14/2008 10:03 PM 314448 --a------ C:\WINDOWS\system32\awtqnopP.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cc92c7e3-6fca-4a0a-92ac-f60f74c33eec}]
05/14/2008 10:10 PM 98928 --a------ C:\WINDOWS\system32\dgjasoeq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765728274}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fc3a74e5-f281-4f10-ae1e-733078684f3c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ffff0001-0002-101a-a3c9-08002b2f49fb}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FFFFFFFF-BBBB-4146-86FD-A722E8AB3489}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/05/2005 05:56 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [06/18/2005 12:50 PM]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [08/01/2005 06:26 PM]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [10/11/2005 08:17 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [05/04/2005 02:59 PM]
"APVXDWIN"="C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.exe" [07/19/2007 07:23 PM]
"spa_start"="C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll" [05/05/2008 07:16 AM]
"{1dfb1062-f415-f018-f2cf-532f14b79614}"="C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll" [05/05/2008 07:16 AM]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/03/2008 03:20 AM]
"7027473e"="C:\WINDOWS\system32\bgslubpc.dll" [05/14/2008 10:10 PM]
"BM731474a2"="C:\WINDOWS\system32\fyqdydny.dll" [05/14/2008 10:04 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
"DisableTaskMgr"=1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]
"{C7BBC1FA-E415-4926-9A47-9AB58D0B3BC8}"= C:\WINDOWS\system32\opnlMcbx.dll [05/10/2008 07:03 PM 25728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebProxy"= {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wmsdkns.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 02/16/2007 12:02 AM 50736 C:\WINDOWS\system32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnlMcbx]
opnlMcbx.dll 05/10/2008 07:03 PM 25728 C:\WINDOWS\system32\opnlMcbx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\awtqnopP

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Awola6]
"C:\Documents and Settings\Troy\Application Data\Awola6\Awola6.exe" /MIN

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Windows Adapter 5.1.3214]
C:\Documents and Settings\Troy\Application Data\apvfs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{66186F05-BBBB-4a39-864F-72D84615C679}]
rundll32 sockins32.dll,InitModule



-- End of Deckard's System Scanner: finished at 2008-05-14 22:47:53 ------------

Attached Files


Edited by SifuMike, 23 May 2008 - 11:12 PM.
insert DSS log


#3 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:23 PM

Posted 23 May 2008 - 11:06 PM

Hello sportman32922,

Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
  • Finally copy and paste the contents of the results file Report.txt back onto the forum with a new Deckards System Scanner log. Please do not attach your logs, as that makes it hard to read.

-- If this error message is displayed when running SDFix: "The command prompt has been disabled by your administrator. Press any key to continue..."
Please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Enable_Command_Prompt.reg
Press Ok and then run SDFix again.

-- If the Command Prompt window flashes on then off again on XP or Win 2000, please go to Start Menu > Run > and copy/paste the following line:
%systemdrive%\SDFix\apps\FixPath.exe /Q
Reboot and then run SDFix again.

-- If SDFix still does not run, check the %comspec% variable. Right-click My Computer > click Properties > Advanced > Environment Variables and check that the ComSpec variable points to cmd.exe.
%SystemRoot%\system32\cmd.exe

Edited by SifuMike, 23 May 2008 - 11:07 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#4 sportman32922

sportman32922
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 27 May 2008 - 08:43 PM

hello this is my new notes from the fix program you all asked me to run...



Deckard's System Scanner v20071014.68
Run by th on 2008-05-27 06:12:15
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as th.exe) --------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:14:00 AM, on 5/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\WebProxy.exe
G:\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\th.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\avciman.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\psimreal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cpmsky.biz/bc/123kah.php
R3 - URLSearchHook: Yahoo! uC - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: AddTask Class - {24F06550-65E3-4D1C-8CFE-839C296B5530} - C:\Program Files\eread7.0\IEeREAD.dll
O2 - BHO: {7db5c567-0fa3-e1ea-c154-e742ae58d9f4} - {4f9d85ea-247e-451c-ae1e-3af0765c5bd7} - C:\WINDOWS\system32\bvpodvdk.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: AddTask Class - {6A19C29D-ED45-4483-8999-9F939C8161F2} - C:\Program Files\eread7.0\WebHook.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {AF526913-22B8-4934-B62B-BD26BF634561} - C:\WINDOWS\system32\efcCtUkj.dll (file missing)
O3 - Toolbar: Yahoo! uC - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [{1dfb1062-f415-f018-f2cf-532f14b79614}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll" DllInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [7027473e] rundll32.exe "C:\WINDOWS\system32\kjokttaa.dll",b
O4 - HKLM\..\Run: [BM731474a2] Rundll32.exe "C:\WINDOWS\system32\pxwfacgg.dll",s
O4 - HKCU\..\Run: [Systray] rundll32.exe sockins32.dll,RunMain
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe

--
End of file - 8895 bytes

-- Files created between 2008-04-27 and 2008-05-27 -----------------------------

2008-05-26 22:17:24 0 d-------- C:\WINDOWS\ERUNT
2008-05-17 12:00:59 0 d-------- C:\Documents and Settings\th1\Application Data\SUPERAntiSpyware.com
2008-05-17 10:49:03 98960 --a------ C:\WINDOWS\system32\bvpodvdk.dll
2008-05-17 10:40:05 82960 --a------ C:\WINDOWS\system32\kjokttaa.dll
2008-05-17 10:37:46 90224 --a------ C:\WINDOWS\system32\pxwfacgg.dll
2008-05-17 10:37:03 1342239 --ahs---- C:\WINDOWS\system32\HjjTAJjl.ini2
2008-05-17 10:31:55 0 d-------- C:\Documents and Settings\th\Application Data\SUPERAntiSpyware.com
2008-05-16 21:51:20 82992 --a------ C:\WINDOWS\system32\jehwgpet.dll
2008-05-16 21:49:16 98896 --a------ C:\WINDOWS\system32\ltclktcs.dll
2008-05-16 21:49:06 90240 --a------ C:\WINDOWS\system32\gnyhvpvu.dll
2008-05-16 21:48:20 1343526 --ahs---- C:\WINDOWS\system32\jkUtCcfe.ini2
2008-05-14 22:46:45 0 d-------- C:\Program Files\Trend Micro
2008-05-14 22:10:21 98928 --a------ C:\WINDOWS\system32\dgjasoeq.dll
2008-05-14 22:10:01 83152 --a------ C:\WINDOWS\system32\bgslubpc.dll
2008-05-14 22:04:37 90208 --a------ C:\WINDOWS\system32\fyqdydny.dll
2008-05-14 22:03:56 1198371 --ahs---- C:\WINDOWS\system32\Pponqtwa.ini2
2008-05-14 21:58:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-05-14 21:58:56 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-05-14 21:50:42 0 d-------- C:\Documents and Settings\th\Application Data\Macromedia
2008-05-14 21:50:36 0 d-------- C:\Documents and Settings\th\Application Data\Adobe
2008-05-14 21:50:30 0 d-------- C:\Documents and Settings\th\Application Data\Yahoo!
2008-05-14 21:48:49 0 d-------- C:\Documents and Settings\th\Application Data\Identities
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\Templates
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\Start Menu
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\SendTo
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\Recent
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\PrintHood
2008-05-14 21:48:05 1048576 --ah----- C:\Documents and Settings\th\NTUSER.DAT
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\NetHood
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\My Documents <MYDOCU~1>
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\Local Settings
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\Favorites
2008-05-14 21:48:05 0 d-------- C:\Documents and Settings\th\Desktop
2008-05-14 21:48:05 0 d---s---- C:\Documents and Settings\th\Cookies
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\Application Data
2008-05-14 17:03:28 0 d-------- C:\Documents and Settings\th1\Application Data\Macromedia
2008-05-14 17:03:18 0 d-------- C:\Documents and Settings\th1\Application Data\Adobe
2008-05-14 17:03:12 0 d-------- C:\Documents and Settings\th1\Application Data\Yahoo!
2008-05-14 17:01:03 0 d-------- C:\Documents and Settings\th1\Application Data\Identities
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\Templates
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\Start Menu
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\SendTo
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\Recent
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\PrintHood
2008-05-14 17:00:12 786432 --ah----- C:\Documents and Settings\th1\NTUSER.DAT
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\NetHood
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\My Documents <MYDOCU~1>
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\Local Settings
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\Favorites
2008-05-14 17:00:12 0 d-------- C:\Documents and Settings\th1\Desktop
2008-05-14 17:00:12 0 d---s---- C:\Documents and Settings\th1\Cookies
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\Application Data
2008-05-14 17:00:12 0 d---s---- C:\Documents and Settings\th1\Application Data\Microsoft
2008-05-14 16:56:46 83152 --a------ C:\WINDOWS\system32\mabxljsa.dll
2008-05-14 16:56:40 98928 --a------ C:\WINDOWS\system32\xukubahs.dll
2008-05-14 16:54:13 90208 --a------ C:\WINDOWS\system32\xcjnnugj.dll
2008-05-14 16:53:31 1195811 --ahs---- C:\WINDOWS\system32\hjRrAcdd.ini2
2008-05-11 21:42:38 98912 --a------ C:\WINDOWS\system32\rwkjhvog.dll
2008-05-11 21:39:39 83024 --a------ C:\WINDOWS\system32\lqsglqft.dll
2008-05-11 21:37:22 90208 --a------ C:\WINDOWS\system32\toojhugf.dll
2008-05-11 21:36:37 1036033 --ahs---- C:\WINDOWS\system32\kknWxyay.ini2
2008-05-11 20:39:04 98912 --a------ C:\WINDOWS\system32\amvbhila.dll
2008-05-11 20:39:01 83024 --a------ C:\WINDOWS\system32\ovaalwnt.dll
2008-05-11 20:36:47 90208 --a------ C:\WINDOWS\system32\ortmnofc.dll
2008-05-11 20:36:00 1036155 --ahs---- C:\WINDOWS\system32\ortEOXbc.ini2
2008-05-11 18:47:08 98912 --a------ C:\WINDOWS\system32\dteyvyov.dll
2008-05-11 18:44:58 83024 --a------ C:\WINDOWS\system32\xkqwjdki.dll
2008-05-11 18:44:51 90208 --a------ C:\WINDOWS\system32\yavsvcde.dll
2008-05-11 18:44:06 1036005 --ahs---- C:\WINDOWS\system32\PpsAHkkj.ini2
2008-05-11 18:40:21 0 d-------- C:\Documents and Settings\Administrator\Application Data\DivX
2008-05-10 23:04:25 6455 --ahs---- C:\WINDOWS\system32\wEeggfii.ini2
2008-05-10 19:06:07 0 d-------- C:\Program Files\Common Files\?ystem
2008-05-10 19:01:54 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-05-10 19:01:52 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-05-10 19:01:40 0 d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-05-10 19:01:39 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-05-10 19:01:30 25600 --a------ C:\WINDOWS\b2new.exe
2008-05-08 05:27:22 0 d-------- C:\WINDOWS\pss
2008-04-28 08:20:41 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-28 08:20:39 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-28 08:01:12 0 d-------- C:\Program Files\XoftSpySE


-- Find3M Report ---------------------------------------------------------------

2008-05-11 18:33:24 0 d-------- C:\Program Files\Common Files
2008-05-10 19:06:07 0 d-------- C:\Program Files\Common Files\?ystem
2008-05-07 07:45:18 0 d-------- C:\Program Files\Hp
2008-04-28 07:58:48 0 d-------- C:\Program Files\Ares
2008-04-22 22:36:29 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-20 16:08:59 6656 --a------ C:\WINDOWS\tions.dll
2008-04-19 22:02:39 0 d-------- C:\Program Files\Yahoo!
2008-04-11 17:46:22 0 d-------- C:\Program Files\Java
2008-04-07 10:00:07 0 d-------- C:\Program Files\eread7.0
2008-04-05 12:08:28 0 d-------- C:\Program Files\real
2008-04-04 15:51:07 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-03 00:00:25 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-30 22:22:04 0 d-------- C:\Program Files\Lavasoft
2008-03-30 20:51:02 6656 --a------ C:\WINDOWS\ctions.dll
2008-03-30 15:37:45 0 d-------- C:\Program Files\FrostWire
2008-03-06 11:27:53 281 --a------ C:\WINDOWS\system32\PavCPL.dat
2008-03-06 11:13:35 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-03-03 03:30:50 50 --a------ C:\AUTOEXEC.BAT
2008-02-27 02:47:08 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-02-27 02:39:32 0 -rahs---- C:\MSDOS.SYS
2008-02-27 02:39:32 0 -rahs---- C:\IO.SYS
2008-02-27 02:39:32 0 --a------ C:\CONFIG.SYS
2008-02-27 02:34:57 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{24F06550-65E3-4D1C-8CFE-839C296B5530}]
06/28/2007 05:25 PM 57344 --------- C:\Program Files\eread7.0\IEeREAD.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f9d85ea-247e-451c-ae1e-3af0765c5bd7}]
05/17/2008 10:49 AM 98960 --a------ C:\WINDOWS\system32\bvpodvdk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A19C29D-ED45-4483-8999-9F939C8161F2}]
03/10/2008 12:08 PM 81920 --------- C:\Program Files\eread7.0\WebHook.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF526913-22B8-4934-B62B-BD26BF634561}]
C:\WINDOWS\system32\efcCtUkj.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/05/2005 05:56 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [06/18/2005 12:50 PM]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [08/01/2005 06:26 PM]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [10/11/2005 08:17 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [05/04/2005 02:59 PM]
"APVXDWIN"="C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.exe" [07/19/2007 07:23 PM]
"{1dfb1062-f415-f018-f2cf-532f14b79614}"="C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/03/2008 03:20 AM]
"7027473e"="C:\WINDOWS\system32\kjokttaa.dll" [05/17/2008 10:40 AM]
"BM731474a2"="C:\WINDOWS\system32\pxwfacgg.dll" [05/17/2008 10:37 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Systray"="sockins32.dll,RunMain" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 02/16/2007 12:02 AM 50736 C:\WINDOWS\system32\avldr.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ljJATjjH

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Awola6]
"C:\Documents and Settings\Troy\Application Data\Awola6\Awola6.exe" /MIN

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Windows Adapter 5.1.3214]
C:\Documents and Settings\Troy\Application Data\apvfs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1b47811-0370-11dd-9fb8-0014a56a4155}]
AutoRun\command- G:\Autorun.exe /run
Shell00\Command- G:\Autorun.exe /run
Shell01\Command- G:\Autorun.exe /action
Shell02\Command- G:\Autorun.exe /uninstall




-- End of Deckard's System Scanner: finished at 2008-05-27 06:14:49 ------------

#5 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 37,009 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:08:23 PM

Posted 27 May 2008 - 09:27 PM

Hello sportman32922,

I have merged your latest topic, which you misposted in the Am I Infected forum with your previously existing topic in the HJT forum. Please be sure to follow ALL of SifuMike's instructions and in the order requested. Please keep your responses to this thread using the Add Reply button at the bottom of the topics. Creating new topics confuses things and delays the assistance you receive.

Back to you SifuMike.

Orange Blossom :thumbsup:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#6 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:23 PM

Posted 27 May 2008 - 09:35 PM

Hello sportman32922,

Please do not keeping opening new threads. You will never get any help if you do that.

I asked you to run SDFix. Did you do that? If so, then post the log.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 sportman32922

sportman32922
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 27 May 2008 - 10:49 PM

yes i ran a sdfix...


SDFix: Version 1.185
Run by Administrator on Tue 05/27/2008 at 11:28 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\ADMINI~1\Desktop\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-27 23:39:57
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares"
"C:\\Program Files\\FrostWire\\FrostWire.exe"="C:\\Program Files\\FrostWire\\FrostWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\WINDOWS\\TEMP\\gqxb.exe"="C:\\WINDOWS\\TEMP\\gqxb.exe:*:Enabled:DHCP Client"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :


File Backups: - C:\DOCUME~1\ADMINI~1\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes :

Fri 7 Mar 2008 24 ..SH. --- "C:\WINDOWS\SFAD61C57.tmp"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Tue 1 Apr 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 10 May 2008 89,088 ..SHR --- "C:\Program Files\Common Files\?ystem\dvdplay.exe"
Wed 26 Mar 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\385cb67dda0ffd4dea8c0d990dc65796\BIT1.tmp"

Finished!

#8 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:23 PM

Posted 27 May 2008 - 10:52 PM

Hi sportman32922,

Did you run SDfix more than one time? That log looks very strange, as it should have found something.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 sportman32922

sportman32922
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 27 May 2008 - 10:55 PM

yes ive ran it more than once..so i dont know what i should do now...

#10 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:23 PM

Posted 27 May 2008 - 10:58 PM

Why did you run I more than once? :thumbsup: I needed to see the first log it produced. The second log is useless to me! Now I dont know what it removed. :)
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#11 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:23 PM

Posted 27 May 2008 - 11:14 PM

sportman32922,

Now we will have to start over. :thumbsup:

Do you have another language besides English on your computer? I see unprinable characters in your log.

Run Deckards System Scanner and post the main.txt log and we will take it from there.

Edited by SifuMike, 27 May 2008 - 11:17 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#12 sportman32922

sportman32922
  • Topic Starter

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:08:23 PM

Posted 30 May 2008 - 04:37 PM

here is my new hijackthis log...

Deckard's System Scanner v20071014.68
Run by th on 2008-05-30 17:28:31
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- HijackThis (run as th.exe) --------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:28:37 PM, on 5/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\WebProxy.exe
C:\WINDOWS\explorer.exe
F:\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\th.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\avciman.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\psimreal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cpmsky.biz/bc/123kah.php
R3 - URLSearchHook: Yahoo! uC - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: AddTask Class - {24F06550-65E3-4D1C-8CFE-839C296B5530} - C:\Program Files\eread7.0\IEeREAD.dll
O2 - BHO: {7db5c567-0fa3-e1ea-c154-e742ae58d9f4} - {4f9d85ea-247e-451c-ae1e-3af0765c5bd7} - C:\WINDOWS\system32\bvpodvdk.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: AddTask Class - {6A19C29D-ED45-4483-8999-9F939C8161F2} - C:\Program Files\eread7.0\WebHook.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {AF526913-22B8-4934-B62B-BD26BF634561} - (no file)
O3 - Toolbar: Yahoo! uC - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [{1dfb1062-f415-f018-f2cf-532f14b79614}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll" DllInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [7027473e] rundll32.exe "C:\WINDOWS\system32\kjokttaa.dll",b
O4 - HKLM\..\Run: [BM731474a2] Rundll32.exe "C:\WINDOWS\system32\pxwfacgg.dll",s
O4 - HKCU\..\Run: [Systray] rundll32.exe sockins32.dll,RunMain
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe

--
End of file - 8808 bytes

-- Files created between 2008-04-30 and 2008-05-30 -----------------------------

2008-05-30 16:48:05 0 d---s---- C:\Documents and Settings\th\UserData
2008-05-29 19:42:39 276 --a------ C:\Program Files\Settings.dat
2008-05-29 19:39:52 0 d-------- C:\Program Files\Backup
2008-05-29 19:33:02 1655296 --a------ C:\Program Files\Regpair.exe
2008-05-26 22:17:24 0 d-------- C:\WINDOWS\ERUNT
2008-05-17 12:00:59 0 d-------- C:\Documents and Settings\th1\Application Data\SUPERAntiSpyware.com
2008-05-17 10:49:03 98960 --a------ C:\WINDOWS\system32\bvpodvdk.dll
2008-05-17 10:40:05 82960 --a------ C:\WINDOWS\system32\kjokttaa.dll
2008-05-17 10:37:46 90224 --a------ C:\WINDOWS\system32\pxwfacgg.dll
2008-05-17 10:37:03 1342239 --ahs---- C:\WINDOWS\system32\HjjTAJjl.ini2
2008-05-17 10:31:55 0 d-------- C:\Documents and Settings\th\Application Data\SUPERAntiSpyware.com
2008-05-16 21:51:20 82992 --a------ C:\WINDOWS\system32\jehwgpet.dll
2008-05-16 21:49:16 98896 --a------ C:\WINDOWS\system32\ltclktcs.dll
2008-05-16 21:49:06 90240 --a------ C:\WINDOWS\system32\gnyhvpvu.dll
2008-05-16 21:48:20 1343526 --ahs---- C:\WINDOWS\system32\jkUtCcfe.ini2
2008-05-14 22:46:45 0 d-------- C:\Program Files\Trend Micro
2008-05-14 22:10:21 98928 --a------ C:\WINDOWS\system32\dgjasoeq.dll
2008-05-14 22:10:01 83152 --a------ C:\WINDOWS\system32\bgslubpc.dll
2008-05-14 22:04:37 90208 --a------ C:\WINDOWS\system32\fyqdydny.dll
2008-05-14 22:03:56 1198371 --ahs---- C:\WINDOWS\system32\Pponqtwa.ini2
2008-05-14 21:58:58 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-05-14 21:58:56 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-05-14 21:50:42 0 d-------- C:\Documents and Settings\th\Application Data\Macromedia
2008-05-14 21:50:36 0 d-------- C:\Documents and Settings\th\Application Data\Adobe
2008-05-14 21:50:30 0 d-------- C:\Documents and Settings\th\Application Data\Yahoo!
2008-05-14 21:48:49 0 d-------- C:\Documents and Settings\th\Application Data\Identities
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\Templates
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\Start Menu
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\SendTo
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\Recent
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\PrintHood
2008-05-14 21:48:05 1310720 --ah----- C:\Documents and Settings\th\NTUSER.DAT
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\NetHood
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\My Documents
2008-05-14 21:48:05 0 d--h----- C:\Documents and Settings\th\Local Settings
2008-05-14 21:48:05 0 dr------- C:\Documents and Settings\th\Favorites
2008-05-14 21:48:05 0 d-------- C:\Documents and Settings\th\Desktop
2008-05-14 21:48:05 0 d---s---- C:\Documents and Settings\th\Cookies
2008-05-14 21:48:05 0 dr-h----- C:\Documents and Settings\th\Application Data
2008-05-14 17:03:28 0 d-------- C:\Documents and Settings\th1\Application Data\Macromedia
2008-05-14 17:03:18 0 d-------- C:\Documents and Settings\th1\Application Data\Adobe
2008-05-14 17:03:12 0 d-------- C:\Documents and Settings\th1\Application Data\Yahoo!
2008-05-14 17:01:03 0 d-------- C:\Documents and Settings\th1\Application Data\Identities
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\Templates
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\Start Menu
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\SendTo
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\Recent
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\PrintHood
2008-05-14 17:00:12 786432 --ah----- C:\Documents and Settings\th1\NTUSER.DAT
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\NetHood
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\My Documents
2008-05-14 17:00:12 0 d--h----- C:\Documents and Settings\th1\Local Settings
2008-05-14 17:00:12 0 dr------- C:\Documents and Settings\th1\Favorites
2008-05-14 17:00:12 0 d-------- C:\Documents and Settings\th1\Desktop
2008-05-14 17:00:12 0 d---s---- C:\Documents and Settings\th1\Cookies
2008-05-14 17:00:12 0 dr-h----- C:\Documents and Settings\th1\Application Data
2008-05-14 17:00:12 0 d---s---- C:\Documents and Settings\th1\Application Data\Microsoft
2008-05-14 16:56:46 83152 --a------ C:\WINDOWS\system32\mabxljsa.dll
2008-05-14 16:56:40 98928 --a------ C:\WINDOWS\system32\xukubahs.dll
2008-05-14 16:54:13 90208 --a------ C:\WINDOWS\system32\xcjnnugj.dll
2008-05-14 16:53:31 1195811 --ahs---- C:\WINDOWS\system32\hjRrAcdd.ini2
2008-05-11 21:42:38 98912 --a------ C:\WINDOWS\system32\rwkjhvog.dll
2008-05-11 21:39:39 83024 --a------ C:\WINDOWS\system32\lqsglqft.dll
2008-05-11 21:37:22 90208 --a------ C:\WINDOWS\system32\toojhugf.dll
2008-05-11 21:36:37 1036033 --ahs---- C:\WINDOWS\system32\kknWxyay.ini2
2008-05-11 20:39:04 98912 --a------ C:\WINDOWS\system32\amvbhila.dll
2008-05-11 20:39:01 83024 --a------ C:\WINDOWS\system32\ovaalwnt.dll
2008-05-11 20:36:47 90208 --a------ C:\WINDOWS\system32\ortmnofc.dll
2008-05-11 20:36:00 1036155 --ahs---- C:\WINDOWS\system32\ortEOXbc.ini2
2008-05-11 18:47:08 98912 --a------ C:\WINDOWS\system32\dteyvyov.dll
2008-05-11 18:44:58 83024 --a------ C:\WINDOWS\system32\xkqwjdki.dll
2008-05-11 18:44:51 90208 --a------ C:\WINDOWS\system32\yavsvcde.dll
2008-05-11 18:44:06 1036005 --ahs---- C:\WINDOWS\system32\PpsAHkkj.ini2
2008-05-11 18:40:21 0 d-------- C:\Documents and Settings\Administrator\Application Data\DivX
2008-05-10 23:04:25 6455 --ahs---- C:\WINDOWS\system32\wEeggfii.ini2
2008-05-10 19:06:07 0 d-------- C:\Program Files\Common Files\?ystem
2008-05-10 19:01:54 0 d-------- C:\Documents and Settings\LocalService\Application Data\Macromedia
2008-05-10 19:01:52 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-05-10 19:01:40 0 d-------- C:\Documents and Settings\LocalService\Application Data\Yahoo!
2008-05-10 19:01:39 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-05-10 19:01:30 25600 --a------ C:\WINDOWS\b2new.exe
2008-05-08 05:27:22 0 d-------- C:\WINDOWS\pss


-- Find3M Report ---------------------------------------------------------------

2008-05-29 19:32:12 0 d-------- C:\Program Files\HPQ
2008-05-11 18:33:24 0 d-------- C:\Program Files\Common Files
2008-05-10 19:06:07 0 d-------- C:\Program Files\Common Files\?ystem
2008-05-07 07:45:18 0 d-------- C:\Program Files\Hp
2008-04-28 08:01:16 0 d-------- C:\Program Files\XoftSpySE
2008-04-28 07:58:48 0 d-------- C:\Program Files\Ares
2008-04-22 22:36:29 0 d-------- C:\Program Files\Common Files\Adobe
2008-04-20 16:08:59 6656 --a------ C:\WINDOWS\tions.dll
2008-04-19 22:02:39 0 d-------- C:\Program Files\Yahoo!
2008-04-11 17:46:22 0 d-------- C:\Program Files\Java
2008-04-07 10:00:07 0 d-------- C:\Program Files\eread7.0
2008-04-05 12:08:28 0 d-------- C:\Program Files\real
2008-04-04 15:51:07 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-04-03 00:00:25 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-30 22:22:04 0 d-------- C:\Program Files\Lavasoft
2008-03-30 20:51:02 6656 --a------ C:\WINDOWS\ctions.dll
2008-03-30 15:37:45 0 d-------- C:\Program Files\FrostWire
2008-03-06 11:27:53 281 --a------ C:\WINDOWS\system32\PavCPL.dat
2008-03-06 11:13:35 81984 --a------ C:\WINDOWS\system32\bdod.bin
2008-03-03 03:30:50 50 --a------ C:\AUTOEXEC.BAT


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{24F06550-65E3-4D1C-8CFE-839C296B5530}]
06/28/2007 05:25 PM 57344 --------- C:\Program Files\eread7.0\IEeREAD.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f9d85ea-247e-451c-ae1e-3af0765c5bd7}]
05/17/2008 10:49 AM 98960 --a------ C:\WINDOWS\system32\bvpodvdk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A19C29D-ED45-4483-8999-9F939C8161F2}]
03/10/2008 12:08 PM 81920 --------- C:\Program Files\eread7.0\WebHook.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF526913-22B8-4934-B62B-BD26BF634561}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [08/05/2005 05:56 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [06/18/2005 12:50 PM]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [08/01/2005 06:26 PM]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [10/11/2005 08:17 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [05/04/2005 02:59 PM]
"APVXDWIN"="C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.exe" [07/19/2007 07:23 PM]
"{1dfb1062-f415-f018-f2cf-532f14b79614}"="C:\WINDOWS\system32\{a0740eb2-fac6-ae7e-b12e-df327cee6c94}.dll" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [03/03/2008 03:20 AM]
"7027473e"="C:\WINDOWS\system32\kjokttaa.dll" [05/17/2008 10:40 AM]
"BM731474a2"="C:\WINDOWS\system32\pxwfacgg.dll" [05/17/2008 10:37 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Systray"="sockins32.dll,RunMain" []

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 12:55 PM 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 12:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 02/16/2007 12:02 AM 50736 C:\WINDOWS\system32\avldr.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ljJATjjH

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Awola6]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Windows Adapter 5.1.3214]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{71dc4d78-fdb9-11dc-9fab-0014a56a4155}]
AutoRun\command- F:\Autorun.exe /run
Shell00\Command- F:\Autorun.exe /run
Shell01\Command- F:\Autorun.exe /action
Shell02\Command- F:\Autorun.exe /uninstall

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1b47811-0370-11dd-9fb8-0014a56a4155}]
AutoRun\command- G:\Autorun.exe /run
Shell00\Command- G:\Autorun.exe /run
Shell01\Command- G:\Autorun.exe /action
Shell02\Command- G:\Autorun.exe /uninstall

-- End of Deckard's System Scanner: finished at 2008-05-30 17:29:15 ------------

Attached Files

  • Attached File  main.txt   21.11KB   32 downloads

Edited by SifuMike, 30 May 2008 - 07:16 PM.
insert DSS log


#13 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:23 PM

Posted 30 May 2008 - 07:26 PM

Hi sportman32922,

We will run ComboFix.

You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert.
It is intended by its creator to be used under the guidance and supervision of an expert, not for private use.
Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.


You need to disable your Panda Antivirus before running ComboFix, as it will prevent it from running.


Please visit this webpage for instructions for downloading and running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

To work properly, you must install ComboFix on the Desktop.

When following the instructions install the Windows XP Recovery Console if you are using XP. <== IMPORTANT
It is a simple procedure that will only take a few moments of your time.


You DO NOT need to have the Windows CD to install Recovery Console!

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.


We need Recovery Console because malware damages a lot and causes an instable system - and because of that, it may happen that your computer won't be able to boot anymore. With the Recovery Console installed, there are extra options present to repair whatever malware damaged.
Also, even though you're not infected, the presence of the Recovery Console is a useful feature in case a computer won't boot anymore because of several other reasons. Read here what you can do with the Recovery Console.

Extra note: After you have installed the Recovery Console - if you reboot your computer, right after reboot, you'll see the option for the Recovery Console now as well.
Don't select to run the Recovery Console as we don't need it.
By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows.

A caution -
Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.
Do not run Combofix more than once.
Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

Post the ComboFix log. Do NOT attach the log, as that makes it hard to read.

Edited by SifuMike, 30 May 2008 - 07:30 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#14 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:23 PM

Posted 05 June 2008 - 09:11 PM

Due to inactivity, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users