Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Taskbar and other applications freeze after attempt to remove threats


  • This topic is locked This topic is locked
2 replies to this topic

#1 helpinfected

helpinfected

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:12:47 AM

Posted 13 November 2009 - 02:56 PM

After removing MSA and B.exe's scanning and deleting threats and going in the registry deleting infected and suspicious values, this problem persists. Here are the DDS Logs
Can't open any folders and cant access start menu so I'm here in safe mode with networking trying to find hope

I run Vista Home Premium 64-bit

DDS (Ver_09-10-26.01) - NTFSX64 NETWORK
Run by Khare Honore at 14:48:26.91 on Fri 11/13/2009
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_14
Microsoft® Windows Vistaāā€˛¢ Home Premium 6.0.6001.1.1252.1.1033.18.4094.2981 [GMT -5:00]

AV: Trend Micro AntiVirus *On-access scanning enabled* (Outdated) {7D2296BC-32CC-4519-917E-52E652474AF5}
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:Windowssystem32wininit.exe
C:Windowssystem32lsm.exe
C:Windowssystem32svchost.exe -k DcomLaunch
C:Windowssystem32svchost.exe -k rpcss
C:WindowsSystem32svchost.exe -k secsvcs
C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:Windowssystem32svchost.exe -k netsvcs
C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted
C:Windowssystem32svchost.exe -k NetworkService
C:Windowssystem32svchost.exe -k LocalService
C:Windowssystem32svchost.exe -k LocalServiceNoNetwork
C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted
C:WindowsExplorer.EXE
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Windowssystem32wbemunsecapp.exe
C:Windowssystem32wbemwmiprvse.exe
C:Windowsexplorer.exe
C:Program Files (x86)XfireXfire.exe
C:Program Files (x86)Xfirexfire64.exe
C:Program Files (x86)Xfirexfire64.exe
C:Program Files (x86)Mozilla Firefoxfirefox.exe
C:UsersKhare HonoreDownloadsdds.scr
C:Windowssystem32wbemwmiprvse.exe

============== Pseudo HJT Report ===============

mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
mDefault_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod=ASUS
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:program files (x86)common filesadobeacrobatactivexAcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:program files (x86)askbardisbarbinaskBar.dll
BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:program files (x86)flashgetjccatch.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:progra~2spybot~1SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:program files (x86)common filesmicrosoft sharedwindows liveWindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:program files (x86)javajre6binjp2ssv.dll
BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:program files (x86)flashgetgetflash.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:program files (x86)askbardisbarbinaskBar.dll
uRun: [Sidebar] c:program fileswindows sidebarsidebar.exe /autoRun
uRun: [PlayNC Launcher]
uRun: [msnmsgr] "c:program files (x86)windows livemessengermsnmsgr.exe" /background
uRun: [ehTray.exe] c:windowsehomeehTray.exe
uRun: [Driver Updater]
uRun: [uTorrent] "c:program files (x86)utorrentuTorrent.exe"
uRun: [Aim6] "c:program files (x86)aim6aim6.exe" /d locale=en-US ee://aol/imApp
uRun: [igndlm.exe] c:program files (x86)download managerDLM.exe /windowsstart /startifwork
uRun: [SpybotSD TeaTimer] c:program files (x86)spybot - search & destroyTeaTimer.exe
uRun: [VeohPlugin] "c:program files (x86)veoh networksveohwebplayerveohwebplayer.exe"
mRun: [Adobe Reader Speed Launcher] "c:program files (x86)adobereader 8.0readerReader_sl.exe"
mRun: [CLMLServer] "c:program files (x86)cyberlinkpower2goCLMLSvc.exe"
mRun: [P2Go_Menu] "c:program files (x86)cyberlinkpower2gomuitransfermuistartmenu.exe" "c:program files (x86)cyberlinkpower2go" updatewithcreateonce "softwarecyberlinkpower2go6.0"
mRun: [HControlUser] c:program files (x86)asusatk hotkeyHControlUser.exe
mRun: [ATKOSD2] c:program files (x86)asusatkosd2ATKOSD2.exe
mRun: [ADSMTray] c:program filesasusasus data security managerADSMTray.exe
mRun: [ATKMEDIA] "c:program files (x86)asusatk mediaDMEDIA.EXE"
mRun: [DirectConsole2] c:program files (x86)asusdirect consoleDirect Console.exe
mRun: [PWRISOVM.EXE] "c:program files (x86)powerisoPWRISOVM.EXE"
mRun: [SunJavaUpdateSched] "c:program files (x86)javajre6binjusched.exe"
mRun: [TkBellExe] "c:program files (x86)common filesrealupdate_obrealsched.exe" -osboot
mRun: [QuickTime Task] "c:program files (x86)quicktimeQTTask.exe" -atboottime
mRun: [iTunesHelper] "c:program files (x86)itunesiTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:program files (x86)malwarebytes' anti-malwarembam.exe" /runcleanupscript
StartupFolder: c:userskhareh~1appdataroamingmicros~1windowsstartm~1programsstartupxfire.lnk - c:program files (x86)xfireXfire.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Download All with FlashGet - c:program files (x86)flashgetjc_all.htm
IE: &Download with FlashGet - c:program files (x86)flashgetjc_link.htm
IE: E&xport to Microsoft Excel - c:progra~2micros~1office12EXCEL.EXE/3000
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:program files (x86)flashgetFlashGet.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:program files (x86)windows livewriterWriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:progra~2micros~1office12ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~2micros~1office12REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:progra~2spybot~1SDHelper.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/asquared.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
LSA: Notification Packages = scecli c:program filesasusasus data security managerASPWDFLT
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:program files (x86)common fileslightscribeLSRunOnce.exe"
TB-X64: {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No File
mRun-x64: [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
mRun-x64: [UfSeAgnt.exe] "c:program filestrend microinternet securityUfSeAgnt.exe"
mRun-x64: [NvCplDaemon] RUNDLL32.EXE c:windowssystem32NvCpl.dll,NvStartup

================= FIREFOX ===================

FF - ProfilePath - c:userskhareh~1appdataroamingmozillafirefoxprofileswcy9cbph.default
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://msn.com/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=
FF - plugin: c:program files (x86)download managernpfpdlm.dll
FF - plugin: c:program files (x86)googleupdate1.2.183.13npGoogleOneClick8.dll
FF - plugin: c:program files (x86)microsoftoffice livenpOLW.dll
FF - plugin: c:program files (x86)mozilla firefoxpluginsnpijjiautoinstallpluginff.dll
FF - plugin: c:program files (x86)mozilla firefoxpluginsnpijjiFFPlugin1.dll
FF - plugin: c:program files (x86)mozilla firefoxpluginsnpPandoWebInst.dll
FF - plugin: c:program files (x86)veoh networksveohwebplayernpWebPlayerVideoPluginATL.dll
FF - plugin: c:program files (x86)viewpointviewpoint media playernpViewpoint.dll
FF - plugin: c:program files (x86)vistacodecpackrmnetscape6nppl3260.dll
FF - plugin: c:program files (x86)vistacodecpackrmnetscape6nprjplug.dll
FF - plugin: c:program files (x86)vistacodecpackrmnetscape6nprpjplug.dll
FF - plugin: c:program files (x86)windows livephoto galleryNPWLPG.dll
FF - plugin: c:programdatanexonusngmnpNxGameUS.dll
FF - plugin: c:userskhare honoreappdataroamingmozillafirefoxprofileswcy9cbph.defaultextensionsiaplayer@instantaction.compluginsnpiaplayer.dll
FF - plugin: c:userskhare honoreappdataroamingmozillafirefoxprofileswcy9cbph.defaultextensionsnpdyyno@dyyno.compluginsnpDyyno.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:windowsmicrosoft.netframeworkv3.5windows presentation foundationdotnetassistantextension
FF - HiddenExtension: Java Console: No Registry Reference - c:program files (x86)mozilla firefoxextensions{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 lullaby;lullaby;c:windowssystem32driverslullaby.sys [2009-4-1 16440]
R3 itecir;ITECIR Infrared Receiver;c:windowssystem32driversitecir.sys [2009-4-1 59392]
R3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:windowssystem32driversNETw5v64.sys [2009-4-1 5430272]
S1 SASDIFSV;SASDIFSV;c:userskhareh~1appdatalocaltempsas_selfextractSASDIFSV.SYS [2009-9-4 9968]
S1 SASKUTIL;SASKUTIL;c:userskhareh~1appdatalocaltempsas_selfextractSASKUTIL.sys [2009-9-4 74480]
S2 ASKUpgrade;ASKUpgrade;c:program files (x86)askbardisbarbinASKUpgrade.exe [2009-7-22 234888]
S2 ASMMAP64;ASMMAP64;c:program filesatkgfnexASMMAP64.sys [2009-4-1 14904]
S2 gupdate1ca04f1b2c7ea1c;Google Update Service (gupdate1ca04f1b2c7ea1c);c:program files (x86)googleupdateGoogleUpdate.exe [2009-7-14 133104]
S2 SBSDWSCService;SBSD Security Center Service;c:program files (x86)spybot - search & destroySDWinSec.exe [2009-9-7 1153368]
S2 tmpreflt;tmpreflt;c:windowssystem32driverstmpreflt.sys [2009-7-15 42000]
S2 TmProxy;Trend Micro Proxy Service;c:program filestrend microinternet securityTmProxy.exe [2009-6-5 900360]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:windowsmicrosoft.netframework64v2.0.50727mscorsvw.exe [2009-6-5 93184]
S3 npggsvc;nProtect GameGuard Service;c:windowssystem32gamemon.des -service --> c:windowssystem32GameMon.des -service [?]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:windowssystem32driversnvhda64v.sys [2009-4-30 81440]
S3 PerfHost;Performance Counter DLL Host;c:windowssyswow64perfhost.exe [2008-1-20 19968]
S3 sdAuxService;PC Tools Auxiliary Service;c:program files (x86)spyware doctorpctsAuxs.exe [2009-11-11 348752]
S3 USBAAPL64;Apple Mobile USB Driver;c:windowssystem32driversusbaapl64.sys [2009-8-28 49152]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:windowssystem32driversyk60x64.sys [2006-11-2 273408]

=============== Created Last 30 ================

2009-11-13 02:21:46 0 d-----w- c:userskhareh~1appdataroamingSUPERAntiSpyware.com
2009-11-13 02:21:46 0 d-----w- c:programdataSUPERAntiSpyware.com
2009-11-13 00:52:29 2335270 ----a-w- c:windowssyswow649ae80C3.mht
2009-11-13 00:46:38 0 d-----w- c:userskhare honorePavark
2009-11-12 00:23:57 0 d-----w- C:VundoFix Backups
2009-11-12 00:13:34 0 d-----w- c:program files (x86)common filesPC Tools
2009-11-12 00:12:12 0 d-----w- c:userskhareh~1appdataroamingPC Tools
2009-11-12 00:12:12 0 d-----w- c:programdataPC Tools
2009-11-12 00:12:12 0 d-----w- c:program files (x86)Spyware Doctor
2009-11-11 23:55:18 691 ----a-w- c:userskhareh~1appdataroamingGetValue.vbs
2009-11-11 23:55:18 35 ----a-w- c:userskhareh~1appdataroamingSetValue.bat
2009-11-11 23:42:43 0 d-----w- c:userskhareh~1appdataroamingAVG8
2009-11-11 23:41:11 3728 ----a-w- c:windowssyswow64tmp.reg
2009-11-11 22:43:07 0 d-----w- c:program files (x86)Trend Micro
2009-11-10 23:35:14 0 d-----w- c:program filesRecuva
2009-11-10 19:53:09 0 d-----w- c:userskhareh~1appdataroamingMalwarebytes
2009-11-10 19:53:02 22104 ----a-w- c:windowssystem32driversmbam.sys
2009-11-10 19:53:02 0 d-----w- c:programdataMalwarebytes
2009-11-10 19:53:02 0 d-----w- c:program files (x86)Malwarebytes' Anti-Malware
2009-11-10 19:40:34 437248 ----a-w- c:windowssystem32WSDApi.dll
2009-11-10 19:40:34 351232 ----a-w- c:windowssyswow64WSDApi.dll
2009-11-10 19:40:32 2749952 ----a-w- c:windowssystem32win32k.sys
2009-11-10 01:58:29 0 d-----w- c:program files (x86)GetData
2009-11-10 01:25:28 0 d-----w- c:userskhareh~1appdataroamingThinstall
2009-11-10 01:10:39 0 d-----w- c:program files (x86)Aimersoft
2009-11-10 01:08:52 4398360 ----a-w- c:windowssystem32d3dx9_32.dll
2009-11-10 01:08:09 0 d-----w- c:program files (x86)Microsoft SQL Server Compact Edition
2009-11-10 01:06:09 0 d-----w- c:program files (x86)Microsoft
2009-11-09 23:53:36 224 ----a-w- c:windowssyswow649B13A86D.plf
2009-11-09 20:42:37 0 d-----w- c:program files (x86)Music Rescue
2009-11-09 20:38:44 0 d-----w- c:programdataParetoLogic
2009-11-09 20:38:44 0 d-----w- c:program files (x86)ParetoLogic
2009-11-09 20:38:44 0 d-----w- c:program files (x86)common filesParetoLogic
2009-11-09 20:37:49 0 d-----w- c:programdataCached Installations
2009-11-09 03:16:03 68232 ----a-w- c:windowsUnDeployV.exe
2009-11-09 03:16:03 0 d-----w- c:program files (x86)DDR - iPod Recovery(Demo)
2009-11-06 02:14:42 41872 ----a-w- c:windowssyswow64xfcodec.dll
2009-11-06 02:14:42 27536 ----a-w- c:windowssystem32xfcodec64.dll
2009-11-05 00:23:49 225280 ----a-w- c:windowssyswow64rewire.dll
2009-11-05 00:23:31 1554944 ----a-w- c:windowssyswow64vorbis.acm
2009-11-05 00:23:21 0 d-----w- c:program files (x86)VstPlugins
2009-11-05 00:23:20 0 d-----w- c:program files (x86)Outsim
2009-11-05 00:21:36 0 d-----w- c:program files (x86)Image-Line
2009-11-04 20:00:10 3584000 ----a-w- c:windowssyswow64mshtml.dll
2009-11-01 03:36:03 0 d-----w- c:program filesVentrilo
2009-11-01 03:36:01 262 ----a-w- c:windows{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
2009-10-30 20:25:57 0 d-----w- c:windowssystem32EventProviders
2009-10-30 01:18:57 0 d-----w- c:program filesiPod
2009-10-30 01:18:50 0 d-----w- c:program filesiTunes
2009-10-30 01:18:50 0 d-----w- c:program files (x86)iTunes
2009-10-28 23:46:31 372736 ----a-w- c:windowssystem32unregmp2.exe
2009-10-28 23:46:31 310784 ----a-w- c:windowssyswow64unregmp2.exe
2009-10-28 23:46:29 10624000 ----a-w- c:windowssyswow64wmp.dll
2009-10-28 23:46:28 8147968 ----a-w- c:windowssystem32wmploc.DLL
2009-10-28 23:46:28 8147456 ----a-w- c:windowssyswow64wmploc.DLL
2009-10-26 18:48:17 2621440 ----a-w- c:windowssystem32wucltux.dll
2009-10-26 18:47:51 98816 ----a-w- c:windowssystem32wudriver.dll
2009-10-26 18:47:51 87552 ----a-w- c:windowssyswow64wudriver.dll
2009-10-26 18:47:51 575704 ----a-w- c:windowssyswow64wuapi.dll
2009-10-26 18:47:51 35552 ----a-w- c:windowssyswow64wups.dll
2009-10-26 18:47:35 36864 ----a-w- c:windowssystem32wuapp.exe
2009-10-26 18:47:35 33792 ----a-w- c:windowssyswow64wuapp.exe
2009-10-26 18:47:35 185416 ----a-w- c:windowssystem32wuwebv.dll
2009-10-26 18:47:35 171608 ----a-w- c:windowssyswow64wuwebv.dll
2009-10-26 18:45:20 0 d-----w- c:programdataWindowsSearch
2009-10-24 19:41:19 0 d-----w- c:programdataFLEXnet
2009-10-24 16:53:28 0 d-----w- c:windowssyswow64spool
2009-10-24 16:50:49 0 d-----w- c:program files (x86)common filesMacrovision Shared
2009-10-16 01:24:49 34152 ----a-w- c:windowssystem32driversGEARAspiWDM.sys
2009-10-16 01:24:49 126312 ----a-w- c:windowssystem32GEARAspi64.dll
2009-10-16 01:24:49 107368 ----a-w- c:windowssyswow64GEARAspi.dll
2009-10-16 01:24:10 0 d-----w- c:programdata{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}

==================== Find3M ====================

2009-11-13 00:24:27 45056 ----a-w- c:windowssystem32acovcnt.exe
2009-11-13 00:24:04 17408 ----a-w- c:windowssystem32rpcnetp.exe
2009-11-13 00:23:49 49304 ----a-w- c:programdatanvModes.dat
2009-11-13 00:23:38 56680 ----a-w- c:windowssyswow64rpcnet.dll
2009-11-13 00:23:38 17408 ----a-w- c:windowssyswow64rpcnetp.dll
2009-11-13 00:23:24 17408 ----a-w- c:windowssyswow64rpcnetp.exe
2009-11-03 01:42:06 226688 ------w- c:windowssystem32MpSigStub.exe
2009-10-30 20:38:26 51200 ----a-w- c:windowsinfinfpub.dat
2009-10-30 20:38:26 143360 ----a-w- c:windowsinfinfstrng.dat
2009-10-16 01:18:52 86016 ----a-w- c:windowsinfinfstor.dat
2009-09-10 17:53:48 268800 ----a-w- c:windowssystem32msv1_0.dll
2009-09-10 17:30:12 213504 ----a-w- c:windowssyswow64msv1_0.dll
2009-09-04 12:52:46 82944 ----a-w- c:windowssystem32msasn1.dll
2009-09-04 12:24:34 61440 ----a-w- c:windowssyswow64msasn1.dll
2009-09-03 21:01:09 185920 ----a-w- c:windowssyswow64rmoc3260.dll
2009-09-03 21:01:04 6656 ----a-w- c:windowssyswow64pndx5016.dll
2009-09-03 21:01:04 5632 ----a-w- c:windowssyswow64pndx5032.dll
2009-09-03 21:00:49 278528 ----a-w- c:windowssyswow64pncrt.dll
2009-08-31 14:12:46 375808 ----a-w- c:windowssystem32psisdecd.dll
2009-08-31 14:12:39 558592 ----a-w- c:windowssystem32EncDec.dll
2009-08-31 13:55:50 293376 ----a-w- c:windowssyswow64psisdecd.dll
2009-08-31 13:55:46 428544 ----a-w- c:windowssyswow64EncDec.dll
2009-08-28 23:42:52 2065696 ----a-w- c:windowssystem32usbaaplrc.dll
2009-08-28 12:51:05 32256 ----a-w- c:windowssystem32Apphlpdm.dll
2009-08-28 12:39:07 28672 ----a-w- c:windowssyswow64Apphlpdm.dll
2009-08-28 10:39:32 4240384 ----a-w- c:windowssystem32GameUXLegacyGDFs.dll
2009-08-28 10:15:30 4240384 ----a-w- c:windowssyswow64GameUXLegacyGDFs.dll
2009-08-27 13:47:55 1032704 ----a-w- c:windowssystem32wininet.dll
2009-08-27 13:43:42 86528 ----a-w- c:windowssystem32ieencode.dll
2009-08-27 13:32:41 833024 ----a-w- c:windowssyswow64wininet.dll
2009-08-27 13:32:28 1174528 ----a-w- c:windowssyswow64urlmon.dll
2009-08-27 13:31:28 146432 ----a-w- c:windowssyswow64occache.dll
2009-08-27 13:30:22 671232 ----a-w- c:windowssyswow64mstime.dll
2009-08-27 13:30:11 458240 ----a-w- c:windowssyswow64msfeeds.dll
2009-08-27 13:29:41 28160 ----a-w- c:windowssyswow64jsproxy.dll
2009-08-27 13:29:28 270848 ----a-w- c:windowssyswow64iertutil.dll
2009-08-27 13:29:27 6069248 ----a-w- c:windowssyswow64ieframe.dll
2009-08-27 13:29:25 78336 ----a-w- c:windowssyswow64ieencode.dll
2009-08-27 13:29:25 389120 ----a-w- c:windowssyswow64iedkcs32.dll
2009-08-27 13:29:25 380928 ----a-w- c:windowssyswow64ieapfltr.dll
2009-08-27 13:29:25 230400 ----a-w- c:windowssyswow64ieaksie.dll
2009-08-27 11:27:09 32768 ----a-w- c:windowssystem32ieUnatt.exe
2009-08-27 10:58:58 26624 ----a-w- c:windowssyswow64ieUnatt.exe
2009-08-25 21:04:30 75264 ----a-w- c:windowssyswow64uc_holybeast_launching.dll
2009-08-18 03:33:52 1193832 ----a-w- c:windowssyswow64FM20.DLL
2009-04-01 14:08:11 665600 ----a-w- c:windowsinfdrvindex.dat
2008-07-02 02:28:38 61440 ----a-w- c:program files (x86)common filesCPInstallAction.dll
2008-05-22 16:35:54 51962 ----a-w- c:program files (x86)common filesbanner.jpg
2008-01-21 03:21:59 174 --sha-w- c:program filesdesktop.ini
2008-01-21 03:21:59 174 --sha-w- c:program files (x86)desktop.ini
2007-06-12 17:34:50 35822 ----a-w- c:program files (x86)common filesASPG_icon.ico
2006-11-02 15:14:56 30674 ----a-w- c:windowsinfperflib0409perfd.dat
2006-11-02 15:14:56 30674 ----a-w- c:windowsinfperflib0409perfc.dat
2006-11-02 15:14:56 287440 ----a-w- c:windowsinfperflib0409perfi.dat
2006-11-02 15:14:56 287440 ----a-w- c:windowsinfperflib0409perfh.dat
2006-11-02 10:52:12 287440 ----a-w- c:windowsinfperflib0000perfi.dat
2006-11-02 10:52:12 287440 ----a-w- c:windowsinfperflib0000perfh.dat
2006-11-02 10:52:10 30674 ----a-w- c:windowsinfperflib0000perfd.dat
2006-11-02 10:52:10 30674 ----a-w- c:windowsinfperflib0000perfc.dat
2009-04-01 13:34:59 8192 --sha-w- c:windowsusersdefaultNTUSER.DAT

============= FINISH: 14:50:48.09 ===============

and the HJT logs

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:53:54 PM, on 11/13/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18319)
Boot mode: Safe mode with network support

Running processes:
C:Program Files (x86)XfireXfire.exe
C:Program Files (x86)Mozilla Firefoxfirefox.exe
C:WindowsSysWOW64notepad.exe
C:WindowsSysWOW64notepad.exe
C:Program Files (x86)Trend MicroHijackThisHijackThis.exe

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program Files (x86)Common FilesAdobeAcrobatActiveXAcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:Program Files (x86)AskBarDisbarbinaskBar.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:Program Files (x86)FlashGetjccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~2SPYBOT~1SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program Files (x86)Common FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program Files (x86)Javajre6binjp2ssv.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:Program Files (x86)FlashGetgetflash.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:Program Files (x86)AskBarDisbarbinaskBar.dll
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program Files (x86)AdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [CLMLServer] "C:Program Files (x86)CyberLinkPower2GoCLMLSvc.exe"
O4 - HKLM..Run: [P2Go_Menu] "C:Program Files (x86)CyberLinkPower2GoMUITransferMUIStartMenu.exe" "C:Program Files (x86)CyberLinkPower2Go" UpdateWithCreateOnce "SOFTWARECyberLinkPower2Go6.0"
O4 - HKLM..Run: [HControlUser] C:Program Files (x86)ASUSATK HotkeyHControlUser.exe
O4 - HKLM..Run: [ATKOSD2] C:Program Files (x86)ASUSATKOSD2ATKOSD2.exe
O4 - HKLM..Run: [ADSMTray] C:Program FilesASUSASUS Data Security ManagerADSMTray.exe
O4 - HKLM..Run: [ATKMEDIA] "C:Program Files (x86)ASUSATK MediaDMEDIA.EXE"
O4 - HKLM..Run: [DirectConsole2] C:Program Files (x86)ASUSDirect ConsoleDirect Console.exe
O4 - HKLM..Run: [PWRISOVM.EXE] "C:Program Files (x86)PowerISOPWRISOVM.EXE"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program Files (x86)Javajre6binjusched.exe"
O4 - HKLM..Run: [TkBellExe] "C:Program Files (x86)Common FilesRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [QuickTime Task] "C:Program Files (x86)QuickTimeQTTask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "C:Program Files (x86)iTunesiTunesHelper.exe"
O4 - HKLM..Run: [Malwarebytes Anti-Malware (reboot)] "C:Program Files (x86)Malwarebytes' Anti-Malwarembam.exe" /runcleanupscript
O4 - HKCU..Run: [Sidebar] C:Program FilesWindows Sidebarsidebar.exe /autoRun
O4 - HKCU..Run: [msnmsgr] "C:Program Files (x86)Windows LiveMessengermsnmsgr.exe" /background
O4 - HKCU..Run: [ehTray.exe] C:WindowsehomeehTray.exe
O4 - HKCU..Run: [uTorrent] "C:Program Files (x86)uTorrentuTorrent.exe"
O4 - HKCU..Run: [Aim6] "C:Program Files (x86)AIM6aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU..Run: [igndlm.exe] C:Program Files (x86)Download ManagerDLM.exe /windowsstart /startifwork
O4 - HKCU..Run: [SpybotSD TeaTimer] C:Program Files (x86)Spybot - Search & DestroyTeaTimer.exe
O4 - HKCU..Run: [VeohPlugin] "C:Program Files (x86)Veoh NetworksVeohWebPlayerveohwebplayer.exe"
O4 - HKUSS-1-5-19..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUSS-1-5-19..Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUSS-1-5-20..Run: [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Xfire.lnk = C:Program Files (x86)XfireXfire.exe
O8 - Extra context menu item: &Download All with FlashGet - C:Program Files (x86)FlashGetjc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:Program Files (x86)FlashGetjc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~2MICROS~1Office12EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program Files (x86)Windows LiveWriterWriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~2MICROS~1Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:PROGRA~2MICROS~1Office12ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~2MICROS~1Office12REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:Program Files (x86)FlashGetFlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:Program Files (x86)FlashGetFlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~2SPYBOT~1SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:PROGRA~2SPYBOT~1SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:Program FilesASUSASUS Data Security ManagerADSMSrv.exe
O23 - Service: @%SystemRoot%system32Alg.exe,-112 (ALG) - Unknown owner - C:WindowsSystem32alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:Program Files (x86)Common FilesAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:Program Files (x86)AskBarDisbarbinASKUpgrade.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:Program Files (x86)ASUSATK HotkeyASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:Program FilesATKGFNEXGFNEXSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:Program Files (x86)BonjourmDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:Windowssystem32DFSR.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:Program Files (x86)Common FilesMacrovision SharedFLEXnet PublisherFNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1ca04f1b2c7ea1c) (gupdate1ca04f1b2c7ea1c) - Google Inc. - C:Program Files (x86)GoogleUpdateGoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program Files (x86)GoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:Program FilesiPodbiniPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:Program Files (x86)Common FilesLightScribeLSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:WindowsSystem32msdtc.exe (file missing)
O23 - Service: @%SystemRoot%System32netlogon.dll,-102 (Netlogon) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:Windowssystem32GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:Windowssystem32nvvsvc.exe (file missing)
O23 - Service: @%systemroot%system32psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: @%systemroot%system32Locator.exe,-2 (RpcLocator) - Unknown owner - C:Windowssystem32locator.exe (file missing)
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:WindowsSysWOW64rpcnet.exe
O23 - Service: @%SystemRoot%system32samsrv.dll,-1 (SamSs) - Unknown owner - C:Windowssystem32lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:Program Files (x86)Spybot - Search & DestroySDWinSec.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program Files (x86)Spyware DoctorpctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program Files (x86)Spyware DoctorpctsSvc.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:Program FilesTrend MicroInternet SecuritySfCtlCom.exe
O23 - Service: @%SystemRoot%system32SLsvc.exe,-101 (slsvc) - Unknown owner - C:Windowssystem32SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%system32snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:WindowsSystem32snmptrap.exe (file missing)
O23 - Service: spmgr - Unknown owner - C:Program FilesASUSNB ProbeSPMspmgr.exe
O23 - Service: @%systemroot%system32spoolsv.exe,-1 (Spooler) - Unknown owner - C:WindowsSystem32spoolsv.exe (file missing)
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:Program FilesTrend MicroBMTMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:Program FilesTrend MicroInternet SecurityTmProxy.exe
O23 - Service: @%SystemRoot%system32ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:Windowssystem32UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%system32vds.exe,-100 (vds) - Unknown owner - C:WindowsSystem32vds.exe (file missing)
O23 - Service: @%systemroot%system32vssvc.exe,-102 (VSS) - Unknown owner - C:Windowssystem32vssvc.exe (file missing)
O23 - Service: @%Systemroot%system32wbemwmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:Windowssystem32wbemWmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%Windows Media Playerwmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:Program Files (x86)Windows Media Playerwmpnetwk.exe (file missing)

--
End of file - 11133 bytes

Merged posts. ~ OB

Attached Files


Edited by Orange Blossom, 13 November 2009 - 03:18 PM.


BC AdBot (Login to Remove)

 


#2 sempai

sempai

    noypi


  • Malware Response Team
  • 5,288 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:3 stars and a sun
  • Local time:01:47 PM

Posted 20 November 2009 - 08:37 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.  

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine.  Please perform the following scan:
  • Download DDS by sUBs from one of the following links.  Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.  No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note:  You may have to disable any script protection running if the scan fails to run.  After downloading the tool, disconnect from the internet and disable all antivirus protection.  Run the scan, enable your A/V and reconnect to the internet.  

Information on A/V control HERE

~Semp

btn_donate_LG.gif
You can help me continue the fight against malware by making a donation, Thank you.

If I am helping you and I didn't reply within 48 hours... Please send me a private message.
Topics that are not replied within 5 days will be close. Please don't PM asking for support, post on the Forums instead.

Member of UNITE (Unified Network of Instructors and Trained Eliminators) 


#3 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,962 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:01:47 AM

Posted 28 November 2009 - 01:00 AM

Due to the lack of feedback, this Topic is now closed.

In case you still have problems, please start a new topic.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users