Start a Conversation

Unsolved

This post is more than 5 years old

P

320

November 22nd, 2007 03:00

Possibe trojan

​ Hi, ​
​ ​
​ For the past couple of days my laptop is acting weird, when I checked the Task Manager I found out that SPBBCSvc.exe keeps building up until it reaches to 500000-600000 Ks. I scanned it with AVG anti-spyware and found couple of high risk items, I really appreciate your help in advance, below is the log from hijack this: ​
​ ​
​ Logfile of Trend Micro HijackThis v2.0.2 ​
​Scan saved at 11:26:54 PM, on 11/21/2007 ​
​Platform: Windows XP SP2 (WinNT 5.01.2600) ​
​MSIE: Internet Explorer v7.00 (7.00.6000.16544) ​
​Boot mode: Normal ​
​ Running processes: ​
​C:\WINDOWS\System32\smss.exe ​
​C:\WINDOWS\system32\winlogon.exe ​
​C:\WINDOWS\system32\services.exe ​
​C:\WINDOWS\system32\lsass.exe ​
​C:\WINDOWS\system32\Ati2evxx.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\Program Files\Intel\Wireless\Bin\EvtEng.exe ​
​C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe ​
​C:\WINDOWS\system32\Ati2evxx.exe ​
​C:\WINDOWS\Explorer.EXE ​
​C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe ​
​C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccProxy.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe ​
​C:\Program Files\Norton Internet Security\ISSVC.exe ​
​C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe ​
​C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe ​
​C:\WINDOWS\system32\spoolsv.exe ​
​C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe ​
​C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe ​
​C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe ​
​C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe ​
​C:\WINDOWS\system32\svchost.exe ​
​C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe ​
​C:\Program Files\Apoint\Apoint.exe ​
​C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe ​
​C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe ​
​C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe ​
​C:\Program Files\Dell\Media Experience\PCMService.exe ​
​C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe ​
​C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe ​
​C:\WINDOWS\system32\dla\tfswctrl.exe ​
​C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe ​
​C:\Program Files\Common Files\Symantec Shared\ccApp.exe ​
​C:\WINDOWS\system32\RunDLL32.exe ​
​C:\Program Files\Winamp\winampa.exe ​
​C:\Program Files\Apoint\Apntex.exe ​
​C:\Program Files\iTunes\iTunesHelper.exe ​
​C:\Program Files\QuickTime\qttask.exe ​
​C:\Program Files\iPod\bin\iPodService.exe ​
​C:\Program Files\Common Files\Real\Update_OB\realsched.exe ​
​C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE ​
​C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe ​
​C:\Program Files\DellSupport\DSAgnt.exe ​
​C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe ​
​C:\Program Files\MSN Messenger\MsnMsgr.Exe ​
​C:\WINDOWS\system32\ctfmon.exe ​
​C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ​
​C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe ​
​C:\Program Files\DAEMON Tools\daemon.exe ​
​C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe ​
​C:\Program Files\Digital Line Detect\DLG.exe ​
​C:\WINDOWS\System32\svchost.exe ​
​C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe ​
​C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe ​
​C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe ​
​C:\WINDOWS\system32\taskmgr.exe ​
​C:\Program Files\Internet Explorer\iexplore.exe ​
​C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe ​
​C:\Program Files\Trend Micro\HijackThis\HijackThis.exe ​
​C:\Program Files\Messenger\msmsgs.exe ​
​ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ​​http://www.dell4me.com/myway​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = ​​http://bfc.myway.com/search/de_srchlft.html​​ ​
​R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = ​​http://go.microsoft.com/fwlink/?LinkId=69157​​ ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = ​​http://go.microsoft.com/fwlink/?LinkId=54896​​ ​
​R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = ​​http://go.microsoft.com/fwlink/?LinkId=54896​​ ​
​R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = ​​http://go.microsoft.com/fwlink/?LinkId=69157​​ ​
​R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = ​​http://www.dell4me.com/myway​​ ​
​R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast ​
​R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll ​
​O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll ​
​O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing) ​
​O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll ​
​O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll ​
​O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) ​
​O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll ​
​O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll ​
​O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll ​
​O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll ​
​O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll ​
​O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll ​
​O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll ​
​O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll ​
​O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) ​
​O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll ​
​O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll ​
​O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe ​
​O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe ​
​O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless ​
​O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe ​
​O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" ​
​O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" ​
​O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe ​
​O4 - HKLM\..\Run: [QBReminderFlash] "C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe" ​
​O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe ​
​O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup ​
​O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start ​
​O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" ​
​O4 - HKLM\..\Run: [VF0070 STISvc] RunDLL32.exe V0070Pin.dll,RunDLL32EP 513 ​
​O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer ​
​O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe ​
​O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ​
​O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun ​
​O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" ​
​O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime ​
​O4 - HKLM\..\Run: [TVolution] C:\Program Files\inKline Global\TVolution\TVolution.exe ​
​O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot ​
​O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup ​
​O4 - HKLM\..\Run: [Bittorrent] C:\WINDOWS\bittorrent.exe ​
​O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized ​
​O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup ​
​O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background ​
​O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" ​
​O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe ​
​O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe ​
​O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog ​
​O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 ​
​O4 - Global Startup: Bluetooth Manager.lnk = ? ​
​O4 - Global Startup: Digital Line Detect.lnk = ? ​
​O8 - Extra context menu item: &Search - ​​http://ka.bar.need2find.com/KA/menusearch.html?p=KA​ ​
​O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm ​
​O8 - Extra context menu item: Add to Windows &Live Favorites - ​​http://favorites.live.com/quickadd.aspx​​ ​
​O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm ​
​O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm ​
​O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 ​
​O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll ​
​O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll ​
​O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - ​​http://www.comcast.net/​​ (file missing) ​
​O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - ​​http://www.comcastsupport.com/​​ (file missing) ​
​O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL ​
​O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - ​​http://online.comcast.net/help/​​ (file missing) ​
​O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll ​
​O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing) ​
​O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing) ​
​O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - ​​http://wwws.musicmatch.com/mmz/openWebRadio.html​​ (file missing) ​
​O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe ​
​O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe ​
​O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe ​
​O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe ​
​O16 - DPF: myEXTRA! 3270 Terminal (SSL) - ​​http://online.thy.com/mcs/components/terminal3270/JavaClient/mainframe/3270TerminalSecure.cab​​ ​
​O16 - DPF: {01118400-3E00-11D2-8470-0060089874ED} - ​​http://activex.microsoft.com/objects/ocget.dll​​ ​
​O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - ​​http://go.microsoft.com/fwlink/?linkid=39204​​ ​
​O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - ​​http://spaces.msn.com//PhotoUpload/MsnPUpld.cab​​ ​
​O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - ​​http://upload.facebook.com/controls/FacebookPhotoUploader.cab​​ ​
​O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - ​​http://download.divx.com/player/DivXBrowserPlugin.cab​​ ​
​O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - ​​http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab​​ ​
​O16 - DPF: {D5D17C21-1719-4640-B0B2-4F3262419920} (JaguarEditControl-ISBANK) - ​​https://www.isbank.com.tr/Internet/lib/JaguarEdit4ISB.CAB​​ ​
​O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - ​​http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx​​ ​
​O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - ​​http://player.radyotvonline.com/ampx_en_dl.cab​​ ​
​O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe ​
​O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe ​
​O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe ​
​O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe ​
​O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe ​
​O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe ​
​O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe ​
​O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe ​
​O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe ​
​O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe ​
​O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe ​
​O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe ​
​O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe ​
​O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe ​
​O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe ​
​O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe ​
​O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe ​
​O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe ​
​O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe ​
​O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe ​
​O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe ​
​O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe ​
​ -- ​
​End of file - 15607 bytes ​
​ ​
No Responses!
No Events found!

Top