Unsolved

This post is more than 5 years old

1 Rookie

 • 

16 Posts

2082

October 18th, 2007 02:00

Blue Screen and unidentifiable driver??


I continue to get the blue screen daily. The Technical information denotes the STOP Message:
0x0000007E (0XC0000005, 0XF752A7EF, 0XF7ACB38, 0XF7ACB934)
(not sure if this changes each time)

AND THE FOLLOWING:

AYXS97.SYS Address F752A7EF base at F7519000, DateStamp 469f344b

I have tried the Dell Driver Reset tool, I have searched the internet for this file name, and I have searched my PC for the file name...I cannot find anything anywhere. I did do a search in REGEDIT, it found it in about 18 places.  I have a screen shot if you need to see it. Any help would be greatly appreciated. Thanks.
 
I have a Dell Dimension XPS 410, and am running Windows XP Media Center Edition 2002 version Service Pack 2 (Build 2600.xpsp_sp2_qfe.070227-2300)
 
HERE IS MY HIJACK THIS LOG
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:16:02 PM, on 10/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Cursors\aolupd.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\RioMSC.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\xxngsjheowt.exe
C:\WINDOWS\system32\plugnplay.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2060909
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2060909
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [rxmuvgsc] C:\WINDOWS\system32\rxmuvgsc.exe
O4 - HKLM\..\Run: [imy] C:\WINDOWS\system32\imy.exe
O4 - HKLM\..\Run: [unmb] C:\WINDOWS\system32\unmb.exe
O4 - HKLM\..\Run: [tokqwqjgri] C:\WINDOWS\system32\tokqwqjgri.exe
O4 - HKLM\..\Run: [reqkrsutfoch] C:\WINDOWS\system32\reqkrsutfoch.exe
O4 - HKLM\..\Run: [id] C:\WINDOWS\system32\id.exe
O4 - HKLM\..\Run: [nw] C:\WINDOWS\system32\nw.exe
O4 - HKLM\..\Run: [nuzrwce] C:\WINDOWS\system32\nuzrwce.exe
O4 - HKLM\..\Run: [ypcqkdvmhhq] C:\WINDOWS\system32\ypcqkdvmhhq.exe
O4 - HKLM\..\Run: [nrcrpol] C:\WINDOWS\system32\nrcrpol.exe
O4 - HKLM\..\Run: [ovx] C:\WINDOWS\system32\ovx.exe
O4 - HKLM\..\Run: C:\WINDOWS\system32\l.exe
O4 - HKLM\..\Run: [gcxhfvainrde] C:\WINDOWS\system32\gcxhfvainrde.exe
O4 - HKLM\..\Run: [frhctggywohn] C:\WINDOWS\system32\frhctggywohn.exe
O4 - HKLM\..\Run: [jigmnbpumeer] C:\WINDOWS\system32\jigmnbpumeer.exe
O4 - HKLM\..\Run: [bhbpbrp] C:\WINDOWS\system32\bhbpbrp.exe
O4 - HKLM\..\Run: [fx] C:\WINDOWS\system32\fx.exe
O4 - HKLM\..\Run: [xxngsjheowt] C:\WINDOWS\system32\xxngsjheowt.exe
O4 - HKLM\..\Run: [enlsbgmanrkt] C:\WINDOWS\system32\enlsbgmanrkt.exe
O4 - HKLM\..\Run: [tdlbn] C:\WINDOWS\system32\tdlbn.exe
O4 - HKLM\..\Run: [qxrwn] C:\WINDOWS\system32\qxrwn.exe
O4 - HKLM\..\Run: [dtp] C:\WINDOWS\system32\dtp.exe
O4 - HKLM\..\Run: [ivvchkhtxl] C:\WINDOWS\system32\ivvchkhtxl.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: C:\WINDOWS\system32\u.exe
O4 - HKLM\..\Run: [Configure Plug n Play Devices] plugnplay.exe
O4 - HKLM\..\Run: [eclvnkmok] C:\WINDOWS\system32\eclvnkmok.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax4507.cab
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///D:/CDVIEWER/CdViewer.cab
O23 - Service: AOL Smart Update Service (AOL_Real-Time_UPD) - Unknown owner - C:\WINDOWS\Cursors\aolupd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: dlcc_device -   - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Print Spooler Service (ytuahb7e6ai94yo) - Unknown owner - C:\WINDOWS\system32\y.exe
--
End of file - 9469 bytes

10.4K Posts

October 18th, 2007 13:00

TMcJury

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :


  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.


  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log











Microsoft MVP Windows-Security



"The world is what you make of it"




1 Rookie

 • 

16 Posts

October 18th, 2007 23:00

HIJACK THIS LOG
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:03:02 PM, on 10/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Cursors\aolupd.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\RioMSC.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\repair\smrs.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\xxngsjheowt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\WINDOWS\system32\plugnplay.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2060909
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2060909
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [rxmuvgsc] C:\WINDOWS\system32\rxmuvgsc.exe
O4 - HKLM\..\Run: [imy] C:\WINDOWS\system32\imy.exe
O4 - HKLM\..\Run: [unmb] C:\WINDOWS\system32\unmb.exe
O4 - HKLM\..\Run: [reqkrsutfoch] C:\WINDOWS\system32\reqkrsutfoch.exe
O4 - HKLM\..\Run: [id] C:\WINDOWS\system32\id.exe
O4 - HKLM\..\Run: [nw] C:\WINDOWS\system32\nw.exe
O4 - HKLM\..\Run: [nuzrwce] C:\WINDOWS\system32\nuzrwce.exe
O4 - HKLM\..\Run: [ypcqkdvmhhq] C:\WINDOWS\system32\ypcqkdvmhhq.exe
O4 - HKLM\..\Run: [nrcrpol] C:\WINDOWS\system32\nrcrpol.exe
O4 - HKLM\..\Run: [ovx] C:\WINDOWS\system32\ovx.exe
O4 - HKLM\..\Run: C:\WINDOWS\system32\l.exe
O4 - HKLM\..\Run: [gcxhfvainrde] C:\WINDOWS\system32\gcxhfvainrde.exe
O4 - HKLM\..\Run: [frhctggywohn] C:\WINDOWS\system32\frhctggywohn.exe
O4 - HKLM\..\Run: [jigmnbpumeer] C:\WINDOWS\system32\jigmnbpumeer.exe
O4 - HKLM\..\Run: [bhbpbrp] C:\WINDOWS\system32\bhbpbrp.exe
O4 - HKLM\..\Run: [fx] C:\WINDOWS\system32\fx.exe
O4 - HKLM\..\Run: [xxngsjheowt] C:\WINDOWS\system32\xxngsjheowt.exe
O4 - HKLM\..\Run: [enlsbgmanrkt] C:\WINDOWS\system32\enlsbgmanrkt.exe
O4 - HKLM\..\Run: [tdlbn] C:\WINDOWS\system32\tdlbn.exe
O4 - HKLM\..\Run: [qxrwn] C:\WINDOWS\system32\qxrwn.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Configure Plug n Play Devices] plugnplay.exe
O4 - HKLM\..\RunServices: [xxngsjheowt] C:\WINDOWS\system32\xxngsjheowt.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax4507.cab
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///D:/CDVIEWER/CdViewer.cab
O23 - Service: AOL Smart Update Service (AOL_Real-Time_UPD) - Unknown owner - C:\WINDOWS\Cursors\aolupd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: dlcc_device -   - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: Smart Media Serviecs (Sys_SM-Service) - Unknown owner - C:\WINDOWS\repair\smrs.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Print Spooler Service (ytuahb7e6ai94yo) - Unknown owner - C:\WINDOWS\system32\cyiuuhkohz.exe
--
End of file - 9336 bytes

1 Rookie

 • 

16 Posts

October 18th, 2007 23:00

SDFix Log

SDFix: Version 1.109
Run by Tom McJury on Thu 10/18/2007 at 06:39 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
ytuahb7e6ai94yo
ImagePath:
C:\WINDOWS\system32\w.exe /service
ytuahb7e6ai94yo - Deleted
 
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...

Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\TOKQWQ~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\AZRBL.EXE - Deleted
C:\WINDOWS\SYSTEM32\DNHNRR~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\DTP.EXE - Deleted
C:\WINDOWS\SYSTEM32\ECLVNK~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\FSZCA.EXE - Deleted
C:\WINDOWS\SYSTEM32\GHHVUS~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\GRSE.EXE - Deleted
C:\WINDOWS\SYSTEM32\IVVCHK~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\JQUWES~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\ODVKF.EXE - Deleted
C:\WINDOWS\SYSTEM32\SISI.EXE - Deleted
C:\WINDOWS\SYSTEM32\TPSIC.EXE - Deleted
C:\WINDOWS\SYSTEM32\U.EXE - Deleted
C:\WINDOWS\SYSTEM32\W.EXE - Deleted
C:\WINDOWS\SYSTEM32\Y.EXE - Deleted
C:\10.TMP - Deleted
C:\12.TMP - Deleted
C:\13.TMP - Deleted
C:\14.TMP - Deleted
C:\WINDOWS\system32\u.exe  - Deleted
C:\WINDOWS\system32\w.exe  - Deleted
 
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
 
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
 

                                 Final Check:
Remaining Services:
------------------
 
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\WINDOWS\\ehome\\ehshell.exe"="C:\\WINDOWS\\ehome\\ehshell.exe:LocalSubNet:Enabled:Media Center"
"C:\\Program Files\\Common Files\\Sonic Shared\\Sonic Central\\Main\\Mediahub.exe"="C:\\Program Files\\Common Files\\Sonic Shared\\Sonic Central\\Main\\Mediahub.exe:*:Enabled:Creator Home"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\WINDOWS\\system32\\dlcccoms.exe"="C:\\WINDOWS\\system32\\dlcccoms.exe:*:Enabled:Dell 924 Server"
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE:*:Enabled:Dell 924 Printer Status"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
---------------
catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-18 18:46:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden files ...
C:\WINDOWS\system32\drivers\Ayxs97.sys
scan completed successfully
hidden files: 1

File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed  3 Oct 2007     5,903,928 ...H. --- "C:\Program Files\Picasa2\setup.exe"
Thu 18 Oct 2007        87,552 ..SHR --- "C:\WINDOWS\repair\smrs.exe"
Wed 17 Oct 2007        56,832 ..SHR --- "C:\WINDOWS\system32\plugnplay.exe"
Sun  7 Nov 2004         4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.key.bak"
Mon 14 May 2007        19,456 ...H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\My Documents\~WRL0633.tmp"
Thu 21 Sep 2006        22,076 ..SH. --- "C:\Documents and Settings\Thomas McJury\License Backup\drmv2key.bak"
Thu 21 Sep 2006        22,076 ..SH. --- "C:\Documents and Settings\Tom McJury\License Backup\drmv2key.bak"
Sun  7 Nov 2004         4,348 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\License Backup\drmv1key.bak"
Wed 22 Nov 2006            20 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\License Backup\drmv1lic.bak"
Sun  7 Nov 2004           488 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\License Backup\drmv2key.bak"
Mon  6 Nov 2006        22,076 ..SH. --- "C:\Documents and Settings\Tom McJury.DD640RB1\My Documents\drmv2key.bak"
Wed 27 Dec 2006        23,903 ..SH. --- "C:\My Music\downloads\License Backup\drmv2key.bak"
Thu 21 Sep 2006        20,252 ..SH. --- "C:\Documents and Settings\All Users\Documents\My Music\drmv2key.bak"
Mon  8 Jan 2007             0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Thu 22 Feb 2007       362,264 A..H. --- "C:\Documents and Settings\Connor McJury\Local Settings\Temp\AutoDetect.exe"
Thu 22 Feb 2007       362,264 A..H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\Local Settings\Temp\AutoDetect.exe"
Mon  6 Nov 2006        22,076 ..SH. --- "C:\Documents and Settings\Tom McJury.DD640RB1\Desktop\Licenses\drmv2key.bak"
Mon  2 Oct 2006        50,280 ...H. --- "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"
Wed 27 Dec 2006        23,903 A.SH. --- "C:\Documents and Settings\All Users\Documents\McJury Shared Documents\My Music\drmv2key.bak"
Mon  3 Sep 2007        19,456 ...H. --- "C:\Documents and Settings\Connor McJury\Application Data\Microsoft\Word\~WRL0003.tmp"
Mon 18 Sep 2006        11,115 ..SH. --- "C:\Documents and Settings\Kyle McJury\My Documents\My Music\License Backup\drmv2key.bak"
Mon 14 May 2007        19,456 ...H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\Application Data\Microsoft\Word\~WRL2261.tmp"
Mon  6 Nov 2006        22,076 ..SH. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\My Documents\My Music\License Backup\drmv2key.bak"
Sun 21 Jan 2007        19,456 ...H. --- "C:\Documents and Settings\Lori McJury.DD640RB1\Application Data\Microsoft\Word\~WRL0004.tmp"
Sun 21 Jan 2007        19,456 ...H. --- "C:\Documents and Settings\Lori McJury.DD640RB1\Application Data\Microsoft\Word\~WRL3438.tmp"
Mon 19 Mar 2007        24,576 ...H. --- "C:\Documents and Settings\Moira McJury\Application Data\Microsoft\Word\~WRL0005.tmp"
Sun  7 Nov 2004         4,348 ...H. --- "C:\Documents and Settings\Moira McJury\Desktop\dad\License Backup\drmv1key.bak"
Mon  9 Oct 2006            20 ...H. --- "C:\Documents and Settings\Moira McJury\Desktop\dad\License Backup\drmv1lic.bak"
Sun  7 Nov 2004           488 ..SH. --- "C:\Documents and Settings\Moira McJury\Desktop\dad\License Backup\drmv2key.bak"
Thu 18 Oct 2007         5,946 A.SH. --- "C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE1.tmp"
Wed 27 Dec 2006        23,903 ..SH. --- "C:\Documents and Settings\Moira McJury\Desktop\My Pictures\My Music\License Backup\drmv2key.bak"
Wed 27 Dec 2006        23,903 ..SH. --- "C:\Documents and Settings\Moira McJury\My Documents\My Pictures\My Music\License Backup\drmv2key.bak"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch6\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Connor McJury\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Connor McJury\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Lori McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Lori McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Moira McJury\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Moira McJury\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Finished!
 
 
HAVE TO POST HIJACK THIS LOG SEPERATELY!!!  TOO MANY CHARACTERS>

10.4K Posts

October 19th, 2007 12:00


TMcJury

1. Please download the Killbox.
  • 1)Save it to the desktop
    2) Rt Click->>Extract all->.Extract it to your Desktop
    3) Double Click Killbox.exe to run it
    4)Select " Delete on Reboot", and then select "All files".
    5) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

    • C:\WINDOWS\repair\smrs.exe
      C:\WINDOWS\system32\xxngsjheowt.exe
      C:\Program Files\BAE\BAE.dll
      C:\Program Files\BAE
      C:\WINDOWS\system32\rxmuvgsc.exe
      C:\WINDOWS\system32\imy.exe
      C:\WINDOWS\system32\unmb.exe
      C:\WINDOWS\system32\reqkrsutfoch.exe
      C:\WINDOWS\system32\id.exe
      C:\WINDOWS\system32\nw.exe
      C:\WINDOWS\system32\nuzrwce.exe
      C:\WINDOWS\system32\ypcqkdvmhhq.exe
      C:\WINDOWS\system32\nrcrpol.exe
      C:\WINDOWS\system32\ovx.exe
      C:\WINDOWS\system32\l.exe
      C:\WINDOWS\system32\gcxhfvainrde.exe
      C:\WINDOWS\system32\frhctggywohn.exe
      C:\WINDOWS\system32\jigmnbpumeer.exe
      C:\WINDOWS\system32\bhbpbrp.exe
      C:\WINDOWS\system32\fx.exe
      C:\WINDOWS\system32\xxngsjheowt.exe
      C:\WINDOWS\system32\enlsbgmanrkt.exe
      C:\WINDOWS\system32\tdlbn.exe
      C:\WINDOWS\system32\qxrwn.exe
      C:\WINDOWS\system32\cyiuuhkohz.exe


























    6) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
    7) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.








2. Rerun Hijackthis (scan only) and place checks beside the following entries
  • O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O4 - HKLM\..\Run: [rxmuvgsc] C:\WINDOWS\system32\rxmuvgsc.exe
    O4 - HKLM\..\Run: [imy] C:\WINDOWS\system32\imy.exe
    O4 - HKLM\..\Run: [unmb] C:\WINDOWS\system32\unmb.exe
    O4 - HKLM\..\Run: [reqkrsutfoch] C:\WINDOWS\system32\reqkrsutfoch.exe
    O4 - HKLM\..\Run: [id] C:\WINDOWS\system32\id.exe
    O4 - HKLM\..\Run: [nw] C:\WINDOWS\system32\nw.exe
    O4 - HKLM\..\Run: [nuzrwce] C:\WINDOWS\system32\nuzrwce.exe
    O4 - HKLM\..\Run: [ypcqkdvmhhq] C:\WINDOWS\system32\ypcqkdvmhhq.exe
    O4 - HKLM\..\Run: [nrcrpol] C:\WINDOWS\system32\nrcrpol.exe
    O4 - HKLM\..\Run: [ovx] C:\WINDOWS\system32\ovx.exe
    O4 - HKLM\..\Run: C:\WINDOWS\system32\l.exe
    O4 - HKLM\..\Run: [gcxhfvainrde] C:\WINDOWS\system32\gcxhfvainrde.exe
    O4 - HKLM\..\Run: [frhctggywohn] C:\WINDOWS\system32\frhctggywohn.exe
    O4 - HKLM\..\Run: [jigmnbpumeer] C:\WINDOWS\system32\jigmnbpumeer.exe
    O4 - HKLM\..\Run: [bhbpbrp] C:\WINDOWS\system32\bhbpbrp.exe
    O4 - HKLM\..\Run: [fx] C:\WINDOWS\system32\fx.exe
    O4 - HKLM\..\Run: [xxngsjheowt] C:\WINDOWS\system32\xxngsjheowt.exe
    O4 - HKLM\..\Run: [enlsbgmanrkt] C:\WINDOWS\system32\enlsbgmanrkt.exe
    O4 - HKLM\..\Run: [tdlbn] C:\WINDOWS\system32\tdlbn.exe
    O4 - HKLM\..\Run: [qxrwn] C:\WINDOWS\system32\qxrwn.exe
    O4 - HKLM\..\RunServices: [xxngsjheowt] C:\WINDOWS\system32\xxngsjheowt.exe





















Close all other open windows except Hijackthis and Select " Fix checked"

Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log











Microsoft MVP Windows-Security



"The world is what you make of it"





1 Rookie

 • 

16 Posts

October 19th, 2007 20:00

It would not allow me to copy the following files into killbox...It ignored them like they weren't even there...
 
C:\WINDOWS\system32\rxmuvgsc.exe
C:\WINDOWS\system32\imy.exe
C:\WINDOWS\system32\unmb.exe
C:\WINDOWS\system32\reqkrsutfoch.exe
C:\WINDOWS\system32\id.exe
C:\WINDOWS\system32\nw.exe
C:\WINDOWS\system32\nuzrwce.exe
C:\WINDOWS\system32\ypcqkdvmhhq.exe

C:\WINDOWS\system32\nrcrpol.exe
C:\WINDOWS\system32\ovx.exe
C:\WINDOWS\system32\l.exe
C:\WINDOWS\system32\gcxhfvainrde.exe
C:\WINDOWS\system32\frhctggywohn.exe
C:\WINDOWS\system32\jigmnbpumeer.exe

10.4K Posts

October 19th, 2007 22:00

TMcJury
 
It wouldn't allow you to copy and paste the files? Did you copy and paste the whole list at once. Or did you try to copy and paste them one at a time?




Microsoft MVP Windows-Security


"The world is what you make of it"



1 Rookie

 • 

16 Posts

October 20th, 2007 00:00

Incredibily strange.  I highlighted the entire list of 25 lines and then, when I pasted into the app, only 10 of them are there.  If I try to delete just one, I am prompted to reboot, it goes throught the 9 second verification, then I get the message "PendingFileRenameOperations Registry Data has been Removed by External Process."

1 Rookie

 • 

16 Posts

October 20th, 2007 01:00

Here's My HIJACK THIS!  I really appreciate all your help!   BTW, I have been using Computer Associates Security Suite, which is offered free of charge from my Internet Service Provider.  If you have any recommendations on better products, let me know.  Thanks again.
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:27:14 PM, on 10/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Cursors\aolupd.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\RioMSC.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\system32\plugnplay.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\v.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2060909
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2060909
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Configure Plug n Play Devices] plugnplay.exe
O4 - HKLM\..\Run: C:\WINDOWS\system32\v.exe
O4 - HKLM\..\RunServices: C:\WINDOWS\system32\v.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax4507.cab
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///D:/CDVIEWER/CdViewer.cab
O23 - Service: AOL Smart Update Service (AOL_Real-Time_UPD) - Unknown owner - C:\WINDOWS\Cursors\aolupd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: dlcc_device -   - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: Smart Media Serviecs (Sys_SM-Service) - Unknown owner - C:\WINDOWS\repair\smrs.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Print Spooler Service (ytuahb7e6ai94yo) - Unknown owner - C:\WINDOWS\system32\v.exe
--
End of file - 8103 bytes

1 Rookie

 • 

16 Posts

October 20th, 2007 01:00

I continued with the rest of your directions...Here is a NEW SD Log; HIJACK THIS TO FOLLOW:
SDFix: Version 1.109
Run by Tom McJury on Fri 10/19/2007 at 10:09 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
ytuahb7e6ai94yo
ImagePath:
C:\WINDOWS\system32\bf.exe /service
ytuahb7e6ai94yo - Deleted
 
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...

Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\AHAFZO.EXE - Deleted
C:\WINDOWS\SYSTEM32\APJIJX~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\BF.EXE - Deleted
C:\WINDOWS\SYSTEM32\CYIUUH~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\KGAEGTM.EXE - Deleted
C:\WINDOWS\SYSTEM32\KT.EXE - Deleted
C:\WINDOWS\SYSTEM32\MBEEOE~1.EXE - Deleted
C:\WINDOWS\SYSTEM32\MMH.EXE - Deleted
C:\WINDOWS\SYSTEM32\TDLHP.EXE - Deleted
C:\WINDOWS\SYSTEM32\TERPIBB.EXE - Deleted
C:\WINDOWS\SYSTEM32\THPEC.EXE - Deleted
C:\WINDOWS\SYSTEM32\XEJYCV~1.EXE - Deleted
C:\DOCUME~1\TOMMCJ~1.DD6\LOCALS~1\Temp\Image_0037i.JPEG.zip  - Deleted
 
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
 
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
 

                                 Final Check:
Remaining Services:
------------------
 
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\WINDOWS\\ehome\\ehshell.exe"="C:\\WINDOWS\\ehome\\ehshell.exe:LocalSubNet:Enabled:Media Center"
"C:\\Program Files\\Common Files\\Sonic Shared\\Sonic Central\\Main\\Mediahub.exe"="C:\\Program Files\\Common Files\\Sonic Shared\\Sonic Central\\Main\\Mediahub.exe:*:Enabled:Creator Home"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\WINDOWS\\system32\\dlcccoms.exe"="C:\\WINDOWS\\system32\\dlcccoms.exe:*:Enabled:Dell 924 Server"
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE:*:Enabled:Dell 924 Printer Status"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
---------------
catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-19 22:18:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden files ...
C:\WINDOWS\system32\drivers\Ayxs97.sys
scan completed successfully
hidden files: 1

File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Wed  3 Oct 2007     5,903,928 ...H. --- "C:\Program Files\Picasa2\setup.exe"
Wed 17 Oct 2007        56,832 ..SHR --- "C:\WINDOWS\system32\plugnplay.exe"
Sun  7 Nov 2004         4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.key.bak"
Mon 14 May 2007        19,456 ...H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\My Documents\~WRL0633.tmp"
Thu 21 Sep 2006        22,076 ..SH. --- "C:\Documents and Settings\Thomas McJury\License Backup\drmv2key.bak"
Thu 21 Sep 2006        22,076 ..SH. --- "C:\Documents and Settings\Tom McJury\License Backup\drmv2key.bak"
Sun  7 Nov 2004         4,348 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\License Backup\drmv1key.bak"
Wed 22 Nov 2006            20 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\License Backup\drmv1lic.bak"
Sun  7 Nov 2004           488 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\License Backup\drmv2key.bak"
Mon  6 Nov 2006        22,076 ..SH. --- "C:\Documents and Settings\Tom McJury.DD640RB1\My Documents\drmv2key.bak"
Wed 27 Dec 2006        23,903 ..SH. --- "C:\My Music\downloads\License Backup\drmv2key.bak"
Thu 21 Sep 2006        20,252 ..SH. --- "C:\Documents and Settings\All Users\Documents\My Music\drmv2key.bak"
Mon  8 Jan 2007             0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Thu 22 Feb 2007       362,264 A..H. --- "C:\Documents and Settings\Connor McJury\Local Settings\Temp\AutoDetect.exe"
Thu 22 Feb 2007       362,264 A..H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\Local Settings\Temp\AutoDetect.exe"
Mon  6 Nov 2006        22,076 ..SH. --- "C:\Documents and Settings\Tom McJury.DD640RB1\Desktop\Licenses\drmv2key.bak"
Mon  2 Oct 2006        50,280 ...H. --- "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"
Wed 27 Dec 2006        23,903 A.SH. --- "C:\Documents and Settings\All Users\Documents\McJury Shared Documents\My Music\drmv2key.bak"
Mon  3 Sep 2007        19,456 ...H. --- "C:\Documents and Settings\Connor McJury\Application Data\Microsoft\Word\~WRL0003.tmp"
Mon 18 Sep 2006        11,115 ..SH. --- "C:\Documents and Settings\Kyle McJury\My Documents\My Music\License Backup\drmv2key.bak"
Mon 14 May 2007        19,456 ...H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\Application Data\Microsoft\Word\~WRL2261.tmp"
Mon  6 Nov 2006        22,076 ..SH. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\My Documents\My Music\License Backup\drmv2key.bak"
Sun 21 Jan 2007        19,456 ...H. --- "C:\Documents and Settings\Lori McJury.DD640RB1\Application Data\Microsoft\Word\~WRL0004.tmp"
Sun 21 Jan 2007        19,456 ...H. --- "C:\Documents and Settings\Lori McJury.DD640RB1\Application Data\Microsoft\Word\~WRL3438.tmp"
Mon 19 Mar 2007        24,576 ...H. --- "C:\Documents and Settings\Moira McJury\Application Data\Microsoft\Word\~WRL0005.tmp"
Sun  7 Nov 2004         4,348 ...H. --- "C:\Documents and Settings\Moira McJury\Desktop\dad\License Backup\drmv1key.bak"
Mon  9 Oct 2006            20 ...H. --- "C:\Documents and Settings\Moira McJury\Desktop\dad\License Backup\drmv1lic.bak"
Sun  7 Nov 2004           488 ..SH. --- "C:\Documents and Settings\Moira McJury\Desktop\dad\License Backup\drmv2key.bak"
Fri 19 Oct 2007         5,946 A.SH. --- "C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE1.tmp"
Wed 27 Dec 2006        23,903 ..SH. --- "C:\Documents and Settings\Moira McJury\Desktop\My Pictures\My Music\License Backup\drmv2key.bak"
Wed 27 Dec 2006        23,903 ..SH. --- "C:\Documents and Settings\Moira McJury\My Documents\My Pictures\My Music\License Backup\drmv2key.bak"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch6\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Connor McJury\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Connor McJury\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Kyle McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Lori McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Lori McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Moira McJury\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Moira McJury\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
Sun  2 Sep 2007             8 ...H. --- "C:\Documents and Settings\Tom McJury.DD640RB1\Application Data\Gtek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
Finished!

10.4K Posts

October 21st, 2007 20:00

TMcJury

You are most welcome. And I can make some recommendations in closing

Please download Combofix and save to your desktop:
  • Note: It is important that it is saved directly to your desktop
    Close any open browsers.
    Double click on combofix.exe and follow the prompts.
    When it's finished it will produce a log.
    Post the contents of the C:\ComboFix.txt into your next reply.
    Note: Do not mouseclick combofix's window whilst it's running.
    That may cause the program to freeze/hang.
















Microsoft MVP Windows-Security


"The world is what you make of it"




1 Rookie

 • 

16 Posts

October 21st, 2007 22:00

Ran the Combo fix...  Went through it's steps, then I got the Blue screen with the following message:
TERMINAL_SERVER_DRIVER_ADE_INCORRECT_MEMORY_REFERENCE
ATI2drag.dll - Address DB03156A base at BF012000, DATESTAMP 00000000
 
I rebooted, and the Combofix finished,  Here is the log:
ComboFix 07-10-22.1 - Tom McJury 2007-10-21 19:16:48.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.538 [GMT -4:00]
Running from: C:\Documents and Settings\Tom McJury.DD640RB1\Desktop\ComboFix.exe
 * Created a new restore point
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\C.tmp
C:\Documents and Settings\Moira McJury\Application Data\macromedia\Flash Player\#SharedObjects\QHCVAMUR\www.broadcaster.com
C:\Documents and Settings\Moira McJury\Application Data\macromedia\Flash Player\#SharedObjects\QHCVAMUR\www.broadcaster.com\played_list.sol
C:\Documents and Settings\Moira McJury\Application Data\macromedia\Flash Player\#SharedObjects\QHCVAMUR\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Moira McJury\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\Moira McJury\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\WINDOWS\system32\drivers\AYXS97.sys
C:\WINDOWS\system32\v.exe
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_AYXS97
-------\RpcApi

(((((((((((((((((((((((((   Files Created from 2007-09-22 to 2007-10-22  )))))))))))))))))))))))))))))))
.
2007-10-21 19:15 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-20 06:53 224,714 --a------ C:\WINDOWS\system32\zxeb.exe
2007-10-18 18:38   d-------- C:\WINDOWS\ERUNT
2007-10-18 09:49 87,552 --a------ C:\up21.exe
2007-10-17 23:15   d-------- C:\Program Files\Trend Micro
2007-10-17 15:51   d-------- C:\Program Files\SupportSoft
2007-10-17 14:28 56,832 -r-hs---- C:\WINDOWS\system32\plugnplay.exe
2007-10-17 08:28 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-10-17 01:24 286 --a------ C:\sysrestore.exe
2007-10-16 22:11   d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2007-10-13 22:06 224,655 --a------ C:\WINDOWS\system32\uw.exe
2007-10-12 20:52 224,655 --a------ C:\WINDOWS\system32\ignp.exe
2007-10-12 14:05 224,655 --a------ C:\WINDOWS\system32\xqowlf.exe
2007-10-12 12:38 224,655 --a------ C:\WINDOWS\system32\qxrwn.exe
2007-10-12 10:36 224,655 --a------ C:\WINDOWS\system32\tdlbn.exe
2007-10-12 09:50 224,655 --------- C:\WINDOWS\system32\enlsbgmanrkt.exe
2007-10-12 06:31 224,655 --------- C:\WINDOWS\system32\xxngsjheowt.exe
2007-10-12 00:29 224,655 --------- C:\WINDOWS\system32\fx.exe
2007-10-03 16:40   d-------- C:\Program Files\MP3 Player Utilities 3.13
2007-10-03 09:07 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-10-03 09:07 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-10-03 09:05   d-------- C:\Program Files\Picasa2
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-21 16:28 --------- d-----w C:\Program Files\Dl_cats
2007-10-20 01:56 --------- d-----w C:\Program Files\BAE
2007-10-17 20:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2007-10-17 03:52 1,258 ----a-w C:\Documents and Settings\Tom McJury.DD640RB1\Application Data\wklnhst.dat
2007-10-17 03:20 --------- d-----w C:\Program Files\QuickTime
2007-10-17 03:19 --------- d-----w C:\Program Files\Intellimover
2007-10-17 03:19 --------- d-----w C:\Program Files\eMusic Download Manager
2007-10-17 03:19 --------- d-----w C:\Program Files\Dell
2007-10-17 03:19 --------- d-----w C:\Program Files\Common Files\aolshare
2007-10-02 23:58 4,902 ------w C:\Documents and Settings\Connor McJury\Application Data\wklnhst.dat
2007-09-20 19:18 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-09-20 19:12 --------- d-----w C:\Program Files\Jasc Software Inc
2007-09-20 19:12 --------- d-----w C:\Program Files\Common Files\Jasc Software Inc
2007-09-20 19:12 --------- d-----w C:\Documents and Settings\Tom McJury.DD640RB1\Application Data\Jasc Software Inc
2007-09-11 07:45 177,965 ------w C:\bootlogsect.exe
2007-09-03 23:10 --------- d--h--w C:\Documents and Settings\Connor McJury\Application Data\Gtek
2007-09-03 14:51 --------- d-----w C:\Documents and Settings\Moira McJury\Application Data\Gtek
2007-09-03 00:10 --------- d-----w C:\Program Files\Linksys EasyLink Advisor
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\MCX4\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\MCX3\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\MCX2\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\MCX1\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Gtek
2007-08-24 05:06 --------- d-----w C:\Documents and Settings\Moira McJury\Application Data\Sonic
2007-08-24 05:06 --------- d-----w C:\Documents and Settings\Moira McJury\Application Data\Leadertech
2007-08-22 15:57 --------- d-----w C:\Program Files\Wal-Mart Music Downloads Store
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 23:19 92,504 ------w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 23:19 549,720 ------w C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 23:19 53,080 ------w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 23:19 43,352 ------w C:\WINDOWS\system32\wups2.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 23:19 325,976 ------w C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 23:19 271,224 ------w C:\WINDOWS\system32\mucltui.dll
2007-07-30 23:19 207,736 ------w C:\WINDOWS\system32\muweb.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 23:19 203,096 ------w C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 23:19 1,712,984 ------w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-30 23:18 33,624 ------w C:\WINDOWS\system32\dllcache\wups.dll
2007-05-21 22:06 89,088 ------w C:\WINDOWS\Cursors\aolupd.exe
2006-10-09 15:35 251 -c----w C:\Program Files\wt3d.ini
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 07:15]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 05:40]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 05:40]
"BuildBU"="c:\dell\bldbubg.exe" [2006-09-09 17:08]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 17:20 C:\WINDOWS\stsystra.exe]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2006-02-24 16:11]
"Configure Plug n Play Devices"="plugnplay.exe" [2007-10-17 14:28 C:\WINDOWS\system32\plugnplay.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 05:40]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" []
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"v"=C:\WINDOWS\system32\v.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Extender Resource Monitor.lnk - C:\WINDOWS\ehome\RMSysTry.exe [2005-10-20 20:55:40]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 04:15:54]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 22:07:32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
R2 AOL_Real-Time_UPD;AOL Smart Update Service;"C:\WINDOWS\Cursors\aolupd.exe"
R2 elagopro;GoProto Protocol Driver for LELA;C:\WINDOWS\system32\DRIVERS\elagopro.sys
R2 elaunidr;UniDriver for LELA;C:\WINDOWS\system32\DRIVERS\elaunidr.sys
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe
S2 Sys_SM-Service;Smart Media Serviecs;"C:\WINDOWS\repair\smrs.exe"
S2 ytuahb7e6ai94yo;Print Spooler Service;C:\WINDOWS\system32\v.exe /service
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe -k QWAVE
S3 QWAVEDRV;QWAVE driver;C:\WINDOWS\system32\DRIVERS\qwavedrv.sys
S3 RIOUNIV;Rio universal USB driver;C:\WINDOWS\system32\Drivers\RIOUNIV.sys
S3 Wdm1;USB Bridge Cable Driver;C:\WINDOWS\system32\Drivers\usbbc.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE QWAVE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f94cdd4-7b89-11dc-9c1a-001676b4f111}]
AutoRun\command - F:\Autorun.exe /run
Shell00\Command - F:\Autorun.exe /run
Shell01\Command - F:\Autorun.exe /action
Shell02\Command - F:\Autorun.exe /uninstall
.
Contents of the 'Scheduled Tasks' folder
"2007-10-19 07:00:00 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-22 19:25:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-10-22 19:26:56 - machine was rebooted
.
 --- E O F ---

10.4K Posts

October 22nd, 2007 13:00

TMcJury

The BSOD error
  • TERMINAL_SERVER_DRIVER_ADE_INCORRECT_MEMORY_REFERENCE
    ATI2drag.dll

has to do with your graphic's card. Once we get your PC clean you may need to repost that information on another of the Dell support boards.


1. Open NotePad (not wordpad). Copy and paste the following into Notepad

File::
C:\WINDOWS\system32\zxeb.exe
C:\up21.exe
C:\WINDOWS\system32\uw.exe
C:\WINDOWS\system32\ignp.exe
C:\WINDOWS\system32\xqowlf.exe
C:\WINDOWS\system32\qxrwn.exe
C:\WINDOWS\system32\tdlbn.exe
C:\WINDOWS\system32\enlsbgmanrkt.exe
C:\WINDOWS\system32\xxngsjheowt.exe
C:\WINDOWS\system32\fx.exe
C:\WINDOWS\system32\v.exe
C:\Program Files\SpywareBot\SpywareBot.exe

Folder::
C:\Program Files\SpywareBot

Driver::
ytuahb7e6ai94yo

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"v"=-

Using the Image as a reference, drag CFScript into ComboFix.exe

user posted image
  • You will be prompted to run Combofix again, Do so
    Following the same rules as indicated in my first post
    Then post the contents of the C:\ComboFix.txt log in your reply



Microsoft MVP Windows-Security


"The world is what you make of it"

1 Rookie

 • 

16 Posts

October 23rd, 2007 00:00

 How do you know all this stuff!?!?!?!?  You've been a huge help.
One thing...I am assuming that - after you had me copy the infor into the notepad, that I should save it with the name CFScript, and then drag THAT onto ComboFix.  That's what I did.
 
Here's my log:
ComboFix 07-10-22.1 - Tom McJury 2007-10-23 20:53:38.3 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.2.1252.1.1033.18.640 [GMT -4:00]
Running from: C:\Documents and Settings\Tom McJury.DD640RB1\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tom McJury.DD640RB1\Desktop\CFScript_used_2007-10-23@19.34.txt
 * Created a new restore point
FILE::
C:\Program Files\SpywareBot\SpywareBot.exe
C:\up21.exe
C:\WINDOWS\system32\enlsbgmanrkt.exe
C:\WINDOWS\system32\fx.exe
C:\WINDOWS\system32\ignp.exe
C:\WINDOWS\system32\qxrwn.exe
C:\WINDOWS\system32\tdlbn.exe
C:\WINDOWS\system32\uw.exe
C:\WINDOWS\system32\v.exe
C:\WINDOWS\system32\xqowlf.exe
C:\WINDOWS\system32\xxngsjheowt.exe
C:\WINDOWS\system32\zxeb.exe
.
(((((((((((((((((((((((((   Files Created from 2007-09-24 to 2007-10-24  )))))))))))))))))))))))))))))))
.
2007-10-21 19:15 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-18 18:38   d-------- C:\WINDOWS\ERUNT
2007-10-17 23:15   d-------- C:\Program Files\Trend Micro
2007-10-17 15:51   d-------- C:\Program Files\SupportSoft
2007-10-17 14:28 56,832 -r-hs---- C:\WINDOWS\system32\plugnplay.exe
2007-10-17 08:28 23,600 --a------ C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-10-17 01:24 286 --a------ C:\sysrestore.exe
2007-10-16 22:11   d-------- C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}
2007-10-03 16:40   d-------- C:\Program Files\MP3 Player Utilities 3.13
2007-10-03 09:07 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-10-03 09:07 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-10-03 09:05   d-------- C:\Program Files\Picasa2
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-23 21:26 --------- d-----w C:\Program Files\Dl_cats
2007-10-20 01:56 --------- d-----w C:\Program Files\BAE
2007-10-17 20:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\CA
2007-10-17 03:52 1,258 ----a-w C:\Documents and Settings\Tom McJury.DD640RB1\Application Data\wklnhst.dat
2007-10-17 03:20 --------- d-----w C:\Program Files\QuickTime
2007-10-17 03:19 --------- d-----w C:\Program Files\Intellimover
2007-10-17 03:19 --------- d-----w C:\Program Files\eMusic Download Manager
2007-10-17 03:19 --------- d-----w C:\Program Files\Dell
2007-10-17 03:19 --------- d-----w C:\Program Files\Common Files\aolshare
2007-10-02 23:58 4,902 ------w C:\Documents and Settings\Connor McJury\Application Data\wklnhst.dat
2007-09-20 19:18 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-09-20 19:12 --------- d-----w C:\Program Files\Jasc Software Inc
2007-09-20 19:12 --------- d-----w C:\Program Files\Common Files\Jasc Software Inc
2007-09-20 19:12 --------- d-----w C:\Documents and Settings\Tom McJury.DD640RB1\Application Data\Jasc Software Inc
2007-09-11 07:45 177,965 ------w C:\bootlogsect.exe
2007-09-03 23:10 --------- d--h--w C:\Documents and Settings\Connor McJury\Application Data\Gtek
2007-09-03 14:51 --------- d-----w C:\Documents and Settings\Moira McJury\Application Data\Gtek
2007-09-03 00:10 --------- d-----w C:\Program Files\Linksys EasyLink Advisor
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\MCX4\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\MCX3\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\MCX2\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\MCX1\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Gtek
2007-09-03 00:09 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Gtek
2007-08-24 05:06 --------- d-----w C:\Documents and Settings\Moira McJury\Application Data\Sonic
2007-08-24 05:06 --------- d-----w C:\Documents and Settings\Moira McJury\Application Data\Leadertech
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 10:04 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 3,584,512 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-07-30 23:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 23:19 92,504 ------w C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 23:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 23:19 549,720 ------w C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 23:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 23:19 53,080 ------w C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 23:19 43,352 ------w C:\WINDOWS\system32\wups2.dll
2007-07-30 23:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 23:19 325,976 ------w C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 23:19 271,224 ------w C:\WINDOWS\system32\mucltui.dll
2007-07-30 23:19 207,736 ------w C:\WINDOWS\system32\muweb.dll
2007-07-30 23:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 23:19 203,096 ------w C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 23:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 23:19 1,712,984 ------w C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 23:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-30 23:18 33,624 ------w C:\WINDOWS\system32\dllcache\wups.dll
2007-05-21 22:06 89,088 ------w C:\WINDOWS\Cursors\aolupd.exe
2006-10-09 15:35 251 -c----w C:\Program Files\wt3d.ini
.
(((((((((((((((((((((((((((((   snapshot@2007-10-22_19.25.53.60   )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-20 02:09:01 4,714,496 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\ 00000001\ntuser.dat
+ 2007-10-23 00:56:51 4,714,496 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\ 00000001\ntuser.dat
- 2007-10-20 02:09:01 155,648 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\ 00000002\UsrClass.dat
+ 2007-10-23 00:56:51 155,648 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\ 00000002\UsrClass.dat
+ 2007-10-24 00:48:34 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1dc.dat
+ 2007-10-24 00:48:34 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_c0.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 07:15]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 03:12]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 05:20]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 05:40]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 05:40]
"BuildBU"="c:\dell\bldbubg.exe" [2006-09-09 17:08]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 17:20 C:\WINDOWS\stsystra.exe]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2006-02-24 16:11]
"Configure Plug n Play Devices"="plugnplay.exe" [2007-10-17 14:28 C:\WINDOWS\system32\plugnplay.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 05:00]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 05:40]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" []
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 18:16]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26]
Extender Resource Monitor.lnk - C:\WINDOWS\ehome\RMSysTry.exe [2005-10-20 20:55:40]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 04:15:54]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 22:07:32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
R2 AOL_Real-Time_UPD;AOL Smart Update Service;"C:\WINDOWS\Cursors\aolupd.exe"
R2 elagopro;GoProto Protocol Driver for LELA;C:\WINDOWS\system32\DRIVERS\elagopro.sys
R2 elaunidr;UniDriver for LELA;C:\WINDOWS\system32\DRIVERS\elaunidr.sys
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe
S2 Sys_SM-Service;Smart Media Serviecs;"C:\WINDOWS\repair\smrs.exe"
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe -k QWAVE
S3 QWAVEDRV;QWAVE driver;C:\WINDOWS\system32\DRIVERS\qwavedrv.sys
S3 RIOUNIV;Rio universal USB driver;C:\WINDOWS\system32\Drivers\RIOUNIV.sys
S3 Wdm1;USB Bridge Cable Driver;C:\WINDOWS\system32\Drivers\usbbc.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE QWAVE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f94cdd4-7b89-11dc-9c1a-001676b4f111}]
AutoRun\command - F:\Autorun.exe /run
Shell00\Command - F:\Autorun.exe /run
Shell01\Command - F:\Autorun.exe /action
Shell02\Command - F:\Autorun.exe /uninstall
.
Contents of the 'Scheduled Tasks' folder
"2007-10-19 07:00:00 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-23 20:55:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-10-23 20:56:59
C:\ComboFix2.txt ... 2007-10-23 19:37
C:\ComboFix3.txt ... 2007-10-22 19:26
.
 --- E O F ---

10.4K Posts

October 23rd, 2007 11:00

TMcJury

How do you know all this stuff!?!?!?!?

It's a lot of study, but a lot of fun as well.

Missed one file, that needs to go

1. Using Windows Explorer
  • (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate and Delete the following file
  • C:\sysrestore.exe
Close Windows explorer ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log












Microsoft MVP Windows-Security


"The world is what you make of it"




1 Rookie

 • 

16 Posts

October 23rd, 2007 11:00

Done.  Here is log:
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:51:29 AM, on 10/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Cursors\aolupd.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\WINDOWS\system32\RioMSC.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\dell\bldbubg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\plugnplay.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2060909
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Configure Plug n Play Devices] plugnplay.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax4507.cab
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///D:/CDVIEWER/CdViewer.cab
O23 - Service: AOL Smart Update Service (AOL_Real-Time_UPD) - Unknown owner - C:\WINDOWS\Cursors\aolupd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: dlcc_device -   - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: Intel(R) Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\Elservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe
O23 - Service: Smart Media Serviecs (Sys_SM-Service) - Unknown owner - C:\WINDOWS\repair\smrs.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 7598 bytes
No Events found!

Top