Announcement Banner
UNSOLVED

klhack

updated

18 years ago

K

klhack

8 Posts

0

5657

April 7th, 2009 07:00

system security version 4.51

I need some help to get this out of my computer system. I have a log list if anyone knows what i am talking about. i went on to trend micro hijackthis to find out how to get rid of it and i can't find it in my system..... can anyone help me?

  • bamajim

    10376 Posts

    542

    0

    Posted April 8th, 2009 08:00

    klhack

    Post your Hijackthis log as a reply to this thread and we will take a look

  • klhack

    8 Posts

    542

    0

    Posted April 8th, 2009 13:00

    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [DellOSD] C:\Windows\System32\FastUserSwitching.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {2703049B-D81D-4763-A3C6-AF8932FCBD8F} (CheckFileStatus.UserControl1) -
    O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) -
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
    O23 - Service: Remote Access Media Server (Apache2.2) - Apache Software Foundation - C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: DELLODDSrv - Unknown owner - C:\Windows\System32\WinService.exe
    O23 - Service: dldt_device -   - C:\Windows\system32\dldtcoms.exe
    O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

  • bamajim

    10376 Posts

    542

    0

    Posted April 8th, 2009 15:00

    klhack

    The log you posted is missing the top portion, Please repost the entire log

  • klhack

    8 Posts

    542

    0

    Posted April 8th, 2009 17:00

    StartupList report, 4/7/2009, 8:49:26 AM
    StartupList version: 1.52.2
    Started from : C:\Users\KAREN HACKETT\Desktop\HijackThis.EXE
    Detected: Windows Vista SP1 (WinNT 6.00.1905)
    Detected: Internet Explorer v7.00 (7.00.6001.18000)
    * Using default options
    ==================================================

    Running processes:

    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Dell\DellDock\DellDock.exe
    C:\Windows\RtHDVCpl.exe
    C:\Windows\System32\WLTRAY.EXE
    C:\Windows\System32\FastUserSwitching.exe
    C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Windows\UMStor\Res.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Dell V305\dldtmon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\System32\MediaButtons.exe
    C:\Program Files\Dell Remote Access\ezi_ra.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Users\KAREN HACKETT\Documents\RCA Detective\RCADetective.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\System32\TestUnitReady.exe
    C:\Windows\System32\DELLODD.exe
    C:\Program Files\Dell V305\dldtMsdMon.exe
    C:\Windows\System32\DELLOSD.exe
    C:\Windows\System32\mobsync.exe
    C:\ProgramData\106570476\106570476.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
    C:\Program Files\AVG\AVG8\aAvgApi.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\windows defender\MSASCui.exe
    C:\Users\KAREN HACKETT\Desktop\HijackThis.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\Users\KAREN HACKETT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
    Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
    RCA Detective.lnk = C:\Users\KAREN HACKETT\Documents\RCA Detective\RCADetective.exe

    Shell folders Common Startup:
    [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
    Dell Remote Access.lnk = ?
    Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\Windows\system32\userinit.exe,

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    RtHDVCpl = RtHDVCpl.exe
    Broadcom Wireless Manager UI = C:\Windows\system32\WLTRAY.exe
    DellOSD = C:\Windows\System32\FastUserSwitching.exe
    Google Desktop Search = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    PCMService = "C:\Program Files\Dell\MediaDirect\PCMService.exe"
    ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    Dell DataSafe Online = "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
    dellsupportcenter = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    USB Storage Toolbox = C:\Windows\UMStor\Res.EXE
    dldtmon.exe = "C:\Program Files\Dell V305\dldtmon.exe"
    dldtamon = "C:\Program Files\Dell V305\dldtamon.exe"
    Easy Dock = C:\Users\KAREN HACKETT\Documents\RCA EasyRip\EZDock.exe
    QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
    IgfxTray = C:\Windows\system32\igfxtray.exe
    HotKeysCmds = C:\Windows\system32\hkcmd.exe
    Persistence = C:\Windows\system32\igfxpers.exe
    Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe"
    AVG8_TRAY = C:\PROGRA~1\AVG\AVG8\avgtray.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

    (Default) =

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    ehTray.exe = C:\Windows\ehome\ehTray.exe
    WMPNSCFG = C:\Program Files\Windows Media Player\WMPNSCFG.exe

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    [OptionalComponents]
     =

    --------------------------------------------------

    Load/Run keys from C:\Windows\WIN.INI:

    load=*INI section not found*
    run=*INI section not found*

    Load/Run keys from Registry:

    HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\Windows: load=
    HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll

    --------------------------------------------------

    Shell & screensaver key from C:\Windows\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=explorer.exe
    SCRNSAVE.EXE=C:\Windows\system32\Ribbons.scr
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry key not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
    WormRadar.com IESiteBlocker.NavFilter - C:\Program Files\AVG\AVG8\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
    NCO 2.0 IE BHO - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
    Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll - {6D53EC84-6AAE-4787-AEEE-F4628F01010C}
    (no name) - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL - {A057A204-BACC-4D26-9990-79A187E2698E}
    (no name) - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
    (no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
    Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E}
    Browser Address Error Redirector - C:\Program Files\Dell\BAE\BAE.dll - {CA6319C0-31B7-401E-A518-A07C3DB8F777}
    (no name) - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll - {d2ce3e00-f94a-4740-988e-03dc2f38c34f}
    (no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Norton Internet Security - Run Full System Scan - KAREN HACKETT.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [CheckFileStatus.UserControl1]
    InProcServer32 = C:\Windows\Downloaded Program Files\CheckFileStatus.ocx
    CODEBASE = https://am.hrblock.com/ActivexComponent/CheckFileStatus.CAB

    [PogoWebLauncher Control]
    InProcServer32 = C:\Windows\DOWNLO~1\POGOWE~1.OCX
    CODEBASE = http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB

    [System Requirements Lab Class]
    InProcServer32 = C:\Windows\Downloaded Program Files\sysreqlab_ind.dll
    CODEBASE = http://www.srtest.com/srl_bin/sysreqlab_ind.cab
    OSD = C:\Windows\Downloaded Program Files\sysreqlab.osd

    [Invoke Solutions Participant Control(MR)]
    InProcServer32 = C:\PROGRA~1\INVOKE~1\PARTIC~1\6.2\MILIVE~1.OCX
    CODEBASE = http://rms2.invokesolutions.com/events/bin/6.2.0.1450/MILive.cab

    --------------------------------------------------

    Enumerating Winsock LSP files:

    NameSpace #1: C:\Windows\system32\NLAapi.dll
    NameSpace #2: C:\Windows\system32\napinsp.dll
    NameSpace #3: C:\Windows\system32\pnrpnsp.dll
    NameSpace #4: C:\Windows\system32\pnrpnsp.dll

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    WebCheck: C:\Windows\system32\webcheck.dll

    --------------------------------------------------
    End of report, 10,445 bytes
    Report generated in 0.171 seconds

    Command line options:
       /verbose  - to add additional info on each section
       /complete - to include empty sections and unsuspicious data
       /full     - to include several rarely-important sections
       /force9x  - to include Win9x-only startups even if running on WinNT
       /forcent  - to include WinNT-only startups even if running on Win9x
       /forceall - to include all Win9x and WinNT startups, regardless of platform
       /history  - to list version history only

  • klhack

    8 Posts

    542

    0

    Posted April 8th, 2009 17:00

    StartupList report, 4/7/2009, 8:49:26 AM
    StartupList version: 1.52.2
    Started from : C:\Users\KAREN HACKETT\Desktop\HijackThis.EXE
    Detected: Windows Vista SP1 (WinNT 6.00.1905)
    Detected: Internet Explorer v7.00 (7.00.6001.18000)
    * Using default options
    ==================================================

    Running processes:

    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Dell\DellDock\DellDock.exe
    C:\Windows\RtHDVCpl.exe
    C:\Windows\System32\WLTRAY.EXE
    C:\Windows\System32\FastUserSwitching.exe
    C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Windows\UMStor\Res.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Dell V305\dldtmon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\System32\MediaButtons.exe
    C:\Program Files\Dell Remote Access\ezi_ra.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Users\KAREN HACKETT\Documents\RCA Detective\RCADetective.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Windows\System32\TestUnitReady.exe
    C:\Windows\System32\DELLODD.exe
    C:\Program Files\Dell V305\dldtMsdMon.exe
    C:\Windows\System32\DELLOSD.exe
    C:\Windows\System32\mobsync.exe
    C:\ProgramData\106570476\106570476.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
    C:\Program Files\AVG\AVG8\aAvgApi.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\windows defender\MSASCui.exe
    C:\Users\KAREN HACKETT\Desktop\HijackThis.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\Users\KAREN HACKETT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
    Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
    RCA Detective.lnk = C:\Users\KAREN HACKETT\Documents\RCA Detective\RCADetective.exe

    Shell folders Common Startup:
    [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
    Dell Remote Access.lnk = ?
    Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\Windows\system32\userinit.exe,

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    RtHDVCpl = RtHDVCpl.exe
    Broadcom Wireless Manager UI = C:\Windows\system32\WLTRAY.exe
    DellOSD = C:\Windows\System32\FastUserSwitching.exe
    Google Desktop Search = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    PCMService = "C:\Program Files\Dell\MediaDirect\PCMService.exe"
    ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    Dell DataSafe Online = "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
    dellsupportcenter = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    USB Storage Toolbox = C:\Windows\UMStor\Res.EXE
    dldtmon.exe = "C:\Program Files\Dell V305\dldtmon.exe"
    dldtamon = "C:\Program Files\Dell V305\dldtamon.exe"
    Easy Dock = C:\Users\KAREN HACKETT\Documents\RCA EasyRip\EZDock.exe
    QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
    IgfxTray = C:\Windows\system32\igfxtray.exe
    HotKeysCmds = C:\Windows\system32\hkcmd.exe
    Persistence = C:\Windows\system32\igfxpers.exe
    Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe"
    AVG8_TRAY = C:\PROGRA~1\AVG\AVG8\avgtray.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

    (Default) =

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    ehTray.exe = C:\Windows\ehome\ehTray.exe
    WMPNSCFG = C:\Program Files\Windows Media Player\WMPNSCFG.exe

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    [OptionalComponents]
     =

    --------------------------------------------------

    Load/Run keys from C:\Windows\WIN.INI:

    load=*INI section not found*
    run=*INI section not found*

    Load/Run keys from Registry:

    HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\Windows: load=
    HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll

    --------------------------------------------------

    Shell & screensaver key from C:\Windows\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=explorer.exe
    SCRNSAVE.EXE=C:\Windows\system32\Ribbons.scr
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry key not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    --------------------------------------------------


    Enumerating Browser Helper Objects:

    AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
    WormRadar.com IESiteBlocker.NavFilter - C:\Program Files\AVG\AVG8\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
    NCO 2.0 IE BHO - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
    Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll - {6D53EC84-6AAE-4787-AEEE-F4628F01010C}
    (no name) - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL - {A057A204-BACC-4D26-9990-79A187E2698E}
    (no name) - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
    (no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
    Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E}
    Browser Address Error Redirector - C:\Program Files\Dell\BAE\BAE.dll - {CA6319C0-31B7-401E-A518-A07C3DB8F777}
    (no name) - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll - {d2ce3e00-f94a-4740-988e-03dc2f38c34f}
    (no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Norton Internet Security - Run Full System Scan - KAREN HACKETT.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [CheckFileStatus.UserControl1]
    InProcServer32 = C:\Windows\Downloaded Program Files\CheckFileStatus.ocx
    CODEBASE = https://am.hrblock.com/ActivexComponent/CheckFileStatus.CAB

    [PogoWebLauncher Control]
    InProcServer32 = C:\Windows\DOWNLO~1\POGOWE~1.OCX
    CODEBASE = http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB

    [System Requirements Lab Class]
    InProcServer32 = C:\Windows\Downloaded Program Files\sysreqlab_ind.dll
    CODEBASE = http://www.srtest.com/srl_bin/sysreqlab_ind.cab
    OSD = C:\Windows\Downloaded Program Files\sysreqlab.osd

    [Invoke Solutions Participant Control(MR)]
    InProcServer32 = C:\PROGRA~1\INVOKE~1\PARTIC~1\6.2\MILIVE~1.OCX
    CODEBASE = http://rms2.invokesolutions.com/events/bin/6.2.0.1450/MILive.cab

    --------------------------------------------------

    Enumerating Winsock LSP files:

    NameSpace #1: C:\Windows\system32\NLAapi.dll
    NameSpace #2: C:\Windows\system32\napinsp.dll
    NameSpace #3: C:\Windows\system32\pnrpnsp.dll
    NameSpace #4: C:\Windows\system32\pnrpnsp.dll

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    WebCheck: C:\Windows\system32\webcheck.dll

    --------------------------------------------------
    End of report, 10,445 bytes
    Report generated in 0.171 seconds

    Command line options:
       /verbose  - to add additional info on each section
       /complete - to include empty sections and unsuspicious data
       /full     - to include several rarely-important sections
       /force9x  - to include Win9x-only startups even if running on WinNT
       /forcent  - to include WinNT-only startups even if running on Win9x
       /forceall - to include all Win9x and WinNT startups, regardless of platform
       /history  - to list version history only

  • bamajim

    10376 Posts

    542

    0

    Posted April 9th, 2009 10:00


    klhack

    1. Go HERE and download File Lister.
    • Save it to your Desktop
    • Rt Click ->> Extract all ->> And extract it to your Desktop
    • Additional help on extracting zip files can be found HERE
    • Open the File Lister Folder.
    • Note: Leave the FileLister.vbe file in the folder and run it from there.
    • Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
    • As the program runs, it will appear that nothing is happening.
    • When the program is fnished it will produce a log for you C:\Files.txt

    Copy and paste the contents of that log in your reply.

  • klhack

    8 Posts

    542

    0

    Posted April 11th, 2009 15:00

     

    this is what i am coming up with... i don't think it is right . how long does the program take?

     

    adp94xx
    adpahci
    amdide
    arcsas
    bcm42rly
    bcm43xx
    blbdrive
    bowser
    brfiltlo
    brfiltup
    brserid
    brserwdm
    brusbmdm
    brusbser
    circlass
    clfs
    coh_mon
    crusoe
    dfsc
    dlxpdisplayname
    dxgkrnl
    e1express
    e1g60
    ecache
    eectrl
    elxstor
    eraserutilrebootdrv
    errdev
    fileinfo
    filetrace
    gagp30kx
    hidbth
    hidir
    hpcisss
    iastorv
    idsvix86
    igfx
    ipmidrv
    iscsiprt
    iteatapi
    iteraid
    jl2005c
    lltdio
    lsi_fc
    lsi_sas
    lsi_scsi
    luafv
    megasas
    megasr
    mpio
    mpsdrv
    mrxsmb10
    mrxsmb20
    msahci
    msdsm
    msisadrv
    msrpc
    nativewifip
    nfrd960
    nsiproxy
    ntrigdigi
    nvstor
    packet
    peauth
    ql2300
    ql40xx
    qwavedrv
    r300
    rdpencdd
    rspndr
    rtl8169
    rtndpt60
    rtstor
    sbp2port
    sermouse
    sffdisk
    sffp_mmc
    sffp_sd
    sisraid2
    sisraid4
    spbbcdrv
    spldr
    srtsp
    srtspl
    srtspx
    srv2
    srvnet
    symim
    symndisv
    tcpip6
    tcpipreg
    tdx
    tssecsrv
    tunmp
    tunnel
    uagp35
    uliagpkx
    uliahci
    ulsata
    ulsata2
    umbus
    usbcir
    viac7
    volmgr
    volmgrx
    vsmraid
    wacompen
    wanarpv6
    wdf01000
    wmiacpi
    wpdusb
    aelookupsvc
    aertfilters
    apache2.2
    appinfo
    audioendpointbuilder
    automatic liveupdate scheduler
    ***
    certpropsvc
    cltnetcnservice
    comhost
    delloddsrv
    dfsr
    dldtcatscustconnectservice
    dldt_device
    dockloginservice
    dsl-db
    dsl-fs-sync
    ehrecvr
    ehsched
    ehstart
    emdmgmt
    fdphost
    fdrespub
    googledesktopmanager-092308-165331
    gotoassist
    gpsvc
    hnmsvc
    ikeext
    ipbusenum
    iphlpsvc
    keyiso
    ktmrm
    liveupdate notice
    lltdsvc
    mcx2svc
    mmcss
    mpssvc
    msiscsi
    netprofm
    nlasvc
    p2pimsvc
    p2psvc
    pcasvc
    pnrpautoreg
    pnrpsvc
    profsvc
    qwave
    scpolicysvc
    sdrsvc
    sessionenv
    slsvc
    sluinotify
    snmptrap
    sprtsvc_dellsupportcenter
    stllssvr
    sysmain
    tabletinputservice
    tbs
    threadorder
    trustedinstaller
    ui0detect
    uxsms
    wcncsvc
    wcspluginservice
    wdiservicehost
    wdisystemhost
    wecsvc
    wercplsupport
    wersvc
    windefend
    winhttpautoproxysvc
    winrm
    wlansvc
    wltrysvc
    wpcsvc
    wpdbusenum
    wsearch

     

  • klhack

    8 Posts

    542

    0

    Posted April 11th, 2009 15:00

    it also tells me that c:\Files.txt  cannot be found. then it askes me if i would like to create it and i hit yes and then it opens to a blank notepad and thats it.

  • bamajim

    10376 Posts

    542

    0

    Posted April 13th, 2009 07:00


    klhack

    Please download Malwarebytes' Anti-Malware from Here or Here

    Double Click mbam-setup.exe to install the application.
    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.

    Extra Note:

    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

  • klhack

    8 Posts

    114

    0

    Posted April 13th, 2009 14:00

    Malwarebytes' Anti-Malware 1.36
    Database version: 1977
    Windows 6.0.6001 Service Pack 1

    4/13/2009 4:04:52 PM
    mbam-log-2009-04-13 (16-04-52).txt

    Scan type: Quick Scan
    Objects scanned: 70870
    Time elapsed: 3 minute(s), 37 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 8
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\cpbrkpie.coupon6ctrl.1 (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{a85a5e6a-de2c-4f4e-99dc-f469df5a0eec} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\TypeLib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{6e780f0b-bcd6-40cb-b2db-7af47ab4d4a4} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a750a6d862d4} (Adware.Coupons) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Windows\CouponPrinter.ocx (Adware.Coupons) -> Quarantined and deleted successfully.
    C:\Users\KAREN HACKETT\AppData\Local\Temp\Low\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully.