| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| | |
| Thread Tools |
19-Feb-2007, 10:56 PM
#16 | |||||
| Hi, Bluerain80 You are still getting infected. Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. O2 - BHO: (no name) - {124CA449-6D75-57E5-327C-0AA2BFCDE6B3} - C:\WINDOWS\system32\husnsib.dll O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels88.exe O4 - HKLM\..\Run: [ezorscg.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ezorscg.dll,wewnkae O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\system32\kernels88.exe Now close all windows and browsers, other than HiJackThis, then click Fix Checked. Close Hijackthis.
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems Ugrading Java:
__________________ Unanswered threads for 5 days will no longer be part of my subscriptions. |
| |
|
20-Feb-2007, 12:54 AM
#17 |
| Whew, that took a while but it's done SUPERAntiSpyware Scan Log Generated 02/19/2007 at 08:29 PM Application Version : 3.5.1016 Core Rules Database Version : 3186 Trace Rules Database Version: 1196 Scan type : Complete Scan Total Scan Time : 01:02:25 Memory items scanned : 304 Memory threats detected : 0 Registry items scanned : 5465 Registry threats detected : 0 File items scanned : 81414 File threats detected : 72 Adware.Tracking Cookie C:\Documents and Settings\YJH\Cookies\yjh@hitbox[2].txt C:\Documents and Settings\YJH\Cookies\yjh@cgi-bin[3].txt C:\Documents and Settings\YJH\Cookies\yjh@ehg-dig.hitbox[1].txt C:\Documents and Settings\YJH\Cookies\yjh@partygaming.122.2o7[1].txt C:\Documents and Settings\YJH\Cookies\yjh@www.upspiral[1].txt C:\Documents and Settings\YJH\Cookies\yjh@spylog[1].txt C:\Documents and Settings\YJH\Cookies\yjh@nads9.nasads[2].txt C:\Documents and Settings\YJH\Cookies\yjh@adrevolver[2].txt C:\Documents and Settings\YJH\Cookies\yjh@adbrite[1].txt C:\Documents and Settings\YJH\Cookies\yjh@realmedia[1].txt C:\Documents and Settings\YJH\Cookies\yjh@mb[2].txt C:\Documents and Settings\YJH\Cookies\yjh@toplist.gallery-dump[2].txt C:\Documents and Settings\YJH\Cookies\yjh@findwhat[1].txt C:\Documents and Settings\YJH\Cookies\yjh@zedo[1].txt C:\Documents and Settings\YJH\Cookies\yjh@pro-market[1].txt C:\Documents and Settings\YJH\Cookies\yjh@atdmt[2].txt C:\Documents and Settings\YJH\Cookies\yjh@ad1.dmcmedia.co[1].txt C:\Documents and Settings\YJH\Cookies\yjh@partypoker[2].txt C:\Documents and Settings\YJH\Cookies\yjh@ads.realtechnetwork[1].txt C:\Documents and Settings\YJH\Cookies\yjh@geosign.112.2o7[1].txt C:\Documents and Settings\YJH\Cookies\yjh@goclick[1].txt C:\Documents and Settings\YJH\Cookies\yjh@counter.plugin[1].txt C:\Documents and Settings\YJH\Cookies\yjh@upspiral[2].txt C:\Documents and Settings\YJH\Cookies\yjh@counter.surfcounters[1].txt C:\Documents and Settings\YJH\Cookies\yjh@media.pc.ign[1].txt C:\Documents and Settings\YJH\Cookies\yjh@ad.yieldmanager[1].txt C:\Documents and Settings\YJH\Cookies\yjh@adtech[2].txt C:\Documents and Settings\YJH\Cookies\yjh@tribalfusion[1].txt C:\Documents and Settings\YJH\Cookies\yjh@ads.pointroll[2].txt C:\Documents and Settings\YJH\Cookies\yjh@reduxads.valuead[2].txt C:\Documents and Settings\YJH\Cookies\yjh@2o7[2].txt C:\Documents and Settings\YJH\Cookies\yjh@www.888[1].txt C:\Documents and Settings\YJH\Cookies\yjh@mb[3].txt C:\Documents and Settings\YJH\Cookies\yjh@doubleclick[1].txt C:\Documents and Settings\YJH\Cookies\yjh@media.fastclick[2].txt C:\Documents and Settings\YJH\Cookies\yjh@revsci[2].txt C:\Documents and Settings\YJH\Cookies\yjh@www.burstnet[1].txt C:\Documents and Settings\YJH\Cookies\yjh@overture[1].txt C:\Documents and Settings\YJH\Cookies\yjh@fastclick[1].txt C:\Documents and Settings\YJH\Cookies\yjh@adserver[1].txt C:\Documents and Settings\YJH\Cookies\yjh@adult.dvdempire[1].txt C:\Documents and Settings\YJH\Cookies\yjh@adrevolver[1].txt C:\Documents and Settings\YJH\Cookies\yjh@tripod[1].txt C:\Documents and Settings\YJH\Cookies\yjh@enhance[2].txt C:\Documents and Settings\YJH\Cookies\yjh@advertising[1].txt C:\Documents and Settings\YJH\Cookies\yjh@mb[1].txt C:\Documents and Settings\YJH\Cookies\yjh@statcounter[2].txt C:\Documents and Settings\YJH\Cookies\yjh@ads.revsci[1].txt Malware.Ultimate Defender C:\Program Files\Ultimate Defender C:\DOCUMENTS AND SETTINGS\YJH\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\0HI3OLER\UDEFENDER_QGAHO26BYG[1].EXE Unclassified.Unknown Origin C:\DOCUMENTS AND SETTINGS\YJH\DESKTOP\BACKUPS\BACKUP-20070217-215454-891.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{64FCA2A6-3513-4806-84BD-9F028CDAD2BA}\RP735\A0145430.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{64FCA2A6-3513-4806-84BD-9F028CDAD2BA}\RP735\A0145431.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{64FCA2A6-3513-4806-84BD-9F028CDAD2BA}\RP735\A0145503.EXE C:\_OTMOVEIT\MOVEDFILES\DOCUMENTS AND SETTINGS\YJH\DESKTOP\BACKUPS\BACKUP-20070217-215454-627.DLL Trojan.Downloader-DoneDU C:\DOCUMENTS AND SETTINGS\YJH\DESKTOP\BACKUPS\BACKUP-20070219-191206-598.DLL C:\SYSTEM VOLUME INFORMATION\_RESTORE{64FCA2A6-3513-4806-84BD-9F028CDAD2BA}\RP736\A0146576.DLL Trojan.Downloader-H91 C:\DOCUMENTS AND SETTINGS\YJH\LOCAL SETTINGS\TEMP\H91746.EXE Dialer.Dial/Gen Variant C:\DOCUMENTS AND SETTINGS\YJH\LOCAL SETTINGS\TEMP\MA1XDD1.GAME C:\SYSTEM VOLUME INFORMATION\_RESTORE{64FCA2A6-3513-4806-84BD-9F028CDAD2BA}\RP736\A0146559.EXE C:\WINDOWS\SYSTEM32\MAX1D641.EXE Trojan.Downloader-Gen/FS C:\DOCUMENTS AND SETTINGS\YJH\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\OPQ3K5IN\ML[1].EXE Adware.ClickSpring C:\SYSTEM VOLUME INFORMATION\_RESTORE{64FCA2A6-3513-4806-84BD-9F028CDAD2BA}\RP735\A0145504.EXE Unclassified.Unknown Origin/System C:\SYSTEM VOLUME INFORMATION\_RESTORE{64FCA2A6-3513-4806-84BD-9F028CDAD2BA}\RP735\A0145508.EXE Adware.DigitalNames C:\WINDOWS\SYSTEM32\DGTSTART.EXE Trojan.VXGame-Gen C:\WINDOWS\SYSTEM32\DLH9JKD1Q2.EXE C:\WINDOWS\SYSTEM32\DLH9JKD1Q5.EXE C:\WINDOWS\SYSTEM32\DLH9JKD1Q6.EXE C:\WINDOWS\SYSTEM32\DLH9JKD1Q7.EXE C:\WINDOWS\SYSTEM32\DLH9JKD1Q8.EXE Worm.Rbot Variant C:\WINDOWS\SYSTEM32\SSE001.EXE Trace.Known Threat Sources C:\Documents and Settings\YJH\Local Settings\Temporary Internet Files\Content.IE5\0LIJOT2N\get_lic[1].htm ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Logfile of HijackThis v1.99.1 Scan saved at 8:54:29 PM, on 2/19/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Ahnlab\Smart Update Utility\Ahnsdsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\PROGRA~1\Ahnlab\V3\MonSvcNT.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\YJH\Desktop\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: V3 - {9E3849D6-41EF-4B2F-86B7-632EF90758E4} - C:\Program Files\Ahnlab\V3\V3Bar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: (no name) - {07b7f771-1b8e-4b7b-823e-ffac1732aa9f} - (no file) (HKCU) O15 - Trusted Zone: http://free.aol.com O16 - DPF: {00001023-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter23 Class) - http://download.netmarble.com/web/nm...MStarter23.cab O16 - DPF: {04E7BADF-F3B9-420D-B82D-8D8CADEFE4F9} (CyImage2Ctl Class) - http://cyimg6.cyworld.nate.com/Image...ageUpload2.cab O16 - DPF: {124250DD-E2CC-4B5B-AE7E-C9AC8A11DF43} (StreamNote2 Control) - http://cyber.jungchul.com/data17/Exp...treamNote2.cab O16 - DPF: {1D046A46-955A-4FBC-800E-67F123047B2B} (Sso001 Control) - http://www.ibegin.co.kr/setstart/setstart/sso001i.cab O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://file.nx.com/activex/public_new/nxpm.cab O16 - DPF: {5DAEF053-DEF0-4752-A963-CCE9B49B0B79} (Gogs Class) - http://app.ipop.co.kr/gogsweb/gogsweb.cab O16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/cab9/dmcc2.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netmarble.com/kdefence/kdfense8.cab O16 - DPF: {A671DC03-71D0-4CF0-895C-7D4A248FC1F1} (skcbgmset Class) - http://cyimg7.cyworld.nate.com/cymus.../skcbgmset.cab O16 - DPF: {AF11AA64-87A5-4146-AF3B-A7BD0F278485} (SBStarter Control) - http://download.soribada.com/down/So...30/SBStart.CAB O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://cafeimg.hanmail.net/cto/xman.cab?ver=1,2,2,0 O16 - DPF: {BF628973-1E86-4D0E-B42C-EDDECFFABDBC} (Bugs AoD Class) - http://player.bugs.co.kr/install/bugsLoader20041008.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ahnlab Task Scheduler - AhnLab, Inc. - C:\Program Files\Ahnlab\Smart Update Utility\Ahnsdsv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: MonSvcNT - AhnLab, Inc. - C:\PROGRA~1\Ahnlab\V3\MonSvcNT.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 01:17 AM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

