Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Worm.win32.netbooster


  • This topic is locked This topic is locked
3 replies to this topic

#1 SaxyLady

SaxyLady

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:11 AM

Posted 18 July 2008 - 11:14 AM

I have run MBAM, ATF Cleaner, and SAS. The machine is running ALMOST normally, although very slowly. When I boot in normal mode, I do not get my desktop displayed correctly. (I am logging in with an account with administrative priviledges. Instead of the wallpaper that was selected, I just get a white screen with my desktop Icons on it.

Below is the log from HijackThis that I just ran. Can anyone help me?!?!?!!!

Thanks in advance!!

----------------------------------------------------------

Deckard's System Scanner v20071014.68
Run by Admin on 2008-07-17 16:39:24
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
9: 2008-07-17 23:39:33 UTC - RP879 - Deckard's System Scanner Restore Point
8: 2008-07-17 22:23:09 UTC - RP878 - Removed Windows Defender
7: 2008-07-17 22:19:26 UTC - RP877 - Removed SUPERAntiSpyware Free Edition
6: 2008-07-17 21:14:11 UTC - RP876 - Software Distribution Service 3.0
5: 2008-07-17 19:54:24 UTC - RP875 - Windows Defender Checkpoint


-- First Restore Point --
1: 2008-07-17 00:36:24 UTC - RP871 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 352 MiB (512 MiB recommended).


-- HijackThis (run as Admin.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:42:51 PM, on 7/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Documents and Settings\Admin\Desktop\MalWare Removers\dss.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Admin.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=763...gitCheckError=5
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://asp.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1127920097093
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0559F51E-A48F-4139-B4E5-9BA6B7C809F8}: NameServer = 4.2.2.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{0559F51E-A48F-4139-B4E5-9BA6B7C809F8}: NameServer = 4.2.2.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{0559F51E-A48F-4139-B4E5-9BA6B7C809F8}: NameServer = 4.2.2.2
O17 - HKLM\System\CS3\Services\Tcpip\..\{0559F51E-A48F-4139-B4E5-9BA6B7C809F8}: NameServer = 4.2.2.2
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O24 - Desktop Component 0: Privacy Protection - (no file)

--
End of file - 7339 bytes

-- File Associations -----------------------------------------------------------

.scr - scrfile - shell\open\command - "%1" %*


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R3 SiS315 - c:\windows\system32\drivers\sisgrp.sys <Not Verified; Silicon Integrated Systems Corporation; SiS ® Compatible Super VGA Miniport Driver for Windows XP>

S3 catchme - c:\docume~1\admin\locals~1\temp\catchme.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

All services whitelisted.


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Simple Communications Controller
Device ID: PCI\VEN_1813&DEV_4000&SUBSYS_00000000&REV_02\3&61AAA01&0&38
Manufacturer:
Name: PCI Simple Communications Controller
PNP Device ID: PCI\VEN_1813&DEV_4000&SUBSYS_00000000&REV_02\3&61AAA01&0&38
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-07-14 13:23:05 340 --a------ C:\WINDOWS\Tasks\HP Usg Daily.job
2008-07-07 20:00:00 620 --a------ C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Lily.job


-- Files created between 2008-06-17 and 2008-07-17 -----------------------------

2008-07-17 16:42:33 0 d-------- C:\Program Files\Trend Micro
2008-07-17 16:29:48 0 dr-hs---- C:\cmdcons
2008-07-17 16:29:45 0 d-------- C:\WINDOWS\setup.pss
2008-07-17 16:29:32 0 d-------- C:\WINDOWS\setupupd
2008-07-17 13:06:01 0 d-------- C:\WINDOWS\ERUNT
2008-07-17 12:57:41 0 d-------- C:\Documents and Settings\Admin\Application Data\Macromedia
2008-07-17 10:21:17 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-17 10:21:00 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-17 10:21:00 0 d-------- C:\Documents and Settings\Admin\Application Data\SUPERAntiSpyware.com
2008-07-17 10:09:36 0 d-------- C:\MalWare Removers
2008-07-17 09:24:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Webshots
2008-07-16 17:03:32 0 d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-16 17:01:52 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-16 17:01:52 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-16 17:01:52 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-16 17:01:52 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-16 17:01:52 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-16 17:01:52 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-16 17:01:52 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-07-16 17:01:52 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-16 17:01:52 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-16 16:31:52 0 d-------- C:\Documents and Settings\Admin\Application Data\Malwarebytes
2008-07-16 16:31:38 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-16 16:31:37 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-15 10:19:43 0 dr-h----- C:\Documents and Settings\Admin\Application Data\yahoo!
2008-07-15 09:35:58 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-14 17:27:34 0 d-------- C:\Documents and Settings\Admin\Application Data\TmpRecentIcons
2008-07-14 17:15:18 0 d-------- C:\Documents and Settings\Admin\Application Data\Adobe
2008-07-14 17:10:56 0 d--hs---- C:\WINDOWS\CSC
2008-07-14 16:51:07 0 d-------- C:\Documents and Settings\Lily\Application Data\TmpRecentIcons
2008-06-18 16:13:21 0 d-------- C:\Documents and Settings\Lily\Application Data\FunWebProducts


-- Find3M Report ---------------------------------------------------------------

2008-07-17 16:41:40 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-17 15:19:36 0 d-------- C:\Program Files\Common Files
2008-07-17 12:54:42 0 d-------- C:\Program Files\filesubmit
2008-07-14 17:13:48 0 d-------- C:\Program Files\Yahoo!
2008-06-02 08:34:05 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-20 12:45:31 39 --a----c- C:\WINDOWS\rhosts


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [04/28/2004 05:19 PM C:\WINDOWS\SOUNDMAN.EXE]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/09/2007 10:59 PM]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [01/14/2007 12:11 AM]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [11/28/2007 08:51 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [10/2/2007 7:03:35 PM]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
"C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VVSN]
C:\Program Files\VVSN\VVSN.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\setup.exe

*Newly Created Service* - COMHOST



-- End of Deckard's System Scanner: finished at 2008-07-17 16:44:03 ------------

Attached Files



BC AdBot (Login to Remove)

 


#2 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,716 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:03:11 PM

Posted 27 July 2008 - 09:24 AM

Hello SaxyLady,

Welcome to BC HijackThis forum. I am farbar. I am going to assist you with your problem.

Apologize for the delay in response we get overwhelmed at times but we are trying our best to keep up.

Thanks and again sorry for the delay.

  • Click Start and then Run to bring up the Run box.
  • Copy and paste the contents of this quote box into the run box:

    "%userprofile%\desktop\dss.exe" /config

  • Close all other open windows.
  • Click OK.
  • A window will now open. Click Check All and then click Scan!.
  • When the scan is complete, two text files will open in Notepad:
    • main.txt <- this one will be maximized
    • extra.txt <- this one will be minimized
  • If not, they both can be found in the C:\Deckard\System Scanner folder.
  • Please copy (Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your next reply.

Next
Please do a scan with Kaspersky Online Scanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


#3 SaxyLady

SaxyLady
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:09:11 AM

Posted 28 July 2008 - 04:38 PM

Farbar,

Thank you very much for your assistance. I have pasted the lastest HiJackThis log below. When I ran the Kaspersky Online Scanner as you requested, it did not find any malware so there was no Scan Report to view or save. The only other thing I did since the previous HiJackThis log, is to swap out a 128MB DIMM for a 256MB DIMM to bring total system memory up to 512MB, although the HJT log still says 480MB (up from 380MB). The system runs fairly "normally", but I am still having the same issue with not having the desktop wallpaper appear, but rather a white screen with the desktop icons.

Thanks,
Mindy


Deckard's System Scanner v20071014.68
Run by Admin on 2008-07-28 10:00:44
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 480 MiB (512 MiB recommended).


-- HijackThis (run as Admin.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:01:10 AM, on 7/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Documents and Settings\Admin\Desktop\dss.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Admin.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=763...gitCheckError=5
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: (no name) - {C17590D2-ECB4-4b15-8820-F58798DCC118} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://asp.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1127920097093
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0559F51E-A48F-4139-B4E5-9BA6B7C809F8}: NameServer = 4.2.2.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{0559F51E-A48F-4139-B4E5-9BA6B7C809F8}: NameServer = 4.2.2.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{0559F51E-A48F-4139-B4E5-9BA6B7C809F8}: NameServer = 4.2.2.2
O17 - HKLM\System\CS3\Services\Tcpip\..\{0559F51E-A48F-4139-B4E5-9BA6B7C809F8}: NameServer = 4.2.2.2
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O24 - Desktop Component 0: Privacy Protection - (no file)

--
End of file - 7434 bytes

-- Files created between 2008-06-28 and 2008-07-28 -----------------------------

2008-07-17 16:42:33 0 d-------- C:\Program Files\Trend Micro
2008-07-17 16:29:48 0 dr-hs---- C:\cmdcons
2008-07-17 16:29:45 0 d-------- C:\WINDOWS\setup.pss
2008-07-17 16:29:32 0 d-------- C:\WINDOWS\setupupd
2008-07-17 13:06:01 0 d-------- C:\WINDOWS\ERUNT
2008-07-17 12:57:41 0 d-------- C:\Documents and Settings\Admin\Application Data\Macromedia
2008-07-17 10:21:17 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-17 10:21:00 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-17 10:21:00 0 d-------- C:\Documents and Settings\Admin\Application Data\SUPERAntiSpyware.com
2008-07-17 10:09:36 0 d-------- C:\MalWare Removers <MALWAR~1>
2008-07-17 09:24:12 0 d-------- C:\Documents and Settings\Administrator\Application Data\Webshots
2008-07-16 17:03:32 0 d-------- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-16 17:01:52 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-16 17:01:52 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-16 17:01:52 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-16 17:01:52 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-16 17:01:52 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-16 17:01:52 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-16 17:01:52 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-16 17:01:52 0 d---s---- C:\Documents and Settings\Administrator\Cookies
2008-07-16 17:01:52 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-16 17:01:52 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-16 16:31:52 0 d-------- C:\Documents and Settings\Admin\Application Data\Malwarebytes
2008-07-16 16:31:38 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-16 16:31:37 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-15 10:19:43 0 dr-h----- C:\Documents and Settings\Admin\Application Data\yahoo!
2008-07-15 09:35:58 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-14 17:27:34 0 d-------- C:\Documents and Settings\Admin\Application Data\TmpRecentIcons
2008-07-14 17:15:18 0 d-------- C:\Documents and Settings\Admin\Application Data\Adobe
2008-07-14 17:10:56 0 d--hs---- C:\WINDOWS\CSC
2008-07-14 16:51:07 0 d-------- C:\Documents and Settings\Lily\Application Data\TmpRecentIcons


-- Find3M Report ---------------------------------------------------------------

2008-07-17 16:41:40 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-17 15:19:36 0 d-------- C:\Program Files\Common Files
2008-07-17 12:54:42 0 d-------- C:\Program Files\filesubmit
2008-07-14 17:13:48 0 d-------- C:\Program Files\Yahoo!
2008-06-02 08:34:05 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-20 12:45:31 39 --a----c- C:\WINDOWS\rhosts


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [04/28/2004 05:19 PM C:\WINDOWS\SOUNDMAN.EXE]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [01/09/2007 10:59 PM]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [01/14/2007 12:11 AM]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [11/28/2007 08:51 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [10/2/2007 7:03:35 PM]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
"C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VVSN]
C:\Program Files\VVSN\VVSN.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\setup.exe

*Newly Created Service* - COMHOST



-- End of Deckard's System Scanner: finished at 2008-07-28 10:02:10 ------------

Edited by SaxyLady, 29 July 2008 - 10:34 AM.


#4 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:03:11 PM

Posted 30 July 2008 - 02:49 AM

As another topic here seems to be resolved, I will close this thread.
Microsoft MVP Consumer Security
Posted Image

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users