XBedoya
asked on
System Restore Problem no internet access
This computer is not opening the internet. Tried to restore it to a prior point but is not taking any of them. Then a pop-up from McAfee privacy service appears and doesn't go away, it didn't do this before.
Try disable McAfee see if you can gain internat access?
Looks like McAfee removes the bad file --> c:/window/system32/fauwcoc q.dll
but didn't clean up the relevant registry entry, that's why the error comes up.
Do you have access to a pc with online access? If so, please download hijackthis.
Can you run Hijackthis and show us the log please?
http://danborg.org/spy/hjt/alternativ.exe
Open Hijackthis, click "Do a system scan and save a logfile" please don't fix anything yet.
but didn't clean up the relevant registry entry, that's why the error comes up.
Do you have access to a pc with online access? If so, please download hijackthis.
Can you run Hijackthis and show us the log please?
http://danborg.org/spy/hjt/alternativ.exe
Open Hijackthis, click "Do a system scan and save a logfile" please don't fix anything yet.
ASKER
I did disable McAfee but still can't go on-line.
I will download the hijackthis from another computer.
I will download the hijackthis from another computer.
ASKER
rpggamergirl,
Here it is:
Logfile of HijackThis v1.99.1
Scan saved at 11:36:19 PM, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\Ati2ev xx.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\spools v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
c:\program files\mcafee.com\agent\mcd etect.exe
c:\PROGRA~1\mcafee.com\vso \mcshield. exe
c:\PROGRA~1\mcafee.com\age nt\mctsksh d.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\PER SON~1\MpfS ervice.exe
C:\PROGRA~1\McAfee\SPAMKI~ 1\MSKSrvr. exe
C:\WINDOWS\system32\svchos t.exe
C:\Program Files\RegistrySmart\Regist rySmart.ex e
C:\WINDOWS\system32\wuaucl t.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\Update Service\is sch.exe
C:\Program Files\McAfee.com\VSO\oascl nt.exe
C:\PROGRA~1\mcafee.com\age nt\mcagent .exe
C:\WINDOWS\System32\DLA\DL ACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
c:\program files\mcafee.com\vso\mcvss hld.exe
C:\PROGRA~1\McAfee\SPAMKI~ 1\MskAgent .exe
C:\PROGRA~1\McAfee.com\PER SON~1\MpfT ray.exe
c:\progra~1\mcafee.com\vso \mcvsescn. exe
C:\PROGRA~1\McAfee.com\Age nt\mcregwi z.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex. exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\Java\jre1.5.0_03\bin \jusched.e xe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\DOCUME~1\JUSTIN~1\LOCAL S~1\Temp\M BDownloade r_876919.e xe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDispla y.exe
C:\WINDOWS\retadpu572.exe
C:\PROGRA~1\McAfee.com\PER SON~1\MpfA gent.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\WINDOWS\system32\dlcjco ms.exe
C:\Program Files\iTunes\iTunesHelper. exe
C:\PROGRA~1\mcafee.com\mps \mscifapp. exe
C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\Tina Morris\Desktop\alternativ. exe
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://www.dell.com
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5 838F569A31 D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH elper.dll
O2 - BHO: 0 - {1BD6FE72-D35B-4A75-1C86-3 8D53F2D146 2} - C:\Program Files\Windows NT\qufatygyw308.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-7 3F568BCB24 E} - c:\program files\mcafee.com\mps\mcbrh lpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B 191550C2A2 2} - c:\program files\mcafee.com\mps\popup killer.dll
O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6 EBB8AF1900 0} - c:\program files\mcafee\spamkiller\mc apfbho.dll
O2 - BHO: (no name) - {4650A081-64C9-44E4-9F6F-5 08F7E4C80B D} - C:\Program Files\Messenger\mesobif831 22.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0 0123456789 0} - C:\WINDOWS\System32\DLA\DL ASHX_W.DLL
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8 EA1C75885F 9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {A7DE354A-CACE-43FC-9906-D A22A557A15 1} - C:\WINDOWS\system32\jkhhe. dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C F10577473F 7} - c:\program files\google\googletoolbar 2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C E66B5AD205 D} - C:\Program Files\Google\GoogleToolbar Notifier\2 .0.301.716 4\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A 07C3DB8F77 7} - c:\Program Files\BAE\BAE.dll
O2 - BHO: (no name) - {DC192567-65F9-4AB6-ADB7-E 13575F8172 6} - C:\WINDOWS\system32\qomkii j.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9 05236F6F65 5} - c:\progra~1\mcafee.com\vso \mcvsshl.d ll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0 09027A5CD4 F} - c:\program files\google\googletoolbar 2.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A A305ED9D92 2} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update Service\is uspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update Service\is sch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VS O\mcmnhdlr .exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oascl nt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age nt\mcagent .exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age nt\McUpdat e.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~ 1\MSKDetct .exe /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL ACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~ 1\MskAgent .exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso \mcvsshld. exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PER SON~1\MpfT ray.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Age nt\mcregwi z.exe /autorun
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\ DRIVERS\W3 2X86\3\DLC Jtime.dll, _RunDLLEnt ry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin \jusched.e xe
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\Regist rySmart.ex e" -boot
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatc h Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\JUSTIN~1\LOCAL S~1\Temp\M BDownloade r_876919.e xe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu572.exe 61A847B5BBF728173599284503 996897C881 250221C867 0836AC4FA7 C883320174 9139
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe " -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper. exe"
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps \mscifapp. exe /embedding
O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\fauwc ocq.dll",f orkonce
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm801MGUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\j2re1.4.2_03\bi n\npjpi142 _03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\j2re1.4.2_03\bi n\npjpi142 _03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B 4C75499B57 8} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3 582CCF489E 1} - c:\program files\mcafee\spamkiller\mc apfbho.dll
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3 582CCF489E 1} - c:\program files\mcafee\spamkiller\mc apfbho.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0 0B0D0A1DE4 5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0 0C0F0318AF E} - C:\WINDOWS\system32\Shdocv w.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1 E41684E07B B} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~ 1\GOEC62~1 .DLL
O20 - Winlogon Notify: jkhhe - C:\WINDOWS\system32\jkhhe. dll
O20 - Winlogon Notify: qomkiij - C:\WINDOWS\SYSTEM32\qomkii j.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev xx.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjco ms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc. exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterServi ce.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcd etect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso \mcshield. exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\age nt\mctsksh d.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age nt\mcupdmg r.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PER SON~1\MpfS ervice.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~ 1\MSKSrvr. exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NC S\Sync\Net Svc.exe
Here it is:
Logfile of HijackThis v1.99.1
Scan saved at 11:36:19 PM, on 8/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
c:\program files\mcafee.com\agent\mcd
c:\PROGRA~1\mcafee.com\vso
c:\PROGRA~1\mcafee.com\age
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\McAfee.com\PER
C:\PROGRA~1\McAfee\SPAMKI~
C:\WINDOWS\system32\svchos
C:\Program Files\RegistrySmart\Regist
C:\WINDOWS\system32\wuaucl
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\Update
C:\Program Files\McAfee.com\VSO\oascl
C:\PROGRA~1\mcafee.com\age
C:\WINDOWS\System32\DLA\DL
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
c:\program files\mcafee.com\vso\mcvss
C:\PROGRA~1\McAfee\SPAMKI~
C:\PROGRA~1\McAfee.com\PER
c:\progra~1\mcafee.com\vso
C:\PROGRA~1\McAfee.com\Age
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\Java\jre1.5.0_03\bin
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\DOCUME~1\JUSTIN~1\LOCAL
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDispla
C:\WINDOWS\retadpu572.exe
C:\PROGRA~1\McAfee.com\PER
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\WINDOWS\system32\dlcjco
C:\Program Files\iTunes\iTunesHelper.
C:\PROGRA~1\mcafee.com\mps
C:\Program Files\Google\GoogleToolbar
C:\Program Files\Digital Line Detect\DLG.exe
C:\Documents and Settings\Tina Morris\Desktop\alternativ.
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: 0 - {1BD6FE72-D35B-4A75-1C86-3
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-7
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B
O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6
O2 - BHO: (no name) - {4650A081-64C9-44E4-9F6F-5
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8
O2 - BHO: (no name) - {A7DE354A-CACE-43FC-9906-D
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A
O2 - BHO: (no name) - {DC192567-65F9-4AB6-ADB7-E
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VS
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oascl
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PER
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Age
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\Regist
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatc
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\JUSTIN~1\LOCAL
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu572.exe 61A847B5BBF728173599284503
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps
O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\system32\fauwc
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm801MGUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
O20 - Winlogon Notify: jkhhe - C:\WINDOWS\system32\jkhhe.
O20 - Winlogon Notify: qomkiij - C:\WINDOWS\SYSTEM32\qomkii
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjco
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcd
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\age
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PER
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NC
Your hijackthis log is very much infected with vundo and conhook among other nasties.
You also MUST uninstall this rogue program that you have there --> WinAntiSpyware 2007
1. Please download VundoFix.exe to your desktop.(run Vundofix twice and show us the log) to check for remaining bad entries.)
http://www.atribune.org/ccount/click.php?id=4
* Double-click VundoFix.exe to run it.
* Click the "Scan for Vundo" button.
* Once it's done scanning, click the "Remove Vundo" button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will reboot your computer, click OK.
* Please post the contents of C:\vundofix.txt.
Note: It is possible that VundoFix encounters a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.
2. Download ComboFix to your Desktop, from either of these locations:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double click "combofix.exe" and follow the prompts.
When finished, it shall produce a log for you.
Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
3. Show us a fresh hijackthis after please.
You also MUST uninstall this rogue program that you have there --> WinAntiSpyware 2007
1. Please download VundoFix.exe to your desktop.(run Vundofix twice and show us the log) to check for remaining bad entries.)
http://www.atribune.org/ccount/click.php?id=4
* Double-click VundoFix.exe to run it.
* Click the "Scan for Vundo" button.
* Once it's done scanning, click the "Remove Vundo" button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will reboot your computer, click OK.
* Please post the contents of C:\vundofix.txt.
Note: It is possible that VundoFix encounters a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above
instructions starting from "Click the Scan for Vundo button." when
VundoFix appears at reboot.
2. Download ComboFix to your Desktop, from either of these locations:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Double click "combofix.exe" and follow the prompts.
When finished, it shall produce a log for you.
Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
3. Show us a fresh hijackthis after please.
ASKER
Good Morning,
I did as you said and here are the logs for the 3 applications: (this is gonna be a long one)
I have a question there are two programs running in this computer and I wonder if I should delete them too, Registry Smart and Registry Booty.
1. VundoFix V6.5.7
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Scan started at 8:55:22 AM 8/9/2007
Listing files found while scanning....
C:\windows\system32\dbsdne pv.exe
C:\windows\system32\ddcbxu t.dll
C:\windows\system32\efyeij vp.ini
C:\WINDOWS\system32\ehhkj. bak1
C:\WINDOWS\system32\ehhkj. bak2
C:\WINDOWS\system32\ehhkj. ini
C:\WINDOWS\system32\ehhkj. ini2
C:\WINDOWS\system32\ehhkj. tmp
C:\WINDOWS\system32\fauwco cq.dll
C:\WINDOWS\system32\hkxyhe nc.dll
C:\windows\system32\jdslxy ap.exe
C:\WINDOWS\system32\jkhhe. dll
C:\windows\system32\mesmid uw.dll
C:\windows\system32\pvjiey fe.dll
C:\WINDOWS\system32\qcocwu af.ini
C:\WINDOWS\system32\qomkii j.dll
C:\windows\system32\rwelst ax.exe
C:\windows\system32\skuvft np.exe
Beginning removal...
Attempting to delete C:\windows\system32\dbsdne pv.exe
C:\windows\system32\dbsdne pv.exe Has been deleted!
Attempting to delete C:\windows\system32\ddcbxu t.dll
C:\windows\system32\ddcbxu t.dll Has been deleted!
Attempting to delete C:\windows\system32\efyeij vp.ini
C:\windows\system32\efyeij vp.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ehhkj. bak1
C:\WINDOWS\system32\ehhkj. bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ehhkj. bak2
C:\WINDOWS\system32\ehhkj. bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ehhkj. ini
C:\WINDOWS\system32\ehhkj. ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ehhkj. ini2
C:\WINDOWS\system32\ehhkj. ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ehhkj. tmp
C:\WINDOWS\system32\ehhkj. tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\fauwco cq.dll
C:\WINDOWS\system32\fauwco cq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\hkxyhe nc.dll
C:\WINDOWS\system32\hkxyhe nc.dll Has been deleted!
Attempting to delete C:\windows\system32\jdslxy ap.exe
C:\windows\system32\jdslxy ap.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\jkhhe. dll
C:\WINDOWS\system32\jkhhe. dll Has been deleted!
Attempting to delete C:\windows\system32\mesmid uw.dll
C:\windows\system32\mesmid uw.dll Has been deleted!
Attempting to delete C:\windows\system32\pvjiey fe.dll
C:\windows\system32\pvjiey fe.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\qcocwu af.ini
C:\WINDOWS\system32\qcocwu af.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\qomkii j.dll
C:\WINDOWS\system32\qomkii j.dll Has been deleted!
Attempting to delete C:\windows\system32\rwelst ax.exe
C:\windows\system32\rwelst ax.exe Has been deleted!
Attempting to delete C:\windows\system32\skuvft np.exe
C:\windows\system32\skuvft np.exe Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.7
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Scan started at 9:04:25 AM 8/9/2007
Listing files found while scanning....
No infected files were found.
2. ComboFix 07-08-09.3 - "Tina Morris" 2007-08-09 9:13:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18. 159 [GMT -4:00]
* Created a new restore point
(((((((((((((((((((((((((( (((((((((( ((( Other Deletions )))))))))))))))))))))))))) )))))))))) )))))))))) )))
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\sales monitor
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\FindI t.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\FindI tHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\findi thotxp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\findi txp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\Highl ight.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\Highl ightHot.bm p
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\highl ighthotxp. png
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\highl ightxp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\Refer ence.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\Refer enceHot.bm p
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\refer encehotxp. png
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\refer encexp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\scree nsaver.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\starw are_toolba r_icon.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\Weath er.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\weath erhotxp.pn g
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\but tons\weath erxp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\con texts\erro r.xml
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\con texts\rela ted.xml
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\Starw are316\con texts\trav el.xml
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\winan tispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\winan tispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLI C~1.\winan tispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\FindIt .bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\FindIt Hot.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\findit hotxp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\findit xp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\Highli ght.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\Highli ghtHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\highli ghthotxp.p ng
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\highli ghtxp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\Refere nce.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\Refere nceHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\refere ncehotxp.p ng
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\refere ncexp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\screen saver.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\starwa re_toolbar _icon.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\Weathe r.bmp
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\weathe rhotxp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\butt ons\weathe rxp.png
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\cont exts\error .xml
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\cont exts\relat ed.xml
C:\DOCUME~1\ALLUSE~1\APPLI C~1\Starwa re316\cont exts\trave l.xml
C:\DOCUME~1\ALLUSE~1\APPLI C~1\WinAnt iSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLI C~1\WinAnt iSpyware 2007\Data\ProductCode
C:\DOCUME~1\JUSTIN~1\APPLI C~1\..\err .log
C:\DOCUME~1\JUSTIN~1\APPLI C~1\WinAnt iSpyware 2007
C:\DOCUME~1\JUSTIN~1\APPLI C~1\WinAnt iSpyware 2007\Logs\update.log
C:\DOCUME~1\MIKEMO~1\APPLI C~1\..\err .log
C:\DOCUME~1\MIKEMO~1\APPLI C~1\WinAnt iSpyware 2007
C:\DOCUME~1\MIKEMO~1\APPLI C~1\WinAnt iSpyware 2007\Logs\update.log
C:\DOCUME~1\TINAMO~1\APPLI C~1.\winan tispyware 2007
C:\DOCUME~1\TINAMO~1\APPLI C~1.\winan tispyware 2007\Logs\update.log
C:\DOCUME~1\TINAMO~1\APPLI C~1\..\err .log
C:\DOCUME~1\TINAMO~1\APPLI C~1\WinAnt iSpyware 2007\Logs\update.log
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.e xe
C:\Program Files\Common Files\Yazzle1281OinUninsta ller.exe
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Scree nSaver\Ima ges\0033B6 76.urr
C:\Program Files\FunWebProducts\Scree nSaver\Ima ges\00A5B0 04.urr
C:\Program Files\FunWebProducts\Share d\06E84DBA .dat
C:\Program Files\Messenger\mesobif831 22.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\Hist ory\search 2
C:\Program Files\MyWebSearch\bar\Sett ings\s_pid .dat
C:\Program Files\MyWebSearch\bar\Sett ings\setti ng2.htm
C:\Program Files\MyWebSearch\bar\Sett ings\setti ng2.htm.ba k
C:\Program Files\MyWebSearch\bar\Sett ings\setti ngs.dat
C:\Program Files\MyWebSearch\bar\Sett ings\setti ngs.dat.ba k
C:\Program Files\Windows NT\qufatygyw.dll
C:\Program Files\Windows NT\qufatygyw15.dll
C:\Program Files\Windows NT\qufatygyw191.dll
C:\Program Files\Windows NT\qufatygyw211.dll
C:\Program Files\Windows NT\qufatygyw252.dll
C:\Program Files\Windows NT\qufatygyw281.dll
C:\Program Files\Windows NT\qufatygyw308.dll
C:\Program Files\Windows NT\qufatygyw434.dll
C:\Program Files\Windows NT\qufatygyw620.dll
C:\Program Files\Windows NT\qufatygyw681.dll
C:\temp\0c2
C:\temp\0c2\tmpRC.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\temp\tn3
C:\WINDOWS\retadpu572.exe
C:\WINDOWS\system32\awlqpu lq.exe
C:\WINDOWS\system32\B0
C:\WINDOWS\system32\B0\mws pasrt83122 .exe
C:\WINDOWS\system32\b02FdU e
C:\WINDOWS\system32\b02FdU e\b02FdUe1 065.exe
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\B1\wr7 3.exe
C:\WINDOWS\system32\B2
C:\WINDOWS\system32\B2\st2 .exe
C:\WINDOWS\system32\B5
C:\WINDOWS\system32\cxstjp ri.exe
C:\WINDOWS\system32\dpdkpr lx.exe
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver s\core.cac he.dsk
C:\WINDOWS\system32\driver s\core.sys
C:\WINDOWS\system32\driver s\fopn.sys
C:\WINDOWS\system32\gokgsa vp.exe
C:\WINDOWS\system32\gsjeio ch.exe
C:\WINDOWS\system32\jiytdx bx.exe
C:\WINDOWS\system32\kbjaoa bk.exe
C:\WINDOWS\system32\vmpyxq bg.exe
C:\WINDOWS\system32\vsytyy kh.exe
C:\WINDOWS\system32\widxnv vp.exe
C:\WINDOWS\system32\wuivvt bm.exe
C:\WINDOWS\tk58.exe
C:\WINDOWS\wr.txt
(((((((((((((((((((((((((( (((((((((( ((( Drivers/Services )))))))))))))))))))))))))) )))))))))) )))))))))) )))
-------\LEGACY_CORE
-------\LEGACY_FOPN
-------\ApiMon
-------\core
((((((((((((((((((((((((( Files Created from 2007-07-09 to 2007-08-09 )))))))))))))))))))))))))) )))))
2007-08-09 09:10 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-09 08:58 24,576 --a------ C:\WINDOWS\system32\VundoF ixSVC.exe
2007-08-09 08:55 <DIR> d-------- C:\VundoFix Backups
2007-08-06 21:57 <DIR> d-------- C:\WINDOWS\system32\mclsph lr
2007-08-06 21:57 <DIR> d-------- C:\WINDOWS\system32\appmgm t
2007-08-05 23:26 <DIR> d-------- C:\WINDOWS\system32\LogFil es
2007-08-05 22:19 <DIR> d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\Corel
2007-07-25 18:08 66,112 --a------ C:\WINDOWS\system32\fendpj sl.exe
2007-07-25 18:02 66,112 --a------ C:\WINDOWS\system32\kjjhgb vs.exe
2007-07-24 19:06 <DIR> d-------- C:\Program Files\AIM6
2007-07-24 19:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLI C~1\AOL Downloads
2007-07-23 16:12 4,672 --a------ C:\WINDOWS\system32\vvkttc re.exe
2007-07-23 16:11 66,112 --a------ C:\WINDOWS\system32\qlgkkn yo.exe
2007-07-22 11:40 94,208 --a------ C:\WINDOWS\system32\mclsp. dll
2007-07-22 11:40 90,112 --a------ C:\WINDOWS\system32\mcrtl3 2.dll
2007-07-22 11:40 32,768 --a------ C:\WINDOWS\system32\instls p.exe
2007-07-22 11:40 11,264 --a------ C:\WINDOWS\system32\sporde r.dll
2007-07-22 11:03 66,112 --a------ C:\WINDOWS\system32\vjqarn mp.exe
2007-07-21 18:50 <DIR> d-------- C:\Program Files\iPod
2007-07-16 14:16 66,624 --a------ C:\WINDOWS\system32\jcykrk vl.dll
2007-07-16 14:11 128,576 --a------ C:\WINDOWS\system32\nggkfg ns.dll
2007-07-16 14:08 66,112 --a------ C:\WINDOWS\system32\hidyms cx.exe
2007-07-13 23:50 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLI C~1\Corel Photo Album
2007-07-13 19:26 <DIR> d-------- C:\Temp
2007-07-11 10:20 <DIR> d-------- C:\Program Files\Uniblue
2007-07-11 10:20 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLI C~1\Uniblu e
2007-07-11 09:53 <DIR> d-------- C:\Program Files\RegCure
2007-07-09 17:57 <DIR> d-------- C:\WINDOWS\.file_store_32
2007-07-09 17:25 <DIR> d-------- C:\WINDOWS\.jagex_cache_34
(((((((((((((((((((((((((( (((((((((( (((( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) ))))))
2007-08-09 09:15 --------- d-------- C:\Program Files\Windows NT
2007-08-09 09:15 --------- d-------- C:\Program Files\Messenger
2007-08-06 21:57 --------- d-------- C:\Program Files\QuickTime
2007-08-06 21:57 --------- d-------- C:\Program Files\MySpace
2007-08-06 21:57 --------- d-------- C:\Program Files\iTunes
2007-08-06 21:57 --------- d-------- C:\Program Files\Common Files\aolshare
2007-08-06 21:57 --------- d-------- C:\Program Files\Apple Software Update
2007-08-06 21:54 --------- d-------- C:\Program Files\Dell
2007-08-06 21:54 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-06 21:54 --------- d-------- C:\Program Files\America Online 9.0
2007-08-06 21:51 --------- d-------- C:\Program Files\AIM
2007-08-06 21:51 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\McAfee .com Personal Firewall
2007-08-05 22:19 56 -r-hs---- C:\WINDOWS\system32\3367DA 2490.sys
2007-08-05 22:19 4184 --ahs---- C:\WINDOWS\system32\KGyGaA vL.sys
2007-08-05 21:56 --------- d-------- C:\Program Files\Dl_cats
2007-07-24 20:55 88 -r-hs---- C:\WINDOWS\system32\9024DA 6733.sys
2007-07-22 11:40 --------- d-------- C:\Program Files\McAfee.com
2007-07-21 17:21 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-16 14:51 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\Google
2007-07-16 14:49 --------- d-------- C:\Program Files\MUSICMATCH
2007-07-06 00:07 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-05 09:31 --------- d-------- C:\Program Files\Common Files\Roxio Shared
2007-07-05 09:30 --------- d-------- C:\Program Files\Roxio
2007-06-21 13:12 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\Apple Computer
2007-06-20 03:31 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\Regist rySmart
2007-06-19 21:59 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\MySpac e
2007-06-18 19:37 --------- d-------- C:\Program Files\RegistrySmart
2007-06-15 18:33 --------- d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-06-12 19:07 --------- d-------- C:\Program Files\MSECache
2007-06-05 20:29 386 --a------ C:\WINDOWS\tmpcpyis.bat
2007-06-05 20:29 122 --a------ C:\WINDOWS\tmpdelis.bat
2007-06-05 20:28 26 --a------ C:\WINDOWS\winstart.bat
2007-05-16 11:12 86528 --------- C:\WINDOWS\system32\dllcac he\directd b.dll
2007-05-16 11:12 85504 --------- C:\WINDOWS\system32\dllcac he\wabimp. dll
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetco mm.dll
2007-05-16 11:12 683520 --------- C:\WINDOWS\system32\dllcac he\inetcom m.dll
2007-05-16 11:12 510976 --------- C:\WINDOWS\system32\dllcac he\wab32.d ll
2007-05-16 11:12 1314816 --------- C:\WINDOWS\system32\dllcac he\msoe.dl l
(((((((((((((((((((((((((( (((((((((( ( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) ))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Brow ser Helper Objects\{A7DE354A-CACE-43F C-9906-DA2 2A557A151} ]
C:\WINDOWS\system32\jkhhe. dll
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"SigmatelSysTrayApp"="stsy stra.exe" [2005-03-22 23:20 C:\WINDOWS\stsystra.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe " [2005-11-01 03:12]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\Update Service\is uspm.exe" [2005-06-10 10:44]
"ISUSScheduler"="C:\Progra m Files\Common Files\InstallShield\Update Service\is sch.exe" [2005-06-10 10:44]
"VSOCheckTask"="C:\PROGRA~ 1\McAfee.c om\VSO\mcm nhdlr.exe" [2005-07-08 18:18]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oascl nt.exe" [2005-08-11 22:02]
"MCAgentExe"="c:\PROGRA~1\ mcafee.com \agent\mca gent.exe" [2005-07-01 19:22]
"MCUpdateExe"="C:\PROGRA~1 \mcafee.co m\agent\Mc Update.exe " [2005-08-26 14:26]
"MSKDetectorExe"="C:\PROGR A~1\McAfee \SPAMKI~1\ MSKDetct.e xe" [2005-07-12 19:05]
"DLA"="C:\WINDOWS\System32 \DLA\DLACT RLW.EXE" [2005-09-08 05:20]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-06-21 13:49]
"MSKAGENTEXE"="C:\PROGRA~1 \McAfee\SP AMKI~1\Msk Agent.exe" [2005-07-12 18:06]
"VirusScan Online"="c:\PROGRA~1\mcafe e.com\vso\ mcvsshld.e xe" [2005-08-10 12:49]
"MPFExe"="C:\PROGRA~1\McAf ee.com\PER SON~1\MpfT ray.exe" [2005-08-18 17:52]
"McRegWiz"="C:\PROGRA~1\Mc Afee.com\A gent\mcreg wiz.exe" [2005-06-01 14:05]
"DLCJCATS"="C:\WINDOWS\Sys tem32\spoo l\DRIVERS\ W32X86\3\D LCJtime.dl l" [2005-08-15 05:40]
"dlcjmon.exe"="C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe" [2005-08-12 08:47]
"MemoryCardManager"="C:\Pr ogram Files\Dell Photo AIO Printer 964\memcard.exe" [2005-08-10 02:12]
"SunJavaUpdateSched"="C:\P rogram Files\Java\jre1.5.0_03\bin \jusched.e xe" [2005-04-13 03:48]
"RegistrySmart"="C:\Progra m Files\RegistrySmart\Regist rySmart.ex e" [2007-06-15 10:36]
"RoxioDragToDisc"="C:\Prog ram Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2005-06-09 09:51]
"MMTray"="C:\Program Files\Musicmatch\Musicmatc h Jukebox\mm_tray.exe" []
"NBInstall"="C:\DOCUME~1\J USTIN~1\LO CALS~1\Tem p\MBDownlo ader_87691 9.exe" [2007-07-13 19:26]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe " [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper. exe" [2007-07-10 09:18]
"MPSExe"="c:\PROGRA~1\mcaf ee.com\mps \mscifapp. exe" [2005-07-26 14:49]
[HKEY_CURRENT_USER\SOFTWAR E\Microsof t\Windows\ CurrentVer sion\Run]
"swg"="C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe" [2007-07-03 08:31]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-06-21 13:36:31]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1 \Google\GO OGLE~1\GOE C62~1.DLL
R1 cdudf_xp;cdudf_xp;C:\WINDO WS\system3 2\drivers\ cdudf_xp.s ys
R1 DVDVRRdr_xp;DVDVRRdr_xp;C: \WINDOWS\s ystem32\dr ivers\DVDV RRdr_xp.sy s
R1 MPFIREWL;MPFIREWL;C:\WINDO WS\system3 2\Drivers\ MpFirewall .sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\s ystem32\dr ivers\pwd_ 2k.sys
R1 UDFReadr;UDFReadr;C:\WINDO WS\system3 2\drivers\ UDFReadr.s ys
R3 dvd_2K;dvd_2K;C:\WINDOWS\s ystem32\dr ivers\dvd_ 2K.sys
S3 mmc_2K;mmc_2K;C:\WINDOWS\s ystem32\dr ivers\mmc_ 2K.sys
S3 TnIDriver;TnIDriver;\??\C: \DOCUME~1\ JUSTIN~1\L OCALS~1\Te mp\tni23.t mp
Contents of the 'Scheduled Tasks' folder
2007-07-21 22:36:23 C:\WINDOWS\Tasks\AppleSoft wareUpdate .job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-09 13:19:24 C:\WINDOWS\Tasks\RegistryS mart Scheduled Scan.job - C:\Program Files\RegistrySmart\Regist rySmart.ex e
************************** ********** ********** ********** ********** ********
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-09 09:18:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************** ********** ********** ********** ********** ********
Completion time: 2007-08-09 9:20:21 - machine was rebooted
C:\ComboFix-quarantined-fi les.txt ... 2007-08-09 09:20
--- E O F ---
and the new
3. Logfile of HijackThis v1.99.1
Scan saved at 9:23:12 AM, on 8/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\Ati2ev xx.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\spools v.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
c:\program files\mcafee.com\agent\mcd etect.exe
c:\PROGRA~1\mcafee.com\vso \mcshield. exe
c:\PROGRA~1\mcafee.com\age nt\mctsksh d.exe
c:\PROGRA~1\mcafee.com\vso \OasClnt.e xe
C:\PROGRA~1\McAfee.com\PER SON~1\MpfS ervice.exe
c:\program files\mcafee.com\vso\mcvss hld.exe
c:\progra~1\mcafee.com\vso \mcvsescn. exe
c:\program files\mcafee.com\agent\mca gent.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\Update Service\is sch.exe
C:\WINDOWS\System32\DLA\DL ACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\McAfee\SPAMKI~ 1\MskAgent .exe
C:\PROGRA~1\McAfee.com\PER SON~1\MpfT ray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex. exe
C:\PROGRA~1\McAfee.com\Age nt\mcregwi z.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\Java\jre1.5.0_03\bin \jusched.e xe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDispla y.exe
C:\Program Files\RegistrySmart\Regist rySmart.ex e
C:\PROGRA~1\McAfee.com\PER SON~1\MpfA gent.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\DOCUME~1\JUSTIN~1\LOCAL S~1\Temp\M BDownloade r_876919.e xe
C:\Program Files\iTunes\iTunesHelper. exe
C:\PROGRA~1\mcafee.com\mps \mscifapp. exe
C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\dlcjco ms.exe
C:\WINDOWS\system32\wuaucl t.exe
C:\WINDOWS\system32\wuaucl t.exe
C:\PROGRA~1\McAfee\SPAMKI~ 1\MSKSrvr. exe
C:\Documents and Settings\Tina Morris\Desktop\alternativ. exe
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH elper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-7 3F568BCB24 E} - c:\program files\mcafee.com\mps\mcbrh lpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B 191550C2A2 2} - c:\program files\mcafee.com\mps\popup killer.dll
O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6 EBB8AF1900 0} - c:\program files\mcafee\spamkiller\mc apfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0 0123456789 0} - C:\WINDOWS\System32\DLA\DL ASHX_W.DLL
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8 EA1C75885F 9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {A7DE354A-CACE-43FC-9906-D A22A557A15 1} - C:\WINDOWS\system32\jkhhe. dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C F10577473F 7} - c:\program files\google\googletoolbar 2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C E66B5AD205 D} - C:\Program Files\Google\GoogleToolbar Notifier\2 .0.301.716 4\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A 07C3DB8F77 7} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9 05236F6F65 5} - c:\progra~1\mcafee.com\vso \mcvsshl.d ll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0 09027A5CD4 F} - c:\program files\google\googletoolbar 2.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A A305ED9D92 2} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update Service\is uspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update Service\is sch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VS O\mcmnhdlr .exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oascl nt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age nt\mcagent .exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age nt\McUpdat e.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~ 1\MSKDetct .exe /startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL ACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~ 1\MskAgent .exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso \mcvsshld. exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PER SON~1\MpfT ray.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Age nt\mcregwi z.exe /autorun
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\ DRIVERS\W3 2X86\3\DLC Jtime.dll, _RunDLLEnt ry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin \jusched.e xe
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\Regist rySmart.ex e" -boot
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatc h Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\JUSTIN~1\LOCAL S~1\Temp\M BDownloade r_876919.e xe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe " -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper. exe"
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps \mscifapp. exe /embedding
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm801MGUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\j2re1.4.2_03\bi n\npjpi142 _03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\j2re1.4.2_03\bi n\npjpi142 _03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B 4C75499B57 8} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3 582CCF489E 1} - c:\program files\mcafee\spamkiller\mc apfbho.dll
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3 582CCF489E 1} - c:\program files\mcafee\spamkiller\mc apfbho.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0 0B0D0A1DE4 5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0 0C0F0318AF E} - C:\WINDOWS\system32\Shdocv w.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1 E41684E07B B} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~ 1\GOEC62~1 .DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev xx.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjco ms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc. exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterServi ce.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcd etect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso \mcshield. exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\age nt\mctsksh d.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age nt\mcupdmg r.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PER SON~1\MpfS ervice.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~ 1\MSKSrvr. exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NC S\Sync\Net Svc.exe
Let me know how this looks.
Thank you,
XBedoya
I did as you said and here are the logs for the 3 applications: (this is gonna be a long one)
I have a question there are two programs running in this computer and I wonder if I should delete them too, Registry Smart and Registry Booty.
1. VundoFix V6.5.7
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Scan started at 8:55:22 AM 8/9/2007
Listing files found while scanning....
C:\windows\system32\dbsdne
C:\windows\system32\ddcbxu
C:\windows\system32\efyeij
C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\fauwco
C:\WINDOWS\system32\hkxyhe
C:\windows\system32\jdslxy
C:\WINDOWS\system32\jkhhe.
C:\windows\system32\mesmid
C:\windows\system32\pvjiey
C:\WINDOWS\system32\qcocwu
C:\WINDOWS\system32\qomkii
C:\windows\system32\rwelst
C:\windows\system32\skuvft
Beginning removal...
Attempting to delete C:\windows\system32\dbsdne
C:\windows\system32\dbsdne
Attempting to delete C:\windows\system32\ddcbxu
C:\windows\system32\ddcbxu
Attempting to delete C:\windows\system32\efyeij
C:\windows\system32\efyeij
Attempting to delete C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
Attempting to delete C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
Attempting to delete C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
Attempting to delete C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
Attempting to delete C:\WINDOWS\system32\ehhkj.
C:\WINDOWS\system32\ehhkj.
Attempting to delete C:\WINDOWS\system32\fauwco
C:\WINDOWS\system32\fauwco
Attempting to delete C:\WINDOWS\system32\hkxyhe
C:\WINDOWS\system32\hkxyhe
Attempting to delete C:\windows\system32\jdslxy
C:\windows\system32\jdslxy
Attempting to delete C:\WINDOWS\system32\jkhhe.
C:\WINDOWS\system32\jkhhe.
Attempting to delete C:\windows\system32\mesmid
C:\windows\system32\mesmid
Attempting to delete C:\windows\system32\pvjiey
C:\windows\system32\pvjiey
Attempting to delete C:\WINDOWS\system32\qcocwu
C:\WINDOWS\system32\qcocwu
Attempting to delete C:\WINDOWS\system32\qomkii
C:\WINDOWS\system32\qomkii
Attempting to delete C:\windows\system32\rwelst
C:\windows\system32\rwelst
Attempting to delete C:\windows\system32\skuvft
C:\windows\system32\skuvft
Performing Repairs to the registry.
Done!
VundoFix V6.5.7
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Scan started at 9:04:25 AM 8/9/2007
Listing files found while scanning....
No infected files were found.
2. ComboFix 07-08-09.3 - "Tina Morris" 2007-08-09 9:13:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.
* Created a new restore point
((((((((((((((((((((((((((
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\ALLUSE~1\APPLI
C:\DOCUME~1\JUSTIN~1\APPLI
C:\DOCUME~1\JUSTIN~1\APPLI
C:\DOCUME~1\JUSTIN~1\APPLI
C:\DOCUME~1\MIKEMO~1\APPLI
C:\DOCUME~1\MIKEMO~1\APPLI
C:\DOCUME~1\MIKEMO~1\APPLI
C:\DOCUME~1\TINAMO~1\APPLI
C:\DOCUME~1\TINAMO~1\APPLI
C:\DOCUME~1\TINAMO~1\APPLI
C:\DOCUME~1\TINAMO~1\APPLI
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.e
C:\Program Files\Common Files\Yazzle1281OinUninsta
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Scree
C:\Program Files\FunWebProducts\Scree
C:\Program Files\FunWebProducts\Share
C:\Program Files\Messenger\mesobif831
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\Hist
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\Windows NT\qufatygyw.dll
C:\Program Files\Windows NT\qufatygyw15.dll
C:\Program Files\Windows NT\qufatygyw191.dll
C:\Program Files\Windows NT\qufatygyw211.dll
C:\Program Files\Windows NT\qufatygyw252.dll
C:\Program Files\Windows NT\qufatygyw281.dll
C:\Program Files\Windows NT\qufatygyw308.dll
C:\Program Files\Windows NT\qufatygyw434.dll
C:\Program Files\Windows NT\qufatygyw620.dll
C:\Program Files\Windows NT\qufatygyw681.dll
C:\temp\0c2
C:\temp\0c2\tmpRC.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\temp\tn3
C:\WINDOWS\retadpu572.exe
C:\WINDOWS\system32\awlqpu
C:\WINDOWS\system32\B0
C:\WINDOWS\system32\B0\mws
C:\WINDOWS\system32\b02FdU
C:\WINDOWS\system32\b02FdU
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\B1\wr7
C:\WINDOWS\system32\B2
C:\WINDOWS\system32\B2\st2
C:\WINDOWS\system32\B5
C:\WINDOWS\system32\cxstjp
C:\WINDOWS\system32\dpdkpr
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\gokgsa
C:\WINDOWS\system32\gsjeio
C:\WINDOWS\system32\jiytdx
C:\WINDOWS\system32\kbjaoa
C:\WINDOWS\system32\vmpyxq
C:\WINDOWS\system32\vsytyy
C:\WINDOWS\system32\widxnv
C:\WINDOWS\system32\wuivvt
C:\WINDOWS\tk58.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((
-------\LEGACY_CORE
-------\LEGACY_FOPN
-------\ApiMon
-------\core
((((((((((((((((((((((((( Files Created from 2007-07-09 to 2007-08-09 ))))))))))))))))))))))))))
2007-08-09 09:10 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-09 08:58 24,576 --a------ C:\WINDOWS\system32\VundoF
2007-08-09 08:55 <DIR> d-------- C:\VundoFix Backups
2007-08-06 21:57 <DIR> d-------- C:\WINDOWS\system32\mclsph
2007-08-06 21:57 <DIR> d-------- C:\WINDOWS\system32\appmgm
2007-08-05 23:26 <DIR> d-------- C:\WINDOWS\system32\LogFil
2007-08-05 22:19 <DIR> d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-07-25 18:08 66,112 --a------ C:\WINDOWS\system32\fendpj
2007-07-25 18:02 66,112 --a------ C:\WINDOWS\system32\kjjhgb
2007-07-24 19:06 <DIR> d-------- C:\Program Files\AIM6
2007-07-24 19:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLI
2007-07-23 16:12 4,672 --a------ C:\WINDOWS\system32\vvkttc
2007-07-23 16:11 66,112 --a------ C:\WINDOWS\system32\qlgkkn
2007-07-22 11:40 94,208 --a------ C:\WINDOWS\system32\mclsp.
2007-07-22 11:40 90,112 --a------ C:\WINDOWS\system32\mcrtl3
2007-07-22 11:40 32,768 --a------ C:\WINDOWS\system32\instls
2007-07-22 11:40 11,264 --a------ C:\WINDOWS\system32\sporde
2007-07-22 11:03 66,112 --a------ C:\WINDOWS\system32\vjqarn
2007-07-21 18:50 <DIR> d-------- C:\Program Files\iPod
2007-07-16 14:16 66,624 --a------ C:\WINDOWS\system32\jcykrk
2007-07-16 14:11 128,576 --a------ C:\WINDOWS\system32\nggkfg
2007-07-16 14:08 66,112 --a------ C:\WINDOWS\system32\hidyms
2007-07-13 23:50 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLI
2007-07-13 19:26 <DIR> d-------- C:\Temp
2007-07-11 10:20 <DIR> d-------- C:\Program Files\Uniblue
2007-07-11 10:20 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLI
2007-07-11 09:53 <DIR> d-------- C:\Program Files\RegCure
2007-07-09 17:57 <DIR> d-------- C:\WINDOWS\.file_store_32
2007-07-09 17:25 <DIR> d-------- C:\WINDOWS\.jagex_cache_34
((((((((((((((((((((((((((
2007-08-09 09:15 --------- d-------- C:\Program Files\Windows NT
2007-08-09 09:15 --------- d-------- C:\Program Files\Messenger
2007-08-06 21:57 --------- d-------- C:\Program Files\QuickTime
2007-08-06 21:57 --------- d-------- C:\Program Files\MySpace
2007-08-06 21:57 --------- d-------- C:\Program Files\iTunes
2007-08-06 21:57 --------- d-------- C:\Program Files\Common Files\aolshare
2007-08-06 21:57 --------- d-------- C:\Program Files\Apple Software Update
2007-08-06 21:54 --------- d-------- C:\Program Files\Dell
2007-08-06 21:54 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-06 21:54 --------- d-------- C:\Program Files\America Online 9.0
2007-08-06 21:51 --------- d-------- C:\Program Files\AIM
2007-08-06 21:51 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-08-05 22:19 56 -r-hs---- C:\WINDOWS\system32\3367DA
2007-08-05 22:19 4184 --ahs---- C:\WINDOWS\system32\KGyGaA
2007-08-05 21:56 --------- d-------- C:\Program Files\Dl_cats
2007-07-24 20:55 88 -r-hs---- C:\WINDOWS\system32\9024DA
2007-07-22 11:40 --------- d-------- C:\Program Files\McAfee.com
2007-07-21 17:21 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-16 14:51 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-07-16 14:49 --------- d-------- C:\Program Files\MUSICMATCH
2007-07-06 00:07 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-05 09:31 --------- d-------- C:\Program Files\Common Files\Roxio Shared
2007-07-05 09:30 --------- d-------- C:\Program Files\Roxio
2007-06-21 13:12 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-06-20 03:31 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-06-19 21:59 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-06-18 19:37 --------- d-------- C:\Program Files\RegistrySmart
2007-06-15 18:33 --------- d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-06-12 19:07 --------- d-------- C:\Program Files\MSECache
2007-06-05 20:29 386 --a------ C:\WINDOWS\tmpcpyis.bat
2007-06-05 20:29 122 --a------ C:\WINDOWS\tmpdelis.bat
2007-06-05 20:28 26 --a------ C:\WINDOWS\winstart.bat
2007-05-16 11:12 86528 --------- C:\WINDOWS\system32\dllcac
2007-05-16 11:12 85504 --------- C:\WINDOWS\system32\dllcac
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetco
2007-05-16 11:12 683520 --------- C:\WINDOWS\system32\dllcac
2007-05-16 11:12 510976 --------- C:\WINDOWS\system32\dllcac
2007-05-16 11:12 1314816 --------- C:\WINDOWS\system32\dllcac
((((((((((((((((((((((((((
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Brow
C:\WINDOWS\system32\jkhhe.
[HKEY_LOCAL_MACHINE\SOFTWA
"SigmatelSysTrayApp"="stsy
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\Update
"ISUSScheduler"="C:\Progra
"VSOCheckTask"="C:\PROGRA~
"OASClnt"="C:\Program Files\McAfee.com\VSO\oascl
"MCAgentExe"="c:\PROGRA~1\
"MCUpdateExe"="C:\PROGRA~1
"MSKDetectorExe"="C:\PROGR
"DLA"="C:\WINDOWS\System32
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-06-21 13:49]
"MSKAGENTEXE"="C:\PROGRA~1
"VirusScan Online"="c:\PROGRA~1\mcafe
"MPFExe"="C:\PROGRA~1\McAf
"McRegWiz"="C:\PROGRA~1\Mc
"DLCJCATS"="C:\WINDOWS\Sys
"dlcjmon.exe"="C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe" [2005-08-12 08:47]
"MemoryCardManager"="C:\Pr
"SunJavaUpdateSched"="C:\P
"RegistrySmart"="C:\Progra
"RoxioDragToDisc"="C:\Prog
"MMTray"="C:\Program Files\Musicmatch\Musicmatc
"NBInstall"="C:\DOCUME~1\J
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe
"iTunesHelper"="C:\Program
"MPSExe"="c:\PROGRA~1\mcaf
[HKEY_CURRENT_USER\SOFTWAR
"swg"="C:\Program Files\Google\GoogleToolbar
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-06-21 13:36:31]
[HKEY_LOCAL_MACHINE\softwa
"appinit_dlls"=C:\PROGRA~1
R1 cdudf_xp;cdudf_xp;C:\WINDO
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:
R1 MPFIREWL;MPFIREWL;C:\WINDO
R1 pwd_2k;pwd_2k;C:\WINDOWS\s
R1 UDFReadr;UDFReadr;C:\WINDO
R3 dvd_2K;dvd_2K;C:\WINDOWS\s
S3 mmc_2K;mmc_2K;C:\WINDOWS\s
S3 TnIDriver;TnIDriver;\??\C:
Contents of the 'Scheduled Tasks' folder
2007-07-21 22:36:23 C:\WINDOWS\Tasks\AppleSoft
2007-08-09 13:19:24 C:\WINDOWS\Tasks\RegistryS
**************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-09 09:18:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
Completion time: 2007-08-09 9:20:21 - machine was rebooted
C:\ComboFix-quarantined-fi
--- E O F ---
and the new
3. Logfile of HijackThis v1.99.1
Scan saved at 9:23:12 AM, on 8/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
c:\program files\mcafee.com\agent\mcd
c:\PROGRA~1\mcafee.com\vso
c:\PROGRA~1\mcafee.com\age
c:\PROGRA~1\mcafee.com\vso
C:\PROGRA~1\McAfee.com\PER
c:\program files\mcafee.com\vso\mcvss
c:\progra~1\mcafee.com\vso
c:\program files\mcafee.com\agent\mca
C:\WINDOWS\system32\svchos
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\Update
C:\WINDOWS\System32\DLA\DL
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\McAfee\SPAMKI~
C:\PROGRA~1\McAfee.com\PER
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.
C:\PROGRA~1\McAfee.com\Age
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\Java\jre1.5.0_03\bin
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDispla
C:\Program Files\RegistrySmart\Regist
C:\PROGRA~1\McAfee.com\PER
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\DOCUME~1\JUSTIN~1\LOCAL
C:\Program Files\iTunes\iTunesHelper.
C:\PROGRA~1\mcafee.com\mps
C:\Program Files\Google\GoogleToolbar
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\dlcjco
C:\WINDOWS\system32\wuaucl
C:\WINDOWS\system32\wuaucl
C:\PROGRA~1\McAfee\SPAMKI~
C:\Documents and Settings\Tina Morris\Desktop\alternativ.
R1 - HKLM\Software\Microsoft\In
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-7
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B
O2 - BHO: McAfee Anti-Phishing Filter - {41D68ED8-4CFF-4115-88A6-6
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8
O2 - BHO: (no name) - {A7DE354A-CACE-43FC-9906-D
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VS
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oascl
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PER
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Age
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\Regist
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatc
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\JUSTIN~1\LOCAL
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm801MGUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjco
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcd
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\age
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PER
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NC
Let me know how this looks.
Thank you,
XBedoya
>> have a question there are two programs running in this computer and I wonder if I should delete them too, Registry Smart and Registry Booty.<<
Yes, uninstall them, and use the Add/Remove programs to uninstall them.
RegCure <-- also uninstall this one.
When it's about the registry you need to only use a known reliable program.
These are the registry cleaners that I've used and trusted:
TuneUp utilities <-- still using it.
Registry Mechanic
JVC16
C:\Program Files\Windows NT <--can you check the properties of this folder??? there were so many nasties inside this folder, do you know anything about this folder, did you install it yourself?
Run Hijackthis again and put a check next to these entries and while all browsers and other windows are closed, click "Fix Checked".
O2 - BHO: (no name) - {A7DE354A-CACE-43FC-9906-D A22A557A15 1} - C:\WINDOWS\system32\jkhhe. dll (file missing)
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\Regist rySmart.ex e" -boot
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\JUSTIN~1\LOCAL S~1\Temp\M BDownloade r_876919.e xe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm801MGUS
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1 E41684E07B B} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/CursorManiaFWBInitialSetup1.0.0.15-3.cab
Vundofix and Combofix have removed heaps of bad files but there are still some bad files that needs to be removed.
Open notepad and copy/paste the text inside the lines below into it
-------------------------- ---------- ---------- ---------- ------
File::
C:\DOCUME~1\JUSTIN~1\LOCAL S~1\Temp\M BDownloade r_876919.e xe
C:\WINDOWS\system32\fendpj sl.exe
C:\WINDOWS\system32\kjjhgb vs.exe
C:\WINDOWS\system32\vvkttc re.exe
C:\WINDOWS\system32\qlgkkn yo.exe
C:\WINDOWS\system32\vjqarn mp.exe
C:\WINDOWS\system32\jcykrk vl.dll
C:\WINDOWS\system32\nggkfg ns.dll
C:\WINDOWS\system32\hidyms cx.exe
-------------------------- ---------- ---------- ---------- ------
Save this as CFScript in the same location as ComboFix.exe
drag CFScript into ComboFix.exe
This will start ComboFix again. Follow the prompts. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
You have 2 versions of java there, I suggest uninstalling this version -->j2re1.4.2_03 because that's very vulnerable to vundo/conhook infections. I would suggest using the later or latest version.
Yes, uninstall them, and use the Add/Remove programs to uninstall them.
RegCure <-- also uninstall this one.
When it's about the registry you need to only use a known reliable program.
These are the registry cleaners that I've used and trusted:
TuneUp utilities <-- still using it.
Registry Mechanic
JVC16
C:\Program Files\Windows NT <--can you check the properties of this folder??? there were so many nasties inside this folder, do you know anything about this folder, did you install it yourself?
Run Hijackthis again and put a check next to these entries and while all browsers and other windows are closed, click "Fix Checked".
O2 - BHO: (no name) - {A7DE354A-CACE-43FC-9906-D
O4 - HKLM\..\Run: [RegistrySmart] "C:\Program Files\RegistrySmart\Regist
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\JUSTIN~1\LOCAL
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm801MGUS
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
Vundofix and Combofix have removed heaps of bad files but there are still some bad files that needs to be removed.
Open notepad and copy/paste the text inside the lines below into it
--------------------------
File::
C:\DOCUME~1\JUSTIN~1\LOCAL
C:\WINDOWS\system32\fendpj
C:\WINDOWS\system32\kjjhgb
C:\WINDOWS\system32\vvkttc
C:\WINDOWS\system32\qlgkkn
C:\WINDOWS\system32\vjqarn
C:\WINDOWS\system32\jcykrk
C:\WINDOWS\system32\nggkfg
C:\WINDOWS\system32\hidyms
--------------------------
Save this as CFScript in the same location as ComboFix.exe
drag CFScript into ComboFix.exe
This will start ComboFix again. Follow the prompts. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
You have 2 versions of java there, I suggest uninstalling this version -->j2re1.4.2_03 because that's very vulnerable to vundo/conhook infections. I would suggest using the later or latest version.
ASKER
I looked at the Windows NT folder, I don't know anything about it it says read-only file and it contains the following files:
dialer, hyperterm, rtenejuziv, htm_jis.dll, qufatygyw308. Two folders:
-Accesories: mswrd6.wpc, mswrd8.wpc, wordpad, write.wpc
-PinBall
I will unistall the java application next. I just try the internet but still can't go on-line.
Here is the Log:
ComboFix 07-08-09.3 - "Tina Morris" 2007-08-09 22:12:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18. 191 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Tina Morris\Desktop\CFScript.tx t
* Created a new restore point
FILE::
C:\DOCUME~1\JUSTIN~1\LOCAL S~1\Temp\M BDownloade r_876919.e xe
C:\WINDOWS\system32\fendpj sl.exe
C:\WINDOWS\system32\kjjhgb vs.exe
C:\WINDOWS\system32\vvkttc re.exe
C:\WINDOWS\system32\qlgkkn yo.exe
C:\WINDOWS\system32\vjqarn mp.exe
C:\WINDOWS\system32\jcykrk vl.dll
C:\WINDOWS\system32\nggkfg ns.dll
C:\WINDOWS\system32\hidyms cx.exe
(((((((((((((((((((((((((( (((((((((( ((( Other Deletions )))))))))))))))))))))))))) )))))))))) )))))))))) )))
C:\DOCUME~1\JUSTIN~1\LOCAL S~1\Temp\M BDownloade r_876919.e xe
C:\WINDOWS\system32\fendpj sl.exe
C:\WINDOWS\system32\hidyms cx.exe
C:\WINDOWS\system32\jcykrk vl.dll
C:\WINDOWS\system32\kjjhgb vs.exe
C:\WINDOWS\system32\nggkfg ns.dll
C:\WINDOWS\system32\qlgkkn yo.exe
C:\WINDOWS\system32\vjqarn mp.exe
C:\WINDOWS\system32\vvkttc re.exe
((((((((((((((((((((((((( Files Created from 2007-07-10 to 2007-08-10 )))))))))))))))))))))))))) )))))
2007-08-09 09:10 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-09 08:58 24,576 --a------ C:\WINDOWS\system32\VundoF ixSVC.exe
2007-08-09 08:55 <DIR> d-------- C:\VundoFix Backups
2007-08-06 21:57 <DIR> d-------- C:\WINDOWS\system32\mclsph lr
2007-08-06 21:57 <DIR> d-------- C:\WINDOWS\system32\appmgm t
2007-08-05 23:26 <DIR> d-------- C:\WINDOWS\system32\LogFil es
2007-08-05 22:19 <DIR> d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\Corel
2007-07-24 19:06 <DIR> d-------- C:\Program Files\AIM6
2007-07-24 19:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLI C~1\AOL Downloads
2007-07-22 11:40 94,208 --a------ C:\WINDOWS\system32\mclsp. dll
2007-07-22 11:40 90,112 --a------ C:\WINDOWS\system32\mcrtl3 2.dll
2007-07-22 11:40 32,768 --a------ C:\WINDOWS\system32\instls p.exe
2007-07-22 11:40 11,264 --a------ C:\WINDOWS\system32\sporde r.dll
2007-07-21 18:50 <DIR> d-------- C:\Program Files\iPod
2007-07-13 23:50 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLI C~1\Corel Photo Album
2007-07-13 19:26 <DIR> d-------- C:\Temp
2007-07-11 10:20 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLI C~1\Uniblu e
2007-07-11 09:53 <DIR> d-------- C:\Program Files\RegCure
2007-07-09 17:57 <DIR> d-------- C:\WINDOWS\.file_store_32
2007-07-09 17:25 <DIR> d-------- C:\WINDOWS\.jagex_cache_34
(((((((((((((((((((((((((( (((((((((( (((( Find3M Report )))))))))))))))))))))))))) )))))))))) )))))))))) ))))))
2007-08-09 09:15 --------- d-------- C:\Program Files\Windows NT
2007-08-09 09:15 --------- d-------- C:\Program Files\Messenger
2007-08-06 21:57 --------- d-------- C:\Program Files\QuickTime
2007-08-06 21:57 --------- d-------- C:\Program Files\MySpace
2007-08-06 21:57 --------- d-------- C:\Program Files\iTunes
2007-08-06 21:57 --------- d-------- C:\Program Files\Common Files\aolshare
2007-08-06 21:57 --------- d-------- C:\Program Files\Apple Software Update
2007-08-06 21:54 --------- d-------- C:\Program Files\Dell
2007-08-06 21:54 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-06 21:54 --------- d-------- C:\Program Files\America Online 9.0
2007-08-06 21:51 --------- d-------- C:\Program Files\AIM
2007-08-06 21:51 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\McAfee .com Personal Firewall
2007-08-05 22:19 56 -r-hs---- C:\WINDOWS\system32\3367DA 2490.sys
2007-08-05 22:19 4184 --ahs---- C:\WINDOWS\system32\KGyGaA vL.sys
2007-08-05 21:56 --------- d-------- C:\Program Files\Dl_cats
2007-07-24 20:55 88 -r-hs---- C:\WINDOWS\system32\9024DA 6733.sys
2007-07-22 11:40 --------- d-------- C:\Program Files\McAfee.com
2007-07-21 17:21 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-16 14:51 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\Google
2007-07-16 14:49 --------- d-------- C:\Program Files\MUSICMATCH
2007-07-06 00:07 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-05 09:31 --------- d-------- C:\Program Files\Common Files\Roxio Shared
2007-07-05 09:30 --------- d-------- C:\Program Files\Roxio
2007-06-21 13:12 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\Apple Computer
2007-06-20 03:31 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\Regist rySmart
2007-06-19 21:59 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI C~1\MySpac e
2007-06-15 18:33 --------- d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-06-12 19:07 --------- d-------- C:\Program Files\MSECache
2007-06-05 20:29 386 --a------ C:\WINDOWS\tmpcpyis.bat
2007-06-05 20:29 122 --a------ C:\WINDOWS\tmpdelis.bat
2007-06-05 20:28 26 --a------ C:\WINDOWS\winstart.bat
2007-05-16 11:12 86528 --------- C:\WINDOWS\system32\dllcac he\directd b.dll
2007-05-16 11:12 85504 --------- C:\WINDOWS\system32\dllcac he\wabimp. dll
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetco mm.dll
2007-05-16 11:12 683520 --------- C:\WINDOWS\system32\dllcac he\inetcom m.dll
2007-05-16 11:12 510976 --------- C:\WINDOWS\system32\dllcac he\wab32.d ll
2007-05-16 11:12 1314816 --------- C:\WINDOWS\system32\dllcac he\msoe.dl l
(((((((((((((((((((((((((( (((((((((( ( Reg Loading Points )))))))))))))))))))))))))) )))))))))) )))))))))) ))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"SigmatelSysTrayApp"="stsy stra.exe" [2005-03-22 23:20 C:\WINDOWS\stsystra.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe " [2005-11-01 03:12]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\Update Service\is uspm.exe" [2005-06-10 10:44]
"ISUSScheduler"="C:\Progra m Files\Common Files\InstallShield\Update Service\is sch.exe" [2005-06-10 10:44]
"VSOCheckTask"="C:\PROGRA~ 1\McAfee.c om\VSO\mcm nhdlr.exe" [2005-07-08 18:18]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oascl nt.exe" [2005-08-11 22:02]
"MCAgentExe"="c:\PROGRA~1\ mcafee.com \agent\mca gent.exe" [2005-07-01 19:22]
"MCUpdateExe"="C:\PROGRA~1 \mcafee.co m\agent\mc update.exe " [2005-08-26 14:26]
"MSKDetectorExe"="C:\PROGR A~1\McAfee \SPAMKI~1\ MSKDetct.e xe" [2005-07-12 19:05]
"DLA"="C:\WINDOWS\System32 \DLA\DLACT RLW.EXE" [2005-09-08 05:20]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-06-21 13:49]
"MSKAGENTEXE"="C:\PROGRA~1 \McAfee\SP AMKI~1\Msk Agent.exe" [2005-07-12 18:06]
"VirusScan Online"="c:\PROGRA~1\mcafe e.com\vso\ mcvsshld.e xe" [2005-08-10 12:49]
"MPFExe"="C:\PROGRA~1\McAf ee.com\PER SON~1\MpfT ray.exe" [2005-08-18 17:52]
"McRegWiz"="C:\PROGRA~1\Mc Afee.com\A gent\mcreg wiz.exe" [2005-06-01 14:05]
"DLCJCATS"="C:\WINDOWS\Sys tem32\spoo l\DRIVERS\ W32X86\3\D LCJtime.dl l" [2005-08-15 05:40]
"dlcjmon.exe"="C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe" [2005-08-12 08:47]
"MemoryCardManager"="C:\Pr ogram Files\Dell Photo AIO Printer 964\memcard.exe" [2005-08-10 02:12]
"SunJavaUpdateSched"="C:\P rogram Files\Java\jre1.5.0_03\bin \jusched.e xe" [2005-04-13 03:48]
"RoxioDragToDisc"="C:\Prog ram Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2005-06-09 09:51]
"MMTray"="C:\Program Files\Musicmatch\Musicmatc h Jukebox\mm_tray.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe " [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper. exe" [2007-07-10 09:18]
"MPSExe"="c:\PROGRA~1\mcaf ee.com\mps \mscifapp. exe" [2005-07-26 14:49]
[HKEY_CURRENT_USER\SOFTWAR E\Microsof t\Windows\ CurrentVer sion\Run]
"swg"="C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe" [2007-07-03 08:31]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-06-21 13:36:31]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1 \Google\GO OGLE~1\GOE C62~1.DLL
R1 cdudf_xp;cdudf_xp;C:\WINDO WS\system3 2\drivers\ cdudf_xp.s ys
R1 DVDVRRdr_xp;DVDVRRdr_xp;C: \WINDOWS\s ystem32\dr ivers\DVDV RRdr_xp.sy s
R1 MPFIREWL;MPFIREWL;C:\WINDO WS\system3 2\Drivers\ MpFirewall .sys
R1 pwd_2k;pwd_2k;C:\WINDOWS\s ystem32\dr ivers\pwd_ 2k.sys
R1 UDFReadr;UDFReadr;C:\WINDO WS\system3 2\drivers\ UDFReadr.s ys
R3 dvd_2K;dvd_2K;C:\WINDOWS\s ystem32\dr ivers\dvd_ 2K.sys
S3 mmc_2K;mmc_2K;C:\WINDOWS\s ystem32\dr ivers\mmc_ 2K.sys
S3 TnIDriver;TnIDriver;\??\C: \DOCUME~1\ JUSTIN~1\L OCALS~1\Te mp\tni23.t mp
Contents of the 'Scheduled Tasks' folder
2007-07-21 22:36:23 C:\WINDOWS\Tasks\AppleSoft wareUpdate .job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
2007-08-09 13:19:24 C:\WINDOWS\Tasks\RegistryS mart Scheduled Scan.job - C:\Program Files\RegistrySmart\Regist rySmart.ex e
************************** ********** ********** ********** ********** ********
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-09 22:15:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************** ********** ********** ********** ********** ********
Completion time: 2007-08-09 22:17:52 - machine was rebooted
C:\ComboFix-quarantined-fi les.txt ... 2007-08-09 22:17
C:\ComboFix2.txt ... 2007-08-09 09:20
--- E O F ---
dialer, hyperterm, rtenejuziv, htm_jis.dll, qufatygyw308. Two folders:
-Accesories: mswrd6.wpc, mswrd8.wpc, wordpad, write.wpc
-PinBall
I will unistall the java application next. I just try the internet but still can't go on-line.
Here is the Log:
ComboFix 07-08-09.3 - "Tina Morris" 2007-08-09 22:12:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.
Command switches used :: C:\Documents and Settings\Tina Morris\Desktop\CFScript.tx
* Created a new restore point
FILE::
C:\DOCUME~1\JUSTIN~1\LOCAL
C:\WINDOWS\system32\fendpj
C:\WINDOWS\system32\kjjhgb
C:\WINDOWS\system32\vvkttc
C:\WINDOWS\system32\qlgkkn
C:\WINDOWS\system32\vjqarn
C:\WINDOWS\system32\jcykrk
C:\WINDOWS\system32\nggkfg
C:\WINDOWS\system32\hidyms
((((((((((((((((((((((((((
C:\DOCUME~1\JUSTIN~1\LOCAL
C:\WINDOWS\system32\fendpj
C:\WINDOWS\system32\hidyms
C:\WINDOWS\system32\jcykrk
C:\WINDOWS\system32\kjjhgb
C:\WINDOWS\system32\nggkfg
C:\WINDOWS\system32\qlgkkn
C:\WINDOWS\system32\vjqarn
C:\WINDOWS\system32\vvkttc
((((((((((((((((((((((((( Files Created from 2007-07-10 to 2007-08-10 ))))))))))))))))))))))))))
2007-08-09 09:10 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-09 08:58 24,576 --a------ C:\WINDOWS\system32\VundoF
2007-08-09 08:55 <DIR> d-------- C:\VundoFix Backups
2007-08-06 21:57 <DIR> d-------- C:\WINDOWS\system32\mclsph
2007-08-06 21:57 <DIR> d-------- C:\WINDOWS\system32\appmgm
2007-08-05 23:26 <DIR> d-------- C:\WINDOWS\system32\LogFil
2007-08-05 22:19 <DIR> d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-07-24 19:06 <DIR> d-------- C:\Program Files\AIM6
2007-07-24 19:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLI
2007-07-22 11:40 94,208 --a------ C:\WINDOWS\system32\mclsp.
2007-07-22 11:40 90,112 --a------ C:\WINDOWS\system32\mcrtl3
2007-07-22 11:40 32,768 --a------ C:\WINDOWS\system32\instls
2007-07-22 11:40 11,264 --a------ C:\WINDOWS\system32\sporde
2007-07-21 18:50 <DIR> d-------- C:\Program Files\iPod
2007-07-13 23:50 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLI
2007-07-13 19:26 <DIR> d-------- C:\Temp
2007-07-11 10:20 <DIR> d-------- C:\DOCUME~1\JUSTIN~1\APPLI
2007-07-11 09:53 <DIR> d-------- C:\Program Files\RegCure
2007-07-09 17:57 <DIR> d-------- C:\WINDOWS\.file_store_32
2007-07-09 17:25 <DIR> d-------- C:\WINDOWS\.jagex_cache_34
((((((((((((((((((((((((((
2007-08-09 09:15 --------- d-------- C:\Program Files\Windows NT
2007-08-09 09:15 --------- d-------- C:\Program Files\Messenger
2007-08-06 21:57 --------- d-------- C:\Program Files\QuickTime
2007-08-06 21:57 --------- d-------- C:\Program Files\MySpace
2007-08-06 21:57 --------- d-------- C:\Program Files\iTunes
2007-08-06 21:57 --------- d-------- C:\Program Files\Common Files\aolshare
2007-08-06 21:57 --------- d-------- C:\Program Files\Apple Software Update
2007-08-06 21:54 --------- d-------- C:\Program Files\Dell
2007-08-06 21:54 --------- d-------- C:\Program Files\Common Files\AOL
2007-08-06 21:54 --------- d-------- C:\Program Files\America Online 9.0
2007-08-06 21:51 --------- d-------- C:\Program Files\AIM
2007-08-06 21:51 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-08-05 22:19 56 -r-hs---- C:\WINDOWS\system32\3367DA
2007-08-05 22:19 4184 --ahs---- C:\WINDOWS\system32\KGyGaA
2007-08-05 21:56 --------- d-------- C:\Program Files\Dl_cats
2007-07-24 20:55 88 -r-hs---- C:\WINDOWS\system32\9024DA
2007-07-22 11:40 --------- d-------- C:\Program Files\McAfee.com
2007-07-21 17:21 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-07-16 14:51 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-07-16 14:49 --------- d-------- C:\Program Files\MUSICMATCH
2007-07-06 00:07 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-05 09:31 --------- d-------- C:\Program Files\Common Files\Roxio Shared
2007-07-05 09:30 --------- d-------- C:\Program Files\Roxio
2007-06-21 13:12 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-06-20 03:31 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-06-19 21:59 --------- d-------- C:\DOCUME~1\TINAMO~1\APPLI
2007-06-15 18:33 --------- d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-06-12 19:07 --------- d-------- C:\Program Files\MSECache
2007-06-05 20:29 386 --a------ C:\WINDOWS\tmpcpyis.bat
2007-06-05 20:29 122 --a------ C:\WINDOWS\tmpdelis.bat
2007-06-05 20:28 26 --a------ C:\WINDOWS\winstart.bat
2007-05-16 11:12 86528 --------- C:\WINDOWS\system32\dllcac
2007-05-16 11:12 85504 --------- C:\WINDOWS\system32\dllcac
2007-05-16 11:12 683520 --a------ C:\WINDOWS\system32\inetco
2007-05-16 11:12 683520 --------- C:\WINDOWS\system32\dllcac
2007-05-16 11:12 510976 --------- C:\WINDOWS\system32\dllcac
2007-05-16 11:12 1314816 --------- C:\WINDOWS\system32\dllcac
((((((((((((((((((((((((((
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWA
"SigmatelSysTrayApp"="stsy
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 21:05]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\Update
"ISUSScheduler"="C:\Progra
"VSOCheckTask"="C:\PROGRA~
"OASClnt"="C:\Program Files\McAfee.com\VSO\oascl
"MCAgentExe"="c:\PROGRA~1\
"MCUpdateExe"="C:\PROGRA~1
"MSKDetectorExe"="C:\PROGR
"DLA"="C:\WINDOWS\System32
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-06-21 13:49]
"MSKAGENTEXE"="C:\PROGRA~1
"VirusScan Online"="c:\PROGRA~1\mcafe
"MPFExe"="C:\PROGRA~1\McAf
"McRegWiz"="C:\PROGRA~1\Mc
"DLCJCATS"="C:\WINDOWS\Sys
"dlcjmon.exe"="C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe" [2005-08-12 08:47]
"MemoryCardManager"="C:\Pr
"SunJavaUpdateSched"="C:\P
"RoxioDragToDisc"="C:\Prog
"MMTray"="C:\Program Files\Musicmatch\Musicmatc
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe
"iTunesHelper"="C:\Program
"MPSExe"="c:\PROGRA~1\mcaf
[HKEY_CURRENT_USER\SOFTWAR
"swg"="C:\Program Files\Google\GoogleToolbar
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-06-21 13:36:31]
[HKEY_LOCAL_MACHINE\softwa
"appinit_dlls"=C:\PROGRA~1
R1 cdudf_xp;cdudf_xp;C:\WINDO
R1 DVDVRRdr_xp;DVDVRRdr_xp;C:
R1 MPFIREWL;MPFIREWL;C:\WINDO
R1 pwd_2k;pwd_2k;C:\WINDOWS\s
R1 UDFReadr;UDFReadr;C:\WINDO
R3 dvd_2K;dvd_2K;C:\WINDOWS\s
S3 mmc_2K;mmc_2K;C:\WINDOWS\s
S3 TnIDriver;TnIDriver;\??\C:
Contents of the 'Scheduled Tasks' folder
2007-07-21 22:36:23 C:\WINDOWS\Tasks\AppleSoft
2007-08-09 13:19:24 C:\WINDOWS\Tasks\RegistryS
**************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-09 22:15:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
Completion time: 2007-08-09 22:17:52 - machine was rebooted
C:\ComboFix-quarantined-fi
C:\ComboFix2.txt ... 2007-08-09 09:20
--- E O F ---
>I will unistall the java application next. I just try the internet but still can't go on-line<
XBedoya,
Your core DLL files may require registering following possible(or probable) damage during the cleanup of the virus infection.
IEFix - is a general purpose repair utility for Internet Explorer which repairs Internet Explorer by registering it's core DLL files and reinstalls using the IE.INF file.
More Information is given below >>
"IEFix - General purpose fix for Internet Explorer":
http://windowsxp.mvps.org/IEFIX.htm
XBedoya,
Your core DLL files may require registering following possible(or probable) damage during the cleanup of the virus infection.
IEFix - is a general purpose repair utility for Internet Explorer which repairs Internet Explorer by registering it's core DLL files and reinstalls using the IE.INF file.
More Information is given below >>
"IEFix - General purpose fix for Internet Explorer":
http://windowsxp.mvps.org/IEFIX.htm
If the IEFix doesn't resolve your problem, take a look at this previous E_E thread and note the excellent comments, in particular by war1.
Initially IE7 was running but it was replaced by IE6. You could use the appropriate recommendations here, to "cleanup & repair" possible IE damage >>
https://www.experts-exchange.com/questions/22318333/Internet-Explorer-hang.html
Initially IE7 was running but it was replaced by IE6. You could use the appropriate recommendations here, to "cleanup & repair" possible IE damage >>
https://www.experts-exchange.com/questions/22318333/Internet-Explorer-hang.html
ASKER
Hi Jonvee, I did run the IEFix but nothing happened. I read the comments that you suggested but couldn't do what it says, first of all I can't go on-line at all and as soon as I open the IE nothing else works I can't call on any menu and I wanted to try the other thing but it says that I need the WinXP CD so I got to find it first.
I am increasing the points since I believe that the level of difficulty on this matter is greater than I thought.
I am increasing the points since I believe that the level of difficulty on this matter is greater than I thought.
Perhaps you can download the "IEFix" and save to CD, then insert the CD in your problematic PC, and run.
You could also try > Start > Run
Then in the 'Open' field, type sfc /scannow (note the space between c and /)
But again you may be asked for that WinXP CD.
You could also try > Start > Run
Then in the 'Open' field, type sfc /scannow (note the space between c and /)
But again you may be asked for that WinXP CD.
You haven't uninstall RegistrySmart yet? It's still showing there and it's still having a scheduled task.
Still have more files to delete, delete the CFScript that you created before, and create a new one below:
Open notepad and copy/paste the text inside the lines below into it
-------------------------- ---------- --------
File::
C:\WINDOWS\system32\3367DA 2490.sys
C:\WINDOWS\system32\9024DA 6733.sys
C:\DOCUME~1\TINAMO~1\APPLI C~1\Regist rySmart
-------------------------- ---------- --------
Save this as CFScript in the same location as ComboFix.exe
drag CFScript into ComboFix.exe
This will start ComboFix again. Follow the prompts
then run SDFix, even if it doesn't find any, it will fix registry entries that were modified by some nasties.
Download SDFix and save it to your desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.
* Open the extracted folder and double click "RunThis.bat" to start the script.
* Type "Y" to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back
Still have more files to delete, delete the CFScript that you created before, and create a new one below:
Open notepad and copy/paste the text inside the lines below into it
--------------------------
File::
C:\WINDOWS\system32\3367DA
C:\WINDOWS\system32\9024DA
C:\DOCUME~1\TINAMO~1\APPLI
--------------------------
Save this as CFScript in the same location as ComboFix.exe
drag CFScript into ComboFix.exe
This will start ComboFix again. Follow the prompts
then run SDFix, even if it doesn't find any, it will fix registry entries that were modified by some nasties.
Download SDFix and save it to your desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.zip
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in Safe Mode by doing the following :
* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, a menu with options should appear;
* Select the first option, to run Windows in Safe Mode, then press "Enter".
* Choose your usual account.
* Open the extracted folder and double click "RunThis.bat" to start the script.
* Type "Y" to begin the script.
* It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* Your system will take longer that normal to restart as the fixtool will be running and removing files.
* When the desktop loads the Fixtool will complete the removal and display "Finished", then press any key to end the script and load your desktop icons.
* Finally open the SDFix folder on your desktop and copy and paste the contents of the results file "Report.txt" back
Also clean your temp folders:
Download and run ATF Cleaner by Atribune.
http://www.atribune.org/ccount/click.php?id=1
Reboot your computer into Safe Mode.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser,
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
OR:
CCleaner:
http://www.ccleaner.com/download/
Download and run ATF Cleaner by Atribune.
http://www.atribune.org/ccount/click.php?id=1
Reboot your computer into Safe Mode.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser,
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
OR:
CCleaner:
http://www.ccleaner.com/download/
ASKER
Good Morning,
Sorry I was away for the weekend. Tonight after work I will sepnd more time in this project.
Thank you for the new comments.
Sorry I was away for the weekend. Tonight after work I will sepnd more time in this project.
Thank you for the new comments.
ASKER
I am still looking for the Windows CD. Following are the results of the SDFix tool but I am still unable to go on-line.
SDFix: Version 1.98
Run by Tina Morris on Mon 08/13/2007 at 09:41 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchos t.exe
No streams found.
C:\WINDOWS\system32\ntoskr nl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system \currentco ntrolset\s ervices\sh aredaccess \parameter s\firewall policy\sta ndardprofi le\authori zedapplica tions\list ]
[HKEY_LOCAL_MACHINE\system \currentco ntrolset\s ervices\sh aredaccess \parameter s\firewall policy\dom ainprofile \authorize dapplicati ons\list]
Remaining Files:
---------------
Files with Hidden Attributes:
C:\WINDOWS\system32\KGyGaA vL.sys
C:\Documents and Settings\Mike Morris\Application Data\Gtek\GTUpdate\AUpdate \Channels\ ch_u1\lock .tmp
C:\Documents and Settings\Mike Morris\Application Data\Gtek\GTUpdate\AUpdate \Channels\ ch_u2\lock .tmp
C:\Documents and Settings\Mike Morris\Application Data\Gtek\GTUpdate\AUpdate \Channels\ ch_u3\lock .tmp
C:\Documents and Settings\Mike Morris\Application Data\Gtek\GTUpdate\AUpdate \Channels\ ch_u4\lock .tmp
C:\WINDOWS\system32\config \DEFAULT.t mp.LOG
C:\WINDOWS\system32\config \SAM.tmp.L OG
C:\WINDOWS\system32\config \SECURITY. tmp.LOG
C:\WINDOWS\system32\config \SOFTWARE. tmp.LOG
C:\WINDOWS\system32\config \SYSTEM.tm p.LOG
Finished
SDFix: Version 1.98
Run by Tina Morris on Mon 08/13/2007 at 09:41 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchos
No streams found.
C:\WINDOWS\system32\ntoskr
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system
[HKEY_LOCAL_MACHINE\system
Remaining Files:
---------------
Files with Hidden Attributes:
C:\WINDOWS\system32\KGyGaA
C:\Documents and Settings\Mike Morris\Application Data\Gtek\GTUpdate\AUpdate
C:\Documents and Settings\Mike Morris\Application Data\Gtek\GTUpdate\AUpdate
C:\Documents and Settings\Mike Morris\Application Data\Gtek\GTUpdate\AUpdate
C:\Documents and Settings\Mike Morris\Application Data\Gtek\GTUpdate\AUpdate
C:\WINDOWS\system32\config
C:\WINDOWS\system32\config
C:\WINDOWS\system32\config
C:\WINDOWS\system32\config
C:\WINDOWS\system32\config
Finished
Still no internet access?
Run this tool winsockfix see if it helps, and also show us a fresh hijackthis log please.
http://www.majorgeeks.com/download4372.html
McAfee hasn't protected you since a lot of nasties were showing in those logs, I would suggest uninstalling McAfee and see if it's also causing those lost of connection. MacAfee's spam filter can be very aggressive.
Run this tool winsockfix see if it helps, and also show us a fresh hijackthis log please.
http://www.majorgeeks.com/download4372.html
McAfee hasn't protected you since a lot of nasties were showing in those logs, I would suggest uninstalling McAfee and see if it's also causing those lost of connection. MacAfee's spam filter can be very aggressive.
XBedoya,
Are you connected directly to the internet, or Networking via a Router ?
If the latter, try rebooting the Router.
Presume you are still unsuccessful downloading the "IEFix" to CD as suggested on 08.11 ?
Let's hope that WinXP CD soon reappears :)
Are you connected directly to the internet, or Networking via a Router ?
If the latter, try rebooting the Router.
Presume you are still unsuccessful downloading the "IEFix" to CD as suggested on 08.11 ?
Let's hope that WinXP CD soon reappears :)
ASKER
Here it is the most recent HIjackThis after running the winsockfix. I have internet conecction now. Should I still try the IEFix?
Logfile of HijackThis v1.99.1
Scan saved at 10:07:43 PM, on 8/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\Ati2ev xx.exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\spools v.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\Update Service\is sch.exe
C:\WINDOWS\System32\DLA\DL ACTRLW.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex. exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDispla y.exe
C:\Program Files\iTunes\iTunesHelper. exe
C:\Program Files\Java\jre1.5.0_03\bin \jusched.e xe
C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\dlcjco ms.exe
C:\Program Files\iPod\bin\iPodService .exe
C:\WINDOWS\system32\wscntf y.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\wuaucl t.exe
C:\Documents and Settings\Tina Morris\Desktop\alternativ. exe
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH elper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0 0123456789 0} - C:\WINDOWS\System32\DLA\DL ASHX_W.DLL
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8 EA1C75885F 9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C F10577473F 7} - c:\program files\google\googletoolbar 2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C E66B5AD205 D} - C:\Program Files\Google\GoogleToolbar Notifier\2 .0.301.716 4\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A 07C3DB8F77 7} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0 09027A5CD4 F} - c:\program files\google\googletoolbar 2.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A A305ED9D92 2} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update Service\is uspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update Service\is sch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL ACTRLW.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\ DRIVERS\W3 2X86\3\DLC Jtime.dll, _RunDLLEnt ry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatc h Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe " -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper. exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin \jusched.e xe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MS KDetct.exe /uninstall
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.5.0_03\bin \npjpi150_ 03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0 0401C60850 1} - C:\Program Files\Java\jre1.5.0_03\bin \npjpi150_ 03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B 4C75499B57 8} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0 0B0D0A1DE4 5} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0 0C0F0318AF E} - C:\WINDOWS\system32\Shdocv w.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~ 1\GOEC62~1 .DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev xx.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjco ms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc. exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterServi ce.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NC S\Sync\Net Svc.exe
Logfile of HijackThis v1.99.1
Scan saved at 10:07:43 PM, on 8/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\Ati2ev
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\WINDOWS\system32\svchos
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\Update
C:\WINDOWS\System32\DLA\DL
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDispla
C:\Program Files\iTunes\iTunesHelper.
C:\Program Files\Java\jre1.5.0_03\bin
C:\Program Files\Google\GoogleToolbar
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\dlcjco
C:\Program Files\iPod\bin\iPodService
C:\WINDOWS\system32\wscntf
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\wuaucl
C:\Documents and Settings\Tina Morris\Desktop\alternativ.
R1 - HKLM\Software\Microsoft\In
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\Update
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatc
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MS
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-0
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjco
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NC
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
rpggamergirl,
Thank you very much. Job well done.
XBedoya
Thank you very much. Job well done.
XBedoya
XBedoya,
You're welcome!
Glad to be of assistance. Thank you for using Experts-Exchange.
Best wishes!
~rpggamergirl
You're welcome!
Glad to be of assistance. Thank you for using Experts-Exchange.
Best wishes!
~rpggamergirl