Been Dealing with this for Months. PLEASE HELP !!!

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

rts5678

Thread Starter
Joined
Jun 1, 2007
Messages
4
My computer has been hijacked by malware, spyware, and what not. Blank desktops, popups, multiple norton warnings are an everyday thing. I am tired of this.

I posted this in another forum but did not get help.

Can someone please help me here. I'd be so grateful.

Given below is my Hijack This log:



Logfile of HijackThis v1.99.1
Scan saved at 7:21:02 PM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\jecsccgs.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Documents and Settings\All Users\Application Data\tezchiby.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Documents and Settings\faisal\Desktop\ETC\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [tezchiby.exe] C:\Documents and Settings\All Users\Application Data\tezchiby.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [j9231639] rundll32 C:\WINDOWS\system32\j9231639.dll sook
O4 - HKLM\..\Run: [Flashget] "C:\Program Files\FlashGet\FlashGet.exe" /min
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\xhqkgmdc.dll",realset
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\jecsccgs.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MpService - Canon Inc - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
 

Cheeseball81

Retired Moderator
Joined
Mar 3, 2004
Messages
84,315
Hi and welcome

Download the Trial version of Superantispyware Pro (SAS):
http://www.superantispyware.com/superantispyware.html?rid=3132


Install it and double-click the icon on your desktop to run it.
· It will ask if you want to update the program definitions, click Yes.
· Under Configuration and Preferences, click the Preferences button.
· Click the Scanning Control tab.
· Under Scanner Options make sure the following are checked:
o Close browsers before scanning
o Scan for tracking cookies
o Terminate memory threats before quarantining.
o Please leave the others unchecked.
o Click the Close button to leave the control center screen.
· On the main screen, under Scan for Harmful Software click Scan your computer.
· On the left check C:\Fixed Drive.
· On the right, under Complete Scan, choose Perform Complete Scan.
· Click Next to start the scan. Please be patient while it scans your computer.
· After the scan is complete a summary box will appear. Click OK.
· Make sure everything in the white box has a check next to it, then click Next.
· It will quarantine what it found and if it asks if you want to reboot, click Yes.
· To retrieve the removal information for me please do the following:
o After reboot, double-click the SUPERAntispyware icon on your desktop.
o Click Preferences. Click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o It will open in your default text editor (such as Notepad/Wordpad).
o Please highlight everything in the notepad, then right-click and choose copy.
· Click close and close again to exit the program.
· Please paste that information here for me with a new Hijack This log.
 

rts5678

Thread Starter
Joined
Jun 1, 2007
Messages
4
SuperAntiSypware Log:

------------------------

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 07/16/2007 at 12:02 PM

Application Version : 3.9.1008

Core Rules Database Version : 3269
Trace Rules Database Version: 1280

Scan type : Complete Scan
Total Scan Time : 08:18:53

Memory items scanned : 394
Memory threats detected : 3
Registry items scanned : 7463
Registry threats detected : 59
File items scanned : 876600
File threats detected : 199

Unclassified.Unknown Origin/System
C:\WINDOWS\SYSTEM32\JKHHI.DLL
C:\WINDOWS\SYSTEM32\JKHHI.DLL
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\jkhhi

Trojan.Downloader-Gen/SwampDonk
C:\WINDOWS\SYSTEM32\XXYYWTS.DLL
C:\WINDOWS\SYSTEM32\XXYYWTS.DLL
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\xxyywts
C:\WINDOWS\SYSTEM32\AWTRRQQ.DLL
C:\WINDOWS\SYSTEM32\DDCYYYX.DLL

Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\TNIDVCTM.DLL
C:\WINDOWS\SYSTEM32\TNIDVCTM.DLL
HKLM\Software\Classes\CLSID\{06184206-C766-4605-92BF-8CF7129C317A}
HKCR\CLSID\{06184206-C766-4605-92BF-8CF7129C317A}
HKCR\CLSID\{06184206-C766-4605-92BF-8CF7129C317A}\InprocServer32
HKCR\CLSID\{06184206-C766-4605-92BF-8CF7129C317A}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{92A444D2-F945-4dd9-89A1-896A6C2D8D22}
HKCR\CLSID\{92A444D2-F945-4DD9-89A1-896A6C2D8D22}
HKCR\CLSID\{92A444D2-F945-4DD9-89A1-896A6C2D8D22}\InprocServer32
HKCR\CLSID\{92A444D2-F945-4DD9-89A1-896A6C2D8D22}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\RVXPQFSK.DLL
HKLM\Software\Classes\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}
HKCR\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}
HKCR\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}\InprocServer32
HKCR\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}
HKCR\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}
HKCR\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}\InprocServer32
HKCR\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\LDPWBXWA.DLL
HKLM\Software\Classes\CLSID\{E12BFF69-38A7-406e-A8EF-2738107A7831}
HKCR\CLSID\{E12BFF69-38A7-406E-A8EF-2738107A7831}
HKCR\CLSID\{E12BFF69-38A7-406E-A8EF-2738107A7831}\InprocServer32
HKCR\CLSID\{E12BFF69-38A7-406E-A8EF-2738107A7831}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\UIYAPXNB.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06184206-C766-4605-92BF-8CF7129C317A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B71FA585-B351-4E48-8DA8-22F6F705EC73}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E12BFF69-38A7-406e-A8EF-2738107A7831}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{B71FA585-B351-4E48-8DA8-22F6F705EC73}
HKCR\CLSID\{92A444D2-F945-4DD9-89A1-896A6C2D8D22}
HKCR\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}
HKCR\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}
HKCR\CLSID\{E12BFF69-38A7-406E-A8EF-2738107A7831}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP118\A0024863.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP119\A0024939.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP120\A0025047.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP121\A0025139.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP121\A0025164.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP122\A0026197.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP123\A0027233.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP125\A0027288.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP125\A0027356.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP129\A0029430.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0030683.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0030684.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0030726.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0031726.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0031727.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0033726.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0033761.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP139\A0036612.DLL
C:\WINDOWS\SYSTEM32\AABRSUWO.DLL
C:\WINDOWS\SYSTEM32\AXPIWPJJ.DLL
C:\WINDOWS\SYSTEM32\DLPGBUIN.DLL
C:\WINDOWS\SYSTEM32\FXJPGJBM.DLL
C:\WINDOWS\SYSTEM32\LOMRHLBJ.DLL
C:\WINDOWS\SYSTEM32\MFDLQKRP.DLL
C:\WINDOWS\SYSTEM32\NONGTTVS.DLL
C:\WINDOWS\SYSTEM32\OARTPPCG.DLL
C:\WINDOWS\SYSTEM32\OMXDPACF.DLL
C:\WINDOWS\SYSTEM32\PEBTVMHD.DLL
C:\WINDOWS\SYSTEM32\URVOKVRB.DLL
C:\WINDOWS\SYSTEM32\VVKESHEB.DLL
C:\WINDOWS\SYSTEM32\XHQKGMDC.DLL

Trojan.Downloader-Gen/JSnat
[tezchiby.exe] C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\TEZCHIBY.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\TEZCHIBY.EXE
C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN38A.TMP.EXE
C:\WINDOWS\TEMP\WIN92.TMP.EXE
C:\WINDOWS\Prefetch\TEZCHIBY.EXE-0DC8C833.pf

Trojan.Downloader-CREW
HKLM\Software\Classes\CLSID\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}
HKCR\CLSID\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}
HKCR\CLSID\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}\InprocServer32
HKCR\CLSID\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\APPDQISX.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}
C:\WINDOWS\SYSTEM32\QYLAMGBY.DLL

Trojan.Downloader/Dialer-LiveCall
HKLM\Software\Classes\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}
HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}
HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}
HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}\InprocServer32
HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}\InprocServer32#ThreadingModel
HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}\ProgID
C:\WINDOWS\SYSTEM32\IEHELPER3.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49E0E0F0-5C30-11D4-945D-000000000000}

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{5ADF3862-9E2E-4ad3-86F7-4510E6550CD0}
HKCR\CLSID\{5ADF3862-9E2E-4AD3-86F7-4510E6550CD0}
HKCR\CLSID\{5ADF3862-9E2E-4AD3-86F7-4510E6550CD0}\InprocServer32
HKCR\CLSID\{5ADF3862-9E2E-4AD3-86F7-4510E6550CD0}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\AXIKIOGS.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5ADF3862-9E2E-4ad3-86F7-4510E6550CD0}
HKCR\CLSID\{5ADF3862-9E2E-4AD3-86F7-4510E6550CD0}

Adware.ANRus/CN
HKLM\Software\Classes\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}
HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}
HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}
HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}\InprocServer32
HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}\InprocServer32#ThreadingModel
HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}\ProgID
C:\WINDOWS\SYSTEM32\HPI3.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6280729-9251-41D7-BC1C-572C9548C962}

Adware.eZula
HKLM\System\ControlSet001\Services\DomainService
C:\WINDOWS\SYSTEM32\JECSCCGS.EXE
HKLM\System\ControlSet003\Services\DomainService
HKLM\System\CurrentControlSet\Services\DomainService
C:\WINDOWS\SYSTEM32\AUTEFFCG.EXE
C:\WINDOWS\SYSTEM32\BGFQLUVN.EXE
C:\WINDOWS\SYSTEM32\CFSFRIAU.EXE
C:\WINDOWS\SYSTEM32\FERXVUTB.EXE
C:\WINDOWS\SYSTEM32\NIPWJNKH.EXE
C:\WINDOWS\SYSTEM32\PKVMQCSV.EXE
C:\WINDOWS\SYSTEM32\QBJVOVPF.EXE
C:\WINDOWS\SYSTEM32\ROWTNNNC.EXE
C:\WINDOWS\SYSTEM32\UABAMJHR.EXE
C:\WINDOWS\Prefetch\JECSCCGS.EXE-2F13C753.pf

Adware.Tracking Cookie
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][3].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][4].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
C:\Documents and Settings\faisal\Cookies\[email protected][3].txt

Trojan.Downloader-WinMQX32
C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\GOS380.TMP

Trojan.Unknown Origin
C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN388.TMP.EXE
C:\WINDOWS\TEMP\WIN82.TMP.EXE

Trojan.Downloader-Gen/Mandingo
C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN38C.TMP.EXE
C:\WINDOWS\TEMP\WIN84.TMP.EXE

Trojan.Downloader-SVCHost/Fake
C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN38E.TMP.EXE
C:\WINDOWS\TEMP\WIN86.TMP.EXE

Trojan.Downloader-Gen/Inst2
C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN390.TMP.EXE
C:\WINDOWS\TEMP\WIN88.TMP.EXE

Trojan.Downloader-Gen/AllowCookie
C:\WINDOWS\SYSTEM32\DPRWUCCE.EXE
C:\WINDOWS\SYSTEM32\FHSBJNPO.EXE
C:\WINDOWS\SYSTEM32\UIAJSBUF.EXE

Trojan.Downloader-UltimateFixer
C:\WINDOWS\SYSTEM32\SCCHK32.EXE

Trojan.Downloader-Gen/TStamp
C:\WINDOWS\SYSTEM32\UBTCNRAU.EXE

Trace.Known Threat Sources
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\W1MJOXIB\download2[1].htm
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\IABKLP09\icon5[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\S92741E3\index[1].htm
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\WLIZOHQZ\arrow[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CPYB0DMF\top[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\IABKLP09\managers[1].htm
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\GHE3W5YJ\star[2].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0DIJ0TIV\fonbox2[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\GHE3W5YJ\baba[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\8PYBC927\scanner[1].htm
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OV3BAWPP\boot[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\K1QBWTER\styles[1].css
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CP6JO5U3\knop[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\LKG7XH8T\box[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\S92741E3\fonbox1[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\9TXMZN5B\us[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CP6JO5U3\footer-bg[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0PI70XYB\index[1].htm
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\2PR4TCVU\icon1[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CPYB0DMF\index[1].htm
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0DIJ0TIV\logo-bg[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\FJLFRXGO\icon2[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OV3BAWPP\icon4[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\G9INCHMJ\part4[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\LKG7XH8T\win_fixer_banner[1].swf
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\Z7LV3LOW\sirena2[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CP6JO5U3\logo3[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CPYB0DMF\spacer[2].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\K1QBWTER\boton2[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\FJLFRXGO\test[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OHA78LIJ\bg1[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OHA78LIJ\banner3[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\W1MJOXIB\t4[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\U3BJ2VXE\t3[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\G9INCHMJ\part3[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0PI70XYB\part5[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CP6JO5U3\CA85QZ8X.js
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\FJLFRXGO\checksoft[1].js
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OHA78LIJ\part7[1].jpg
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\2PR4TCVU\brd-top-3[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\W1MJOXIB\part6[1].jpg
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\8PYBC927\t1[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\Z7LV3LOW\bg3[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0DIJ0TIV\t2[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OV3BAWPP\top[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\S92741E3\brd-top-1[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\LKG7XH8T\2007[1].htm
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CHS5QRGT\bg2[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\K1QBWTER\t5[1].gif
C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\S92741E3\bg6[1].gif
 

rts5678

Thread Starter
Joined
Jun 1, 2007
Messages
4
Hijack This Log after the SuperAntiSpyware Scan:


Logfile of HijackThis v1.99.1
Scan saved at 2:08:11 PM, on 7/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\faisal\Desktop\ETC\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Flashget] "C:\Program Files\FlashGet\FlashGet.exe" /min
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MpService - Canon Inc - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
 

Cheeseball81

Retired Moderator
Joined
Mar 3, 2004
Messages
84,315
Run ActiveScan online virus scan:
http://www.pandasoftware.com/products/activescan.htm

Once you are on the Panda site click the Scan your PC button.
A new window will open...click the Check Now button.
Enter your Country.
Enter your State/Province.
Enter your e-mail address and click send.
Select either Home User or Company.
Click the big Scan Now button.
If it wants to install an ActiveX component allow it.
It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
When download is complete, click on My Computer to start the scan.
When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the ActiveScan report.
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top