Page 1 of 2 12 LastLast
Results 1 to 10 of 18

Thread: Please help

  1. #1
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default Please help

    Hi, I've been having problems with my computer for quite a long time and now it's gotten worse because everything is loading quite slowly. I have read the before you post thread and unfortunately, I can't run the kapersky online scanner. I've tried running spybot in safe mode but command service never goes away. I've been tempted to just delete files and follow other threads but instead I'll rely on more informed people because I am clueless. Thanks in advance.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:11:44 PM, on 10/5/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Common Files\Command Software\dvpapi.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINNT\explorer.exe
    C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe
    C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
    C:\WINNT\system32\winsock4.exe
    C:\Program Files\NetAssistant\bin\mpbtn.exe
    C:\Program Files\CCleaner\CCleaner.exe
    C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\enternet.exe
    C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINNT\System32\freecell.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: Shell=explorer.exe winsock4.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [Win32 Info] windowsnfo.exe
    O4 - HKLM\..\Run: [Keyboard Driver (do not remove)] ESOLVER.EXE
    O4 - HKLM\..\Run: [REGRUN] C:\WINNT\system32\iexplorer\a.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [winsockdriver] winsock4.exe
    O4 - HKLM\..\RunServices: [Win32 Info] windowsnfo.exe
    O4 - HKLM\..\RunServices: [sys33] Sys33.exe
    O4 - HKLM\..\RunServices: [MSN Checker] msnchecker.exe
    O4 - HKLM\..\RunServices: [System Support] sym.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
    O4 - HKCU\..\RunServices: [Win32 Info] windowsnfo.exe
    O4 - HKCU\..\RunServices: [HTML Help System] hhs.pif
    O4 - HKCU\..\RunServices: [Browser Help Svc] BHSV.EXE
    O4 - HKCU\..\RunServices: [MSN Checker] msnchecker.exe
    O4 - HKCU\..\RunServices: [Updt Service] updt.pif
    O4 - HKCU\..\RunOnce: [winsockdriver] winsock4.exe
    O4 - HKUS\.DEFAULT\..\Run: [Win32 Info] windowsnfo.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [OS Security] mswind32.pif (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Browser Help Svc] BHSV.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Configuration Loader] msgfix.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [MSN Checker] msnchecker.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Aupw] "C:\Program Files\mssa\ostn.exe" -vt yazr (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunServices: [Win32 Info] windowsnfo.exe (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.pestpatrol.com/pestscan/pestscan.cab
    O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O19 - User stylesheet: (file missing)
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\TmV0d29yaw\command.exe (file missing)
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
    O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe
    O23 - Service: SBHookSvc - Motive Communications, Inc. - C:\PROGRA~1\NETASS~1\SMARTB~1\SBHookSvc.exe

    --
    End of file - 6119 bytes

  2. #2
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon

    this one didn't show up last time because I used ccleaner to get rid of it at startup. It just comes back when I log back in.

  3. #3
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi X-ray

    One or more of the identified infections is a backdoor trojan.

    This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

    I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

    Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

    How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

    When Should I Format, How Should I Reinstall

    We can attempt to clean this machine but i can't guarantee that it will be 100% secure afterwards.

    Should you have any questions, please feel free to ask.

    Please let us know what you have decided to do in your next post.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  4. #4
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    I'd like to get the machine get cleaned because I'm unsure about the other option.

  5. #5
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Practically other option means re-formatting (you'll loose everything on your hard disk and you need windows CD for that, too).

    If you however like to proceed with that I can give you
    instructions
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #6
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    I do like to proceed, thank you very much.

  7. #7
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    I understood it that way that you want to continue with cleaning.

    If not, just say and I'll give you re-format instructions.

    Download SDFix and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Please then reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard ready for posting back on the forum).
    • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #8
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    ok I've followed your steps. I appreciate the help

    SDFix: Version 1.108

    Run by Administrator on Fri 10/12/2007 at 4:40p

    Microsoft Windows 2000 [Version 5.00.2195]

    Running From: C:\SDFix

    Safe Mode:
    Checking Services:

    Name:
    cmdService

    ImagePath:
    C:\WINNT\TmV0d29yaw\command.exe

    cmdService - Deleted



    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting...


    Normal Mode:
    Checking Files:

    Trojan Files Found:

    C:\WINNT\TmV0d29yaw\nApXxZ6VuT.vbs - Deleted
    C:\Documents and Settings\Administrator\Application Data\Install.dat - Deleted
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\abc123.pid - Deleted
    C:\WINNT\csrs.exe - Deleted
    C:\WINNT\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe - Deleted
    C:\WINNT\system32\4_exception.nls - Deleted
    C:\WINNT\system32\game.exe - Deleted
    C:\WINNT\system32\KBRunOnce2.t__ - Deleted
    C:\WINNT\system32\msnchecker.exe - Deleted


    Folder C:\Documents and Settings\All Users\Documents\Settings - Removed

    Removing Temp Files...

    ADS Check:

    C:\WINNT
    No streams found.

    C:\WINNT\system32
    No streams found.

    C:\WINNT\system32\svchost.exe
    No streams found.

    C:\WINNT\system32\ntoskrnl.exe
    No streams found.



    Final Check:

    Remaining Services:
    ------------------




    Remaining Files:
    ---------------

    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes:

    Thu 19 Jun 2003 286,141 A.SHR --- "C:\msnchecker.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\msnchecke7.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\msnchecke5.exe"
    Sat 18 Aug 2001 286,141 A.SHR --- "C:\msnchecke0.exe"
    Sat 18 Aug 2001 286,141 A.SHR --- "C:\msnchecke1.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\msnchecke2.exe"
    Fri 24 Feb 2006 122,368 ..SHR --- "C:\WINNT\iexpress.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\WINNT\msnchecker.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\WINNT\msnchecke7.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\WINNT\msnchecke4.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\WINNT\msnchecke8.exe"
    Mon 16 Jan 2006 121,856 ..SHR --- "C:\WINNT\msinm.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\WINNT\msnchecke0.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\WINNT\msnchecke1.exe"
    Thu 19 Jun 2003 286,141 A.SHR --- "C:\WINNT\msnchecke3.exe"
    Tue 7 Feb 2006 122,368 A.SHR --- "C:\WINNT\nav32.exe"
    Wed 1 Feb 2006 122,368 ..SHR --- "C:\WINNT\nvcr32.exe"
    Mon 16 Jan 2006 121,856 ..SHR --- "C:\WINNT\rund1132.exe"
    Wed 18 Jan 2006 122,368 ..SHR --- "C:\WINNT\svbhost.exe"
    Thu 2 Mar 2006 122,368 ..SHR --- "C:\WINNT\wscntify.exe"
    Thu 29 Aug 2002 91,136 A.SH. --- "C:\Program Files\Internet Explorer\IEXPLORE.EXE"
    Mon 27 Feb 2006 56,832 A.SH. --- "C:\Program Files\Outlook Express\MSIMN.EXE"
    Wed 30 Nov 2005 244,311 ...H. --- "C:\WINNT\bak\DLLLOADRS.EXE"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke2.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke3.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke0.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke1.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke7.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke5.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke8.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke4.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke9.exe"
    Thu 19 Jun 2003 286,141 ..SHR --- "C:\WINNT\system32\msnchecke6.exe"
    Sun 15 Oct 2006 27,648 ...H. --- "C:\Documents and Settings\Administrator\My Documents\~WRL0001.tmp"
    Tue 7 Mar 2006 25,600 ...H. --- "C:\Documents and Settings\Administrator\My Documents\~WRL0573.tmp"
    Mon 5 Dec 2005 81,920 ...H. --- "C:\Documents and Settings\Administrator\My Documents\~WRL0842.tmp"
    Tue 19 Sep 2006 26,624 ...H. --- "C:\Documents and Settings\Administrator\My Documents\~WRL2391.tmp"
    Tue 7 Mar 2006 29,696 ...H. --- "C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\~WRL0002.tmp"

    Finished!

  9. #9
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:57:28 PM, on 10/12/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Common Files\Command Software\dvpapi.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\notepad.exe
    C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINNT\system32\winsock4.exe
    C:\WINNT\system32\msiexec.exe
    C:\Program Files\NetAssistant\bin\mpbtn.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    c:\program files\internet explorer\iexplore.exe
    C:\WINNT\system32\MsiExec.exe
    C:\WINNT\system32\MsiExec.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: Shell=explorer.exe winsock4.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [Keyboard Driver (do not remove)] ESOLVER.EXE
    O4 - HKLM\..\Run: [REGRUN] C:\WINNT\system32\iexplorer\a.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [winsockdriver] winsock4.exe
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\RunServices: [sys33] Sys33.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
    O4 - HKCU\..\RunServices: [HTML Help System] hhs.pif
    O4 - HKCU\..\RunServices: [Browser Help Svc] BHSV.EXE
    O4 - HKCU\..\RunServices: [Updt Service] updt.pif
    O4 - HKCU\..\RunOnce: [winsockdriver] winsock4.exe
    O4 - HKUS\.DEFAULT\..\Run: [Win32 Info] windowsnfo.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [OS Security] mswind32.pif (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Browser Help Svc] BHSV.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Configuration Loader] msgfix.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Aupw] "C:\Program Files\mssa\ostn.exe" -vt yazr (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunServices: [Win32 Info] windowsnfo.exe (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.pestpatrol.com/pestscan/pestscan.cab
    O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O19 - User stylesheet: (file missing)
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
    O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe
    O23 - Service: SBHookSvc - Motive Communications, Inc. - C:\PROGRA~1\NETASS~1\SMARTB~1\SBHookSvc.exe

    --
    End of file - 5610 bytes

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi and sorry for delay.

    1. Download combofix from one of these links:
    Link1
    Link2
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    Post:

    - a fresh HijackThis log
    - combofix report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •