Results 1 to 8 of 8

Thread: What the heck?

  1. #1
    Junior Member
    Join Date
    Dec 2008
    Posts
    4

    Default What the heck?

    I let my cousin check her email on my work computer. She also surfed a couple of websites. At first, I was getting a small windows popup that said something like "avenohehehehe" Something like that would pop up every few minutes. Now, when I try to go to google.com, I get routed to a fake Microsoft site that says I have been infected please click the link. I also have problems sending faxes....keeps telling me that the line is busy, well it's not.

    Any help would be very appreciated. Thank you in advance for any help.

    Here is my Hijack Log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:01:23 PM, on 12/11/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\WINDOWS\system32\LxrSII1s.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\DOCUME~1\RICHAR~1\LOCALS~1\Temp\AutoDetect.exe
    C:\Documents and Settings\Richard Gongora\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\PROGRA~1\MICROS~2\rapimgr.exe
    C:\WINDOWS\system32\fxssvc.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\WINDOWS\System32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Yahoo!\browser\ybrowser.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O1 - Hosts: 61.157.217.210 www.yahoo.com
    O1 - Hosts: 61.157.217.210 www.google.com
    O1 - Hosts: 61.157.217.210 www.google.co.uk
    O1 - Hosts: 61.157.217.210 www.myspace.com
    O1 - Hosts: 61.157.217.210 www.youtube.com
    O1 - Hosts: 61.157.217.210 www.facebook.com
    O1 - Hosts: 61.157.217.210 www.antispy.com
    O1 - Hosts: 61.157.217.210 www.yahoo.com
    O1 - Hosts: 61.157.217.210 www.yahoo.co.uk
    O1 - Hosts: 61.157.217.210 www.antispyware.com
    O1 - Hosts: 61.157.217.210 antispyware.com
    O1 - Hosts: 61.157.217.210 antispy.com
    O1 - Hosts: 61.157.217.210 www.msn.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.gg.com
    O1 - Hosts: 123.251.143.110 www.ghfhj.com
    O1 - Hosts: 123.251.143.110 www.cvnbcvnb.com
    O1 - Hosts: 123.251.143.110 www.1.com
    O1 - Hosts: 123.251.143.110 www.3.com
    O1 - Hosts: 123.251.143.110 www.asdf4asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfawsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfatsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfadsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfafsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfagsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasgdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdhfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfjd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfkd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfld.com
    O1 - Hosts: 123.251.143.110 www.asdfasdf,d.com
    O1 - Hosts: 123.251.143.110 www.asxdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdzfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdcfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfvasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfabsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasndfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdmfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.11asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.as222dfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfa33sdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasd44fd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd5.com
    O1 - Hosts: 123.251.143.110 www.as66dfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf77asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf8asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf9asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf0asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf-asdfd.com
    O1 - Hosts: 123.251.143.110 www.aqqsdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.aswwdfasdfd.com
    O1 - Hosts: 123.16.197.121 www.asdhhfasdfdyy.com
    O1 - Hosts: 61.157.217.210 www.live.com
    O1 - Hosts: 123.251.143.110 www.asdwwwfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfeasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfrrasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfttasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfyyasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfuuuasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfaiisdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfaoosdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfappsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasssdfd.com
    O1 - Hosts: 123.251.143.110 www.aswwdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdeefasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfffasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfavvvsdfd.com
    O1 - Hosts: 123.251.143.110 www.asnnndfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdmmmfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfaffsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdhhfasdfd.com
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [Ceedo AutoDetect] C:\DOCUME~1\RICHAR~1\LOCALS~1\Temp\AutoDetect.exe /active
    O4 - HKCU\..\Run: [LxrAutorun] C:\Documents and Settings\Richard Gongora\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [Ceedo Repair] C:\DOCUME~1\RICHAR~1\LOCALS~1\Temp\AutoDetect.exe /repair /drive=
    O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?Link...04&clcid=0x409
    O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/02d8ee6b...p/RdxIE601.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1150834424372
    O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents...1/imloader.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6844D58D-02C6-4074-A860-6E5989CB4B2A}: NameServer = 209.244.0.3 209.244.0.4
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: McAfee Application Installer Cleanup (0017721228868555) (0017721228868555mcinstcleanup) - Unknown owner - C:\DOCUME~1\RICHAR~1\LOCALS~1\Temp\001772~1.EXE (file missing)
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    --
    End of file - 14821 bytes

  2. #2
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi,

    we will get a download to use. link and directions:

    Please download Malwarebytes' Anti-Malware (MBAM) to your desktop:

    http://www.malwarebytes.org/mbam.php

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform FULL SCAN, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

    please post the MBAM log in reply. after you use MBAM, rescan and post a new hjt log also.......
    How Can I Reduce My Risk?

  3. #3
    Junior Member
    Join Date
    Dec 2008
    Posts
    4

    Default MBAM and New HijackThis log

    Malwarebytes' Anti-Malware 1.31
    Database version: 1513
    Windows 5.1.2600 Service Pack 3

    12/18/2008 1:50:09 PM
    mbam-log-2008-12-18 (13-50-09).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 236207
    Time elapsed: 3 hour(s), 59 minute(s), 32 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{deceaaa2-370a-49bb-9362-68c3a58ddc62} (Adware.180Solutions) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    New HijackThis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:51:44 PM, on 12/18/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\WINDOWS\system32\LxrSII1s.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\DOCUME~1\RICHAR~1\LOCALS~1\Temp\AutoDetect.exe
    C:\Documents and Settings\Richard Gongora\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\fxssvc.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\PROGRA~1\MICROS~2\rapimgr.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\WINDOWS\System32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\VE LXi Apprentice 7.5v5\Program\App2.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O1 - Hosts: 61.157.217.210 www.yahoo.com
    O1 - Hosts: 61.157.217.210 www.google.com
    O1 - Hosts: 61.157.217.210 www.google.co.uk
    O1 - Hosts: 61.157.217.210 www.myspace.com
    O1 - Hosts: 61.157.217.210 www.youtube.com
    O1 - Hosts: 61.157.217.210 www.facebook.com
    O1 - Hosts: 61.157.217.210 www.antispy.com
    O1 - Hosts: 61.157.217.210 www.yahoo.com
    O1 - Hosts: 61.157.217.210 www.yahoo.co.uk
    O1 - Hosts: 61.157.217.210 www.antispyware.com
    O1 - Hosts: 61.157.217.210 antispyware.com
    O1 - Hosts: 61.157.217.210 antispy.com
    O1 - Hosts: 61.157.217.210 www.msn.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.gg.com
    O1 - Hosts: 123.251.143.110 www.ghfhj.com
    O1 - Hosts: 123.251.143.110 www.cvnbcvnb.com
    O1 - Hosts: 123.251.143.110 www.1.com
    O1 - Hosts: 123.251.143.110 www.3.com
    O1 - Hosts: 123.251.143.110 www.asdf4asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfawsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfatsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfadsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfafsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfagsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasgdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdhfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfjd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfkd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfld.com
    O1 - Hosts: 123.251.143.110 www.asdfasdf,d.com
    O1 - Hosts: 123.251.143.110 www.asxdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdzfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdcfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfvasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfabsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasndfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdmfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.11asdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.as222dfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfa33sdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasd44fd.com
    O1 - Hosts: 123.251.143.110 www.asdfasdfd5.com
    O1 - Hosts: 123.251.143.110 www.as66dfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf77asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf8asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf9asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf0asdfd.com
    O1 - Hosts: 123.251.143.110 www.asdf-asdfd.com
    O1 - Hosts: 123.251.143.110 www.aqqsdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.aswwdfasdfd.com
    O1 - Hosts: 123.16.197.121 www.asdhhfasdfdyy.com
    O1 - Hosts: 61.157.217.210 www.live.com
    O1 - Hosts: 123.251.143.110 www.asdwwwfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfeasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfrrasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfttasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfyyasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfuuuasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfaiisdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfaoosdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfappsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfasssdfd.com
    O1 - Hosts: 123.251.143.110 www.aswwdfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdeefasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfffasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfavvvsdfd.com
    O1 - Hosts: 123.251.143.110 www.asnnndfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdmmmfasdfd.com
    O1 - Hosts: 123.251.143.110 www.asdfaffsdfd.com
    O1 - Hosts: 123.251.143.110 www.asdhhfasdfd.com
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [Ceedo AutoDetect] C:\DOCUME~1\RICHAR~1\LOCALS~1\Temp\AutoDetect.exe /active
    O4 - HKCU\..\Run: [LxrAutorun] C:\Documents and Settings\Richard Gongora\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [Ceedo Repair] C:\DOCUME~1\RICHAR~1\LOCALS~1\Temp\AutoDetect.exe /repair /drive=
    O4 - HKCU\..\RunOnce: [MPlayer2_FixUp] C:\WINDOWS\inf\unregmp2.exe /Fixups
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?Link...04&clcid=0x409
    O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/02d8ee6b...p/RdxIE601.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1150834424372
    O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents...1/imloader.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    --
    End of file - 14719 bytes

    Thank you for helping me.....What's next?

  4. #4
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi rrgongora,

    we will use hjt, but first disable spybots tea timer so it wont interfere. how?

    1. Run Spybot-S&D in Advanced Mode.
    2. If it is not already set to do this Go to the Mode menu select "Advanced Mode"
    3. On the left hand side, Click on Tools
    4. Then click on the Resident Icon in the List
    5. Uncheck "Resident TeaTimer" and OK any prompts.
    6. Restart your computer.

    next we will use hjt:

    start HJT, click the "Scan" button. check the items below, close any open windows, then click "Fixed checked"

    select ALL those 01 items in the hjt log:

    O1 - Hosts: 61.157.217.210 www.yahoo.com
    O1 - Hosts: 61.157.217.210 www.google.com
    O1 - Hosts: 61.157.217.210 www.google.co.uk
    ----------------------------
    we will get another download to use also. its called combofix. there is a guide you need to read before using it. it will explain all you need to know about getting it running. just follow the guide. after you run combofix please post the log.

    the guide:
    http://www.bleepingcomputer.com/comb...o-use-combofix
    How Can I Reduce My Risk?

  5. #5
    Junior Member
    Join Date
    Dec 2008
    Posts
    4

    Default New ComboFix Log

    I removed all the 01 items after the HJT scan.
    Placed Microsoft Bootdisk-ENU on top of ComboFix and let the scan run.
    Here is the log:

    ComboFix 08-12-18.03 - Richard Gongora 2008-12-19 10:59:39.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.592 [GMT -6:00]
    Running from: c:\documents and settings\Richard Gongora\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Richard Gongora\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    * Created a new restore point
    * Resident AV is active

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\INSTALL.LOG
    c:\windows\system32\tmp.reg

    .
    ((((((((((((((((((((((((( Files Created from 2008-11-19 to 2008-12-19 )))))))))))))))))))))))))))))))
    .

    2008-12-18 09:33 . 2008-12-18 09:33 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
    2008-12-18 09:33 . 2008-12-18 09:33 <DIR> d-------- c:\documents and settings\Richard Gongora\Application Data\Malwarebytes
    2008-12-18 09:33 . 2008-12-18 09:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-12-18 09:33 . 2008-12-03 19:52 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
    2008-12-18 09:33 . 2008-12-03 19:52 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
    2008-12-17 18:10 . 2008-12-17 18:10 <DIR> d-------- c:\program files\NBFree MP3 to WMA Converter
    2008-12-17 14:49 . 2008-12-17 14:49 <DIR> d-------- c:\program files\Windows Media Connect 2
    2008-12-17 14:46 . 2008-12-17 14:47 <DIR> d-------- c:\windows\SYSTEM32\DRIVERS\UMDF
    2008-12-16 15:27 . 2008-12-16 15:27 <DIR> d-------- c:\program files\Flash Player Mobile
    2008-12-16 15:26 . 2008-12-16 15:26 <DIR> d-------- c:\program files\Macromedia Flash Player ActiveX
    2008-12-16 10:52 . 2008-12-16 10:52 <DIR> d-------- c:\documents and settings\LocalService\Application Data\SACore
    2008-12-10 15:51 . 2008-12-10 17:25 <DIR> d-------- c:\documents and settings\Richard Gongora\.housecall6.6
    2008-12-10 15:40 . 2008-12-10 15:40 <DIR> d-------- c:\program files\Trend Micro
    2008-12-10 10:32 . 2008-12-10 10:32 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP
    2008-12-09 18:27 . 2008-12-09 18:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\SiteAdvisor
    2008-12-09 18:27 . 2008-12-19 09:46 9,705 --a------ c:\windows\SYSTEM32\Config.MPF
    2008-12-09 18:22 . 2007-11-22 06:44 201,320 --a------ c:\windows\SYSTEM32\DRIVERS\mfehidk.sys
    2008-12-09 18:22 . 2007-07-13 06:20 113,952 --a------ c:\windows\SYSTEM32\DRIVERS\Mpfp.sys
    2008-12-09 18:22 . 2007-11-22 06:44 79,304 --a------ c:\windows\SYSTEM32\DRIVERS\mfeavfk.sys
    2008-12-09 18:22 . 2007-12-02 12:51 40,488 --a------ c:\windows\SYSTEM32\DRIVERS\mfesmfk.sys
    2008-12-09 18:22 . 2007-11-22 06:44 35,240 --a------ c:\windows\SYSTEM32\DRIVERS\mfebopk.sys
    2008-12-09 18:22 . 2007-11-22 06:44 33,832 --a------ c:\windows\SYSTEM32\DRIVERS\mferkdk.sys
    2008-12-09 18:21 . 2008-12-09 18:22 <DIR> d-------- c:\program files\McAfee.com
    2008-12-09 18:21 . 2008-12-15 13:09 <DIR> d-------- c:\program files\McAfee
    2008-12-09 18:21 . 2008-12-09 18:22 <DIR> d-------- c:\program files\Common Files\McAfee
    2008-12-09 17:49 . 2008-12-09 17:49 <DIR> d-------- c:\program files\TeaTimer (Spybot - Search & Destroy)
    2008-12-09 17:49 . 2008-12-09 17:49 <DIR> d-------- c:\program files\SDHelper (Spybot - Search & Destroy)
    2008-12-09 14:02 . 2008-12-09 18:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\McAfee
    2008-11-19 14:59 . 2008-11-19 14:59 10,943 --a------ c:\windows\ATMREG.ATM
    2008-11-19 14:48 . 2008-11-19 14:48 <DIR> d-------- c:\documents and settings\Richard Gongora\Application Data\Jasc

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-10 21:26 --------- d-----w c:\program files\Spybot - Search & Destroy
    2008-12-10 21:15 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-12-10 16:32 --------- d-----w c:\program files\SpywareBlaster
    2008-12-09 23:38 --------- d-----w c:\program files\Yahoo!
    2008-11-25 21:28 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-11-12 17:19 --------- d-----w c:\documents and settings\Richard Gongora\Application Data\Yahoo!
    2008-11-11 22:43 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
    2008-11-11 20:26 --------- d-----w c:\program files\DivX
    2008-10-31 17:08 --------- d-----w c:\program files\Microsoft ActiveSync
    2008-10-28 22:36 823,296 ----a-w c:\windows\SYSTEM32\divx_xx0c.dll
    2008-10-28 22:36 823,296 ----a-w c:\windows\SYSTEM32\divx_xx07.dll
    2008-10-28 22:35 815,104 ----a-w c:\windows\SYSTEM32\divx_xx0a.dll
    2008-10-28 22:35 802,816 ----a-w c:\windows\SYSTEM32\divx_xx11.dll
    2008-10-28 22:35 684,032 ----a-w c:\windows\SYSTEM32\DivX.dll
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-24 11:21 455,296 ------w c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
    2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
    2008-10-23 12:36 286,720 ------w c:\windows\SYSTEM32\DLLCACHE\gdi32.dll
    2008-10-17 08:08 3,593,216 ----a-w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
    2008-10-16 20:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
    2008-10-16 20:13 202,776 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuweb.dll
    2008-10-16 20:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
    2008-10-16 20:13 1,809,944 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuaueng.dll
    2008-10-16 20:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
    2008-10-16 20:12 561,688 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuapi.dll
    2008-10-16 20:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
    2008-10-16 20:12 323,608 ----a-w c:\windows\SYSTEM32\DLLCACHE\wucltui.dll
    2008-10-16 20:09 92,696 ----a-w c:\windows\SYSTEM32\DLLCACHE\cdm.dll
    2008-10-16 20:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
    2008-10-16 20:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
    2008-10-16 20:09 51,224 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuauclt.exe
    2008-10-16 20:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
    2008-10-16 20:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
    2008-10-16 20:08 34,328 ----a-w c:\windows\SYSTEM32\DLLCACHE\wups.dll
    2008-10-16 20:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
    2008-10-16 20:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
    2008-10-16 13:11 70,656 ------w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
    2008-10-16 13:11 13,824 ------w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
    2008-10-15 16:34 337,408 ------w c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
    2008-10-15 07:06 633,632 ------w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
    2008-10-15 07:04 161,792 ------w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
    2008-10-03 10:02 247,326 ----a-w c:\windows\SYSTEM32\strmdll.dll
    2008-10-03 10:02 247,326 ------w c:\windows\SYSTEM32\DLLCACHE\strmdll.dll
    2008-09-30 22:43 1,286,152 ----a-w c:\windows\SYSTEM32\msxml4.dll
    2008-09-25 08:03 81,920 ----a-w c:\windows\SYSTEM32\dpl100.dll
    2008-09-25 08:03 593,920 ----a-w c:\windows\SYSTEM32\dpuGUI11.dll
    2008-09-25 08:03 57,344 ----a-w c:\windows\SYSTEM32\dpv11.dll
    2008-09-25 08:03 53,248 ----a-w c:\windows\SYSTEM32\dpuGUI10.dll
    2008-09-25 08:03 524,288 ----a-w c:\windows\SYSTEM32\DivXsm.exe
    2008-09-25 08:03 344,064 ----a-w c:\windows\SYSTEM32\dpus11.dll
    2008-09-25 08:03 294,912 ----a-w c:\windows\SYSTEM32\dpu11.dll
    2008-09-25 08:03 294,912 ----a-w c:\windows\SYSTEM32\dpu10.dll
    2008-09-25 08:03 196,608 ----a-w c:\windows\SYSTEM32\dtu100.dll
    2008-09-25 08:03 161,096 ----a-w c:\windows\SYSTEM32\DivXCodecVersionChecker.exe
    2008-09-19 21:57 3,596,288 ----a-w c:\windows\SYSTEM32\qt-dx331.dll
    2008-09-19 21:57 129,784 ------w c:\windows\SYSTEM32\pxafs.dll
    2008-09-19 21:57 120,056 ------w c:\windows\SYSTEM32\pxcpyi64.exe
    2008-09-19 21:57 118,520 ------w c:\windows\SYSTEM32\pxinsi64.exe
    2008-09-19 21:55 200,704 ----a-w c:\windows\SYSTEM32\ssldivx.dll
    2008-09-19 21:55 1,044,480 ----a-w c:\windows\SYSTEM32\libdivx.dll
    2008-09-19 21:54 12,288 ----a-w c:\windows\SYSTEM32\DivXWMPExtType.dll
    2006-06-14 20:02 25,600 ----a-w c:\documents and settings\Richard Gongora\usbsermptxp.sys
    2006-06-14 20:02 22,768 ----a-w c:\documents and settings\Richard Gongora\usbsermpt.sys
    2004-06-10 19:27 170 ---ha-w c:\documents and settings\Richard Gongora\hpothb07.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
    "LxrAutorun"="c:\documents and settings\Richard Gongora\Local Settings\Application Data\Lexar Media\LxrAutorun.exe" [2006-11-09 24576]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
    "IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
    "dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-06-22 98304]
    "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
    "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2007-11-30 1164576]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 c:\windows\SYSTEM32\bthprops.cpl]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 147456]
    hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2004-06-10 28672]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.mi-sc4"= mi-sc4.acm
    "SENTINEL"= snti386.dll

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
    backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
    backup=c:\windows\pss\Kodak software updater.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
    --a------ 2003-07-14 13:30 98304 c:\program files\SBC Yahoo!\Connection Manager\IP Insight\ipmon32.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
    --a------ 2003-10-06 09:05 53248 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --a------ 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
    --------- 2003-08-26 18:47 204800 c:\program files\Dell\Media Experience\PCMService.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2006-06-22 13:09 98304 c:\program files\QuickTime\qttask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
    --a------ 2003-02-13 00:01 155648 c:\program files\Common Files\Sonic\Update Manager\sgtray.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    --a------ 2006-10-26 21:21 4662776 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
    --a------ 2006-07-21 16:19 129536 c:\progra~1\Yahoo!\browser\ybrwicon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
    --a------ 2008-04-13 18:12 110592 c:\windows\SYSTEM32\bthprops.cpl

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "FirewallDisableNotify"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\PROGRA~1\\Yahoo!\\MESSEN~1\\yserver.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
    "c:\\Program Files\\VE LXi Apprentice 7.5v5\\Program\\App.exe"=
    "c:\\Program Files\\VE LXi Apprentice 7.5v5\\Program\\App2.exe"=
    "c:\\Program Files\\Common Files\\ABC 13 E-lert\\TrueWeather.exe"=
    "c:\\Program Files\\Yahoo!\\browser\\ybrowser.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
    "1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
    "500:UDP"= 500:UDP:@xpsp2res.dll,-22017
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMhelpr.sys [2004-10-19 4064]
    R2 LxrSII1d;Secure II Driver;\??\c:\windows\system32\Drivers\LxrSII1d.sys [2007-05-25 72672]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-12-09 203280]
    S3 MDMH2USB;I-O DATA MDM-H2/USB Driver;c:\windows\system32\Drivers\MDMH2USB.sys [2005-03-11 14848]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1413b3c1-64c3-11dd-891b-0015e966a6b1}]
    \Shell\AutoRun\command - f:\windows\IronKey.exe

    *Newly Created Service* - PROCEXP90
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-15 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

    2008-12-10 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

    2008-12-19 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
    - c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-07-07 09:42]
    .
    - - - - ORPHANS REMOVED - - - -

    MSConfigStartUp-Vinade Reminder - c:\program files\Vinade\Reminder\Reminder.exe
    MSConfigStartUp-YOP - c:\progra~1\Yahoo!\YOP\yop.exe


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://att.yahoo.com
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    mDefault_Page_URL = hxxp://att.yahoo.com
    mDefault_Search_URL = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    mSearch Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
    mStart Page = hxxp://att.yahoo.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    TCP: {6844D58D-02C6-4074-A860-6E5989CB4B2A} = 209.244.0.3 209.244.0.4
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-19 11:02:29
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2008-12-19 11:04:55
    ComboFix-quarantined-files.txt 2008-12-19 17:04:02

    Pre-Run: 32,368,222,208 bytes free
    Post-Run: 32,454,283,264 bytes free

    242 --- E O F --- 2008-12-18 20:15:27


    Thanks again for all your help.

  6. #6
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi,

    ok good thanks for the info. dosnt look bad at all as far as malware goes. got worried when i saw all these instances of IE running:


    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe

    can you rescan and post a new hjt log.
    How Can I Reduce My Risk?

  7. #7
    Junior Member
    Join Date
    Dec 2008
    Posts
    4

    Default Here is the New HJT log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 9:36:27 AM, on 12/22/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\WINDOWS\system32\LxrSII1s.exe
    C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Documents and Settings\Richard Gongora\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\WINDOWS\system32\fxssvc.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\PROGRA~1\MICROS~2\rapimgr.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\WINDOWS\System32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\SearchSuggest\YSearchSuggest.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [LxrAutorun] C:\Documents and Settings\Richard Gongora\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
    O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?Link...04&clcid=0x409
    O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper20073151.dll
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1150834424372
    O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents...1/imloader.cab
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

    --
    End of file - 9797 bytes

    Thank you for your patience

  8. #8
    Emeritus
    Join Date
    Nov 2005
    Location
    @localhost
    Posts
    6,066

    Default

    hi,

    got worried when i saw all these instances of IE running:

    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    never mind about that, thats not IE or internet explorer. its windows GUI.

    if all looks good on your end; you can remove combofix like this:
    start>run and type in:
    combofix /u
    click ok or enter
    note: there is a space after the x and before the /

    some info for you:

    Reducing Your Risk:
    The Short Version

    1) Keep your OS,(Windows) browser (IE, FireFox) and other Software up to date to "patch" vulnerabilities.
    2) Know what you are installing to your computer. Alot of software can come bundled with unwanted add-ons.
    3) Install and keep them all updated: one antivirus and two or three anti-malware applications. If not updated they will soon be worthless.
    4) Refrain from clicking on links or attachments you receive via E-Mail, IM, Chat Rooms or Social Sites, no matter how tempting or legitimate the message.
    5) Don't click on ads/pop ups or offers from websites requesting that you install software to your computer.
    6) Don't click on offers to "scan" your computer.
    7) Set up and use limited accounts for everyday use, rather than administrator accounts.
    8) Install a third party software firewall.
    9) Consider using an alternate browser and E-mail client.
    10) If your habits include: warez, cracks etc or p2p file sharing then you are much more likely to encounter malicious code. Do you trust the source?

    longer version in link below.
    happy safe surfing out there
    How Can I Reduce My Risk?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •