1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Been Dealing with this for Months. PLEASE HELP !!!

Discussion in 'Virus & Other Malware Removal' started by rts5678, Jul 15, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. rts5678

    rts5678 Thread Starter

    Joined:
    Jun 1, 2007
    Messages:
    4
    My computer has been hijacked by malware, spyware, and what not. Blank desktops, popups, multiple norton warnings are an everyday thing. I am tired of this.

    I posted this in another forum but did not get help.

    Can someone please help me here. I'd be so grateful.

    Given below is my Hijack This log:



    Logfile of HijackThis v1.99.1
    Scan saved at 7:21:02 PM, on 7/15/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\system32\jecsccgs.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
    C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
    C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
    C:\WINDOWS\system32\ICO.EXE
    C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
    C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\Documents and Settings\All Users\Application Data\tezchiby.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\Program Files\Apoint\Apntex.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Documents and Settings\faisal\Desktop\ETC\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
    R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
    O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
    O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
    O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
    O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [tezchiby.exe] C:\Documents and Settings\All Users\Application Data\tezchiby.exe
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [j9231639] rundll32 C:\WINDOWS\system32\j9231639.dll sook
    O4 - HKLM\..\Run: [Flashget] "C:\Program Files\FlashGet\FlashGet.exe" /min
    O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\xhqkgmdc.dll",realset
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: DomainService - - C:\WINDOWS\system32\jecsccgs.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MpService - Canon Inc - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
     
  2. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Hi and welcome

    Download the Trial version of Superantispyware Pro (SAS):
    http://www.superantispyware.com/superantispyware.html?rid=3132


    Install it and double-click the icon on your desktop to run it.
    · It will ask if you want to update the program definitions, click Yes.
    · Under Configuration and Preferences, click the Preferences button.
    · Click the Scanning Control tab.
    · Under Scanner Options make sure the following are checked:
    o Close browsers before scanning
    o Scan for tracking cookies
    o Terminate memory threats before quarantining.
    o Please leave the others unchecked.
    o Click the Close button to leave the control center screen.
    · On the main screen, under Scan for Harmful Software click Scan your computer.
    · On the left check C:\Fixed Drive.
    · On the right, under Complete Scan, choose Perform Complete Scan.
    · Click Next to start the scan. Please be patient while it scans your computer.
    · After the scan is complete a summary box will appear. Click OK.
    · Make sure everything in the white box has a check next to it, then click Next.
    · It will quarantine what it found and if it asks if you want to reboot, click Yes.
    · To retrieve the removal information for me please do the following:
    o After reboot, double-click the SUPERAntispyware icon on your desktop.
    o Click Preferences. Click the Statistics/Logs tab.
    o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    o It will open in your default text editor (such as Notepad/Wordpad).
    o Please highlight everything in the notepad, then right-click and choose copy.
    · Click close and close again to exit the program.
    · Please paste that information here for me with a new Hijack This log.
     
  3. rts5678

    rts5678 Thread Starter

    Joined:
    Jun 1, 2007
    Messages:
    4
    SuperAntiSypware Log:

    ------------------------

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 07/16/2007 at 12:02 PM

    Application Version : 3.9.1008

    Core Rules Database Version : 3269
    Trace Rules Database Version: 1280

    Scan type : Complete Scan
    Total Scan Time : 08:18:53

    Memory items scanned : 394
    Memory threats detected : 3
    Registry items scanned : 7463
    Registry threats detected : 59
    File items scanned : 876600
    File threats detected : 199

    Unclassified.Unknown Origin/System
    C:\WINDOWS\SYSTEM32\JKHHI.DLL
    C:\WINDOWS\SYSTEM32\JKHHI.DLL
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\jkhhi

    Trojan.Downloader-Gen/SwampDonk
    C:\WINDOWS\SYSTEM32\XXYYWTS.DLL
    C:\WINDOWS\SYSTEM32\XXYYWTS.DLL
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\xxyywts
    C:\WINDOWS\SYSTEM32\AWTRRQQ.DLL
    C:\WINDOWS\SYSTEM32\DDCYYYX.DLL

    Adware.Vundo Variant
    C:\WINDOWS\SYSTEM32\TNIDVCTM.DLL
    C:\WINDOWS\SYSTEM32\TNIDVCTM.DLL
    HKLM\Software\Classes\CLSID\{06184206-C766-4605-92BF-8CF7129C317A}
    HKCR\CLSID\{06184206-C766-4605-92BF-8CF7129C317A}
    HKCR\CLSID\{06184206-C766-4605-92BF-8CF7129C317A}\InprocServer32
    HKCR\CLSID\{06184206-C766-4605-92BF-8CF7129C317A}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{92A444D2-F945-4dd9-89A1-896A6C2D8D22}
    HKCR\CLSID\{92A444D2-F945-4DD9-89A1-896A6C2D8D22}
    HKCR\CLSID\{92A444D2-F945-4DD9-89A1-896A6C2D8D22}\InprocServer32
    HKCR\CLSID\{92A444D2-F945-4DD9-89A1-896A6C2D8D22}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\RVXPQFSK.DLL
    HKLM\Software\Classes\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}
    HKCR\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}
    HKCR\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}\InprocServer32
    HKCR\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}\InprocServer32#ThreadingModel
    HKLM\Software\Classes\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}
    HKCR\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}
    HKCR\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}\InprocServer32
    HKCR\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\LDPWBXWA.DLL
    HKLM\Software\Classes\CLSID\{E12BFF69-38A7-406e-A8EF-2738107A7831}
    HKCR\CLSID\{E12BFF69-38A7-406E-A8EF-2738107A7831}
    HKCR\CLSID\{E12BFF69-38A7-406E-A8EF-2738107A7831}\InprocServer32
    HKCR\CLSID\{E12BFF69-38A7-406E-A8EF-2738107A7831}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\UIYAPXNB.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06184206-C766-4605-92BF-8CF7129C317A}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B71FA585-B351-4E48-8DA8-22F6F705EC73}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E12BFF69-38A7-406e-A8EF-2738107A7831}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{B71FA585-B351-4E48-8DA8-22F6F705EC73}
    HKCR\CLSID\{92A444D2-F945-4DD9-89A1-896A6C2D8D22}
    HKCR\CLSID\{B71FA585-B351-4E48-8DA8-22F6F705EC73}
    HKCR\CLSID\{CD3447D4-CA39-4377-8084-30E86331D74C}
    HKCR\CLSID\{E12BFF69-38A7-406E-A8EF-2738107A7831}
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP118\A0024863.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP119\A0024939.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP120\A0025047.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP121\A0025139.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP121\A0025164.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP122\A0026197.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP123\A0027233.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP125\A0027288.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP125\A0027356.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP129\A0029430.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0030683.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0030684.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0030726.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0031726.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0031727.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0033726.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP131\A0033761.DLL
    C:\SYSTEM VOLUME INFORMATION\_RESTORE{ECE42D92-315C-418E-8F32-95DC4FF2BBEF}\RP139\A0036612.DLL
    C:\WINDOWS\SYSTEM32\AABRSUWO.DLL
    C:\WINDOWS\SYSTEM32\AXPIWPJJ.DLL
    C:\WINDOWS\SYSTEM32\DLPGBUIN.DLL
    C:\WINDOWS\SYSTEM32\FXJPGJBM.DLL
    C:\WINDOWS\SYSTEM32\LOMRHLBJ.DLL
    C:\WINDOWS\SYSTEM32\MFDLQKRP.DLL
    C:\WINDOWS\SYSTEM32\NONGTTVS.DLL
    C:\WINDOWS\SYSTEM32\OARTPPCG.DLL
    C:\WINDOWS\SYSTEM32\OMXDPACF.DLL
    C:\WINDOWS\SYSTEM32\PEBTVMHD.DLL
    C:\WINDOWS\SYSTEM32\URVOKVRB.DLL
    C:\WINDOWS\SYSTEM32\VVKESHEB.DLL
    C:\WINDOWS\SYSTEM32\XHQKGMDC.DLL

    Trojan.Downloader-Gen/JSnat
    [tezchiby.exe] C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\TEZCHIBY.EXE
    C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\TEZCHIBY.EXE
    C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN38A.TMP.EXE
    C:\WINDOWS\TEMP\WIN92.TMP.EXE
    C:\WINDOWS\Prefetch\TEZCHIBY.EXE-0DC8C833.pf

    Trojan.Downloader-CREW
    HKLM\Software\Classes\CLSID\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}
    HKCR\CLSID\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}
    HKCR\CLSID\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}\InprocServer32
    HKCR\CLSID\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\APPDQISX.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1C3BE549-45F7-4C83-B378-EDEA44CAC480}
    C:\WINDOWS\SYSTEM32\QYLAMGBY.DLL

    Trojan.Downloader/Dialer-LiveCall
    HKLM\Software\Classes\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}
    HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}
    HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}
    HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}\InprocServer32
    HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}\InprocServer32#ThreadingModel
    HKCR\CLSID\{49E0E0F0-5C30-11D4-945D-000000000000}\ProgID
    C:\WINDOWS\SYSTEM32\IEHELPER3.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49E0E0F0-5C30-11D4-945D-000000000000}

    Unclassified.Unknown Origin
    HKLM\Software\Classes\CLSID\{5ADF3862-9E2E-4ad3-86F7-4510E6550CD0}
    HKCR\CLSID\{5ADF3862-9E2E-4AD3-86F7-4510E6550CD0}
    HKCR\CLSID\{5ADF3862-9E2E-4AD3-86F7-4510E6550CD0}\InprocServer32
    HKCR\CLSID\{5ADF3862-9E2E-4AD3-86F7-4510E6550CD0}\InprocServer32#ThreadingModel
    C:\WINDOWS\SYSTEM32\AXIKIOGS.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5ADF3862-9E2E-4ad3-86F7-4510E6550CD0}
    HKCR\CLSID\{5ADF3862-9E2E-4AD3-86F7-4510E6550CD0}

    Adware.ANRus/CN
    HKLM\Software\Classes\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}
    HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}
    HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}
    HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}\InprocServer32
    HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}\InprocServer32#ThreadingModel
    HKCR\CLSID\{E6280729-9251-41D7-BC1C-572C9548C962}\ProgID
    C:\WINDOWS\SYSTEM32\HPI3.DLL
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6280729-9251-41D7-BC1C-572C9548C962}

    Adware.eZula
    HKLM\System\ControlSet001\Services\DomainService
    C:\WINDOWS\SYSTEM32\JECSCCGS.EXE
    HKLM\System\ControlSet003\Services\DomainService
    HKLM\System\CurrentControlSet\Services\DomainService
    C:\WINDOWS\SYSTEM32\AUTEFFCG.EXE
    C:\WINDOWS\SYSTEM32\BGFQLUVN.EXE
    C:\WINDOWS\SYSTEM32\CFSFRIAU.EXE
    C:\WINDOWS\SYSTEM32\FERXVUTB.EXE
    C:\WINDOWS\SYSTEM32\NIPWJNKH.EXE
    C:\WINDOWS\SYSTEM32\PKVMQCSV.EXE
    C:\WINDOWS\SYSTEM32\QBJVOVPF.EXE
    C:\WINDOWS\SYSTEM32\ROWTNNNC.EXE
    C:\WINDOWS\SYSTEM32\UABAMJHR.EXE
    C:\WINDOWS\Prefetch\JECSCCGS.EXE-2F13C753.pf

    Adware.Tracking Cookie
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][3].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected].websponsors[2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][4].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][2].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][1].txt
    C:\Documents and Settings\faisal\Cookies\[email protected][3].txt

    Trojan.Downloader-WinMQX32
    C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\GOS380.TMP

    Trojan.Unknown Origin
    C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN388.TMP.EXE
    C:\WINDOWS\TEMP\WIN82.TMP.EXE

    Trojan.Downloader-Gen/Mandingo
    C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN38C.TMP.EXE
    C:\WINDOWS\TEMP\WIN84.TMP.EXE

    Trojan.Downloader-SVCHost/Fake
    C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN38E.TMP.EXE
    C:\WINDOWS\TEMP\WIN86.TMP.EXE

    Trojan.Downloader-Gen/Inst2
    C:\DOCUMENTS AND SETTINGS\FAISAL\LOCAL SETTINGS\TEMP\WIN390.TMP.EXE
    C:\WINDOWS\TEMP\WIN88.TMP.EXE

    Trojan.Downloader-Gen/AllowCookie
    C:\WINDOWS\SYSTEM32\DPRWUCCE.EXE
    C:\WINDOWS\SYSTEM32\FHSBJNPO.EXE
    C:\WINDOWS\SYSTEM32\UIAJSBUF.EXE

    Trojan.Downloader-UltimateFixer
    C:\WINDOWS\SYSTEM32\SCCHK32.EXE

    Trojan.Downloader-Gen/TStamp
    C:\WINDOWS\SYSTEM32\UBTCNRAU.EXE

    Trace.Known Threat Sources
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\W1MJOXIB\download2[1].htm
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\IABKLP09\icon5[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\S92741E3\index[1].htm
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\WLIZOHQZ\arrow[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CPYB0DMF\top[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\IABKLP09\managers[1].htm
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\GHE3W5YJ\star[2].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0DIJ0TIV\fonbox2[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\GHE3W5YJ\baba[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\8PYBC927\scanner[1].htm
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OV3BAWPP\boot[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\K1QBWTER\styles[1].css
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CP6JO5U3\knop[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\LKG7XH8T\box[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\S92741E3\fonbox1[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\9TXMZN5B\us[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CP6JO5U3\footer-bg[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0PI70XYB\index[1].htm
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\2PR4TCVU\icon1[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CPYB0DMF\index[1].htm
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0DIJ0TIV\logo-bg[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\FJLFRXGO\icon2[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OV3BAWPP\icon4[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\G9INCHMJ\part4[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\LKG7XH8T\win_fixer_banner[1].swf
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\Z7LV3LOW\sirena2[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CP6JO5U3\logo3[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CPYB0DMF\spacer[2].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\K1QBWTER\boton2[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\FJLFRXGO\test[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OHA78LIJ\bg1[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OHA78LIJ\banner3[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\W1MJOXIB\t4[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\U3BJ2VXE\t3[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\G9INCHMJ\part3[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0PI70XYB\part5[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CP6JO5U3\CA85QZ8X.js
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\FJLFRXGO\checksoft[1].js
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OHA78LIJ\part7[1].jpg
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\2PR4TCVU\brd-top-3[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\W1MJOXIB\part6[1].jpg
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\8PYBC927\t1[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\Z7LV3LOW\bg3[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\0DIJ0TIV\t2[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\OV3BAWPP\top[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\S92741E3\brd-top-1[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\LKG7XH8T\2007[1].htm
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\CHS5QRGT\bg2[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\K1QBWTER\t5[1].gif
    C:\Documents and Settings\faisal\Local Settings\Temporary Internet Files\Content.IE5\S92741E3\bg6[1].gif
     
  4. rts5678

    rts5678 Thread Starter

    Joined:
    Jun 1, 2007
    Messages:
    4
    Hijack This Log after the SuperAntiSpyware Scan:


    Logfile of HijackThis v1.99.1
    Scan saved at 2:08:11 PM, on 7/16/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
    C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
    C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
    C:\WINDOWS\system32\ICO.EXE
    C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
    C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
    C:\Documents and Settings\faisal\Desktop\ETC\hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
    R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
    O2 - BHO: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
    O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
    O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
    O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
    O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [Flashget] "C:\Program Files\FlashGet\FlashGet.exe" /min
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/mickey/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MpService - Canon Inc - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
     
  5. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Run ActiveScan online virus scan:
    http://www.pandasoftware.com/products/activescan.htm

    Once you are on the Panda site click the Scan your PC button.
    A new window will open...click the Check Now button.
    Enter your Country.
    Enter your State/Province.
    Enter your e-mail address and click send.
    Select either Home User or Company.
    Click the big Scan Now button.
    If it wants to install an ActiveX component allow it.
    It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    When download is complete, click on My Computer to start the scan.
    When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    Post the contents of the ActiveScan report.
     
  6. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/596231

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice