Trojan:Win32/Virtumonde.O, I think? Or maybe more?

Reply

Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #11
Jul 27th, 2007
Yeah, I checked, Vundofix and ComboFix do not work properly with Vista.. sigh....this next one does. But first, please fix this entry with hijackthis:

O4 - HKCU\..\Run: [MemoryManager] rundll32.exe "C:\Users\ADVINC~1\AppData\Local\Temp\wrbwxbij.dll",sitypnow

==Download killbox from here:- http://www.downloads.subratam.org/KillBox.zip -unzip it onto your desktop.
Dclick killbox to start it.
Select "Delete on reboot", click the "all files" button.
>Highlight the pathnames in the following lines as one block and copy them into clipboard [press Ctrl+C] [ or rclick, copy...]:-

C:\windows\system32\pstss.bak1
C:\Windows\system32\pstss.ini
C:\Windows\system32\sstsp.dll
C:\Windows\system32\vtuvvtu.dll
C:\Users\ADVINC~1\AppData\Local\Temp\wrbwxbij.dll

In killbox, go File menu, choose Paste from clipboard. Click the red and white X button, click Yes on the reboot prompt, click OK if a pendingfilerenameoperation box opens. [do not be concerned if it says it cannot find a file...]
I am not sure if that last file will have the same name -it has changed with restarts. If you have not restarted your sys since you made the last hijackthis log we should be okay...
Last edited by gerbil; Jul 27th, 2007 at 12:30 pm.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Jul 2007
Posts: 16
Reputation: JustaBeing is an unknown quantity at this point 
Solved Threads: 0
JustaBeing JustaBeing is offline Offline
Newbie Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #12
Jul 27th, 2007
I did what you said, and when that PendingFileRenameOperation popped up it said this "PendingFileRenameOperation Registry Data has been removed by External Process!"

I clicked "OK" as you said, is that normal. I'm I fix, or is there still other problems?

Also, here is the logfile now, if you want to check again.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:40:32 AM, on 27/07/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\hp\KBD\kbd.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\ADVINC~1\AppData\Local\Temp\cbrtujop.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\taskeng.exe
C:\Users\Advincula\Desktop\KillBox.exe
C:\Users\Advincula\Desktop\imabunny.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Windows\system32\sstsp.dll,CreateProtectProc
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{65CB202F-C53A-47EC-A58C-BF660DF2134C}: NameServer = 64.71.255.198
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 6871 bytes
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #13
Jul 27th, 2007
If you fixed this entry before, it has regenerated....
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Windows\system32\sstsp.dll,CreateProtectProc
...but killbox should have deleted the file
C:\Windows\system32\sstsp.dll
Please fix that entry with hijackthis, and check by browsing that the file does not exist now.
Last edited by gerbil; Jul 27th, 2007 at 12:52 pm.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Jul 2007
Posts: 16
Reputation: JustaBeing is an unknown quantity at this point 
Solved Threads: 0
JustaBeing JustaBeing is offline Offline
Newbie Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #14
Jul 27th, 2007
So, I tried to delete the file that you have requested to remove using Hijackthis.

When I pressed "Fix Checked" it to delete it, it said it was done successfully, I decided to scan it again to see if it disappears but it's still there, right now, only that is the problem.

Were getting so close, I can feel it!
Last edited by JustaBeing; Jul 27th, 2007 at 1:12 pm.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #15
Jul 27th, 2007
Please check to see if any of these files exist:
C:\windows\system32\pstss.bak1
C:\Windows\system32\pstss.ini
C:\Windows\system32\sstsp.dll
C:\Windows\system32\vtuvvtu.dll
C:\Users\ADVINC~1\AppData\Local\Temp\wrbwxbij.dll
[hijackthis will reomove the ergistry entry represented by that O4 listing, but will not actually delete the file in system32..]
Last edited by gerbil; Jul 27th, 2007 at 1:25 pm.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Jul 2007
Posts: 16
Reputation: JustaBeing is an unknown quantity at this point 
Solved Threads: 0
JustaBeing JustaBeing is offline Offline
Newbie Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #16
Jul 27th, 2007
So I checked my files too see if they are there, and none of them are in the system32, I find it weird, because at some points, I still get some advertisements.

Maybe they are hidden? I don't really know, but this virus is a nasty one.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #17
Jul 27th, 2007
Darn. There is a hidden file regenerating that entry.
Delete c:\vundofix.txt.
==GET AVG antispyware 7.5 here.. http://free.grisoft.com/doc/5390/lng/us/tpl/v5
or here.. http://free.grisoft.com/freeweb.php/...i-spyware-free
-the link is almost at the bottom of the page , avgas 7.5.0.50. Install it and UPDATE it.
==Get CCleaner from http://www.ccleaner.com/ - and put it in a new folder. You should aim to keep this one for general use. I set it from the installation checkboxes to only open from the recycle bin. It's neater that way.
Restart your machine in safe mode, dclick VundoFix.exe to start it, click the Scan for Vundo button.
When the scan completes click the Remove Vundo button.
Now run CCleaner from the recycle bin rclick menu using its default settings [if you set up CCleaner as i suggested, rclicking the bin icon should give you the Open CCleaner option...]. Select the Cleaner icon, press Run Cleaner.
Start AVG a-s 7.5;
-under Scanner/ Settings please set Recommended Actions to QUARANTINE, and run the complete system scan.
-press Apply all Actions and Save the log file.
Post that log file, plus the contents of C:\vundofix.txt plus a new HijackThis log.
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: May 2005
Posts: 3,204
Reputation: gerbil will become famous soon enough gerbil will become famous soon enough 
Solved Threads: 188
gerbil gerbil is offline Offline
Nearly a Senior Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #18
Jul 27th, 2007
And I am sorry, but I really must go to bed - it is sooo late here..
Deep, deep in the woods, but walking about.
Reply With Quote Quick reply to this message  
Join Date: Jul 2007
Posts: 16
Reputation: JustaBeing is an unknown quantity at this point 
Solved Threads: 0
JustaBeing JustaBeing is offline Offline
Newbie Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #19
Jul 27th, 2007
Oh my god, when I have download the AVG Anti-Spyware and installed it, everything in my desktop is all messed up and all my icons seems like it was duplicated, but half really, everything looks normal, but now it's messed up.

Just a little warning, I'll give out the others that you requested soon.
Reply With Quote Quick reply to this message  
Join Date: Jul 2007
Posts: 16
Reputation: JustaBeing is an unknown quantity at this point 
Solved Threads: 0
JustaBeing JustaBeing is offline Offline
Newbie Poster

Re: Trojan:Win32/Virtumonde.O, I think? Or maybe more?

 
0
  #20
Jul 27th, 2007
Okay, I did everything I told you.


First, here is the VundoFix.txt:


VundoFix V6.5.6

Checking Java version...

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 1:23:53 PM 27/07/2007

Listing files found while scanning....

C:\windows\system32\pstss.bak1
C:\windows\system32\pstss.ini
C:\windows\system32\sstsp.dll
C:\windows\system32\vtuvvtu.dll

Beginning removal...

Attempting to delete C:\windows\system32\pstss.bak1
C:\windows\system32\pstss.bak1 Has been deleted!

Attempting to delete C:\windows\system32\pstss.ini
C:\windows\system32\pstss.ini Has been deleted!

Attempting to delete C:\windows\system32\sstsp.dll
C:\windows\system32\sstsp.dll Has been deleted!

Attempting to delete C:\windows\system32\vtuvvtu.dll
C:\windows\system32\vtuvvtu.dll Has been deleted!

Performing Repairs to the registry.
Done!


And here is the Report on the program the Anti-Virus Spyware:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 2:23:07 PM 27/07/2007

+ Scan result:



C:\!KillBox\vtuvvtu.dll -> Adware.Virtumonde : No action taken.
C:\!KillBox\vtuvvtu.dll( 2) -> Adware.Virtumonde : No action taken.
C:\!KillBox\vtuvvtu.dll( 7) -> Adware.Virtumonde : No action taken.
C:\VundoFix Backups\vtuvvtu.dll.bad -> Adware.Virtumonde : No action taken.
:mozilla.40:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.41:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.42:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.31:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.34:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.35:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.51:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.38:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.50:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.32:C:\Users\Advincula\AppData\Roaming\Mozilla\Firefox\Profiles\3j4qtk8r.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Windows\System32\windii32.dll -> Trojan.Dialer.qn : No action taken.


::Report end


Also, here is the logfile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:24:58 PM, on 27/07/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\hp\KBD\kbd.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Advincula\Desktop\imabunny.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Windows\system32\sstsp.dll,CreateProtectProc
O4 - HKCU\..\Run: [MemoryManager] rundll32.exe "C:\Users\ADVINC~1\AppData\Local\Temp\ysylvowe.dll",sitypnow
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{65CB202F-C53A-47EC-A58C-BF660DF2134C}: NameServer = 64.71.255.198
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7055 bytes

I've done everything, and heres a good thing, my computer is going faster now, if you see any problems, please reply back.

Also, for other people who see this, please see if everything is alright.

Thank you.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC