Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan.bho, Caused Compter Crash


  • This topic is locked This topic is locked
2 replies to this topic

#1 jerg_064

jerg_064

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:35 AM

Posted 10 August 2008 - 01:54 PM

I had no problem removing Virtumonde Trojans, but when i used malwarebytes to try to remove this Trojan.BHO my computer failed to start windows upon restart. I had to use a windows start-up disk to repair. But it just booted me back up to an older configuration with all 4 viruses. I removed the three normal ones, but i have yet to try and remove the BHO again for fear of computer crash. Any suggestions.

Also the highjackthis only gave me the main log, no extra.

Deckard's System Scanner v20071014.68
Run by Steve on 2008-08-10 14:38:51
Computer is in Normal Mode.
--------------------------------------------------------------------------------

Percentage of Memory in Use: 89% (more than 75%).
Total Physical Memory: 958 MiB (1024 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-08-10 14:39:21
Platform: Windows Vista Service Pack 1 (6.00.6001)
MSIE: Internet Explorer (7.00.6000.16386)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\taskeng.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Windows\System32\dwm.exe
C:\Windows\explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\System32\SearchFilterHost.exe
C:\Users\Steve\Desktop\dss.exe
C:\Windows\System32\dllhost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...n&pf=laptop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: (no name) - {100B21CD-3B97-44FB-B1C0-EA6249E482E8} - (no file)
O2 - BHO: (no name) - {276A51C8-DE43-479F-9CB8-905D9113D2E9} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {66c97a75-266d-4821-8737-ec332f334431} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {95E2C5A6-18CB-444E-83D2-080475E41971} - (no file)
O2 - BHO: (no name) - {A10ECB93-3657-4A7E-B6C7-4D00B566139C} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [MRT] "C:\Windows\system32\MRT.exe" /R
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P10 /q C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\IMCE71B8\GOOGLE~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\441AYQV8\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\99SY8D6V\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WB0QDRWD\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\DWUS3OTR\B26292~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\GS071H12\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\DQBLENQE\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\99SY8D6V\__ORD_~2.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WB0QDRWD\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\QA4OJRND\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\JJBLNBF5\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\QYXG7I5I\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\VDZA40V7\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\JJBLNBF5\CLIENT~2.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\CFSI3M0G\FAVICO~3.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\UKMZIT8M\DOCUME~1.SH! c:\users\steve\appdata\local\temp\PLUGTM~1.SH! (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\Users\Steve\AppData\Local\Temp\~DFC59E.tmp C:\Users\Steve\AppData\Local\Temp\~DFC58F.tmp (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P10 /q C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\IMCE71B8\GOOGLE~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\441AYQV8\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\99SY8D6V\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WB0QDRWD\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\DWUS3OTR\B26292~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\GS071H12\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\DQBLENQE\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\99SY8D6V\__ORD_~2.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WB0QDRWD\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\QA4OJRND\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\JJBLNBF5\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\QYXG7I5I\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\VDZA40V7\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\JJBLNBF5\CLIENT~2.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\CFSI3M0G\FAVICO~3.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\UKMZIT8M\DOCUME~1.SH! c:\users\steve\appdata\local\temp\PLUGTM~1.SH! (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\Users\Steve\AppData\Local\Temp\~DFC59E.tmp C:\Users\Steve\AppData\Local\Temp\~DFC58F.tmp (User 'Default user')
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Bluetooth\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: msdde - {D01E038A-4B55-417E-9DDC-F58D5C3FEA4A} - (no file)
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McProxy\McProxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\Mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MpfSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\msksrver.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\System32\VundoFixSVC.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\System32\drivers\XAudio.exe


--
End of file - 16389 bytes

-- Files created between 2008-07-10 and 2008-08-10 -----------------------------

2008-07-15 17:44:58 0 d-------- C:\Users\All Users\Google Updater
2008-07-14 18:42:01 0 d-------- C:\Program Files\Groove Games


-- Find3M Report ---------------------------------------------------------------

2008-08-10 14:16:45 0 d-------- C:\Users\Steve\AppData\Roaming\Yahoo!
2008-08-10 14:11:31 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-10 14:07:16 13025 --a------ C:\Users\Steve\AppData\Roaming\nvModes.001
2008-08-10 11:18:27 13025 --a------ C:\Users\Steve\AppData\Roaming\nvModes.dat
2008-08-01 18:22:09 0 d-------- C:\Users\Steve\AppData\Roaming\Hewlett-Packard
2008-07-28 21:49:56 12 --a------ C:\Windows\bthservsdp.dat
2008-07-19 19:44:29 0 d-------- C:\Program Files\Hewlett-Packard
2008-07-19 14:24:23 0 d-------- C:\Program Files\CDC Studyware
2008-07-18 21:08:07 0 d-------- C:\Program Files\HP
2008-07-18 20:57:39 0 d-------- C:\Program Files\MSN Messenger
2008-07-18 20:35:42 174 --ahs---- C:\Program Files\desktop.ini
2008-07-18 20:23:28 0 d-------- C:\Program Files\Windows Calendar
2008-07-18 20:23:27 0 d-------- C:\Program Files\Windows Sidebar
2008-07-18 20:23:27 0 d-------- C:\Program Files\Movie Maker
2008-07-18 20:23:26 0 d-------- C:\Program Files\Windows Mail
2008-07-18 20:23:23 0 d-------- C:\Program Files\Windows Journal
2008-07-18 20:23:23 0 d-------- C:\Program Files\Windows Collaboration
2008-07-18 20:23:22 0 d-------- C:\Program Files\Windows Photo Gallery
2008-07-18 20:23:12 0 d-------- C:\Program Files\Windows Defender
2008-07-15 17:45:00 0 d-------- C:\Program Files\Google
2008-07-04 12:36:23 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-30 20:59:03 0 d-------- C:\Program Files\McAfee
2008-06-30 20:17:44 95808 -----n--- C:\Windows\system32\tstwgxau.dll
2008-06-30 16:35:02 0 d-------- C:\Users\Steve\AppData\Roaming\Malwarebytes
2008-05-27 17:53:35 24576 --a------ C:\Windows\system32\VundoFixSVC.exe <Not Verified; Atribune.org; Vundofix Service>
2008-05-26 22:22:05 2624 --a------ C:\Windows\system32\iehvltuk.exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{100B21CD-3B97-44FB-B1C0-EA6249E482E8}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{276A51C8-DE43-479F-9CB8-905D9113D2E9}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66c97a75-266d-4821-8737-ec332f334431}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95E2C5A6-18CB-444E-83D2-080475E41971}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A10ECB93-3657-4A7E-B6C7-4D00B566139C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [01/19/2008 03:38 AM]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [11/06/2006 02:58 PM]
"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [04/15/2008 01:42 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [12/19/2006 11:58 AM]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [02/16/2005 08:15 PM]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [02/08/2007 10:39 PM]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [08/04/2007 02:33 AM]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [03/28/2008 02:05 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/22/2008 01:35 PM]
"SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [09/15/2007 02:29 AM]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [02/27/2007 11:26 AM]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [02/27/2007 11:26 AM]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [02/27/2007 11:26 AM]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [05/08/2007 04:24 PM]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [10/03/2007 03:15 PM]
"MRT"="C:\Windows\system32\MRT.exe" [06/25/2008 12:15 PM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [11/21/2006 08:36 PM]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [02/16/2005 08:15 PM]
"msnmsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [01/19/2007 12:54 PM]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [01/19/2008 03:33 AM]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [01/19/2008 03:33 AM]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [01/28/2008 11:43 AM]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"DelayShred"="c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\Users\Steve\AppData\Local\Temp\~DFC59E.tmp C:\Users\Steve\AppData\Local\Temp\~DFC58F.tmp

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DelayShred"="C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P10 /q C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\IMCE71B8\GOOGLE~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\441AYQV8\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\99SY8D6V\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WB0QDRWD\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\DWUS3OTR\B26292~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\GS071H12\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\DQBLENQE\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\99SY8D6V\__ORD_~2.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\WB0QDRWD\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\QA4OJRND\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\JJBLNBF5\CLIENT~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\QYXG7I5I\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\VDZA40V7\ADS_1_~1.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\JJBLNBF5\CLIENT~2.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\CFSI3M0G\FAVICO~3.SH! C:\Users\Steve\AppData\Local\MICROS~1\Windows\TEMPOR~1\Content.IE5\UKMZIT8M\DOCUME~1.SH! c:\users\steve\appdata\local\temp\PLUGTM~1.SH!

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Connections.lnk - C:\Program Files\HP Connections\6811507\Program\HP Connections.exe [12/19/2006 11:40:43 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"=2 (0x2)
"EnableLUA"=0 (0x0)
"EnableUIADesktopToggle"=0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
@="SecurityDevices"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3cf4079a]
rundll32.exe "C:\Windows\system32\qiojlnah.dll",b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM3fc73406]
Rundll32.exe "C:\Windows\system32\iticmwol.dll",s

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService nsi lltdsvc SSDPSRV upnphost SCardSvr w32time EventSystem RemoteRegistry WinHttpAutoProxySvc lanmanworkstation TBS SLUINotify THREADORDER fdrespub netprofm fdphost wcncsvc QWAVE Mcx2Svc WebClient SstpSvc
LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
bthsvcs BthServ
iissvcs w3svc was
apphost apphostsvc


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8ea1b7d-d26a-11dc-bc87-001b241b618b}]
AutoRun\command- F:\LaunchU3.exe -a


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
C:\Windows\system32\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



-- End of Deckard's System Scanner: finished at 2008-08-10 14:40:21 ------------

BC AdBot (Login to Remove)

 


m

#2 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:04:35 PM

Posted 21 August 2008 - 11:57 AM

Hello and welcome to BC

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. We aim to provide the valuable service known to come from BC to every member we can, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

Thanks and again sorry for the delay.

Please see here for instructions
how to install HijackThis and make a logfile. Save it into convenient location and include it to your next reply, please.

Next
Please do a scan with Kaspersky Online Scanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Please post back with HijackThis log and Kaspersky report.

Regards
Microsoft MVP Consumer Security
Posted Image

Posted Image

#3 Shaba

Shaba

    Koutsi


  • Members
  • 7,872 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Finland
  • Local time:04:35 PM

Posted 26 August 2008 - 04:53 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
Microsoft MVP Consumer Security
Posted Image

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users