celluloidheros
New member
Hello, I made the mistake of downloading a file using Bittorrent since then, my computer has been doing 4-5 odd things and is very slow. i read the Sticky's and RAN SB 1.4 in Safe Mode, Ran Panda, Vundo.fix, Smitfraudfix, It seemed to help some but i still have some issues.
Here is the Active Scan report
Incident Status Location
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\SYSTEM32\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\Mozilla Firefox\SmitfraudFix\Process.exe
Spyware:Spyware/Vundo Not disinfected C:\VundoFix Backups\sqqugtfj.dll.bad
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Don Crandall\Local Settings\Temp\bisA.exe
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Don Crandall\Cookies\don crandall@hitbox[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Don Crandall\Cookies\don crandall@stats1.reliablestats[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Don Crandall\Cookies\don crandall@advertising[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[.dist.belnk.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[.belnk.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[ad.yieldmanager.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[www.systemdoctor.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[stats1.reliablestats.com/]
2,3) I rand SB 1.4 in SAFE Mode and it removed 10 or so items.
4) Hijack This Log file
Logfile of HijackThis v1.99.1
Scan saved at 7:20:12 AM, on 4/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\msngr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HJK ThiS\HijkThis.exe
O2 - BHO: (no name) - {058DB58B-1A37-44F6-8910-04332FECADCB} - C:\WINDOWS\system32\vtuvsqr.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\sqqugtfj.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: (no name) - {AC2E0F4E-6D3F-4896-9B47-B16E08BC260D} - C:\WINDOWS\system32\vtsqr.dll
O2 - BHO: (no name) - {DB79A386-1ADF-4218-BDE6-25DD2CA739B4} - C:\WINDOWS\system32\gebca.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [%%DELETE_VALUE%%] CreateCD50
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: vtsqr - C:\WINDOWS\system32\vtsqr.dll
O20 - Winlogon Notify: vtuvsqr - C:\WINDOWS\SYSTEM32\vtuvsqr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Windows Server Management Services (WSMSPSVC) - Unknown owner - C:\WINDOWS\msngr.exe
5) Here is the Smitfraud log
SmitFraudFix v2.162
Scan done at 19:48:44.04, Sun 04/01/2007
Run from C:\Documents and Settings\Don Crandall\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» DNS Before Fix
Description: SiS 900 PCI Fast Ethernet Adapter
DNS Server Search Order: 24.92.226.9
DNS Server Search Order: 24.92.226.102
HKLM\SYSTEM\CCS\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS1\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS2\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
»»»»»»»»»»»»»»»»»»»»»»»» DNS After Fix
Description: SiS 900 PCI Fast Ethernet Adapter
DNS Server Search Order: 24.92.226.9
DNS Server Search Order: 24.92.226.102
HKLM\SYSTEM\CCS\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS1\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS2\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
6)
Here is the Vundofix log, The VUNDO fix seemed to do more than anything.
VundoFix V6.3.18
Checking Java version...
Java version is 1.5.0.11
Scan started at 12:06:49 PM 4/1/2007
Listing files found while scanning....
C:\WINDOWS\SYSTEM32\acbeg.bak1
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\acbeg.tmp
C:\WINDOWS\SYSTEM32\byxyyvw.dll
C:\WINDOWS\SYSTEM32\cbxxwxx.dll
C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\SYSTEM32\gebxywv.dll
C:\WINDOWS\SYSTEM32\khffgfd.dll
C:\WINDOWS\SYSTEM32\ljjjhfd.dll
C:\WINDOWS\SYSTEM32\ljjkiii.dll
C:\WINDOWS\SYSTEM32\sqqugtfj.dll
C:\WINDOWS\SYSTEM32\ssqrqon.dll
C:\WINDOWS\SYSTEM32\wvuusqq.dll
C:\WINDOWS\SYSTEM32\xxyxvvv.dll
C:\WINDOWS\SYSTEM32\yayyyvw.dll
Beginning removal...
Attempting to delete C:\WINDOWS\SYSTEM32\acbeg.bak1
C:\WINDOWS\SYSTEM32\acbeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\acbeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\acbeg.tmp
C:\WINDOWS\system32\acbeg.tmp Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\byxyyvw.dll
C:\WINDOWS\SYSTEM32\byxyyvw.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\cbxxwxx.dll
C:\WINDOWS\SYSTEM32\cbxxwxx.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\gebca.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\gebxywv.dll
C:\WINDOWS\SYSTEM32\gebxywv.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\khffgfd.dll
C:\WINDOWS\SYSTEM32\khffgfd.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\ljjjhfd.dll
C:\WINDOWS\SYSTEM32\ljjjhfd.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\ljjkiii.dll
C:\WINDOWS\SYSTEM32\ljjkiii.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\sqqugtfj.dll
C:\WINDOWS\SYSTEM32\sqqugtfj.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\ssqrqon.dll
C:\WINDOWS\SYSTEM32\ssqrqon.dll Could not be deleted.
Attempting to delete C:\WINDOWS\SYSTEM32\wvuusqq.dll
C:\WINDOWS\SYSTEM32\wvuusqq.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\xxyxvvv.dll
C:\WINDOWS\SYSTEM32\xxyxvvv.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\yayyyvw.dll
C:\WINDOWS\SYSTEM32\yayyyvw.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\SYSTEM32\ssqrqon.dll
C:\WINDOWS\SYSTEM32\ssqrqon.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
VundoFix V6.3.18
Checking Java version...
Java version is 1.5.0.11
Scan started at 8:02:31 PM 4/1/2007
Listing files found while scanning....
No infected files were found.
7) I am getting a RUNDLL Error that says Error loading A(with a little line on top) Y (with 2 dots on top) and then a square symbol so it says "error loading "aysquare"
8) I am getting a Themida pop-up that says a program is protected with this and can only be open for 20 minutes.
9) The CID Pop-ups seem to have stopped but other IE6 Popups are still happening.
Thanks in advance for all of your help. Celluloidheros
Here is the Active Scan report
Incident Status Location
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\SYSTEM32\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\Mozilla Firefox\SmitfraudFix\Process.exe
Spyware:Spyware/Vundo Not disinfected C:\VundoFix Backups\sqqugtfj.dll.bad
Adware:Adware/Lop Not disinfected C:\Documents and Settings\Don Crandall\Local Settings\Temp\bisA.exe
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Don Crandall\Cookies\don crandall@hitbox[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Don Crandall\Cookies\don crandall@stats1.reliablestats[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Don Crandall\Cookies\don crandall@advertising[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[.dist.belnk.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[.belnk.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[ad.yieldmanager.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[.systemdoctor.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[www.systemdoctor.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Don Crandall\Application Data\Mozilla\Firefox\Profiles\oah2x1ml.default\COOKIES.TXT[stats1.reliablestats.com/]
2,3) I rand SB 1.4 in SAFE Mode and it removed 10 or so items.
4) Hijack This Log file
Logfile of HijackThis v1.99.1
Scan saved at 7:20:12 AM, on 4/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\msngr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HJK ThiS\HijkThis.exe
O2 - BHO: (no name) - {058DB58B-1A37-44F6-8910-04332FECADCB} - C:\WINDOWS\system32\vtuvsqr.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\sqqugtfj.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: (no name) - {AC2E0F4E-6D3F-4896-9B47-B16E08BC260D} - C:\WINDOWS\system32\vtsqr.dll
O2 - BHO: (no name) - {DB79A386-1ADF-4218-BDE6-25DD2CA739B4} - C:\WINDOWS\system32\gebca.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [%%DELETE_VALUE%%] CreateCD50
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\NEROPH~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: vtsqr - C:\WINDOWS\system32\vtsqr.dll
O20 - Winlogon Notify: vtuvsqr - C:\WINDOWS\SYSTEM32\vtuvsqr.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Windows Server Management Services (WSMSPSVC) - Unknown owner - C:\WINDOWS\msngr.exe
5) Here is the Smitfraud log
SmitFraudFix v2.162
Scan done at 19:48:44.04, Sun 04/01/2007
Run from C:\Documents and Settings\Don Crandall\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» DNS Before Fix
Description: SiS 900 PCI Fast Ethernet Adapter
DNS Server Search Order: 24.92.226.9
DNS Server Search Order: 24.92.226.102
HKLM\SYSTEM\CCS\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS1\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS2\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
»»»»»»»»»»»»»»»»»»»»»»»» DNS After Fix
Description: SiS 900 PCI Fast Ethernet Adapter
DNS Server Search Order: 24.92.226.9
DNS Server Search Order: 24.92.226.102
HKLM\SYSTEM\CCS\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS1\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS2\Services\Tcpip\..\{BDA00FD2-2DFE-4B7C-ACFE-BA9A465FED7F}: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=24.92.226.9 24.92.226.102
6)
Here is the Vundofix log, The VUNDO fix seemed to do more than anything.
VundoFix V6.3.18
Checking Java version...
Java version is 1.5.0.11
Scan started at 12:06:49 PM 4/1/2007
Listing files found while scanning....
C:\WINDOWS\SYSTEM32\acbeg.bak1
C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\acbeg.tmp
C:\WINDOWS\SYSTEM32\byxyyvw.dll
C:\WINDOWS\SYSTEM32\cbxxwxx.dll
C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\SYSTEM32\gebxywv.dll
C:\WINDOWS\SYSTEM32\khffgfd.dll
C:\WINDOWS\SYSTEM32\ljjjhfd.dll
C:\WINDOWS\SYSTEM32\ljjkiii.dll
C:\WINDOWS\SYSTEM32\sqqugtfj.dll
C:\WINDOWS\SYSTEM32\ssqrqon.dll
C:\WINDOWS\SYSTEM32\wvuusqq.dll
C:\WINDOWS\SYSTEM32\xxyxvvv.dll
C:\WINDOWS\SYSTEM32\yayyyvw.dll
Beginning removal...
Attempting to delete C:\WINDOWS\SYSTEM32\acbeg.bak1
C:\WINDOWS\SYSTEM32\acbeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\acbeg.ini
C:\WINDOWS\system32\acbeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\acbeg.ini2
C:\WINDOWS\system32\acbeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\acbeg.tmp
C:\WINDOWS\system32\acbeg.tmp Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\byxyyvw.dll
C:\WINDOWS\SYSTEM32\byxyyvw.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\cbxxwxx.dll
C:\WINDOWS\SYSTEM32\cbxxwxx.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\gebca.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\gebxywv.dll
C:\WINDOWS\SYSTEM32\gebxywv.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\khffgfd.dll
C:\WINDOWS\SYSTEM32\khffgfd.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\ljjjhfd.dll
C:\WINDOWS\SYSTEM32\ljjjhfd.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\ljjkiii.dll
C:\WINDOWS\SYSTEM32\ljjkiii.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\sqqugtfj.dll
C:\WINDOWS\SYSTEM32\sqqugtfj.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\ssqrqon.dll
C:\WINDOWS\SYSTEM32\ssqrqon.dll Could not be deleted.
Attempting to delete C:\WINDOWS\SYSTEM32\wvuusqq.dll
C:\WINDOWS\SYSTEM32\wvuusqq.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\xxyxvvv.dll
C:\WINDOWS\SYSTEM32\xxyxvvv.dll Has been deleted!
Attempting to delete C:\WINDOWS\SYSTEM32\yayyyvw.dll
C:\WINDOWS\SYSTEM32\yayyyvw.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\SYSTEM32\ssqrqon.dll
C:\WINDOWS\SYSTEM32\ssqrqon.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
VundoFix V6.3.18
Checking Java version...
Java version is 1.5.0.11
Scan started at 8:02:31 PM 4/1/2007
Listing files found while scanning....
No infected files were found.
7) I am getting a RUNDLL Error that says Error loading A(with a little line on top) Y (with 2 dots on top) and then a square symbol so it says "error loading "aysquare"
8) I am getting a Themida pop-up that says a program is protected with this and can only be open for 20 minutes.
9) The CID Pop-ups seem to have stopped but other IE6 Popups are still happening.
Thanks in advance for all of your help. Celluloidheros