Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Looks Like I Have The Darksma Virus/malware Installed


  • This topic is locked This topic is locked
14 replies to this topic

#1 tsherma

tsherma

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 23 July 2008 - 01:00 PM

I have run Mcafee and also my Comcast spyware tool. It is actually the Comcast tool that sees Darksma, not Mcafee. I try to remove it, but it just keeps coming back.
here is my HJT log file.
Any help would really be apreciated.

Deckard's System Scanner v20071014.68
Run by Owner on 2008-07-23 13:40:56
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Total Physical Memory: 480 MiB (512 MiB recommended).


-- HijackThis (run as Owner.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:41:22 PM, on 7/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\S3tray2.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe
C:\Program Files\TiVo\Desktop\TiVoNotify.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Documents and Settings\Owner\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus9.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: {4b6ce727-e34e-3cf9-e844-b48f22ada471} - {174ada22-f84b-448e-9fc3-e43e727ec6b4} - C:\WINDOWS\system32\ggwjty.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: (no name) - {82336A8D-6CD0-4647-B791-75FCA8CF2B39} - C:\WINDOWS\system32\fcccyAtt.dll (file missing)
O2 - BHO: (no name) - {BB5C2A03-5B0F-4C1C-ABA9-57655C8E45EC} - C:\WINDOWS\system32\tuvWpPgD.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [00ae122b] rundll32.exe "C:\WINDOWS\system32\lopecjtt.dll",b
O4 - HKLM\..\Run: [BM039d21b7] Rundll32.exe "C:\WINDOWS\system32\wmfiyjgo.dll",s
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [TivoTransfer] "C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" /service /registry /auto:TivoTransfer
O4 - HKCU\..\Run: [TivoNotify] "C:\Program Files\TiVo\Desktop\TiVoNotify.exe" /service /registry /auto:TivoNotify
O4 - HKCU\..\Run: [TivoServer] "C:\Program Files\TiVo\Desktop\TiVoServer.exe" /service /registry
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Ubhxj] "C:\Program Files\Common Files\?ymbols\arpa.exe"
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.avsystemcare.com
O15 - Trusted Zone: *.gomyhit.com
O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.onerateld.com
O15 - Trusted Zone: *.safetydownload.com
O15 - Trusted Zone: *.storageguardsoft.com
O15 - Trusted Zone: *.trustedantivirus.com
O15 - Trusted Zone: *.virusschlacht.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)
O15 - Trusted Zone: *.sxload.net (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: fcccyAtt - fcccyAtt.dll (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe

--
End of file - 8921 bytes

-- Files created between 2008-06-23 and 2008-07-23 -----------------------------

2008-07-23 13:41:09 0 d-------- C:\Program Files\Trend Micro
2008-07-22 17:06:54 83328 --a------ C:\WINDOWS\system32\lopecjtt.dll
2008-07-22 17:06:24 105328 --a------ C:\WINDOWS\system32\pbbchvyp.dll
2008-07-22 17:06:24 105328 --a------ C:\WINDOWS\system32\ggwjty.dll
2008-07-22 17:06:15 91488 --a------ C:\WINDOWS\system32\wmfiyjgo.dll
2008-07-21 17:08:23 0 d-------- C:\Program Files\ComcastToolbar
2008-07-21 15:00:03 0 d-------- C:\Program Files\Common Files\Scanner
2008-07-21 14:59:59 0 d-------- C:\Documents and Settings\Owner\Application Data\ComcastToolbar
2008-07-21 10:56:50 143360 --a------ C:\WINDOWS\system32\dunzip32.dll <Not Verified; Inner Media, Inc.; DynaZIP-32 Multi-Threading UnZIP DLL>
2008-07-21 10:49:50 0 d-------- C:\Program Files\McAfee.com
2008-07-21 10:49:22 0 d-------- C:\Program Files\Common Files\McAfee
2008-07-21 10:48:54 0 d-------- C:\Program Files\McAfee
2008-07-21 09:43:33 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-07-19 23:08:34 859825 --ahs---- C:\WINDOWS\system32\DgPpWvut.ini2
2008-07-19 23:08:25 314656 --a------ C:\WINDOWS\system32\tuvWpPgD.dll
2008-07-19 23:04:06 0 d-------- C:\Program Files\Common Files\?ymbols
2008-07-19 23:03:31 0 d-------- C:\Program Files\Common Files\F?nts
2008-07-19 23:03:14 0 d-------- C:\WINDOWS\system32\carH01
2008-07-19 23:03:13 0 d-------- C:\Temp


-- Find3M Report ---------------------------------------------------------------

2008-07-21 17:08:22 0 d-------- C:\Program Files\Common Files\?ymbols
2008-07-21 17:06:38 0 d-------- C:\Program Files\Common Files
2008-07-21 17:06:29 0 d-------- C:\Program Files\Easy Internet signup
2008-07-21 10:48:40 0 d-------- C:\Program Files\Common Files\F?nts
2008-07-04 22:29:26 0 d-------- C:\Documents and Settings\Owner\Application Data\AdobeUM
2008-07-03 17:45:28 0 d-------- C:\Documents and Settings\Owner\Application Data\Adobe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{174ada22-f84b-448e-9fc3-e43e727ec6b4}]
07/22/2008 05:06 PM 105328 --a------ C:\WINDOWS\system32\ggwjty.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{82336A8D-6CD0-4647-B791-75FCA8CF2B39}]
C:\WINDOWS\system32\fcccyAtt.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB5C2A03-5B0F-4C1C-ABA9-57655C8E45EC}]
07/19/2008 11:08 PM 314656 --a------ C:\WINDOWS\system32\tuvWpPgD.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 07:04 PM]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [04/07/2003 10:07 AM]
"KBD"="C:\HP\KBD\KBD.EXE" [02/11/2003 11:02 PM]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [09/14/2002 12:42 AM]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [05/03/2003 02:19 AM]
"nwiz"="nwiz.exe" [05/03/2003 02:19 AM C:\WINDOWS\system32\nwiz.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [07/31/2002 11:28 PM]
"S3TRAY2"="S3tray2.exe" [02/25/2003 04:33 AM C:\WINDOWS\system32\S3tray2.exe]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [06/16/2004 06:03 AM]
"MXOBG"="C:\WINDOWS\MXOALDR.EXE" [10/10/2003 11:23 AM]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [11/01/2007 07:12 PM]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [08/04/2004 03:56 AM]
"00ae122b"="C:\WINDOWS\system32\lopecjtt.dll" [07/22/2008 05:06 PM]
"BM039d21b7"="C:\WINDOWS\system32\wmfiyjgo.dll" [07/22/2008 05:06 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVIEW"="nview.dll,nViewLoadHook" []
"TivoTransfer"="C:\Program Files\Common Files\TiVo Shared\Transfer\TiVoTransfer.exe" [09/25/2007 10:33 AM]
"TivoNotify"="C:\Program Files\TiVo\Desktop\TiVoNotify.exe" [09/25/2007 10:34 AM]
"TivoServer"="C:\Program Files\TiVo\Desktop\TiVoServer.exe" [09/25/2007 10:35 AM]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [03/30/2006 04:45 PM]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [03/27/2007 03:22 PM]
"Ubhxj"="C:\Program Files\Common Files\?ymbols\arpa.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [4/23/2008 3:38:16 AM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"disableregistrytools"=0 (0x0)
"disabletaskmgr"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{82336A8D-6CD0-4647-B791-75FCA8CF2B39}"= C:\WINDOWS\system32\fcccyAtt.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fcccyAtt]
fcccyAtt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 02/21/2003 06:50 AM 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\tuvWpPgD

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 2000 Series.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hp psc 2000 Series.lnk.disabled
backup=C:\WINDOWS\pss\hp psc 2000 Series.lnk.disabledCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk.disabled
backup=C:\WINDOWS\pss\hpoddt01.exe.lnk.disabledCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk.disabled]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk.disabled
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnk.disabledCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DIGServices]
C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ]
"C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
"C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SFP]
C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
"C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xloadnet]
"C:\Program Files\xloadnet\xloadnet.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinDefend"=2 (0x2)
"SymWSC"=2 (0x2)
"omniserv"=2 (0x2)
"gusvc"=3 (0x3)
"CurtainsSysSvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"mmtask"=C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"ReminderApp"=C:\Program Files\Nova Development\Greeting Card Factory Deluxe\ReminderApp.exe




-- End of Deckard's System Scanner: finished at 2008-07-23 13:42:02 ------------



Thanks Again

BC AdBot (Login to Remove)

 


m

#2 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:11:48 AM

Posted 24 July 2008 - 07:13 PM

Hello, my name is fenzodahl512 and welcome to BC., Please do the following....


Please download ATF Cleaner by Atribune.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.





NEXT


Please visit below webpage for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. DO NOT select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix (located in C:\combofix.txt) when you've accomplished that, along with a new HijackThis log.




Regards
fenzodahl512

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#3 tsherma

tsherma
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 25 July 2008 - 05:44 PM

Thanks fenzodahl512!!!!
So fsar so good. I followed your instructions and here are the attached Combo Fix and HJT log files.
Thanks again

Attached Files



#4 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:11:48 AM

Posted 25 July 2008 - 06:05 PM

1. Please open Notepad
  • Click Start, then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

Folder::
C:\WINDOWS\system32\carH01
C:\Temp\btxv15
C:\Program Files\Common Files\?ymbols

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ubhxj"=-

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.



NEXT


I noticed you already have Malwarebytes'.. Please run and update it...
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Please post the following logs in your next reply..

1. ComboFix
2. Malwarebytes'
3. A fresh HijackThis (after Malwarebytes' step)


Regards
fenzodahl512

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#5 tsherma

tsherma
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 25 July 2008 - 10:38 PM

Here are the 3 log files you requested.
I do want to add one thing, before I started these scans I had rebooted, and when I did the windows updates ran and installed 7 updates. I am not sure if that is a good thing or bad thing, but I figured it was worth mentioning.
Thanks Again!!!!!

Attached Files



#6 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:11:48 AM

Posted 26 July 2008 - 07:52 AM

Do you add imageservr.com to your Internet Trusted Zones? If not, fix below with HijackThis..

O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.imageservr.com (HKLM)



----------------


Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\WINDOWS\system32\carH01
    C:\Temp\btxv15
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Ubhxj
    EmptyTemp
    purity
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.




NEXT


Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Please post the following logs in your next reply..

1. OTMoveIt2
2. Kaspersky Webscanner
3. A fresh DSS log (after Kaspersky step)
4. Tell me about your computer condition..


Regards
fenzodahl512

Edited by fenzodahl512, 26 July 2008 - 07:53 AM.

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#7 tsherma

tsherma
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 27 July 2008 - 10:31 AM

Ok, everything is looking good. I am able to browse with no problems, it is running faster and I have not seen any pop-ups.
Here are the log files you requested....

Thanks Again!!!!!!!

Attached Files



#8 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:11:48 AM

Posted 27 July 2008 - 02:48 PM

Great!.. Now lets do this...


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
    Please note that the space between x and / is needed

    Posted Image


Lastly, to keep your operating system up to date please visit the link below monthlyPlease read these excellent articles by miekiemoes :
Help! My computer is slow!
How to prevent Malware

And another excellent article by CastleCops Malware Prevention: Prevent Re-infection

Please reply to this thread once more and tell us about the computer behaviour before we can close this thread :thumbsup:



Have a safe and happy computing day!


Regards
fenzodahl512

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#9 tsherma

tsherma
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 29 July 2008 - 07:50 AM

Things are definitely looking better, but I do have a questions/concern. My system takes an extremely long time from booting up until I am able to launch and open a website. I assume this is just the firewall at work, but is there anyway to improve it? This is the issue that got me in trouble to begin with. My system was running slow across the board, so in an effort to figure out why, I disabled the AntiVirus software that was supplied by my ISP. Imediately my system was running back at full speed. I realize that there has to be some comprimise when running any antivirus software, but are there anyway tricks to improve it?

Also another thing I noticed is that when I ran the spyware scan that came with my ISP toolbar it still picks up a couple of items which it is able to remove, and happily Darksma is not on the list, but is that to be expected that a few items will always show up just through the course of normal browsing, or should I be worried.


Thanks again for all of your help.

#10 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:11:48 AM

Posted 29 July 2008 - 01:09 PM

Things are definitely looking better, but I do have a questions/concern. My system takes an extremely long time from booting up until I am able to launch and open a website. I assume this is just the firewall at work, but is there anyway to improve it? This is the issue that got me in trouble to begin with. My system was running slow across the board, so in an effort to figure out why, I disabled the AntiVirus software that was supplied by my ISP. Imediately my system was running back at full speed. I realize that there has to be some comprimise when running any antivirus software, but are there anyway tricks to improve it?

Also another thing I noticed is that when I ran the spyware scan that came with my ISP toolbar it still picks up a couple of items which it is able to remove, and happily Darksma is not on the list, but is that to be expected that a few items will always show up just through the course of normal browsing, or should I be worried.


Thanks again for all of your help.



Ok.. lets go this one by one..

1. Please read this article and do all steps suggested.. After that, please tell me if your computer is improved..

Help! My computer is slow!


2. Since you mentioned that your antivirus is slowing your computer down (McAfee isn't it?) Tell me, do you still want to use McAfee or do you want to try other alternatives?

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#11 tsherma

tsherma
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 29 July 2008 - 02:28 PM

I am not committed to Mcaffee. It just happens to be the free software that my ISP provided. I would happily be open to suggestions.

I am at work now, but when I get home I will try your suggestions for helping my system performance. I have done the majority already. I have cleaned up my MSConfig, run defrag, cleared temp files, and deleted old programs. But I do only have 512k memory, and using Mcafee may in fact be my problem. Perhaps a less resource intensive antivirus program may be my answer.

Thanks

Edited by tsherma, 29 July 2008 - 02:36 PM.


#12 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:11:48 AM

Posted 29 July 2008 - 02:51 PM

If you decide to uninstall McAfee, please use McAfee Removal Tool.. link below:

http://majorgeeks.com/McAfee_Consumer_Prod...Tool_d5420.html



For alternative free antivirus, I recommend you below. Please install ONLY ONE of them..If you are low on memory I suggest you to install either Avira Antivir or PCTools Antivirus..

As for memory, I highly suggest you to upgrade to at least 1gb of RAM.. Make sure that RAM is compatible to your computer :thumbsup:


Regards
fenzodahl512

Edited by fenzodahl512, 29 July 2008 - 02:53 PM.

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#13 tsherma

tsherma
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 29 July 2008 - 04:05 PM

If you decide to uninstall McAfee, please use McAfee Removal Tool.. link below:

http://majorgeeks.com/McAfee_Consumer_Prod...Tool_d5420.html



For alternative free antivirus, I recommend you below. Please install ONLY ONE of them..

If you are low on memory I suggest you to install either Avira Antivir or PCTools Antivirus..

As for memory, I highly suggest you to upgrade to at least 1gb of RAM.. Make sure that RAM is compatible to your computer :thumbsup:


Regards
fenzodahl512


I know you wouldn't be recomending these free alternatives if they didn't work, but are they as effective as all the big name products out there. In other words, is Avira and PCtools as good a Mcafee?

And I certainly do realize that more ram would help. This is a 6 year old PC and I have just been too lazy to go out and upgrade it. And also I figured eventually my wife would let me buy a new one.

#14 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:11:48 AM

Posted 29 July 2008 - 04:24 PM

I know you wouldn't be recomending these free alternatives if they didn't work, but are they as effective as all the big name products out there. In other words, is Avira and PCtools as good a Mcafee?


Let just say that personally, I use Avira Antivir and I wouldn't swap it with McAfee.. I pair it with Malwarebytes' and PCTools Firewall (need to configure a bit..) and it works wonders in my laptop ;) ...


And I certainly do realize that more ram would help. This is a 6 year old PC and I have just been too lazy to go out and upgrade it. And also I figured eventually my wife would let me buy a new one


6-year old!! Wow.. I envy you.. It's quite hard to seek RAM that match with your computer.. Maybe if your wife will let you (to buy a new one).. :thumbsup:

If there's nothing more I'm gonna close this topic :)

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#15 tsherma

tsherma
  • Topic Starter

  • Members
  • 19 posts
  • OFFLINE
  •  
  • Local time:10:48 PM

Posted 30 July 2008 - 07:09 AM

Yes, I think I should be fine now. You may close the topic.

Thank you very much for all of your help!!!!!!!! :thumbsup:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users