PDA

View Full Version : help under attack this is my 2nd comp hacked:(



montyAUS
2007-08-29, 13:33
hi id just like 2 say thanks in advance for any efforts much appreciated..i have been looking up and researching but this is a bit beyond my knowledge(for the moment):P

if this is successful i will try and fix my other computer but i cant connect it to the internet ..2 dangerous atm.

thank you very much!!:)


KASPERSKY ONLINE SCANNER REPORT
Wednesday, August 29, 2007 11:02:41 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 29/08/2007
Kaspersky Anti-Virus database records: 395359


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target Critical Areas
C:\WINDOWS
C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\

Scan Statistics
Total number of scanned objects 20479
Number of viruses found 9
Number of infected objects 17
Number of suspicious objects 0
Duration of the scan process 00:28:51

Infected Object Name Virus Name Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped

C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\qkzgopzj.exe Infected: not-a-virus:AdWare.Win32.HotBar.bw skipped

C:\WINDOWS\system32\ckujtaoj.exe/data0018/data0002 Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

C:\WINDOWS\system32\ckujtaoj.exe/data0018/data0003 Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

C:\WINDOWS\system32\ckujtaoj.exe/data0018/data0004 Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

C:\WINDOWS\system32\ckujtaoj.exe/data0018 Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

C:\WINDOWS\system32\ckujtaoj.exe NSIS: infected - 4 skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\Temp\ZLT07399.TMP Object is locked skipped

C:\WINDOWS\Temp\ZLT05b0d.TMP Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped

C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\ACER-2E68C49B20.ldb Object is locked skipped

C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped

C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~DFBA4F.tmp Object is locked skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\PCTurboProSetup.exe/file02 Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\PCTurboProSetup.exe/file10 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\PCTurboProSetup.exe Inno: infected - 2 skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\miniinst.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\Installer.exe Infected: Backdoor.Win32.Hupigon.gs skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file01 Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file02/file01 Infected: Trojan-Downloader.Win32.Agent.alr skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file02 Infected: Trojan-Downloader.Win32.Agent.alr skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file18 Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file83 Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe Inno: infected - 5 skipped

Scan process completed.


KASPERSKY ONLINE SCANNER REPORT
Wednesday, August 29, 2007 11:08:07 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 29/08/2007
Kaspersky Anti-Virus database records: 395359


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target Memory


Scan Statistics
Total number of scanned objects 1641
Number of viruses found 6
Number of infected objects 28
Number of suspicious objects 0
Duration of the scan process 00:00:51

Infected Object Name Virus Name Last Action
[3904] WSCNTFY.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[3916] EXPLORER.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[232] SynTPLpr.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[208] SynTPEnh.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[292] SOUNDMAN.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[392] AGRSMMSG.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[424] RUNDLL32.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[436] Keyhook.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[1420] PCMService.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[1200] QtZgAcer.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[604] OpWareSE4.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[664] HbtWeatherOnTray.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtWeatherOnTray.exe Infected: not-a-virus:AdWare.Win32.Hotbar.an skipped

[664] HbtWeatherOnTray.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[1656] HbtOEAddOn.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtOEAddOn.exe Infected: not-a-virus:AdWare.Win32.HotBar.bt skipped

[1656] HbtOEAddOn.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[1640] MSNMSGR.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[1632] CTFMON.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[1028] TeaTimer.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[2088] SISTRAY.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[2176] Monitor.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[1912] HBTV.EXE => C:\Program Files\Hbtools\HBTV\HBTV.exe Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

[1912] HBTV.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[1912] HBTV.EXE => c:\program files\hbtools\hbtv\hbtvhelper.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

[3788] IEXPLORE.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

[3788] IEXPLORE.EXE => c:\program files\hbtools\hbtv\hbtvhelper.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

[3788] IEXPLORE.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostIE.dll Infected: not-a-virus:AdWare.Win32.HotBar.bx skipped

[3788] IEXPLORE.EXE => C:\Program Files\HbTools\Bin\4.8.4.0\HbtCoreSrv.dll Infected: not-a-virus:AdWare.Win32.HotBar.bz skipped

[2540] WLLoginProxy.exe => C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostOE.dll Infected: not-a-virus:AdWare.Win32.Hotbar.ar skipped

Scan process completed.


KASPERSKY ONLINE SCANNER REPORT
Wednesday, August 29, 2007 11:02:41 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 29/08/2007
Kaspersky Anti-Virus database records: 395359


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target Critical Areas
C:\WINDOWS
C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\

Scan Statistics
Total number of scanned objects 20479
Number of viruses found 9
Number of infected objects 17
Number of suspicious objects 0
Duration of the scan process 00:28:51

Infected Object Name Virus Name Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped

C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\qkzgopzj.exe Infected: not-a-virus:AdWare.Win32.HotBar.bw skipped

C:\WINDOWS\system32\ckujtaoj.exe/data0018/data0002 Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

C:\WINDOWS\system32\ckujtaoj.exe/data0018/data0003 Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

C:\WINDOWS\system32\ckujtaoj.exe/data0018/data0004 Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

C:\WINDOWS\system32\ckujtaoj.exe/data0018 Infected: not-a-virus:AdWare.Win32.180Solutions.ay skipped

C:\WINDOWS\system32\ckujtaoj.exe NSIS: infected - 4 skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\Temp\ZLT07399.TMP Object is locked skipped

C:\WINDOWS\Temp\ZLT05b0d.TMP Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped

C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped

C:\WINDOWS\Internet Logs\ACER-2E68C49B20.ldb Object is locked skipped

C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped

C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~DFBA4F.tmp Object is locked skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\PCTurboProSetup.exe/file02 Infected: not-a-virus:Downloader.Win32.WinFixer.l skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\PCTurboProSetup.exe/file10 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\PCTurboProSetup.exe Inno: infected - 2 skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\miniinst.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\Installer.exe Infected: Backdoor.Win32.Hupigon.gs skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file01 Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file02/file01 Infected: Trojan-Downloader.Win32.Agent.alr skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file02 Infected: Trojan-Downloader.Win32.Agent.alr skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file18 Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe/file83 Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped

C:\DOCUME~1\SANDRA~1\LOCALS~1\Temp\~freesetup.exe Inno: infected - 5 skipped

Scan process completed.


ahhh ok thats the kapersky online scan...i ommitted results that were clean...hope thats ok

montyAUS
2007-08-29, 13:34
(sorry couldnt fit all in one post)
soooo then i did the hijackthis scan(lol u should of seen my foray into that program for the first time on my other computer that originally got hacked) very funny..anyway here is the report..
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:52:48 PM, on 29/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Arcade\PCMService.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ninemsn.com.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by112fd.bay112.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

--
End of file - 7571 bytes

anyway i will await eagerly any help u may give..
thanks heaps:P

Mr_JAk3
2007-08-30, 20:35
Hello montyAUS and welcome to the Forums :)

You're infected.

Please post an uninstall list to here. Start HijackThis
Click on the Config button
Click on the Misc Tools button
Click on the Open Uninstall Manager button.
Click on the Save list... button and specify where you would like to save this file.
When you press Save button a notepad will open with the contents of that file.
Simply copy and paste the contents of that notepad here on your next reply.

tashi
2007-09-08, 01:47
:scratch:

Due to lack of a response to helper this topic has been archived.

If you need it re-opened please send me a private message (pm) and provide a link to the thread. Applies only to the original poster, anyone else with similar problems please start a new topic.