1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Unknown Trojan, help!

Discussion in 'Malware and Virus Removal Archive' started by michelle1980, 2008/03/25.

  1. 2008/03/25
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    Hi,
    Yesterday I received a trojan while trying to watch a video. When I'm viewing things (even things that aren't online) an error message comes up that says that My computer has been infected by an unknown trojan and that it's dangerous for my system. It also tells me to click OK to download the antispyware program to clean the program. I've read the other posts but whatever I have tried hasn't seemed to work. I really need to get rid of this trojan so whatever help you can give is greatly appreciated :)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:05:07 PM, on 3/24/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16609)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\sttray.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Windows\System32\WLTRAY.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Common Files\AOL\Loader\aolload.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\notepad.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\michelle\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\michelle.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Media Player Codec - {3084A75F-5350-4D8B-BC5F-6B378035C133} - C:\Windows\dsaip32b.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe "
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe "
    O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-21-2610261172-2767058957-2194934642-1000\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O4 - Global Startup: QuickSet.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O13 - Gopher Prefix:
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/stg_drm.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/armhelper.ocx
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 8136 bytes
     
  2. 2008/03/25
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi michelle1980
    Welcome to Windowsbbs. :)

    Please do the following.

    Download Malwarebytes' Anti-Malware (MBAM) from here or here and save the file to your desktop.

    Double click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select 'Perform Quick Scan', then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note below)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Post the entire report in your next reply along with a fresh HijackThis log. Let me know what issues still exist.

    Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

    Thanks
    Geri
     
    Geri,
    #2

  3. to hide this advert.

  4. 2008/03/26
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    Malwarebytes' Anti-Malware 1.09
    Database version: 534

    Scan type: Quick Scan
    Objects scanned: 30242
    Time elapsed: 3 minute(s), 18 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  5. 2008/03/26
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:05:07 PM, on 3/24/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16609)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\sttray.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Windows\System32\WLTRAY.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Common Files\AOL\Loader\aolload.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\notepad.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Users\michelle\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\michelle.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Media Player Codec - {3084A75F-5350-4D8B-BC5F-6B378035C133} - C:\Windows\dsaip32b.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe "
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe "
    O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-21-2610261172-2767058957-2194934642-1000\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O4 - Global Startup: QuickSet.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O13 - Gopher Prefix:
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/stg_drm.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/armhelper.ocx
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 8136 bytes
     
  6. 2008/03/26
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi michelle1980

    Well I thought that would target this infection :cool: but it doesn't.

    So lets do this. Make sure you follow the Vista instructions.

    Download ComboFix from [color= "Red"]Here[/color] to your Desktop.

    It's best to disable realtime protection applications as they sometimes interfere with the tool.
    Check this link for any applicable programs you may have.
    • Close all open programs and windows
    • Double click combofix.exe and follow the prompts.
    • Vista users right click Combofix.exe and select Run As Administrator.
    • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall

    Note - ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.

    Note - Combofix makes some changes when run to prevent autorun/autoplay of ALL CDs, floppies and USB devices, to assist with malware removal & increase security. If this is an issue or makes it difficult for you to use those devices, please ask how to reset it.

    Please post the Combofix log.

    Thanks
    Geri
     
    Geri,
    #5
  7. 2008/03/27
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    ComboFix 08-03-26.3 - michelle 2008-03-27 17:20:50.3 - NTFSx86
    Microsoft® Windows Vistaâ„¢ Home Basic 6.0.6000.0.1252.1.1033.18.397 [GMT -4:00]
    Running from: C:\Users\michelle\Desktop\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((( Files Created from 2008-02-27 to 2008-03-27 )))))))))))))))))))))))))))))))
    .

    No new files created in this timespan

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-27 13:32 --------- d-----w C:\Program Files\Games
    2008-03-27 03:28 --------- d-----w C:\Program Files\Supple -- Episode 1
    2008-03-27 02:09 --------- d-----w C:\Program Files\Sallys
    2008-03-27 02:06 --------- d-----w C:\Program Files\Sallys Salon
    2008-03-27 02:02 --------- d-----w C:\Program Files\SallysSalon_at
    2008-03-25 14:42 --------- d---a-w C:\ProgramData\TEMP
    2008-03-25 02:42 --------- d-----w C:\Users\michelle\AppData\Roaming\Malwarebytes
    2008-03-25 02:42 --------- d-----w C:\ProgramData\Malwarebytes
    2008-03-25 02:42 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
    2008-03-25 00:29 --------- d-----w C:\ProgramData\Kaspersky Lab
    2008-03-25 00:14 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
    2008-03-24 23:49 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-03-24 21:55 691 ----a-w C:\Users\michelle\AppData\Roaming\GetValue.vbs
    2008-03-24 21:55 35 ----a-w C:\Users\michelle\AppData\Roaming\SetValue.bat
    2008-03-24 19:24 --------- d-----w C:\Program Files\Trend Micro
    2008-03-24 18:49 55 ----a-w C:\xmp.bat
    2008-03-24 18:49 212,480 ----a-w C:\Windows\dsaip32b.dll
    2008-03-23 01:21 --------- d-----w C:\Program Files\EA GAMES
    2008-03-22 19:49 86,528 ----a-w C:\Windows\System32\VACFix.exe
    2008-03-20 15:24 --------- d-----w C:\Program Files\AOL Games
    2008-03-20 03:29 --------- d-----w C:\ProgramData\Trymedia
    2008-03-19 02:34 --------- d-----w C:\Users\michelle\AppData\Roaming\LimeWire
    2008-03-15 21:16 82,432 ----a-w C:\Windows\System32\IEDFix.exe
    2008-03-12 01:25 --------- d-----w C:\Program Files\Windows Mail
    2008-03-08 22:59 --------- d-----w C:\Program Files\Fashion Boutique
    2008-03-08 15:49 --------- d-----w C:\Users\michelle\AppData\Roaming\Total Eclipse
    2008-03-08 00:02 --------- d-----w C:\Users\michelle\AppData\Roaming\GameHouse
    2008-03-08 00:02 --------- d-----w C:\ProgramData\n7-89-o9-3r-4t-r9
    2008-03-08 00:02 --------- d-----w C:\Program Files\GameHouse
    2008-02-28 00:39 --------- d-----w C:\ProgramData\Dell
    2008-02-13 01:02 194,560 ----a-w C:\Windows\System32\WebClnt.dll
    2008-02-13 01:02 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
    2008-02-13 00:57 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
    2008-02-13 00:57 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
    2008-02-13 00:57 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
    2008-02-13 00:57 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
    2008-02-13 00:57 24,064 ----a-w C:\Windows\System32\netcfg.exe
    2008-02-13 00:57 22,016 ----a-w C:\Windows\System32\netiougc.exe
    2008-02-13 00:57 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
    2008-02-13 00:57 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
    2008-02-13 00:57 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
    2008-02-13 00:57 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
    2008-02-13 00:57 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
    2008-02-13 00:57 110,136 ----a-w C:\Windows\system32\drivers\ataport.sys
    2008-02-13 00:56 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
    2008-02-13 00:56 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-02-13 00:56 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-02-13 00:56 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-02-13 00:56 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-02-13 00:56 1,686,528 ----a-w C:\Windows\System32\gameux.dll
    2008-02-13 00:53 824,832 ----a-w C:\Windows\System32\wininet.dll
    2008-02-13 00:53 56,320 ----a-w C:\Windows\System32\iesetup.dll
    2008-02-13 00:53 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
    2008-02-13 00:53 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
    2008-02-10 19:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
    2008-02-10 19:00 --------- d-----w C:\Program Files\Real
    2008-02-10 19:00 --------- d-----w C:\Program Files\Common Files\Real
    2008-02-06 18:45 --------- d-----w C:\Users\michelle\AppData\Roaming\PlayFirst
    2008-02-06 18:45 --------- d-----w C:\ProgramData\PlayFirst
    2008-02-06 17:41 --------- d-----w C:\Users\michelle\AppData\Roaming\SpinTop
    2008-01-31 18:50 --------- d-----w C:\Users\michelle\AppData\Roaming\AdobeUM
    2008-01-27 16:08 --------- d-----w C:\Users\michelle\AppData\Roaming\Roxio
    2008-01-09 00:37 11,776 ----a-w C:\Windows\System32\sbunattend.exe
    2007-12-28 16:52 174 --sha-w C:\Program Files\desktop.ini
    2007-12-28 15:43 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
    2007-12-28 15:43 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
    2007-12-28 15:43 542,720 ----a-w C:\Windows\System32\sysmain.dll
    2007-12-28 15:43 502,784 ----a-w C:\Windows\System32\wlansvc.dll
    2007-12-28 15:43 47,104 ----a-w C:\Windows\System32\wlanapi.dll
    2007-12-28 15:43 297,984 ----a-w C:\Windows\System32\wlansec.dll
    2007-12-28 15:43 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
    2007-12-28 15:43 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
    2007-12-28 15:43 2,923,520 ----a-w C:\Windows\explorer.exe
    2007-12-28 15:43 2,027,008 ----a-w C:\Windows\System32\win32k.sys
    2007-12-28 15:42 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
    2007-12-28 15:42 7,680 ----a-w C:\Windows\System32\spwmp.dll
    2007-12-28 15:42 4,096 ----a-w C:\Windows\System32\dxmasf.dll
    2007-12-28 15:42 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
    2007-12-28 15:40 8,704 ----a-w C:\Windows\System32\hcrstco.dll
    2007-12-28 15:40 8,704 ----a-w C:\Windows\System32\hccoin.dll
    2007-12-28 15:40 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
    2007-12-28 15:39 1,327,104 ----a-w C:\Windows\System32\quartz.dll
    2007-12-28 15:38 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
    2007-12-28 15:38 223,232 ----a-w C:\Windows\System32\WMASF.DLL
    2007-12-28 15:38 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
    2007-12-28 15:32 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
    2007-12-28 15:30 750,080 ----a-w C:\Windows\System32\qmgr.dll
    2003-09-04 19:20 811,008 ----a-w C:\Program Files\NPSWF32.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3084A75F-5350-4D8B-BC5F-6B378035C133}]
    2008-03-24 14:49 212480 --a------ C:\Windows\dsaip32b.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WindowsWelcomeCenter "= "oobefldr.dll" [2006-11-02 08:34 2159104 C:\Windows\System32\oobefldr.dll]
    "DellSupportCenter "= "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
    "swg "= "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-25 10:57 68856]
    "Aim6 "= "C:\Program Files\AIM6\aim6.exe" [2007-12-18 15:04 50528]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender "= "C:\Program Files\Windows Defender\MSASCui.exe" [2007-08-03 19:51 1006264]
    "SynTPEnh "= "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-20 13:51 815104]
    "ATICCC "= "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 18:12 90112]
    "SigmatelSysTrayApp "= "sttray.exe" [2007-02-08 01:11 303104 C:\Windows\sttray.exe]
    "Broadcom Wireless Manager UI "= "C:\Windows\system32\WLTRAY.exe" [2006-11-21 20:52 1540096]
    "ISUSScheduler "= "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]
    "PDVDDXSrv "= "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 18:23 118784]
    "ECenter "= "c:\dell\E-Center\EULALauncher.exe" [2007-03-16 06:20 17920]
    "Google Desktop Search "= "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-15 19:57 1862144]
    "ISUSPM Startup "= "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]
    "dscactivate "= "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
    "QuickTime Task "= "C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 16:27 385024]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-06-15 19:43:35 50688]
    QuickSet.lnk - C:\Windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-06-15 19:38:22 45056]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "AntiVirusOverride "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{23E14950-5BAB-4596-86DD-0C1AD30D3A75} "= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{BBD5F0EE-6991-4F99-9DB6-AAB24E2514E6} "= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "TCP Query User{03B058FD-1006-4EA5-9550-2A3F9B055D01}C:\\program files\\limewire\\limewire.exe "= UDP:C:\program files\limewire\limewire.exe:LimeWire
    "UDP Query User{6B872265-534E-4861-AF8B-3B64E2DA0D2B}C:\\program files\\limewire\\limewire.exe "= TCP:C:\program files\limewire\limewire.exe:LimeWire
    "TCP Query User{59BA37AC-498A-467D-8287-203C8049CF4E}C:\\program files\\limewire\\limewire.exe "= UDP:C:\program files\limewire\limewire.exe:LimeWire
    "UDP Query User{6C358BC5-48CC-48E6-9306-75E5D919903B}C:\\program files\\limewire\\limewire.exe "= TCP:C:\program files\limewire\limewire.exe:LimeWire
    "{D5EDAD8B-31D2-4181-8F2C-77C7120FED2C} "= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
    "{E3A59109-59CB-4173-9F38-25C61911B6E3} "= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
    "{0528E383-0F61-43E5-BBEA-B4AD8372F2BC} "= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
    "{9F62E7E1-53BA-4220-9273-C53DE82C0C0E} "= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
    "DFSR-1 "= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

    R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 11:22]
    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
    R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
    R2 Viewpoint Manager Service;Viewpoint Manager Service; "C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
    R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-11 19:10]
    R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-25 01:46]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e26e2b73-1b96-11dc-ab10-806e6f6e6963}]
    \shell\AutoRun\command - E:\Autorun.exe

    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-27 17:25:12
    Windows 6.0.6000 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-03-27 17:25:54
    ComboFix-quarantined-files.txt 2008-03-27 21:25:50
    The system cannot find message text for message number 0x2379 in the message file for Application.
    The system cannot find message text for message number 0x2379 in the message file for Application.
    .
    2008-03-26 13:57:23 --- E O F ---
     
  8. 2008/03/27
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:28:56 PM, on 3/27/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16609)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\sttray.exe
    C:\Windows\System32\WLTRAY.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Common Files\AOL\Loader\aolload.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Windows\Explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Media Player Codec - {3084A75F-5350-4D8B-BC5F-6B378035C133} - C:\Windows\dsaip32b.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe "
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe "
    O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-21-2610261172-2767058957-2194934642-1000\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O4 - Global Startup: QuickSet.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/stg_drm.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/armhelper.ocx
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 8399 bytes
     
  9. 2008/03/28
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi michelle1980

    I see you have P2P software ([color= "Red"] Limewire, BitTorrent uTorrent etc… [/color]) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here,
    here and here.

    I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

    Note: Please be advised that continued use of these programs after being warned of the dangers of infections from them, may result in the discontinued help of future cleaning of your system here at Windowsbbs Virus and Spyware removal.

    Please let me know if you will or will not remove Limewire, so I know how to proceed.

    Thanks
    Geri
     
    Geri,
    #8
  10. 2008/03/29
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    I have already removed Limewire so that is confusing to me and it doesn't come up on the Add/Remove Programs. However, I have removed the other programs that could harm my computer.
     
  11. 2008/03/29
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi michelle1980

    OK please do this.

    Highlight and copy the contents of the code box below and paste it into a blank notepad, then save it to your desktop as;

    Filename: CFScript.txt
    Save As Type: All Files (*.*)

    Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button.
    Click here to see how to use CFScript.txt
    Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log and another fresh HijackThis log.

    Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.

    Code:
    File::
    C:\Windows\dsaip32b.dll
    C:\xmp.bat
    
    DirLook::
    C:\ProgramData\n7-89-o9-3r-4t-r9
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3084A75F-5350-4D8B-BC5F-6B378035C133}]
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\parameters\firewallpolicy\FirewallRules]
     "TCP Query User{03B058FD-1006-4EA5-9550-2A3F9B055D01}C:\\program files\\limewire\\limewire.exe "=-
     "UDP Query User{6B872265-534E-4861-AF8B-3B64E2DA0D2B}C:\\program files\\limewire\\limewire.exe "=-
     "TCP Query User{59BA37AC-498A-467D-8287-203C8049CF4E}C:\\program files\\limewire\\limewire.exe "=-
     "UDP Query User{6C358BC5-48CC-48E6-9306-75E5D919903B}C:\\program files\\limewire\\limewire.exe "=- 
    Please post the CFScript log.

    Thanks
    Geri
     
  12. 2008/03/29
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    ComboFix 08-03-26.3 - michelle 2008-03-29 14:48:02.4 - NTFSx86
    Microsoft® Windows Vistaâ„¢ Home Basic 6.0.6000.0.1252.1.1033.18.412 [GMT -4:00]
    Running from: C:\Users\michelle\Desktop\ComboFix.exe
    Command switches used :: C:\Users\michelle\Desktop\CFScript.txt
    * Created a new restore point
    .
    TimedOut: Windir.dat

    ((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))
    .

    No new files created in this timespan

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-29 15:53 --------- d-----w C:\Program Files\Common Files\Real
    2008-03-29 15:52 --------- d-----w C:\Program Files\Fashion Boutique
    2008-03-28 00:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-03-28 00:25 --------- d-----w C:\Program Files\Infogrames Interactive
    2008-03-27 21:35 --------- d-----w C:\ProgramData\Lavasoft
    2008-03-27 21:34 12,632 ----a-w C:\Windows\System32\lsdelete.exe
    2008-03-27 13:32 --------- d-----w C:\Program Files\Games
    2008-03-27 02:06 --------- d-----w C:\Program Files\Sallys Salon
    2008-03-27 02:02 --------- d-----w C:\Program Files\SallysSalon_at
    2008-03-25 14:42 --------- d---a-w C:\ProgramData\TEMP
    2008-03-25 02:42 --------- d-----w C:\Users\michelle\AppData\Roaming\Malwarebytes
    2008-03-25 02:42 --------- d-----w C:\ProgramData\Malwarebytes
    2008-03-25 02:42 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
    2008-03-25 00:29 --------- d-----w C:\ProgramData\Kaspersky Lab
    2008-03-25 00:14 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
    2008-03-24 23:49 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-03-24 21:55 691 ----a-w C:\Users\michelle\AppData\Roaming\GetValue.vbs
    2008-03-24 21:55 35 ----a-w C:\Users\michelle\AppData\Roaming\SetValue.bat
    2008-03-24 19:24 --------- d-----w C:\Program Files\Trend Micro
    2008-03-24 18:49 55 ----a-w C:\xmp.bat
    2008-03-24 18:49 212,480 ----a-w C:\Windows\dsaip32b.dll
    2008-03-23 01:21 --------- d-----w C:\Program Files\EA GAMES
    2008-03-22 19:49 86,528 ----a-w C:\Windows\System32\VACFix.exe
    2008-03-20 15:24 --------- d-----w C:\Program Files\AOL Games
    2008-03-20 03:29 --------- d-----w C:\ProgramData\Trymedia
    2008-03-19 02:34 --------- d-----w C:\Users\michelle\AppData\Roaming\LimeWire
    2008-03-15 21:16 82,432 ----a-w C:\Windows\System32\IEDFix.exe
    2008-03-12 01:25 --------- d-----w C:\Program Files\Windows Mail
    2008-03-08 15:49 --------- d-----w C:\Users\michelle\AppData\Roaming\Total Eclipse
    2008-03-08 00:02 --------- d-----w C:\Users\michelle\AppData\Roaming\GameHouse
    2008-03-08 00:02 --------- d-----w C:\ProgramData\n7-89-o9-3r-4t-r9
    2008-03-08 00:02 --------- d-----w C:\Program Files\GameHouse
    2008-02-28 00:39 --------- d-----w C:\ProgramData\Dell
    2008-02-13 01:02 194,560 ----a-w C:\Windows\System32\WebClnt.dll
    2008-02-13 01:02 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
    2008-02-13 00:57 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
    2008-02-13 00:57 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
    2008-02-13 00:57 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
    2008-02-13 00:57 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
    2008-02-13 00:57 24,064 ----a-w C:\Windows\System32\netcfg.exe
    2008-02-13 00:57 22,016 ----a-w C:\Windows\System32\netiougc.exe
    2008-02-13 00:57 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
    2008-02-13 00:57 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
    2008-02-13 00:57 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
    2008-02-13 00:57 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
    2008-02-13 00:57 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
    2008-02-13 00:57 110,136 ----a-w C:\Windows\system32\drivers\ataport.sys
    2008-02-13 00:56 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
    2008-02-13 00:56 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-02-13 00:56 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-02-13 00:56 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-02-13 00:56 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-02-13 00:56 1,686,528 ----a-w C:\Windows\System32\gameux.dll
    2008-02-13 00:53 824,832 ----a-w C:\Windows\System32\wininet.dll
    2008-02-13 00:53 56,320 ----a-w C:\Windows\System32\iesetup.dll
    2008-02-13 00:53 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
    2008-02-13 00:53 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
    2008-02-10 19:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
    2008-02-10 19:00 --------- d-----w C:\Program Files\Real
    2008-02-06 18:45 --------- d-----w C:\Users\michelle\AppData\Roaming\PlayFirst
    2008-02-06 18:45 --------- d-----w C:\ProgramData\PlayFirst
    2008-02-06 17:41 --------- d-----w C:\Users\michelle\AppData\Roaming\SpinTop
    2008-01-31 18:50 --------- d-----w C:\Users\michelle\AppData\Roaming\AdobeUM
    2008-01-09 00:37 11,776 ----a-w C:\Windows\System32\sbunattend.exe
    2007-12-28 16:52 174 --sha-w C:\Program Files\desktop.ini
    2003-09-04 19:20 811,008 ----a-w C:\Program Files\NPSWF32.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-03-27_17.25.34.49 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-03-27 17:22:09 67,584 --s-a-w C:\Windows\bootstat.dat
    + 2008-03-29 18:42:27 67,584 --s-a-w C:\Windows\bootstat.dat
    - 2008-03-27 21:22:32 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
    + 2008-03-29 18:43:05 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
    - 2008-03-27 16:06:01 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    + 2008-03-29 15:48:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    - 2008-03-27 21:19:28 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
    + 2008-03-29 18:46:55 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
    - 2008-03-27 16:05:55 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
    + 2008-03-29 15:48:51 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
    - 2008-03-27 21:14:48 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-03-29 18:50:43 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2008-03-27 21:14:48 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-03-29 18:50:43 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-03-27 21:14:48 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-03-29 18:50:43 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-03-27 16:03:16 104,024 ----a-w C:\Windows\System32\perfc009.dat
    + 2008-03-29 15:52:10 104,024 ----a-w C:\Windows\System32\perfc009.dat
    - 2008-03-27 16:03:16 618,648 ----a-w C:\Windows\System32\perfh009.dat
    + 2008-03-29 15:52:10 618,648 ----a-w C:\Windows\System32\perfh009.dat
    - 2008-03-27 16:07:05 9,402 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2610261172-2767058957-2194934642-1001_UserData.bin
    + 2008-03-29 15:48:56 9,410 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2610261172-2767058957-2194934642-1001_UserData.bin
    - 2008-03-27 16:07:03 60,004 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-03-29 15:48:55 60,004 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-03-27 13:34:03 35,342 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-03-29 15:48:47 35,366 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    - 2008-03-27 17:22:15 208,220 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
    + 2008-03-29 18:42:39 208,236 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WindowsWelcomeCenter "= "oobefldr.dll" [2006-11-02 08:34 2159104 C:\Windows\System32\oobefldr.dll]
    "DellSupportCenter "= "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
    "swg "= "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-25 10:57 68856]
    "Aim6 "= "C:\Program Files\AIM6\aim6.exe" [2007-12-18 15:04 50528]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender "= "C:\Program Files\Windows Defender\MSASCui.exe" [2007-08-03 19:51 1006264]
    "SynTPEnh "= "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-20 13:51 815104]
    "ATICCC "= "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 18:12 90112]
    "SigmatelSysTrayApp "= "sttray.exe" [2007-02-08 01:11 303104 C:\Windows\sttray.exe]
    "Broadcom Wireless Manager UI "= "C:\Windows\system32\WLTRAY.exe" [2006-11-21 20:52 1540096]
    "ISUSScheduler "= "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]
    "PDVDDXSrv "= "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 18:23 118784]
    "ECenter "= "c:\dell\E-Center\EULALauncher.exe" [2007-03-16 06:20 17920]
    "Google Desktop Search "= "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-15 19:57 1862144]
    "ISUSPM Startup "= "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]
    "dscactivate "= "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
    "QuickTime Task "= "C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 16:27 385024]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-06-15 19:43:35 50688]
    QuickSet.lnk - C:\Windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-06-15 19:38:22 45056]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
    "AntiVirusOverride "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{23E14950-5BAB-4596-86DD-0C1AD30D3A75} "= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{BBD5F0EE-6991-4F99-9DB6-AAB24E2514E6} "= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{D5EDAD8B-31D2-4181-8F2C-77C7120FED2C} "= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
    "{E3A59109-59CB-4173-9F38-25C61911B6E3} "= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
    "{0528E383-0F61-43E5-BBEA-B4AD8372F2BC} "= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
    "{9F62E7E1-53BA-4220-9273-C53DE82C0C0E} "= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
    "DFSR-1 "= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

    R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 11:22]
    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
    R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
    R2 Viewpoint Manager Service;Viewpoint Manager Service; "C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
    R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-11 19:10]
    R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-25 01:46]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e26e2b73-1b96-11dc-ab10-806e6f6e6963}]
    \shell\AutoRun\command - E:\Autorun.exe

    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-29 14:51:57
    Windows 6.0.6000 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-03-29 14:52:44
    ComboFix-quarantined-files.txt 2008-03-29 18:52:40
    ComboFix2.txt 2008-03-27 21:25:55
    The system cannot find message text for message number 0x2379 in the message file for Application.
    The system cannot find message text for message number 0x2379 in the message file for Application.
    .
    2008-03-28 13:58:22 --- E O F ---
     
  13. 2008/03/29
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    I'm not sure how it happened but the virus is gone! :) Thank you for your help
    Can I download Limewire back onto my computer?
     
    Last edited: 2008/03/29
  14. 2008/03/29
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi michelle1980

    We need to do this again. It did not delete a couple things that it should have.

    Make sure you disable real time protection on Windows Defender and any others you have running. See here.
    Check this link for any applicable programs you may have.

    Delete the CFScript you have on your desktop and the run this one.


    Highlight and copy the contents of the code box below and paste it into a blank notepad, then save it to your desktop as;

    Filename: CFScript.txt
    Save As Type: All Files (*.*)

    Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button.
    Click here to see how to use CFScript.txt
    Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log and another fresh HijackThis log.

    Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.

    Code:
    File::
    C:\Windows\dsaip32b.dll
    C:\xmp.bat
    
    DirLook::
    C:\ProgramData\n7-89-o9-3r-4t-r9 

    :( :cool:
    Did you read any of this??
    you have P2P software ([color= "Red"] Limewire, BitTorrent uTorrent etc… [/color]) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

    Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.

    References for the risk of these programs are here,
    here and here.

    I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

    Note: Please be advised that continued use of these programs after being warned of the dangers of infections from them, may result in the discontinued help of future cleaning of your system here at Windowsbbs Virus and Spyware removal.

    Please post the new CFScript log and a new HJT log.

    Geri
     
  15. 2008/03/31
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    ComboFix 08-03-26.3 - michelle 2008-03-31 15:32:14.6 - NTFSx86
    Microsoft® Windows Vistaâ„¢ Home Basic 6.0.6000.0.1252.1.1033.18.391 [GMT -4:00]
    Running from: C:\Users\michelle\Desktop\ComboFix.exe
    Command switches used :: C:\Users\michelle\Desktop\CFScript.txt
    * Created a new restore point

    FILE ::
    C:\Windows\dsaip32b.dll
    C:\xmp.bat
    .

    ((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-31 )))))))))))))))))))))))))))))))
    .

    No new files created in this timespan

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-29 15:53 --------- d-----w C:\Program Files\Common Files\Real
    2008-03-29 15:52 --------- d-----w C:\Program Files\Fashion Boutique
    2008-03-28 00:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-03-28 00:25 --------- d-----w C:\Program Files\Infogrames Interactive
    2008-03-27 21:35 --------- d-----w C:\ProgramData\Lavasoft
    2008-03-27 21:34 12,632 ----a-w C:\Windows\System32\lsdelete.exe
    2008-03-27 13:32 --------- d-----w C:\Program Files\Games
    2008-03-27 02:06 --------- d-----w C:\Program Files\Sallys Salon
    2008-03-27 02:02 --------- d-----w C:\Program Files\SallysSalon_at
    2008-03-25 14:42 --------- d---a-w C:\ProgramData\TEMP
    2008-03-25 02:42 --------- d-----w C:\Users\michelle\AppData\Roaming\Malwarebytes
    2008-03-25 02:42 --------- d-----w C:\ProgramData\Malwarebytes
    2008-03-25 02:42 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
    2008-03-25 00:29 --------- d-----w C:\ProgramData\Kaspersky Lab
    2008-03-25 00:14 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
    2008-03-24 23:49 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-03-24 21:55 691 ----a-w C:\Users\michelle\AppData\Roaming\GetValue.vbs
    2008-03-24 21:55 35 ----a-w C:\Users\michelle\AppData\Roaming\SetValue.bat
    2008-03-24 19:24 --------- d-----w C:\Program Files\Trend Micro
    2008-03-23 01:21 --------- d-----w C:\Program Files\EA GAMES
    2008-03-22 19:49 86,528 ----a-w C:\Windows\System32\VACFix.exe
    2008-03-20 15:24 --------- d-----w C:\Program Files\AOL Games
    2008-03-20 03:29 --------- d-----w C:\ProgramData\Trymedia
    2008-03-19 02:34 --------- d-----w C:\Users\michelle\AppData\Roaming\LimeWire
    2008-03-15 21:16 82,432 ----a-w C:\Windows\System32\IEDFix.exe
    2008-03-12 01:25 --------- d-----w C:\Program Files\Windows Mail
    2008-03-08 15:49 --------- d-----w C:\Users\michelle\AppData\Roaming\Total Eclipse
    2008-03-08 00:02 --------- d-----w C:\Users\michelle\AppData\Roaming\GameHouse
    2008-03-08 00:02 --------- d-----w C:\ProgramData\n7-89-o9-3r-4t-r9
    2008-03-08 00:02 --------- d-----w C:\Program Files\GameHouse
    2008-02-28 00:39 --------- d-----w C:\ProgramData\Dell
    2008-02-13 01:02 194,560 ----a-w C:\Windows\System32\WebClnt.dll
    2008-02-13 01:02 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
    2008-02-13 00:57 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
    2008-02-13 00:57 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
    2008-02-13 00:57 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
    2008-02-13 00:57 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
    2008-02-13 00:57 24,064 ----a-w C:\Windows\System32\netcfg.exe
    2008-02-13 00:57 22,016 ----a-w C:\Windows\System32\netiougc.exe
    2008-02-13 00:57 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
    2008-02-13 00:57 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
    2008-02-13 00:57 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
    2008-02-13 00:57 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
    2008-02-13 00:57 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
    2008-02-13 00:57 110,136 ----a-w C:\Windows\system32\drivers\ataport.sys
    2008-02-13 00:56 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
    2008-02-13 00:56 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-02-13 00:56 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-02-13 00:56 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-02-13 00:56 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-02-13 00:56 1,686,528 ----a-w C:\Windows\System32\gameux.dll
    2008-02-13 00:53 824,832 ----a-w C:\Windows\System32\wininet.dll
    2008-02-13 00:53 56,320 ----a-w C:\Windows\System32\iesetup.dll
    2008-02-13 00:53 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
    2008-02-13 00:53 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
    2008-02-10 19:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
    2008-02-10 19:00 --------- d-----w C:\Program Files\Real
    2008-02-06 18:45 --------- d-----w C:\Users\michelle\AppData\Roaming\PlayFirst
    2008-02-06 18:45 --------- d-----w C:\ProgramData\PlayFirst
    2008-02-06 17:41 --------- d-----w C:\Users\michelle\AppData\Roaming\SpinTop
    2008-01-31 18:50 --------- d-----w C:\Users\michelle\AppData\Roaming\AdobeUM
    2008-01-09 00:37 11,776 ----a-w C:\Windows\System32\sbunattend.exe
    2007-12-28 16:52 174 --sha-w C:\Program Files\desktop.ini
    2007-12-28 15:43 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
    2007-12-28 15:43 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
    2007-12-28 15:43 542,720 ----a-w C:\Windows\System32\sysmain.dll
    2007-12-28 15:43 502,784 ----a-w C:\Windows\System32\wlansvc.dll
    2007-12-28 15:43 47,104 ----a-w C:\Windows\System32\wlanapi.dll
    2007-12-28 15:43 297,984 ----a-w C:\Windows\System32\wlansec.dll
    2007-12-28 15:43 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
    2007-12-28 15:43 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
    2007-12-28 15:43 2,923,520 ----a-w C:\Windows\explorer.exe
    2007-12-28 15:43 2,027,008 ----a-w C:\Windows\System32\win32k.sys
    2007-12-28 15:42 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
    2007-12-28 15:42 7,680 ----a-w C:\Windows\System32\spwmp.dll
    2007-12-28 15:42 4,096 ----a-w C:\Windows\System32\dxmasf.dll
    2007-12-28 15:42 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
    2007-12-28 15:40 8,704 ----a-w C:\Windows\System32\hcrstco.dll
    2007-12-28 15:40 8,704 ----a-w C:\Windows\System32\hccoin.dll
    2007-12-28 15:40 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
    2007-12-28 15:39 1,327,104 ----a-w C:\Windows\System32\quartz.dll
    2007-12-28 15:38 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
    2007-12-28 15:38 223,232 ----a-w C:\Windows\System32\WMASF.DLL
    2007-12-28 15:38 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
    2007-12-28 15:32 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
    2007-12-28 15:30 750,080 ----a-w C:\Windows\System32\qmgr.dll
    2003-09-04 19:20 811,008 ----a-w C:\Program Files\NPSWF32.dll
    .

    (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .

    ---- Directory of C:\ProgramData\n7-89-o9-3r-4t-r9 ----

    2008-03-07 21:02 51 --a------ C:\ProgramData\n7-89-o9-3r-4t-r9\profile.ini


    ((((((((((((((((((((((((((((( snapshot@2008-03-27_17.25.34.49 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-03-27 17:22:09 67,584 --s-a-w C:\Windows\bootstat.dat
    + 2008-03-31 19:28:01 67,584 --s-a-w C:\Windows\bootstat.dat
    - 2008-03-27 21:22:32 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
    + 2008-03-31 19:28:06 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
    - 2008-03-27 16:06:01 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    + 2008-03-30 14:51:42 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    - 2008-03-27 21:19:28 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
    + 2008-03-31 19:31:23 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
    - 2008-03-27 16:05:55 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
    + 2008-03-30 14:51:36 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
    - 2008-03-27 21:14:48 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-03-31 19:29:00 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2008-03-27 21:14:48 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-03-31 19:29:00 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-03-27 21:14:48 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-03-31 19:29:00 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-03-27 16:03:16 104,024 ----a-w C:\Windows\System32\perfc009.dat
    + 2008-03-30 14:54:36 104,024 ----a-w C:\Windows\System32\perfc009.dat
    - 2008-03-27 16:03:16 618,648 ----a-w C:\Windows\System32\perfh009.dat
    + 2008-03-30 14:54:36 618,648 ----a-w C:\Windows\System32\perfh009.dat
    - 2008-03-27 16:07:05 9,402 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2610261172-2767058957-2194934642-1001_UserData.bin
    + 2008-03-30 14:52:51 9,616 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2610261172-2767058957-2194934642-1001_UserData.bin
    - 2008-03-27 16:07:03 60,004 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-03-30 14:52:48 60,004 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-03-27 13:34:03 35,342 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-03-30 14:52:31 35,534 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    - 2008-03-27 17:22:15 208,220 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
    + 2008-03-31 19:28:05 208,252 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WindowsWelcomeCenter "= "oobefldr.dll" [2006-11-02 08:34 2159104 C:\Windows\System32\oobefldr.dll]
    "DellSupportCenter "= "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 10:23 202544]
    "swg "= "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-25 10:57 68856]
    "Aim6 "= "C:\Program Files\AIM6\aim6.exe" [2007-12-18 15:04 50528]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender "= "C:\Program Files\Windows Defender\MSASCui.exe" [2007-08-03 19:51 1006264]
    "SynTPEnh "= "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-20 13:51 815104]
    "ATICCC "= "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 18:12 90112]
    "SigmatelSysTrayApp "= "sttray.exe" [2007-02-08 01:11 303104 C:\Windows\sttray.exe]
    "Broadcom Wireless Manager UI "= "C:\Windows\system32\WLTRAY.exe" [2006-11-21 20:52 1540096]
    "ISUSScheduler "= "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]
    "PDVDDXSrv "= "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 18:23 118784]
    "ECenter "= "c:\dell\E-Center\EULALauncher.exe" [2007-03-16 06:20 17920]
    "Google Desktop Search "= "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-15 19:57 1862144]
    "ISUSPM Startup "= "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]
    "dscactivate "= "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
    "QuickTime Task "= "C:\Program Files\QuickTime\QTTask.exe" [2008-01-10 16:27 385024]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [2008-01-15 04:22 267048]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-06-15 19:43:35 50688]
    QuickSet.lnk - C:\Windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-06-15 19:38:22 45056]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{23E14950-5BAB-4596-86DD-0C1AD30D3A75} "= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{BBD5F0EE-6991-4F99-9DB6-AAB24E2514E6} "= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
    "{D5EDAD8B-31D2-4181-8F2C-77C7120FED2C} "= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
    "{E3A59109-59CB-4173-9F38-25C61911B6E3} "= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
    "{0528E383-0F61-43E5-BBEA-B4AD8372F2BC} "= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
    "{9F62E7E1-53BA-4220-9273-C53DE82C0C0E} "= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
    "DFSR-1 "= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

    R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 11:22]
    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
    R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2007-11-15 10:23]
    R2 Viewpoint Manager Service;Viewpoint Manager Service; "C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 17:38]
    R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-11 19:10]
    R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-25 01:46]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-31 15:35:34
    Windows 6.0.6000 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-03-31 15:36:14
    ComboFix-quarantined-files.txt 2008-03-31 19:36:11
    ComboFix2.txt 2008-03-30 15:37:15
    ComboFix3.txt 2008-03-29 18:52:45
    ComboFix4.txt 2008-03-27 21:25:55
    The system cannot find message text for message number 0x2379 in the message file for Application.
    The system cannot find message text for message number 0x2379 in the message file for Application.
    .
    2008-03-28 13:58:22 --- E O F ---
     
  16. 2008/03/31
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:38:48 PM, on 3/31/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16609)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\sttray.exe
    C:\Windows\System32\WLTRAY.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\Common Files\AOL\Loader\aolload.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\notepad.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe "
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe "
    O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-21-2610261172-2767058957-2194934642-1000\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O4 - Global Startup: QuickSet.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/stg_drm.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Sally's%20Salon/Images/armhelper.ocx
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 8384 bytes
     
  17. 2008/03/31
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi michelle1980

    OK lets get a on-line scan.

    Please do an online scan with Kaspersky WebScanner

    Click on "Accept" If your pop "“up blocker blocks the ActiveX download, allow it, click on "Accept" again

    You will be promted to install an ActiveX component from Kaspersky, Click Yes or Install.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
      • Extended (if available otherwise Standard)
      • Scan Options:
      • Scan Archives
        Scan Mail Bases
    • Click OK
    • Now under select a target to scan:
      • Select My Computer
    • This will start the program and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete it will display if your system has been infected.
      • Now click on the Save as Text button:
    • Save the file to your desktop.
    • Copy and paste that information in your next post.

    Please post the Kaspersky results.

    Thanks
    Geri
     
  18. 2008/04/02
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    Geri,

    When I tried to download the definitions, it said that there was an error and the process failed. It also says I have to be online, which does not make sense because I am definitely online. Let me know what I should do.

    PS. I have downloaded the Kaspersky before (if that helps).
     
  19. 2008/04/03
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi michelle1980
    Lets try turning off your AV just while you try to get the scan.

    Make sure you enable it right after you get the scan results.

    You are using Norton Correct?
    NORTON ANTIVIRUS
    Please navigate to the system tray on the bottom right hand corner and look for a your Norton icon.

    * right-click it -> chose "Disable Auto-Protect. "
    * select a duration of 5 hours (this assures no interference with the cleanup of your pc)
    * click "Ok. "
    * a popup will warn that protection will now be disabled and the will now have an X in it.

    You succesfully disabled the Norton Antivirus Guard.

    Now try the scan, do not do any surfing while your AV is disabled.

    Geri
     
  20. 2008/04/10
    michelle1980

    michelle1980 Inactive Thread Starter

    Joined:
    2008/03/25
    Messages:
    16
    Likes Received:
    0
    I do not have Norton Anti-virus on my computer.
     
  21. 2008/04/10
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi michelle1980
    What Anti-Virus and firewall are you using?

    Geri
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.