Unsolved

This post is more than 5 years old

10 Posts

1087

June 10th, 2008 02:00

Ref: Post logs for "I found several Trojans" to bugbatter. part 1

This is what SuperAntiSpyware found when my computer was hit.  I ran several anti virus programs after this and I think I might have removed the virus shown here.  I am includings the results of the Hijacj This that I ran today.  Thanks

Eagle 60 

 

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/27/2008 at 11:10 AM

Application Version : 4.1.1046

Core Rules Database Version : 3468
Trace Rules Database Version: 1459

Scan type       : Complete Scan
Total Scan Time : 00:38:47

Memory items scanned      : 433
Memory threats detected   : 5
Registry items scanned    : 7303
Registry threats detected : 34
File items scanned        : 32026
File threats detected     : 120

Trojan.Vundo-Variant/Small-GEN
 C:\WINDOWS\SYSTEM32\SSQOHXVT.DLL
 C:\WINDOWS\SYSTEM32\SSQOHXVT.DLL

Adware.VideoAccessCodec/Gen
 C:\WINDOWS\VREGFWLX.DLL
 C:\WINDOWS\VREGFWLX.DLL

Adware.Vundo-Variant/J
 C:\WINDOWS\VLTDFABW.DLL
 C:\WINDOWS\VLTDFABW.DLL

Trojan.Unclassified/CTFMONA
 C:\WINDOWS\SYSTEM32\CTFMONA.EXE
 C:\WINDOWS\SYSTEM32\CTFMONA.EXE
 [ctfmona] C:\WINDOWS\SYSTEM32\CTFMONA.EXE
 C:\WINDOWS\Prefetch\CTFMONA.EXE-0F567013.pf

Trojan.Dropper/MSPrint-Fake
 C:\DOCUME~1\SYLVIA~1\LOCALS~1\TEMP\MSPRINT.EXE
 C:\DOCUME~1\SYLVIA~1\LOCALS~1\TEMP\MSPRINT.EXE
 [DelayLoad] C:\DOCUME~1\SYLVIA~1\LOCALS~1\TEMP\MSPRINT.EXE
 C:\DOCUMENTS AND SETTINGS\SYLVIA SMITH\LOCAL SETTINGS\TEMP\MSPRINT.EXE
 C:\WINDOWS\Prefetch\MSPRINT.EXE-3149AD4E.pf

Trojan.Vundo-Variant/Small
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27796771-8D05-4EE6-B478-43CE759F2106}
 HKCR\CLSID\{27796771-8D05-4EE6-B478-43CE759F2106}
 HKCR\CLSID\{27796771-8D05-4EE6-B478-43CE759F2106}\InprocServer32
 HKCR\CLSID\{27796771-8D05-4EE6-B478-43CE759F2106}\InprocServer32#ThreadingModel
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B7687FE1-543F-4CA7-A76A-1D9419AF5064}
 HKCR\CLSID\{B7687FE1-543F-4CA7-A76A-1D9419AF5064}
 HKCR\CLSID\{B7687FE1-543F-4CA7-A76A-1D9419AF5064}\InprocServer32
 HKCR\CLSID\{B7687FE1-543F-4CA7-A76A-1D9419AF5064}\InprocServer32#ThreadingModel
 C:\WINDOWS\SYSTEM32\WVULJGHA.DLL
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{27796771-8D05-4EE6-B478-43CE759F2106}
 Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\ssqOHxvT
 C:\WINDOWS\SYSTEM32\GOIBAARL.DLL

Trojan.Unclassified/GTS
 HKLM\Software\Microsoft\Internet Explorer\Toolbar#{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}
 HKCR\CLSID\{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}
 HKCR\CLSID\{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}
 HKCR\CLSID\{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}\InprocServer32
 HKCR\CLSID\{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}\InprocServer32#ThreadingModel
 HKCR\CLSID\{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}\ProgID
 HKCR\CLSID\{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}\Programmable
 HKCR\CLSID\{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}\TypeLib
 HKCR\CLSID\{5BAD7AAD-2121-49AB-8C4B-E175BD23E820}\VersionIndependentProgID
 HKCR\atfxqogp.1
 HKCR\atfxqogp
 HKCR\TypeLib\{17E301A6-F80F-4856-9243-A80AFD2DE075}
 HKCR\TypeLib\{17E301A6-F80F-4856-9243-A80AFD2DE075}\1.0
 HKCR\TypeLib\{17E301A6-F80F-4856-9243-A80AFD2DE075}\1.0\0
 HKCR\TypeLib\{17E301A6-F80F-4856-9243-A80AFD2DE075}\1.0\0\win32
 HKCR\TypeLib\{17E301A6-F80F-4856-9243-A80AFD2DE075}\1.0\FLAGS
 HKCR\TypeLib\{17E301A6-F80F-4856-9243-A80AFD2DE075}\1.0\HELPDIR
 C:\WINDOWS\ATFXQOGP.DLL

Adware.Tracking Cookie
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@adopt.euroclick[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@casalemedia[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@realmedia[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@ad.yieldmanager[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@adopt.specificclick[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@questionmarket[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@tacoda[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@antivirus-scanner[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@zedo[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@qnsr[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@tribalfusion[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@insightexpressai[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@specificclick[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@chitika[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@trafficmp[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@bluestreak[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@partner2profit[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@dynamic.media.adrevolver[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@smartadserver[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@reunion.adbureau[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@ads.revsci[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@www.burstnet[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@imrworldwide[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@adserving.autotrader[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@ads.pointroll[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@cache.trafficmp[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@msnportal.112.2o7[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@media6degrees[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@revsci[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@network.realmedia[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@media.adrevolver[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@adinterax[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@adrevolver[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@invitemedia[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@82.98.235[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@interclick[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@richmedia.yahoo[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@serving-sys[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@2o7[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@media.adrevolver[3].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@eb.adbureau[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@ads.bridgetrack[2].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@bs.serving-sys[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@www.googleadservices[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@server.iad.liveperson[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@burstnet[1].txt
 C:\Documents and Settings\Sylvia Smith\cookies\sylvia_smith@server.iad.liveperson[3].txt
 statse.webtrendslive.com [ C:\Documents and Settings\Amber Smith\Application ----------------------------------------------------------------------------------------------- 

I will attach the rest on another message

4 Apprentice

 • 

20.5K Posts

June 10th, 2008 12:00

Your posts have been split and are in several places on this board. I am going to copy all of them to this one thread, so we can keep all replies in here.

Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.advertising.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.advertising.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.zedo.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.bannerspace.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.atdmt.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.ehg-dig.hitbox.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.ehg-dig.hitbox.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.z1.adserver.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.z1.adserver.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.fastclick.net [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.doubleclick.net [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.ehg.hitbox.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.ehg.hitbox.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
twci.coremetrics.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
statse.webtrendslive.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
statse.webtrendslive.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.qksrv.net [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.qksrv.net [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.bfast.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.2o7.net [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.2o7.net [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.macromedia.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.macromedia.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.valueclick.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.mediaplex.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.macromedia.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.apmebf.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.apmebf.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.windowsmedia.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.windowsmedia.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.windowsmedia.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.targetnet.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.maxserving.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.maxserving.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.bluestreak.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.statcounter.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.statse.webtrendslive.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
.tribalfusion.com [ C:\Documents and Settings\Cecil Smith\Application Data\Mozilla\Firefox\Profiles\default.iwh\cookies.txt ]
C:\Documents and Settings\Cecil Smith\Cookies\cecil_smith@media.adrevolver[1].txt
C:\Documents and Settings\Cecil Smith\Cookies\cecil_smith@tripod[1].txt
C:\Documents and Settings\Cecil Smith\Cookies\cecil_smith@atdmt[2].txt
C:\Documents and Settings\Cecil Smith\Cookies\cecil_smith@ads.wjztfm[2].txt
.doubleclick.net [ C:\Documents and Settings\Ryan Smith\Application Data\Mozilla\Firefox\Profiles\default.pbs\cookies.txt ]
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@dynamic.media.adrevolver[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@revsci[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@tradedoubler[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@adopt.specificclick[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@adsrevenue[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@clickbank[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@trafficmp[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@imrworldwide[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@advertising[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@e-2dj6wjkoapczabp.stats.esomniture[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@doubleclick[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@e-2dj6wckyehazghp.stats.esomniture[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@network.realmedia[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@shopping.112.2o7[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@adrevolver[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@insightexpressai[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@statcounter[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@questionmarket[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@azjmp[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@ad.yieldmanager[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@specificclick[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@tremor.adbureau[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@atdmt[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@dealtime[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@www.burstbeacon[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@interclick[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@ads.addynamix[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@apmebf[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@ads.revsci[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@media.adrevolver[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@media.adrevolver[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@ads.realtechnetwork[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@casalemedia[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@2o7[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@adbrite[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@adopt.euroclick[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@adserver.socialspark[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@bluestreak[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@chitika[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@clicksor[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@collective-media[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@fastclick[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@media6degrees[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@mediaplex[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@overture[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@precisionclick[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@realmedia[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@stat.dealtime[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@tribalfusion[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@valueclick[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@www.burstnet[2].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@www.googleadservices[1].txt
C:\Documents and Settings\Ryan Smith\Cookies\ryan_smith@www.googleadservices[2].txt
Trojan.Net-MU/Gen
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#uninstallString

Adware.Vundo Variant/Rel
HKLM\SOFTWARE\Microsoft\FCOVM
HKLM\SOFTWARE\Microsoft\RemoveRP

Rogue.AdvancedXPFixer-Installer
C:\DOCUMENTS AND SETTINGS\SYLVIA SMITH\LOCAL SETTINGS\TEMP\.TT25.TMP
C:\DOCUMENTS AND SETTINGS\SYLVIA SMITH\LOCAL SETTINGS\TEMP\.TTD6.TMP
C:\WINDOWS\Prefetch\.TT25.TMP-1FAC1287.pf
C:\WINDOWS\Prefetch\.TTD6.TMP-3A8FCD1C.pf

Trojan.Unknown Origin
C:\WINDOWS\SYSTEM32\CTFMONB.BMP


Message Edited by Bugbatter on 06-10-2008 09:47 AM

4 Apprentice

 • 

20.5K Posts

June 10th, 2008 12:00


This is the log from HJT. Thanks again

Eagle 60



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:41:04, on 6/9/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\nosign.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Sierra\Planner\Plnrnote.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Dell Support Center\gs_agent\dsc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [nosign] C:\WINDOWS\\nosign.exe Argus
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKUS\S-1-5-21-3665436291-465681738-991282682-1009\..\Run: [Sonic RecordNow!] (User 'Cecil Smith')
O4 - HKUS\S-1-5-21-3665436291-465681738-991282682-1009\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Cecil Smith')
O4 - HKUS\S-1-5-21-3665436291-465681738-991282682-1009\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User 'Cecil Smith')
O4 - HKUS\S-1-5-21-3665436291-465681738-991282682-1009\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" (User 'Cecil Smith')
O4 - HKUS\S-1-5-21-3665436291-465681738-991282682-1009\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter (User 'Cecil Smith')
O4 - HKUS\S-1-5-21-3665436291-465681738-991282682-1009\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" (User 'Cecil Smith')
O4 - HKUS\S-1-5-21-3665436291-465681738-991282682-1009\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User 'Cecil Smith')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,7/McUpdatePortal.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195696043406
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4432/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: McAfee Application Installer Cleanup (0031551212272146) (0031551212272146mcinstcleanup) - Unknown owner - C:\DOCUME~1\CECILS~1\LOCALS~1\Temp\003155~1.EXE (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 12615 bytes


4 Apprentice

 • 

20.5K Posts

June 10th, 2008 13:00

If you run out of space just reply to yourself. Please follow my instructions in order, and use only the tools and the steps that I have posted for you. Malware removal needs to be done in a certain sequence in order for it to be effective.

10 Posts

June 10th, 2008 13:00

Thanks Bugbatter.  I did not know how to place them on one entry.  When I attempted to post it as one entry the message I received indicated that I had run out of space.  I am currently running my anti virus and Super Antispy Ware programs.  If I find any thing new with them i shall post it.

Eagle60

4 Apprentice

 • 

20.5K Posts

June 10th, 2008 13:00

There isn't much info available on this file: nosign.exe Argus
Do you have an Argus camera? Perhaps this is the software??

Please run HijackThis and place a checkmark next to the following:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU

and this if you, and Admin, or a security program did not set restrictions:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Close all windows except HijackThis and click "Fix Checked".
Close Hijackthis.

Run Disk Cleanup in each user's profile:
Click "Start > Programs > Accessories > System Tools > Disk Cleanup"
Please make sure only the following are checked:
-- Downloaded Program Files
-- Temporary Internet Files
-- Recycle Bin
-- Temporary Files
Click "OK" and Disk Cleanup will delete those files for you.

Reboot.


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version Java components and update.


  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u6 allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each of the Java versions.

  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.

Official JAVA Installation Instructions if needed.


After all that, please post a fresh HijackThis log. I would like to run a follow-up anti-malware scan later, but I don't want to give you too much to do all at once.


10 Posts

June 10th, 2008 23:00

I followed all of your previous instructions concerning disk clean and the latest Java.  The following is the latest Hijack This Log.

Eagle 60

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:27:44, on 6/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\nosign.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Sierra\Planner\Plnrnote.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm?rev=10262
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [nosign] C:\WINDOWS\\nosign.exe Argus
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,7/McUpdatePortal.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195696043406
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4432/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 11647 bytes

4 Apprentice

 • 

20.5K Posts

June 10th, 2008 23:00

You still have a few things to fix.

Please run HijackThis and place a checkmark next to the following:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
R3 - URLSearchHook: (no name) - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - (no file)
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU

and this if you, and Admin, or a security program did not set restrictions:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Close all windows except HijackThis and click "Fix Checked".
Close Hijackthis.
Reboot.

Please download Malwarebytes' Anti-Malware from Here or Here

  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
  • Update Malwarebytes' Anti-Malware
  • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • The next screen will ask you to select the drives to scan. Leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. :(see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.  Please include a fresh HijackThis log as well.

  • Notes:

    **If you encounter this message:"c:\program files\malwarebytes' Anti-Malware\mbamext.dll Unable to register the dll/ocx: RegSvr32 failed with exit code 0x5" Click on ignore mbamext.dll

    **If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.




10 Posts

June 11th, 2008 01:00

Here it is bugbatter.  Thanks for all you do!

Eagle 60

 

Malwarebytes' Anti-Malware 1.17
Database version: 846

9:13:57 PM 6/10/2008
mbam-log-6-10-2008 (21-13-57).txt

Scan type: Quick Scan
Objects scanned: 45128
Time elapsed: 12 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\atfxqogp.bore (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\atfxqogp.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\SYSTEM32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL_tobedeleted (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL_tobedeleted (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History\search_tobedeleted (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL_tobedeleted (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\tmlpcert2005 (Adware.EGDAccess) -> Quarantined and deleted successfully.
_________________________________________________________________________

Latest Hijack This log- Thanks again

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:20:22, on 6/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\nosign.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Sierra\Planner\Plnrnote.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm?rev=10262
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [nosign] C:\WINDOWS\\nosign.exe Argus
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Event Planner Reminders Tray Icon.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,7/McUpdatePortal.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195696043406
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/player.virtools.com/downloads/player/Install3.0/Installer.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4432/mcfscan.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 11314 bytes

4 Apprentice

 • 

20.5K Posts

June 11th, 2008 01:00

You're welcome. Wow, I'm glad we ran MBAM even though you had already used Super Anti-Spyware.

You have Viewpoint installed. Viewpoint developed a behavioral targeting product in 2006. Viewpoint is associated with a program called viewmgr.exe and the ViewPoint Media Player.
Viewpoint is bundled with AOL, AOL Instant Messenger, Adobe Atmosphere, Netscape 7, etc and sometimes not mentioned in the license agreement. Hardware manufacturers pre-install some of these applications.
ViewPoint Toolbar will redirect your search queries and also transmits non personally identifiable information back to their servers. The Viewpoint Toolbar is listed is also classified as a threat in the CounterSpy Threat Library because it hijacks your search queries and also transmits non personally identifiable information back to their servers.
Viewpoint Manager is a media player often bundled with AIM software. Viewpoint Manager is a useless add on.

Because Viewpoint's software will track your web surfing and tailor advertisements based on the web pages you are visiting, I suggest you remove the program.
** Note: Removing Viewpoint Media Player may cause the program that bundled it to not function as intended. For AOL and AIM it is needed to use their 3D icons known as Super Buddies and for customized themes, etc.
If you wish to remove Viewpoint, end process on ViewManager in Task Manager.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.

  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
  • Viewpoint Toolbar
  • Viewpoint Experience Technology
Then remove the Viewpoint folder in your Program Files.


After all that, if everything is running smoothly, it would be good to flush system Restore so you can start fresh.
To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)
Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.

Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.


Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.
If you have installed Malwarebytes' Anti-Malware as part of your cleaning procedures, keep it updated and use it to scan every so often for malware, or upgrade to the paid version for realtime scanning and auto updating.

You may have already taken some of these steps, and depending on your current security, you may not need to implement all of these:

1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

2. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
Note: Zone Alarm Firewall (by Checkpoint) has a free version http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads

3. You might consider installing Mozilla / Firefox.
http://www.mozilla.org/

4. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known
vulnerabilities.

5. Before using or purchasing any Spyware/Malware protection/removal program, always check the following Rogue/Suspect Spyware Lists.
http://www.spywarewarrior.com/rogue_anti-spyware.htm
http://www.malwarebytes.org/database.php

6. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.

7. Practice Safe Surfing with with TrendProtect by Trendmicro.
TrendProtect is a browser plugin that assigns a safety rating to domains listed in your search engine. TrendProtect also adds a new button to your browser's toolbar area. The icon and color of the button changes to indicate whether the page currently open is safe, unsafe, trusted, or unrated, or whether it contains unwanted content.

The following color codes are used by TrendProtect to indicate the safety of each site.

Red for Warning
Yellow for Use Caution
Green for Safe
Grey for Unknown

8. You might consider installing SpywareBlaster: http://www.javacoolsoftware.com/spywareblaster.html
It will:
Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.
Block spyware/tracking cookies in Internet Explorer and Mozilla Firefox.
Restrict the actions of potentially unwanted sites in Internet Explorer.
Tutorial here: http://www.bleepingcomputer.com/forums/tutorial49.html
Periodically check for updates.

9. Here are some helpful articles:
"So how did I get infected in the first place?"
by TonyKlein
http://computercops.biz/postlite7736-.html

"I'm not pulling your leg, honest"
by Sandi Hardmeier
http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

Let us know if we have not resolved your problem. Otherwise, you are good to go.
Happy and Safe Surfing!

Message Edited by Bugbatter on 06-10-2008 10:53 PM

10 Posts

June 11th, 2008 02:00

The software that you mentioned is part of AIM.  My children use this program.  Is there any way to remove this program and still allow the AIM to work?  I would be just as happy to remove AIM entirely from this computer.

 

Thanks for everything.  Have a pleasent week.

 

Eagle 60

4 Apprentice

 • 

20.5K Posts

June 11th, 2008 10:00

You're welcome. :)

"Is there any way to remove this program and still allow the AIM to work?"

I don't know. I do not use AIM, so I cannot test it. Most likely, if you remove it, even if AIM works without it, when AIM updates, Viewpoint will be installed again with the updated version.
You might as well leave it on there if AIM is being used.
Message Edited by Bugbatter on 06-11-2008 07:54 AM
No Events found!

Top