PDA

View Full Version : Surfsidekick 3, command service - my problems



ravenoff
2006-05-24, 18:42
The endless slew of pop ups started with a hidden install of surfsidekick 3. I tinkered around a bit and think I stopped the program from starting up using crap cleaner, but I'm still suffering massive pop ups. Spybot removes everything but Command Service(even in Safe mode) which I'm guessing re-installs everything because every time I run it it finds 100+ problems. I'm now using stopzilla, and spysweeper which makes my computer reasonably useable. I've got my C drive on a separate 10g partition and I'm wondering if it'll just me easier to wipe and reinstall. Thanks in advance

Logfile of HijackThis v1.99.1
Scan saved at 12:40:50 PM, on 5/24/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\STOPzilla!\szntsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Temp\svchost1.exe
C:\WINDOWS\Temp\system.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
D:\DAEMON Tools\daemon.exe
C:\Program Files\ipwins\ipwins.exe
C:\WINDOWS\thiselt.exe
C:\WINDOWS\ms046878101345.exe
D:\STOPzilla!\Stopzilla.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\AXVenore\AXVenore.exe
C:\Program Files\PECarlin\PECarlin.exe
C:\PROGRA~1\COMMON~1\SSTEM~1\javaw.exe
C:\Program Files\Common Files\svchostsys\svchostsys.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
c:\windows\system32\dwdsregt.exe
D:\FIREFOX\FIREFOX.EXE
C:\Program Files\Messenger\wmsmsgs.exe
C:\WINDOWS\System32\wpabaln.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\a?sembly\?canregw.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Hijack This\HijackThis.exe
D:\CCleaner\ccleaner.exe
D:\Winamp\winamp.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qwkfe.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,brqiogt.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {581B36F6-AE39-F5B3-1FDA-F0CAEE21B3CF} - C:\WINDOWS\System32\gachvcn.dll
O2 - BHO: RieMon Class - {70F6A776-579A-4C95-BA88-134253907752} - C:\WINDOWS\System32\irsmfnvb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\WINDOWS\System32\StopzillaBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "d:\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [w1085d4e.dll] RUNDLL32.EXE w1085d4e.dll,I2 00100bbd01085d4e
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [pop06apelt] C:\WINDOWS\thiselt.exe
O4 - HKLM\..\Run: [{59-91-10-02-ZN}] c:\windows\system32\dwdsregt.exe FI002
O4 - HKLM\..\Run: [ms046878101345] C:\WINDOWS\ms046878101345.exe
O4 - HKLM\..\Run: [STOPzilla] "D:\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [AXVenore] "C:\Program Files\AXVenore\AXVenore.exe"
O4 - HKCU\..\Run: [PECarlin] "C:\Program Files\PECarlin\PECarlin.exe"
O4 - HKCU\..\Run: [Bwos] "C:\PROGRA~1\COMMON~1\SSTEM~1\javaw.exe" -vt yazb
O4 - HKCU\..\Run: [sys_up1] C:\Program Files\Common Files\svchostsys\svchostsys.exe
O4 - HKCU\..\Run: [irssyncd] C:\WINDOWS\System32\irssyncd.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\ppdsregn.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{227EE965-768E-4489-ACD2-737C4B1CF51A}: NameServer = 24.29.103.10,24.29.103.11
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: FireDaemon Service: ecure (ecure) - Unknown owner - C:\WINDOWS\Temp\FireDaemon.EXE
O23 - Service: STOPzilla Local Service - International Software Systems Solutions - D:\STOPzilla!\szntsvc.exe
O23 - Service: FireDaemon Service: svchost1 (svchost1) - Unknown owner - C:\WINDOWS\Temp\FireDaemon.EXE
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: FireDaemon Service: system (system) - Unknown owner - C:\WINDOWS\Temp\FireDaemon.EXE
O23 - Service: WUSB54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe (file missing)



ac2_0006.exe Win32/Acee.A cannot cure C:\Documents and Settings\rav\Local Settings\Temp\
MTE4MjM6ODoxNg.exe Win32/SillyDl.YQ cannot cure C:\Documents and Settings\rav\Local Settings\Temp\
tp7543.exe Win32/Qoologic!generic cannot cure C:\Documents and Settings\rav\Local Settings\Temp\
idlemg[1].exe Win32/SillyDl.YQ cannot cure C:\Documents and Settings\rav\Local Settings\Temporary Internet Files\Content.IE5\EJ8T6FW9\
installer_2512[1].exe Win32/Qoologic.AB cannot cure C:\Documents and Settings\rav\Local Settings\Temporary Internet Files\Content.IE5\EJ8T6FW9\
rcverlib[1].exe Win32/Qoologic!generic cannot cure C:\Documents and Settings\rav\Local Settings\Temporary Internet Files\Content.IE5\EJ8T6FW9\
MTE4MjM6ODoxNg[1].exe Win32/SillyDl.YQ cannot cure C:\Documents and Settings\rav\Local Settings\Temporary Internet Files\Content.IE5\QFGZOPWF\
DH.dll_tobedeleted Win32/Zquest.A cannot cure C:\WINDOWS\
idlemg.exe Win32/SillyDl.YQ cannot cure C:\WINDOWS\
dmonwv.dll Win32/Qoologic.AB cannot cure C:\WINDOWS\system32\
fkieq.dat Win32/Qoologic.AB cannot cure C:\WINDOWS\system32\
gachvcn.dll Win32/Clspring!generic cannot cure C:\WINDOWS\system32\
clean.bat BAT/IRCFlood cannot cure C:\WINDOWS\Temp\
unwn.exe Win32/Qoologic!generic cannot cure C:\WINDOWS\

ravenoff
2006-05-24, 21:48
Also, could you tell me if any of the viruses/spyware have the capabilities of key logging or other ways of getting passwords for ebay/paypal/etc that I logged in to.

Thanks

ravenoff
2006-05-26, 06:19
surfsidekick sent my computer into a downward spiral FAST.

In just 1-2 days it got almost completely unusuable.

I did a safe-boot and ran Spybot, Aboutbuster, and Adaware and they "fixed" all they could. Upon reboot I was missing hal.dll and couldn't boot. I decided on a fresh reinstall rather than trying to do a repair on it.

Thanks anyways, keep up the good work!

ravenoff
2006-05-26, 06:26
Oh wait, I would like to know if there were any severly compromising infections that could have gotten ebay/paypal info.

thanks

LonnyRJones
2006-05-29, 18:35
Welcome

If your not recieving help at another forum ? Make and post back with a new hijackthis log please.

tashi
2006-06-06, 03:54
This topic is closed.

ravenoff if you need it re-opened please send me a pm and provide a link to the thread.

Please do not post in other member's topics.
http://forums.spybot.info/showthread.php?p=27009#post27009


BEFORE you post a log, and who will advise you. Preliminary Steps (http://forums.spybot.info/showthread.php?t=288)