Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Possible Malware Infection


  • This topic is locked This topic is locked
8 replies to this topic

#1 AggieUser

AggieUser

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:42 AM

Posted 10 July 2008 - 10:08 AM

I am having a problem where my computer gives me a low memory error (which just started all of a sudden), I get frequent popups, my internet explorer will not run, often applications will not load when I double click on them, and when I right click on them the menu is limited to "Open file location" and one other choice. Also, frequently the right click and middle wheel click buttons on my mouse do not work. My brother was downloading files onto my computer yesterday, and I fear he may have downloaded a virus. My current McAfee subscription and running adaware did not solve the problem

Deckard's System Scanner v20071014.68
Run by Braden on 2008-07-10 09:50:46
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- Last 5 Restore Point(s) --
5: 2008-07-10 13:09:44 UTC - RP259 - Installed Ad-Aware
4: 2008-07-09 15:05:54 UTC - RP258 - Removed ActiveDolls
3: 2008-07-08 16:11:23 UTC - RP257 - Installed ActiveDolls
2: 2008-07-06 17:52:04 UTC - RP256 - Scheduled Checkpoint
1: 2008-07-06 02:03:46 UTC - RP255 - Scheduled Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Braden.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:00:56 AM, on 7/10/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\sttray.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Users\Braden\Program Files\DNA\btdna.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Users\Braden\Desktop\dss.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchFilterHost.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Braden.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [CTFMon] C:\Windows\system32\CTF\ctfmon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\hgGabYSl.dll,#1
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Braden\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Braden\AppData\Local\Temp\cbXNEUNf.dll,#1
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Braden\AppData\Local\Temp\tuvWmNgE.dll,c
O4 - HKCU\..\Run: [265f977a] rundll32.exe "C:\Users\Braden\AppData\Local\Temp\doakkiwy.dll",b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in...l/installer.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9200 bytes

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R3 DSproct - \??\c:\program files\dellsupport\gtaction\triggers\dsproct.sys


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
R2 STacSV (SigmaTel Audio Service) - c:\windows\system32\stacsv.exe <Not Verified; SigmaTel, Inc.; C-Major Audio>
R2 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>

S3 DSBrokerService - "c:\program files\dellsupport\brkrsvc.exe" <Not Verified; ; Gteko BrkrSvc Application>
S3 GoogleDesktopManager-091907-194040 (Google Desktop Manager 5.1.709.19590) - "c:\program files\google\google desktop search\googledesktop.exe" <Not Verified; Google; Google Desktop>
S3 stllssvr - "c:\program files\common files\surething shared\stllssvr.exe" <Not Verified; MicroVision Development, Inc.; SureThing CD Labeler>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA


-- Scheduled Tasks -------------------------------------------------------------

2008-06-15 01:00:02 366 --a------ C:\Windows\Tasks\McDefragTask.job
2008-06-01 01:00:03 368 --a------ C:\Windows\Tasks\McQcTask.job


-- Files created between 2008-06-10 and 2008-07-10 -----------------------------

2008-07-10 10:00:24 0 d-------- C:\Program Files\Trend Micro
2008-07-10 08:11:01 0 d-------- C:\Program Files\Lavasoft
2008-07-10 08:10:59 0 d-------- C:\Users\All Users\Lavasoft
2008-07-10 08:09:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 11:04:00 0 d-------- C:\Users\All Users\Yahoo! Companion
2008-07-09 09:45:35 29568 --a------ C:\Windows\system32\xxyaxWPj.dll
2008-07-09 09:45:35 29568 --a------ C:\Windows\system32\hgGabYSl.dll
2008-07-08 17:34:14 0 d-------- C:\Program Files\Yahoo! Games
2008-07-08 11:10:18 0 d-------- C:\Program Files\Conduit
2008-07-08 11:10:14 0 d-------- C:\Program Files\BitZipperSearch
2008-07-08 11:09:23 0 d-------- C:\Program Files\BitZipper
2008-06-25 22:29:39 0 d-------- C:\ZIPTemp
2008-06-25 22:27:30 0 d-------- C:\TM5Data
2008-06-25 22:25:43 0 d-------- C:\Program Files\Common Files\DAO
2008-06-25 22:25:43 0 d-------- C:\Program Files\Common Files\Business Objects
2008-06-25 22:25:43 0 d-------- C:\Hy-Sport
2008-06-25 21:36:43 0 d-------- C:\Program Files\Lexmark 1200 Series
2008-06-25 21:35:48 299520 --a------ C:\Windows\uninst.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield unInstaller>
2008-06-25 21:35:44 0 -rahs---- C:\MSDOS.SYS
2008-06-25 21:35:44 0 -rahs---- C:\IO.SYS
2008-06-23 11:18:11 0 d-------- C:\Users\All Users\Fugazo
2008-06-20 07:47:06 143360 --a------ C:\Windows\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-06-15 21:39:48 0 d-------- C:\Windows\system32\Adobe
2008-06-11 10:22:15 0 d-------- C:\Users\All Users\Ludia
2008-06-10 12:43:46 0 dr------- C:\Users\Peach Bug\Searches
2008-06-10 12:43:15 0 dr------- C:\Users\Peach Bug\Contacts
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\Templates
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\Start Menu
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\SendTo
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\Recent
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\PrintHood
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\NetHood
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\Local Settings
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\Cookies
2008-06-10 12:42:11 0 d--hs---- C:\Users\Peach Bug\Application Data
2008-06-10 12:42:10 0 d--hs---- C:\Users\Peach Bug\My Documents
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Videos
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Saved Games
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Pictures
2008-06-10 12:42:05 1572864 --ahs---- C:\Users\Peach Bug\NTUSER.DAT
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Music
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Links
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Favorites
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Downloads
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Documents
2008-06-10 12:42:05 0 dr------- C:\Users\Peach Bug\Desktop
2008-06-10 12:42:05 0 d--h----- C:\Users\Peach Bug\AppData


-- Find3M Report ---------------------------------------------------------------

2008-07-10 09:59:55 0 d-------- C:\Users\Braden\AppData\Roaming\DNA
2008-07-10 08:09:15 0 d-------- C:\Program Files\Common Files
2008-07-09 10:46:44 0 d-------- C:\Program Files\McAfee
2008-07-09 09:43:09 0 d-------- C:\Users\Braden\AppData\Roaming\BitTorrent
2008-07-08 11:09:30 0 d-------- C:\Users\Braden\AppData\Roaming\BitZipper
2008-06-25 00:09:24 0 d-------- C:\Users\Braden\AppData\Roaming\Move Networks
2008-06-23 11:16:44 0 d-------- C:\Program Files\Yahoo!
2008-06-22 23:10:34 0 d-------- C:\Users\Braden\AppData\Roaming\Roxio
2008-06-20 12:23:56 0 d-------- C:\Program Files\Common Files\McAfee
2008-06-12 08:55:36 0 d-------- C:\Program Files\Windows Mail
2008-06-11 10:11:48 0 d-------- C:\Program Files\Home Sweet Home
2008-05-19 15:44:21 0 d-------- C:\Program Files\BitTorrent
2008-05-19 15:44:14 0 d-------- C:\Program Files\DNA
2008-05-17 03:00:38 0 d-------- C:\Program Files\AIMTunes
2008-05-17 02:59:54 0 d-------- C:\Program Files\AIM6
2008-05-17 00:33:15 0 d-------- C:\Program Files\AC3Filter
2008-05-17 00:26:10 0 d-------- C:\Program Files\iTunes
2008-05-17 00:26:01 0 d-------- C:\Program Files\iPod
2008-05-17 00:23:51 0 d-------- C:\Program Files\QuickTime
2008-05-17 00:19:10 0 d-------- C:\Program Files\DivX
2008-05-12 20:53:16 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2008-05-12 20:50:16 196608 --a------ C:\Windows\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-05-12 20:50:16 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-05-12 20:50:08 802816 --a------ C:\Windows\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-05-12 20:50:08 823296 --a------ C:\Windows\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:50:08 831488 --a------ C:\Windows\system32\divx_xx0a.dll
2008-05-12 20:50:08 823296 --a------ C:\Windows\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:50:06 682496 --a------ C:\Windows\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:49:02 12288 --a------ C:\Windows\system32\DivXWMPExtType.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}]
11/26/2007 10:46 AM 324936 --a------ c:\PROGRA~1\mcafee\msk\mcapbho.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [09/18/2007 04:41 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [04/27/2007 07:35 PM]
"SigmatelSysTrayApp"="sttray.exe" [03/06/2007 03:37 PM C:\Windows\sttray.exe]
"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [03/21/2007 02:33 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [10/03/2006 11:37 AM]
"@"="" []
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [04/16/2007 04:10 PM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 10:24 AM]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [11/01/2007 09:41 PM]
"CTFMon"="C:\Windows\system32\CTF\ctfmon.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 07:12 PM]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" []
"MSServer"="C:\Windows\system32\hgGabYSl.dll" [07/09/2008 09:45 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 12:09 PM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [03/25/2008 03:21 PM]
"BitTorrent DNA"="C:\Users\Braden\Program Files\DNA\btdna.exe" [05/19/2008 10:13 PM]
"MSServer"="C:\Users\Braden\AppData\Local\Temp\cbXNEUNf.dll,#1" []
"cmds"="C:\Users\Braden\AppData\Local\Temp\tuvWmNgE.dll,c" []
"265f977a"="C:\Users\Braden\AppData\Local\Temp\doakkiwy.dll,b" []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [9/18/2007 9:00:53 AM]
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [7/20/2007 6:13:26 PM]
VPN Client.lnk - C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [12/8/2007 1:26:44 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"=2 (0x2)
"DontDisplayLogonHoursWarnings"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}"= C:\Users\Braden\AppData\Local\Temp\cbXNEUNf.dll [07/09/2008 09:45 AM 29568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a8e2edd-7709-11dc-b4ad-001c23970218}]
AutoRun\command- F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9464bdad-65ed-11dc-8450-806e6f6e6963}]
AutoRun\command- E:\Setup.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-07-10 10:04:10 ------------

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft® Windows Vista™ Home Premium (build 6000)
Architecture: X86; Language: English

CPU 0: AMD Turion™ 64 X2 Mobile Technology TL-60
Percentage of Memory in Use: 36%
Physical Memory (total/avail): 1917.53 MiB / 1218.55 MiB
Pagefile Memory (total/avail): 4057.02 MiB / 3158.52 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1924.32 MiB

C: is Fixed (NTFS) - 99.23 GiB total, 40.29 GiB free.
D: is Fixed (NTFS) - 10 GiB total, 6.27 GiB free.
E: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - Hitachi HTS722012K9A300 ATA Device - 111.79 GiB - 4 partitions
\PARTITION0 - Unknown - 62.72 MiB
\PARTITION1 - Installable File System - 10 GiB - D:
\PARTITION2 (bootable) - Installable File System - 99.23 GiB - C:
\PARTITION3 - Extended w/Extended Int 13 - 2.5 GiB



-- Security Center -------------------------------------------------------------

AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.

FW: McAfee Personal Firewall v (McAfee)
AV: McAfee VirusScan v (McAfee)
AS: McAfee VirusScan v (McAfee)
AS: Windows Defender v1.1.1505.0 (Microsoft Corporation) Disabled

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\ProgramData
APPDATA=C:\Users\Braden\AppData\Roaming
CLASSPATH=.;C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=BRADEN-PC
ComSpec=C:\Windows\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Users\Braden
LOCALAPPDATA=C:\Users\Braden\AppData\Local
LOGONSERVER=\\BRADEN-PC
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 104 Stepping 1, AuthenticAMD
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=6801
ProgramData=C:\ProgramData
ProgramFiles=C:\Program Files
PROMPT=$P$G
PUBLIC=C:\Users\Public
QTJAVA=C:\Program Files\Java\jre1.6.0\lib\ext\QTJava.zip
RoxioCentral=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
SystemDrive=C:
SystemRoot=C:\Windows
TEMP=C:\Users\Braden\AppData\Local\Temp
TMP=C:\Users\Braden\AppData\Local\Temp
USERDOMAIN=Braden-PC
USERNAME=Braden
USERPROFILE=C:\Users\Braden
windir=C:\Windows


-- User Profiles ---------------------------------------------------------------

Braden
Peach Bug
Guest (guest)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
AC3Filter (remove only) --> C:\Program Files\AC3Filter\uninstall.exe
Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Flash Player ActiveX --> C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.8 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
Adobe Shockwave Player --> C:\Windows\System32\Adobe\SHOCKW~1\UNWISE.EXE C:\Windows\System32\Adobe\SHOCKW~1\Install.log
AIM 6 --> C:\Program Files\AIM6\uninst.exe
AIMTunes --> C:\Program Files\AIMTunes\Uninstall.exe
Apple Mobile Device Support --> MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
ATI Catalyst Control Center --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x9
ATI PCI Express (3GIO) Filter Driver --> C:\Program Files\InstallShield Installation Information\{E713653C-8312-4BC6-AFC9-ADE1F2F04AB9}\Setup.exe -runfromtemp -l0x0009 -removeonly
Banctec Service Agreement --> MsiExec.exe /X{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}
BitTorrent --> C:\Program Files\BitTorrent\uninst.exe
BitZipper 5.0.5 --> "C:\Program Files\BitZipper\unins000.exe"
Broadcom Management Programs --> MsiExec.exe /I{C99C0593-3B48-41D9-B42F-6E035B320449}
ccc-Branding --> MsiExec.exe /I{4F5A53E6-3CBE-44D7-91AD-2E535348484F}
Cisco Systems VPN Client 5.0.00.0340 --> MsiExec.exe /X{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}
Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE}
Conexant HDA D330 MDC V.92 Modem --> C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F\HXFSETUP.EXE -U -Idel000fz.inf
Dell DataSafe Online --> MsiExec.exe /I{2C6C74C2-042F-4D36-B7B0-0C538FCF01AB}
Dell Support Center --> MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
Dell System Customization Wizard --> MsiExec.exe /I{13BA7B44-B712-4DEE-A7B8-1DD564F37AE5}
Dell Touchpad --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Dell Wireless WLAN Card --> "C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
DellSupport --> MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
Digital Line Detect --> C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
DivX Codec --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter --> C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player --> C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
DNA --> "C:\Users\Braden\Program Files\DNA\btdna.exe" /UNINSTALL
Games, Music, & Photos Launcher --> MsiExec.exe /I{3E25E350-949F-4DB7-8288-2A60E018B4C1}
Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
iTunes --> MsiExec.exe /I{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}
Java™ SE Runtime Environment 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
Lexmark 1200 Series --> C:\Windows\system32\spool\drivers\w32x86\3\LXCZUN5C.EXE -dLexmark 1200 Series
McAfee SecurityCenter --> C:\Program Files\McAfee\MSC\mcuninst.exe
MediaDirect --> C:\Program Files\InstallShield Installation Information\{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}\setup.exe -runfromtemp -l0x0009 -cluninstall
Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{91110409-6000-11D3-8CFE-0150048383C9}
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Works --> MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
Modem Diagnostic Tool --> MsiExec.exe /I{F63A3748-B93D-4360-9AD4-B064481A5C7B}
Move Networks Media Player for Internet Explorer --> C:\Users\Braden\AppData\Roaming\Move Networks\ie_bin\Uninst.exe
Mozilla Firefox (2.0.0.12) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833) --> MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
NBC Direct Beta --> MsiExec.exe /I{C91EF330-F152-44ED-A33A-0F4FF3FAF813}
NetWaiting --> C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x0009 -removeonly
OpenCASE Media Agent --> MsiExec.exe /I{1771FDC8-D846-4B77-996A-C80DAD42C03F}
OutlookAddinSetup --> MsiExec.exe /I{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}
Product Documentation Launcher --> MsiExec.exe /I{89CEAE14-DD0F-448E-9554-15781EC9DB24}
QuickSet --> MsiExec.exe /I{0F95AA42-0FF6-4D48-9CA1-64C8D0777500}
QuickTime --> MsiExec.exe /I{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}
Respondus LockDown Browser --> C:\Program Files\InstallShield Installation Information\{C0E5147E-C9F3-4360-9ED0-2E875F11766C}\setup.exe -runfromtemp -l0x0009 -removeonly
Roxio Creator Audio --> MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
Roxio Creator BDAV Plugin --> MsiExec.exe /I{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}
Roxio Creator Copy --> MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
Roxio Creator Data --> MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
Roxio Creator DE --> MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
Roxio Creator Tools --> MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
Roxio Express Labeler --> MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Roxio MyDVD DE --> MsiExec.exe /I{D639085F-4B6E-4105-9F37-A0DBB023E2FB}
Roxio Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
ScanSpyware v3.8 --> "C:\Program Files\ScanSpyware v3.8\unins000.exe"
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
SigmaTel Audio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
Sonic Activation Module --> MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
Sportsbook.com --> "C:\Program Files\Sportsbook.com Casino\Install.exe" -u
TEAM MANAGER Lite 5.0 --> MsiExec.exe /I{1087BD66-01A3-40EA-949F-CD511E5189AA}
The Price is Right (remove only) --> "C:\Program Files\Yahoo! Games\The Price is Right\Uninstall.exe"
URL Assistant --> regsvr32 /u /s "C:\Program Files\BAE\BAE.dll"
User's Guides --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.exe"
VideoLAN VLC media player 0.8.6d --> C:\Program Files\VideoLAN\VLC\uninstall.exe
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Virtools 3D Life Player --> C:\Program Files\Virtools\3D Life Player\WebplayerConfig.exe -u
Xvid 1.1.3 final uninstall --> "C:\Program Files\Xvid\unins000.exe"
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type25503 / Error
Event Submitted/Written: 07/10/2008 09:49:59 AM
Event ID/Source: 5007 / WerSvc
Event Description:
The target file for the Windows Feedback Platform (a DLL file containing the list of problems on this computer that require additional data collection for diagnosis) could not be parsed. The error code was 8014FFF9.

Event Record #/Type25499 / Success
Event Submitted/Written: 07/10/2008 09:49:32 AM
Event ID/Source: 5617 / WinMgmt
Event Description:


Event Record #/Type25498 / Success
Event Submitted/Written: 07/10/2008 09:49:28 AM
Event ID/Source: 5615 / WinMgmt
Event Description:


Event Record #/Type25491 / Success
Event Submitted/Written: 07/10/2008 09:48:37 AM
Event ID/Source: 902 / Software Licensing Service
Event Description:
The Software Licensing service has started.

Event Record #/Type25482 / Error
Event Submitted/Written: 07/10/2008 09:31:36 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application iexplore.exe, version 7.0.6000.16681, time stamp 0x48113d17, faulting module mshtml.dll, version 7.0.6000.16681, time stamp 0x48115c39, exception code 0xc0000005, fault offset 0x001a925e,
process id 0x2c6c, application start time 0xiexplore.exe0.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type81781 / Error
Event Submitted/Written: 07/10/2008 09:48:30 AM
Event ID/Source: 6008 / EventLog
Event Description:
The previous system shutdown at 9:47:09 AM on 7/10/2008 was unexpected.

Event Record #/Type81779 / Warning
Event Submitted/Written: 07/10/2008 09:22:41 AM
Event ID/Source: 243 / Win32k
Event Description:
A desktop heap allocation failed.

Event Record #/Type81778 / Error
Event Submitted/Written: 07/10/2008 09:21:23 AM
Event ID/Source: 10016 / DCOM
Event Description:
machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Braden-PCBradenS-1-5-21-2812243635-59155659-1044250643-1000LocalHost (Using LRPC)

Event Record #/Type81777 / Error
Event Submitted/Written: 07/10/2008 09:21:23 AM
Event ID/Source: 10016 / DCOM
Event Description:
machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Braden-PCBradenS-1-5-21-2812243635-59155659-1044250643-1000LocalHost (Using LRPC)

Event Record #/Type81776 / Error
Event Submitted/Written: 07/10/2008 09:21:22 AM
Event ID/Source: 10016 / DCOM
Event Description:
machine-defaultLocalActivation{9BA05972-F6A8-11CF-A442-00A0C90A8F39}Braden-PCBradenS-1-5-21-2812243635-59155659-1044250643-1000LocalHost (Using LRPC)



-- End of Deckard's System Scanner: finished at 2008-07-10 10:04:10 ------------

BC AdBot (Login to Remove)

 


#2 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:42 AM

Posted 11 July 2008 - 11:48 AM

Hello AggieUser,

Please disable Windows Defender before running Malwarebytes' Anti-Malware as it will prevent registry changes.

To disable Windows Defender:
Open Windows Defender.
Click on Tools, General Settings.
Scroll down and uncheck Turn on real-time protection (recommended).
After you uncheck this, click on the Save button and close Windows Defender.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish, so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Copy and Paste the entire Malwarebytes' Anti-Malware report in your next reply along with a fresh DSS Main.txt log.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediatly.

If you encounter this message:"c:\program files\malwarebytes' Anti-Malware\mbamext.dll Unable to register the dll/ocx: RegSvr32 failed with exit code 0x5" Click on ignore mbamext.dll

Edited by SifuMike, 11 July 2008 - 11:53 AM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#3 AggieUser

AggieUser
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:42 AM

Posted 14 July 2008 - 10:27 AM

I'm sorry for my delay in responding, but somehow the notification email got sent to my spam.
Anyways, I did what you said, and here are the logs. My windows defender was already disabled, do I need to enable it after running the scan?

Thanks,
Braden

Malwarebytes' Anti-Malware 1.20
Database version: 948
Windows 6.0.6000

10:21:13 AM 7/14/2008
mbam-log-7-14-2008 (10-21-13).txt

Scan type: Quick Scan
Objects scanned: 41796
Time elapsed: 12 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 12
Registry Values Infected: 5
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 111

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\Users\Braden\AppData\Local\Temp\fccaYrst.dll (Trojan.Vundo) -> Unloaded module successfully.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{684bfe7f-f5b2-4ab3-a95e-eb5036a2d286} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3a103b15-5ee2-4ef9-b694-634d167159e7} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3b5d02f0-cc2f-4b54-8ca8-0cfc65829e9d} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6ef7fcc7-8d8b-4f0c-b1e6-7cf4cdc00d86} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7b8270bf-978c-4ddd-8a1b-62e191f97674} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a02cf331-5043-4def-8f5a-a3a8b710b6c1} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c7665cbb-5d4b-44ac-9aed-487159a2c8d5} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df37427e-bdca-4e5f-9b22-4f78186d0930} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f17a4a1d-af14-40b2-ba07-1b08743414ee} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f73076eb-b967-4809-b344-a34386347bb5} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{684bfe7f-f5b2-4ab3-a95e-eb5036a2d286} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msserver (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msserver (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cmds (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\265f977a (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Braden\AppData\Local\Temp\fccaYrst.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\hgGabYSl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\xxyaxWPj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\amvggtvd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\bYonkjHa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\ddcyVPhE.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\geBqQjgD.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\hnpwyhbr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\jkkLdedE.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\khfGaaXp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\mlJDsQGA.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\mlJYomki.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\nnnkJArp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\nnnMgEwX.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\pMdAtRIA.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\rhbbsudu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\ssqPfccy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\swtlbdpw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp00019b73 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp00019d95 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp0001a39e (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp0001ace1 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp0001b22e (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp0001c541 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp0001cafb (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp0002704f (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp00028e2b (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp0003a39e (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp0006f298 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp00d3cb3e (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tmp02086909 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\tvvidcey.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\urqQgEXO.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\uulcsrid.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\xxyvvSlJ.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7A6Q6ODM\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7A6Q6ODM\kb767887[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7A6Q6ODM\kb767887[3] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7A6Q6ODM\kb767887[4] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7A6Q6ODM\kb767887[5] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7A6Q6ODM\kb767887[6] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7PNY1OJK\css4[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7PNY1OJK\kb456456[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\7PNY1OJK\kb767887[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\BM2HYUK1\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\BM2HYUK1\kb456456[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\BM2HYUK1\kb456456[3] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\BM2HYUK1\kb456456[4] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\BM2HYUK1\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\BM2HYUK1\kb767887[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\DOB2PXYB\css4[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\DOB2PXYB\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\DOB2PXYB\kb456456[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\DOB2PXYB\kb456456[3] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\DOB2PXYB\kb456456[4] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\DOB2PXYB\kb456456[5] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\DOB2PXYB\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\Local Settings\Temporary Internet Files\Content.IE5\DOB2PXYB\kb767887[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\afcsguli.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\awtRLCtR.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\awttqono.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\byXNhgeF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\efCrrsqR.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\fccArsPG.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\hgGyWpOG.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\jkKCtqRl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\khfCuTMF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\ljJCspmL.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\lomwpsfb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\lvmfwuaj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\mlJCVpMF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\mljiIcCv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\nnnnLfCS.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\oPIAQheB.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\rqRJAtsq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\ssqPfeBT.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0001865e (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0001a39e (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0001ae19 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0001af80 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0001bb33 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0005ca6f (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp000cec32 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0041904e (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0053b4ee (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp00be93aa (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp010efab8 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp018279c8 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp024a7385 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\tmp0251464e (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\vTLdBsqP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\wvUlmnkj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\wvUnOHwW.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\wvUoMgde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\xkmeqmcx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\AppData\Local\Temp\xnlgbfjk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Local\Temp\pmnoLfeF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Local\Temp\rglwjckw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Local\Temp\tuvTmLde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Guest\AppData\Local\Temp\vlwvyaxo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\Local Settings\Temporary Internet Files\Content.IE5\ACKEV7OF\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\Local Settings\Temporary Internet Files\Content.IE5\JXW5U20M\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\Local Settings\Temporary Internet Files\Content.IE5\JXW5U20M\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\Local Settings\Temporary Internet Files\Content.IE5\KGAX8DIJ\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\Local Settings\Temporary Internet Files\Content.IE5\KGAX8DIJ\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Peach Bug\Local Settings\Temporary Internet Files\Content.IE5\Y94YJJ5X\css4[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Guest\Local Settings\Temporary Internet Files\Content.IE5\BA1MEXU8\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Guest\Local Settings\Temporary Internet Files\Content.IE5\UBNECZZV\css4[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Guest\Local Settings\Temporary Internet Files\Content.IE5\UBNECZZV\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\Braden\AppData\Local\Temp\fccyyXno.dll (Trojan.Agent) -> Delete on reboot.
C:\Users\Braden\AppData\Local\Temp\tyhdqgcb.dll (Trojan.Vundo) -> Delete on reboot.


Deckard's System Scanner v20071014.68
Run by Braden on 2008-07-14 10:27:11
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Braden.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:16 AM, on 7/14/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\sttray.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM6\aim6.exe
C:\Users\Braden\Program Files\DNA\btdna.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Braden\Desktop\dss(2).exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Braden.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [CTFMon] C:\Windows\system32\CTF\ctfmon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Braden\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Braden\AppData\Local\Temp\fccyyXno.dll,c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in...l/installer.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9244 bytes

-- Files created between 2008-06-14 and 2008-07-14 -----------------------------

2008-07-14 10:06:45 0 d-------- C:\Users\All Users\Malwarebytes
2008-07-14 10:06:36 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-10 10:00:24 0 d-------- C:\Program Files\Trend Micro
2008-07-10 08:11:01 0 d-------- C:\Program Files\Lavasoft
2008-07-10 08:10:59 0 d-------- C:\Users\All Users\Lavasoft
2008-07-10 08:09:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 11:04:00 0 d-------- C:\Users\All Users\Yahoo! Companion
2008-07-08 17:34:14 0 d-------- C:\Program Files\Yahoo! Games
2008-07-08 11:10:18 0 d-------- C:\Program Files\Conduit
2008-07-08 11:10:14 0 d-------- C:\Program Files\BitZipperSearch
2008-07-08 11:09:23 0 d-------- C:\Program Files\BitZipper
2008-06-25 22:29:39 0 d-------- C:\ZIPTemp
2008-06-25 22:27:30 0 d-------- C:\TM5Data
2008-06-25 22:25:43 0 d-------- C:\Program Files\Common Files\DAO
2008-06-25 22:25:43 0 d-------- C:\Program Files\Common Files\Business Objects
2008-06-25 22:25:43 0 d-------- C:\Hy-Sport
2008-06-25 21:36:43 0 d-------- C:\Program Files\Lexmark 1200 Series
2008-06-25 21:35:48 299520 --a------ C:\Windows\uninst.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield unInstaller>
2008-06-25 21:35:44 0 -rahs---- C:\MSDOS.SYS
2008-06-25 21:35:44 0 -rahs---- C:\IO.SYS
2008-06-23 11:18:11 0 d-------- C:\Users\All Users\Fugazo
2008-06-20 07:47:06 143360 --a------ C:\Windows\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-06-15 21:39:48 0 d-------- C:\Windows\system32\Adobe


-- Find3M Report ---------------------------------------------------------------

2008-07-14 10:21:32 0 d-------- C:\Users\Braden\AppData\Roaming\DNA
2008-07-14 10:07:00 0 d-------- C:\Users\Braden\AppData\Roaming\Malwarebytes
2008-07-14 10:04:14 0 d-------- C:\Program Files\McAfee
2008-07-13 10:46:48 0 d-------- C:\Users\Braden\AppData\Roaming\BitTorrent
2008-07-11 09:53:14 174 --ahs---- C:\Program Files\desktop.ini
2008-07-11 07:36:59 0 d-------- C:\Program Files\Windows Mail
2008-07-10 08:09:15 0 d-------- C:\Program Files\Common Files
2008-07-08 11:09:30 0 d-------- C:\Users\Braden\AppData\Roaming\BitZipper
2008-06-25 00:09:24 0 d-------- C:\Users\Braden\AppData\Roaming\Move Networks
2008-06-23 11:16:44 0 d-------- C:\Program Files\Yahoo!
2008-06-22 23:10:34 0 d-------- C:\Users\Braden\AppData\Roaming\Roxio
2008-06-20 12:23:56 0 d-------- C:\Program Files\Common Files\McAfee
2008-06-11 10:11:48 0 d-------- C:\Program Files\Home Sweet Home
2008-05-19 15:44:21 0 d-------- C:\Program Files\BitTorrent
2008-05-19 15:44:14 0 d-------- C:\Program Files\DNA
2008-05-17 03:00:38 0 d-------- C:\Program Files\AIMTunes
2008-05-17 02:59:54 0 d-------- C:\Program Files\AIM6
2008-05-17 00:33:15 0 d-------- C:\Program Files\AC3Filter
2008-05-17 00:26:10 0 d-------- C:\Program Files\iTunes
2008-05-17 00:26:01 0 d-------- C:\Program Files\iPod
2008-05-17 00:23:51 0 d-------- C:\Program Files\QuickTime
2008-05-17 00:19:10 0 d-------- C:\Program Files\DivX
2008-05-12 20:53:16 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2008-05-12 20:50:16 196608 --a------ C:\Windows\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-05-12 20:50:16 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-05-12 20:50:08 802816 --a------ C:\Windows\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-05-12 20:50:08 823296 --a------ C:\Windows\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:50:08 831488 --a------ C:\Windows\system32\divx_xx0a.dll
2008-05-12 20:50:08 823296 --a------ C:\Windows\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:50:06 682496 --a------ C:\Windows\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:49:02 12288 --a------ C:\Windows\system32\DivXWMPExtType.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}]
11/26/2007 10:46 AM 324936 --a------ c:\PROGRA~1\mcafee\msk\mcapbho.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [09/18/2007 04:41 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [04/27/2007 07:35 PM]
"SigmatelSysTrayApp"="sttray.exe" [03/06/2007 03:37 PM C:\Windows\sttray.exe]
"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [03/21/2007 02:33 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [10/03/2006 11:37 AM]
"@"="" []
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [04/16/2007 04:10 PM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 10:24 AM]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [11/01/2007 09:41 PM]
"CTFMon"="C:\Windows\system32\CTF\ctfmon.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 07:12 PM]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" []
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [07/07/2008 05:35 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 12:09 PM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [03/25/2008 03:21 PM]
"BitTorrent DNA"="C:\Users\Braden\Program Files\DNA\btdna.exe" [05/19/2008 10:13 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 07:36 AM]
"cmds"="C:\Users\Braden\AppData\Local\Temp\fccyyXno.dll,c" []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [9/18/2007 9:00:53 AM]
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [7/20/2007 6:13:26 PM]
VPN Client.lnk - C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [12/8/2007 1:26:44 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"=2 (0x2)
"DontDisplayLogonHoursWarnings"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a8e2edd-7709-11dc-b4ad-001c23970218}]
AutoRun\command- F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9464bdad-65ed-11dc-8450-806e6f6e6963}]
AutoRun\command- E:\Setup.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-07-14 10:28:24 ------------

#4 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:42 AM

Posted 14 July 2008 - 12:22 PM

Hi AggieUser,

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of  Java Runtime Environment (JRE) 6 Update 7.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 7".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language  jre-6u7-windows-i586.exe and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    Examples of older versions in Add or Remove Programs:
    Java 2 Runtime Environment, SE v1.4.2
    J2SE Runtime Environment 5.0
    J2SE Runtime Environment 5.0 Update 6
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u7-windows-i586-p.exe to install the newest version.

*******************************************
Download CCleaner and install it. (default location is best). Do not run it yet!

Beginners Guide to CCleaner

*******************************************


Please run HijackThis and click "Scan." Place checks next to the following entries, if present:

O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Braden\AppData\Local\Temp\fccyyXno.dll,c

Close all browsers and other windows except for HijackThis, and click "Fix checked"

*******************************************

Please download the
OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
    (if you are running on Vista then right-click the program and choose Run as Administrator).
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Users\Braden\AppData\Local\Temp\fccyyXno.dll

  • Return to OTMoveIt2, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
  • Note : If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
    C:\_OTMoveIt2\MovedFiles\********_******.log
    (where "********_******" is the "date_time")
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Caution: Be careful of what you copy and paste with this tool. OTMoveIt2 is a powerful program, designed to move highly persistent files and folders. Not following the directions as instructed or using incorrectly could lead to disastrous problems with your operating system.


*******************************************

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders and does not make backups.

Let's empty the temp files:

Run CCleaner.

CAUTION: Please do NOT use the Issues or Registry button. This is a built-in registry cleaner. If you don't know how to use it, you may cause irreparable damage to your system.

1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation.
IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbarfree Basic version instead of the Standard Build.


2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"

3. Then select the items you wish to clean up.

In the Windows Tab:
Clean all entries in the "Internet Explorer" section except Autocomplete Forum History.
Clean all the entries in the "Windows Explorer" section.
Clean all entries in the "System" section except for Start Menu Shortcuts and Desktop Shortcuts.
Clean any others that you choose.

In the Applications Tab:
Clean all including cookies in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section.
Clean any others that you choose.

4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

If it asks you to reboot at the end, click NO.

CCleaner should be run with the above settings for each User Account!

*******************************************

Reboot your computer, post a new DSS Main.txt log, OTMoveIt2 log, and tell me how your computer is running.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#5 AggieUser

AggieUser
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:42 AM

Posted 14 July 2008 - 01:23 PM

My Computer seems to be running much better, and I am not receiving pop-ups anymore. The only other problem I note is that when I log on to the other User Account, I get pop-up messages about the computer not being able to load a module at location C:\Users\Peach_Bug\AppData\Local\Temp\WvUlmnkj.dll

C:\Users\Peach_Bug\AppData\Local\Temp\nnnnLfcs.dll

C:\Users\Peach_Bug\AppData\Local\Temp\xnlgbfjk.dll

They look similar to the thing that I had to delete earlier, and started showing up around the same time as the other problems, so I don't know if this is still a problem? At the least they are annoying.

Thanks

Braden
File/Folder C:\Users\Braden\AppData\Local\Temp\fccyyXno.dll not found.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07142008_125233


Deckard's System Scanner v20071014.68
Run by Braden on 2008-07-14 13:19:59
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Braden.exe) ----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:20:39 PM, on 7/14/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\sttray.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM6\aim6.exe
C:\Users\Braden\Program Files\DNA\btdna.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Users\Braden\Desktop\dss(2).exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Braden.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [CTFMon] C:\Windows\system32\CTF\ctfmon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [Lexmark 1200 Series] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Braden\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in...l/installer.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXE
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: OpenCASE Media Agent - ExtendMedia Inc. - C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9293 bytes

-- Files created between 2008-06-14 and 2008-07-14 -----------------------------

2008-07-14 12:47:09 0 d-------- C:\Program Files\CCleaner
2008-07-14 12:43:15 0 d-------- C:\Program Files\Common Files\Java
2008-07-14 10:06:45 0 d-------- C:\Users\All Users\Malwarebytes
2008-07-14 10:06:36 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-10 10:00:24 0 d-------- C:\Program Files\Trend Micro
2008-07-10 08:11:01 0 d-------- C:\Program Files\Lavasoft
2008-07-10 08:10:59 0 d-------- C:\Users\All Users\Lavasoft
2008-07-10 08:09:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 11:04:00 0 d-------- C:\Users\All Users\Yahoo! Companion
2008-07-08 17:34:14 0 d-------- C:\Program Files\Yahoo! Games
2008-07-08 11:10:18 0 d-------- C:\Program Files\Conduit
2008-07-08 11:10:14 0 d-------- C:\Program Files\BitZipperSearch
2008-07-08 11:09:23 0 d-------- C:\Program Files\BitZipper
2008-06-25 22:29:39 0 d-------- C:\ZIPTemp
2008-06-25 22:27:30 0 d-------- C:\TM5Data
2008-06-25 22:25:43 0 d-------- C:\Program Files\Common Files\DAO
2008-06-25 22:25:43 0 d-------- C:\Program Files\Common Files\Business Objects
2008-06-25 22:25:43 0 d-------- C:\Hy-Sport
2008-06-25 21:36:43 0 d-------- C:\Program Files\Lexmark 1200 Series
2008-06-25 21:35:48 299520 --a------ C:\Windows\uninst.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield unInstaller>
2008-06-25 21:35:44 0 -rahs---- C:\MSDOS.SYS
2008-06-25 21:35:44 0 -rahs---- C:\IO.SYS
2008-06-23 11:18:11 0 d-------- C:\Users\All Users\Fugazo
2008-06-20 07:47:06 143360 --a------ C:\Windows\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-06-15 21:39:48 0 d-------- C:\Windows\system32\Adobe


-- Find3M Report ---------------------------------------------------------------

2008-07-14 13:12:07 0 d-------- C:\Users\Braden\AppData\Roaming\DNA
2008-07-14 12:44:30 0 d-------- C:\Program Files\Java
2008-07-14 12:43:15 0 d-------- C:\Program Files\Common Files
2008-07-14 10:07:00 0 d-------- C:\Users\Braden\AppData\Roaming\Malwarebytes
2008-07-14 10:04:14 0 d-------- C:\Program Files\McAfee
2008-07-13 10:46:48 0 d-------- C:\Users\Braden\AppData\Roaming\BitTorrent
2008-07-11 09:53:14 174 --ahs---- C:\Program Files\desktop.ini
2008-07-11 07:36:59 0 d-------- C:\Program Files\Windows Mail
2008-07-08 11:09:30 0 d-------- C:\Users\Braden\AppData\Roaming\BitZipper
2008-06-25 00:09:24 0 d-------- C:\Users\Braden\AppData\Roaming\Move Networks
2008-06-23 11:16:44 0 d-------- C:\Program Files\Yahoo!
2008-06-22 23:10:34 0 d-------- C:\Users\Braden\AppData\Roaming\Roxio
2008-06-20 12:23:56 0 d-------- C:\Program Files\Common Files\McAfee
2008-06-11 10:11:48 0 d-------- C:\Program Files\Home Sweet Home
2008-05-19 15:44:21 0 d-------- C:\Program Files\BitTorrent
2008-05-19 15:44:14 0 d-------- C:\Program Files\DNA
2008-05-17 03:00:38 0 d-------- C:\Program Files\AIMTunes
2008-05-17 02:59:54 0 d-------- C:\Program Files\AIM6
2008-05-17 00:33:15 0 d-------- C:\Program Files\AC3Filter
2008-05-17 00:26:10 0 d-------- C:\Program Files\iTunes
2008-05-17 00:26:01 0 d-------- C:\Program Files\iPod
2008-05-17 00:23:51 0 d-------- C:\Program Files\QuickTime
2008-05-17 00:19:10 0 d-------- C:\Program Files\DivX
2008-05-12 20:53:16 3596288 --a------ C:\Windows\system32\qt-dx331.dll
2008-05-12 20:50:16 196608 --a------ C:\Windows\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-05-12 20:50:16 81920 --a------ C:\Windows\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-05-12 20:50:08 802816 --a------ C:\Windows\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-05-12 20:50:08 823296 --a------ C:\Windows\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:50:08 831488 --a------ C:\Windows\system32\divx_xx0a.dll
2008-05-12 20:50:08 823296 --a------ C:\Windows\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:50:06 682496 --a------ C:\Windows\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-05-12 20:49:02 12288 --a------ C:\Windows\system32\DivXWMPExtType.dll


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}]
11/26/2007 10:46 AM 324936 --a------ c:\PROGRA~1\mcafee\msk\mcapbho.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [09/18/2007 04:41 PM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [04/27/2007 07:35 PM]
"SigmatelSysTrayApp"="sttray.exe" [03/06/2007 03:37 PM C:\Windows\sttray.exe]
"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [03/21/2007 02:33 PM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [10/03/2006 11:37 AM]
"@"="" []
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [04/16/2007 04:10 PM]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [11/15/2007 10:24 AM]
"CTFMon"="C:\Windows\system32\CTF\ctfmon.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 07:12 PM]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" []
"Malwarebytes Anti-Malware Reboot"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [07/07/2008 05:35 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [03/15/2007 12:09 PM]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [03/25/2008 03:21 PM]
"BitTorrent DNA"="C:\Users\Braden\Program Files\DNA\btdna.exe" [05/19/2008 10:13 PM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 07:36 AM]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [9/18/2007 9:00:53 AM]
QuickSet.lnk - C:\Program Files\Dell\QuickSet\quickset.exe [7/20/2007 6:13:26 PM]
VPN Client.lnk - C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico [12/8/2007 1:26:44 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"=2 (0x2)
"DontDisplayLogonHoursWarnings"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a8e2edd-7709-11dc-b4ad-001c23970218}]
AutoRun\command- F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9464bdad-65ed-11dc-8450-806e6f6e6963}]
AutoRun\command- E:\Setup.EXE


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-07-14 13:21:55 ------------

#6 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:42 AM

Posted 14 July 2008 - 01:38 PM

Hi AggieUser,


My Computer seems to be running much better, and I am not receiving pop-ups anymore. The only other problem I note is that when I log on to the other User Account, I get pop-up messages about the computer not being able to load a module at location C:\Users\Peach_Bug\AppData\Local\Temp\WvUlmnkj.dll
C:\Users\Peach_Bug\AppData\Local\Temp\nnnnLfcs.dll
C:\Users\Peach_Bug\AppData\Local\Temp\xnlgbfjk.dll

They look similar to the thing that I had to delete earlier, and started showing up around the same time as the other problems, so I don't know if this is still a problem?



The other user account may be infected too. :)
Log on to it an run MalwareBytes and let it delete everything it finds. Then post a DSS Main.txt log here in a seperate post (not this thread, as that gets confusing to have two computers in one thread). Call it "AggieUser - 2nd User Account".


This log looks clean. :thumbsup:


Please read and follow Groovicus' Guide to Simple PC Security to help keep yourself from becoming infected again, as well as
How did I get infected?, With steps so it does not happen again!

Edited by SifuMike, 14 July 2008 - 01:41 PM.

If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#7 AggieUser

AggieUser
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:07:42 AM

Posted 14 July 2008 - 01:59 PM

Ok thanks so much.

Posting the second Account presently

#8 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:42 AM

Posted 14 July 2008 - 02:02 PM

Your very welcome. :thumbsup:
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

#9 SifuMike

SifuMike

    malware expert


  • Members
  • 15,385 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Vancouver (not BC) WA (Not DC) USA
  • Local time:05:42 AM

Posted 20 July 2008 - 01:52 PM

Since your problem appears to be resolved, this thread will now be closed. If you need this topic reopened, please contact me or a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
If I've saved you time & money,
please make a donation so I can keep helping people just like you! You can donate using a credit card and PayPal. Thank you!



Posted Image

Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users