Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus/Malware


  • This topic is locked This topic is locked
2 replies to this topic

#1 cwatson2142

cwatson2142

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:05:38 PM

Posted 08 October 2010 - 12:52 AM

Not sure if right place or not, please fogive if in the wrong forums. If ok, somone please take a look and help me out....






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:14:28 AM, on 10/8/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files (x86)\Common Files\Teleca Shared\logger.exe
C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
C:\Program Files (x86)\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
C:\Program Files (x86)\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
C:\Program Files (x86)\Itchycats\itchycats.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: C:\Windows\SysWow64\e5rft9zphj.dll - {D6BA40A1-A502-59BD-F413-04B03A2C8953} - C:\Windows\SysWow64\e5rft9zphj.dll
O4 - HKLM\..\Run: [Mobile Connectivity Suite] "C:\Program Files (x86)\HTC\HTC Sync\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Xteliqijoyiqopa] rundll32.exe "C:\Users\Chris\AppData\Local\atasusevi.dll",Startup
O4 - HKLM\..\Run: [LveehfngbZO] C:\Users\Chris\AppData\Local\Temp\l4h0clt1.exe
O4 - HKLM\..\Run: [Mqvpe] C:\Windows\winamp.exe
O4 - HKLM\..\Run: [Mquxe] C:\Windows\system.exe
O4 - HKLM\..\Run: [Lveehfngpta] C:\Users\Chris\AppData\Local\Temp\services.exe
O4 - HKLM\..\Run: [Lveehfngosf] C:\Users\Chris\AppData\Local\Temp\taskmgr.exe
O4 - HKLM\..\Run: [Mqqyc] C:\Windows\csrss.exe
O4 - HKLM\..\Run: [Lveehfngrsc] C:\Users\Chris\AppData\Local\Temp\winlogon.exe
O4 - HKLM\..\Run: [Lveehfngruf] C:\Users\Chris\AppData\Local\Temp\wininst.exe
O4 - HKLM\..\Run: [Mqsrc] C:\Windows\login.exe
O4 - HKLM\..\Run: [Lveehfngqhj] C:\Users\Chris\AppData\Local\Temp\dxwrk1xpw.exe
O4 - HKLM\..\Run: [Mqpe] C:\Windows\avp.exe
O4 - HKLM\..\Run: [Mqtw+] C:\Windows\nvsvc32.exe
O4 - HKLM\..\Run: [Mquvc] C:\Windows\setup.exe
O4 - HKLM\..\Run: [Mqutc] C:\Windows\sysedit.exe
O4 - HKLM\..\Run: [Lveehfngupf] C:\Users\Chris\AppData\Local\Temp\sysedit.exe
O4 - HKLM\..\Run: [LveehfngrA] C:\Users\Chris\AppData\Local\Temp\win16.exe
O4 - HKLM\..\Run: [LveehfngsfP] C:\Users\Chris\AppData\Local\Temp\nvsvc32.exe
O4 - HKLM\..\Run: [Lveehfngne] C:\Users\Chris\AppData\Local\Temp\mdm.exe
O4 - HKLM\..\Run: [MqvPc] C:\Windows\win32.exe
O4 - HKLM\..\Run: [Lveehfngl/] C:\Users\Chris\AppData\Local\Temp\gdi32.exe
O4 - HKCU\..\Run: [Xteliqijoyiqopa] rundll32.exe "C:\Users\Chris\AppData\Local\atasusevi.dll",Startup
O4 - HKCU\..\Run: [Jyimoqeviwece] rundll32.exe "C:\Users\Chris\AppData\Local\exprvpxt.dll",Startup
O4 - HKCU\..\Run: [uPc+kt0NXqbCxl] rundll32.exe C:\Windows\system32\lc4fenqo.dll, SystemServer
O4 - HKCU\..\Run: [LveehfngbZO] C:\Users\Chris\AppData\Local\Temp\l4h0clt1.exe
O4 - HKCU\..\Run: [Mqvpe] C:\Windows\winamp.exe
O4 - HKCU\..\Run: [Mquxe] C:\Windows\system.exe
O4 - HKCU\..\Run: [Lveehfngpta] C:\Users\Chris\AppData\Local\Temp\services.exe
O4 - HKCU\..\Run: [Lveehfngosf] C:\Users\Chris\AppData\Local\Temp\taskmgr.exe
O4 - HKCU\..\Run: [Mqqyc] C:\Windows\csrss.exe
O4 - HKCU\..\Run: [Lveehfngrsc] C:\Users\Chris\AppData\Local\Temp\winlogon.exe
O4 - HKCU\..\Run: [Lveehfngruf] C:\Users\Chris\AppData\Local\Temp\wininst.exe
O4 - HKCU\..\Run: [Mqsrc] C:\Windows\login.exe
O4 - HKCU\..\Run: [Mqpe] C:\Windows\avp.exe
O4 - HKCU\..\Run: [Mqtw+] C:\Windows\nvsvc32.exe
O4 - HKCU\..\Run: [Mquvc] C:\Windows\setup.exe
O4 - HKCU\..\Run: [Mqutc] C:\Windows\sysedit.exe
O4 - HKCU\..\Run: [Lveehfngupf] C:\Users\Chris\AppData\Local\Temp\sysedit.exe
O4 - HKCU\..\Run: [LveehfngrA] C:\Users\Chris\AppData\Local\Temp\win16.exe
O4 - HKCU\..\Run: [LveehfngsfP] C:\Users\Chris\AppData\Local\Temp\nvsvc32.exe
O4 - HKCU\..\Run: [Lveehfngne] C:\Users\Chris\AppData\Local\Temp\mdm.exe
O4 - HKCU\..\Run: [MqvPc] C:\Windows\win32.exe
O4 - HKCU\..\Run: [Lveehfngl/] C:\Users\Chris\AppData\Local\Temp\gdi32.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10961 bytes


BC AdBot (Login to Remove)

 


#2 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:38 PM

Posted 16 October 2010 - 11:13 AM

Hello cwatson2142 ,



Sorry for the delay. sad.gif If you still need help, please post a new DDS/HijackThis log and I'll be happy to look at it. smile.gif

Thanks,
tea
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?

#3 teacup61

teacup61

    Bleepin' Texan!


  • Malware Response Team
  • 17,075 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:04:38 PM

Posted 22 October 2010 - 02:49 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image


Error reading poptart in Drive A: Delete kids y/n?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users