GrundleLove Posted April 10, 2006 Report Share Posted April 10, 2006 Logfile of HijackThis v1.99.1Scan saved at 3:41:01 PM, on 4/10/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\Program Files\Gizmo Project\mDNSResponder.exeC:\Program Files\ewido anti-malware\ewidoctrl.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\nvsvc32.exeC:\Program Files\Softex\OmniPass\Omniserv.exeC:\Program Files\Softex\OmniPass\OPXPApp.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\windows\system\hpsysdrv.exeC:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exeC:\Program Files\HP\HP Software Update\HPWuSchd.exeC:\WINDOWS\System32\hphmon05.exeC:\HP\KBD\KBD.EXEC:\Program Files\Common Files\Sonic\Update Manager\sgtray.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeC:\Program Files\Java\jre1.5.0_06\bin\jusched.exeC:\WINDOWS\ALCXMNTR.EXEC:\Program Files\QuickTime\qttask.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\WINDOWS\system32\rundll32.exeC:\Program Files\aim\aim.exeC:\Program Files\Valve\Steam\Steam.exec:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\Documents and Settings\Owner.YOUR-XHTR8HVC4P.001\Application Data\F?nts\ati2evxx.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exeC:\DOCUME~1\OWNERY~1.001\MYDOCU~1\MANTEC~1\rundll32.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\DOCUMENTS AND SETTINGS\OWNER.YOUR-XHTR8HVC4P.001\DESKTOP\HijackThis-1.exeR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhostR3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dllF2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\fsndi.exeF2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,pougtaq.exeO3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dllO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exeO4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exeO4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [storageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXEO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\aim\\DeadAIM.ocm",ExportedCheckODLsO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exeO4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXEO4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\ScanSoft\NaturallySpeaking\Program\Ereg.exe" -r "C:\Program Files\ScanSoft\NaturallySpeaking\Program\ereg.ini"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exeO4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /autoO4 - HKLM\..\Run: [w2cf522d.dll] RUNDLL32.EXE w2cf522d.dll,I2 0003c3ab02cf522dO4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -sO4 - HKLM\..\Run: [surfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exeO4 - HKCU\..\Run: [backupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exeO4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [steam] C:\Program Files\Valve\Steam\\Steam.exe -silentO4 - HKCU\..\Run: [iwqwxrx] C:\Documents and Settings\Owner.YOUR-XHTR8HVC4P.001\Application Data\F?nts\ati2evxx.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"O4 - HKCU\..\Run: [rurq] C:\PROGRA~1\COMMON~1\rurq\rurqm.exeO4 - HKCU\..\Run: [surfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exeO4 - HKCU\..\Run: [Notn] "C:\DOCUME~1\OWNERY~1.001\MYDOCU~1\MANTEC~1\rundll32.exe" -vt ndrvO4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO4 - Global Startup: MsnFixer.lnk = ?O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dllO9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dllO9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exeO9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO15 - Trusted Zone: http://click.getmirar.com (HKLM)O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1140928647593O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab34246.cabO16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/apop/default/popcaploader_v6.cabO20 - AppInit_DLLs: repairs303169569.dllO20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\wknbrand.dll (file missing)O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dllO20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dllO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo Project\mDNSResponder.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeO23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exeO23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exeO23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe Link to post Share on other sites
GrundleLove Posted April 11, 2006 Author Report Share Posted April 11, 2006 (edited) sorry guys but i would really appreciate help ASAP. basically, my computer is messed up as of right now. i cant enable widows firewall and nortans is disabled already and i cant enable it. pop-ups come up all the time and i am screwed. i would appreciate any help before i reformat. Edited April 11, 2006 by GrundleLove Link to post Share on other sites
sethook Posted April 11, 2006 Report Share Posted April 11, 2006 Go flush your mouth, potty face....... Link to post Share on other sites
therock247uk Posted April 11, 2006 Report Share Posted April 11, 2006 Go to Start > Settings > Control Panel > Add/Remove and uninstall the following.SurfSideKick 3new.netOpen HijackThis, click Config, click Misc ToolsClick "Open Uninstall Manager"Click "Save List" (generates uninstall_list.txt)Click Save, copy and paste the results in your next post. Link to post Share on other sites
GrundleLove Posted April 11, 2006 Author Report Share Posted April 11, 2006 Go to Start > Settings > Control Panel > Add/Remove and uninstall the following.SurfSideKick 3new.netOpen HijackThis, click Config, click Misc ToolsClick "Open Uninstall Manager"Click "Save List" (generates uninstall_list.txt)Click Save, copy and paste the results in your next post.both of those arent in my "add/remove" programs list. Link to post Share on other sites
GrundleLove Posted April 11, 2006 Author Report Share Posted April 11, 2006 ok i know i shouldn't of...but when i saw the files that were trojens/malware, i hit delete thinking it would delete the file, but it just deleted it from the list...so...umm heres the one after i did that stupid stuffAdobe Bridge 1.0Adobe Common File InstallerAdobe Help Center 1.0Adobe Photoshop CS2Adobe Reader 7.0Adobe Stock Photos 1.0ArcSoft ShowBiz 2avast! AntivirusAVS VideoConverter 3.1.1.151Battlefield 2Battlefield2 Bocage Dogfight Bot SupportBlackhawk Striker from Hewlett-Packard Desktops (remove only)Blasterball 2 from Hewlett-Packard Desktops (remove only)Bounce from Hewlett-Packard Desktops (remove only)Cannonballs from Hewlett-Packard Desktops (remove only)CommandDeadAIMDHDoom 3DOOM 3: Resurrection of EvilDragon NaturallySpeaking 7.0Easy Internet Sign-upEnhanced Ads by Zeno removalewido anti-malwareExcavation from Hewlett-Packard Desktops (remove only)Far CryFEARFive Card Frenzy from Hewlett-Packard Desktops (remove only)GameSpy ArcadeGemMaster 3 from Hewlett-Packard Desktops (remove only)Gizmo Project 1.3Half-Life® 2HijackThis 1.99.1Honeycombs from Hewlett-Packard Desktops (remove only)hp deskjet 3600HP Deskjet Preloaded Printer DriversHP Instant SupportHP OrganizeHP Photo & Imaging 3.0HP Photo and Imaging 2.0 - Photosmart CamerasHP Software UpdateHPImageZoneIntel® Extreme Graphics DriverIntelliMover Data Transfer DemoInterVideo WinDVD PlayeriTunesJ2SE Runtime Environment 5.0 Update 3J2SE Runtime Environment 5.0 Update 6Java 2 Runtime Environment, SE v1.4.1_02Java Web StartKBDLimeWire 4.10.9LiveReg (Symantec Corporation)LiveUpdate 1.80 (Symantec Corporation)Macromedia Flash Player 8Mars Rover from Hewlett-Packard Desktops (remove only)MediaTickets by OINMemories Disc Creator 2.0Microsoft .NET Framework 1.1Microsoft Money 2003Microsoft Money 2003 System PackMicrosoft Plus! Digital Media EditionMicrosoft Visual J# .NET Redistributable Package 1.1Microsoft Works 7.0Mini PuttmIRCMSN Music AssistantMUSICMATCH® JukeboxNero 7 DemoNorton AntiVirus 2003NVIDIA DriversOmniPassOpenOffice.org 2.0Orbital from Hewlett-Packard Desktops (remove only)Otto from Hewlett-Packard Desktops (remove only)PC-Doctor for WindowsPhotosmart 140,240,7200,7600,7700,7900 SeriesPS2Python 2.2 combined Win32 extensionsPython 2.2.1Quicken 2003 New User EditionQuickTimeQuickTime SDKRealOne PlayerRecordNow!S3DisplayS3Gamma2S3Info2S3OverlaySecurity Update for Step By Step Interactive Training (KB898458)Security Update for Windows Media Player (KB911564)Security Update for Windows Media Player 10 (KB911565)Security Update for Windows XP (KB890046)Security Update for Windows XP (KB893756)Security Update for Windows XP (KB896358)Security Update for Windows XP (KB896422)Security Update for Windows XP (KB896423)Security Update for Windows XP (KB896424)Security Update for Windows XP (KB896428)Security Update for Windows XP (KB899587)Security Update for Windows XP (KB899591)Security Update for Windows XP (KB900725)Security Update for Windows XP (KB901017)Security Update for Windows XP (KB901214)Security Update for Windows XP (KB902400)Security Update for Windows XP (KB905414)Security Update for Windows XP (KB905749)Security Update for Windows XP (KB905915)Security Update for Windows XP (KB908519)Security Update for Windows XP (KB911927)Security Update for Windows XP (KB912919)Security Update for Windows XP (KB913446)Slyder from Hewlett-Packard Desktops (remove only)Sonic Update ManagerSpamSubtractSpybot - Search & Destroy 1.4SteamSTX from Hewlett-Packard Desktops (remove only)System Requirements LabTmSunriseDemoMag 1.4.5toolkitUpdate for Windows XP (KB898461)Update for Windows XP (KB910437)Updates from HPVirtual Warfare from Hewlett-Packard Desktops (remove only)WeblinkWinamp (remove only)Windows Genuine Advantage v1.3.0254.0Windows Installer 3.1 (KB893803)Windows Media Format RuntimeWindows Media Player 10Windows XP Hotfix - KB873339Windows XP Hotfix - KB885250Windows XP Hotfix - KB885835Windows XP Hotfix - KB885836Windows XP Hotfix - KB886185Windows XP Hotfix - KB887472Windows XP Hotfix - KB887742Windows XP Hotfix - KB888113Windows XP Hotfix - KB888302Windows XP Hotfix - KB890859Windows XP Hotfix - KB891781Windows XP Service Pack 2WordPerfect Office 11 Link to post Share on other sites
GrundleLove Posted April 12, 2006 Author Report Share Posted April 12, 2006 if i do a systm recovery...is there a chance these virus's will come back? Link to post Share on other sites
Besttechie Posted April 12, 2006 Report Share Posted April 12, 2006 therock247uk will help you clean your system and show you how to help yourself stay protected when he's done cleaning your system. By doing a system restore you won't be helping yourself any, chances are you'll end up reinfected without proper protection, etc. He should post with new directions soon. B Link to post Share on other sites
therock247uk Posted April 12, 2006 Report Share Posted April 12, 2006 Can you please click start > run type thisC:\Program Files\SurfSideKick 3\Ssk.exe /uand press the OK button. A code will be displayed that it will ask you to enter. Enter this code and reboot. Then post a new Hijackthis log here in a reply. Link to post Share on other sites
GrundleLove Posted April 13, 2006 Author Report Share Posted April 13, 2006 i did a system recovery and delted all the unwanted files and aslo got Mcaffe suite 2006 and have that, also ewido and adware and SB:S&D all of the files are gone and my comp is running fine. Link to post Share on other sites
Matt Posted April 27, 2006 Report Share Posted April 27, 2006 Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. Link to post Share on other sites
Recommended Posts