crzydymnd
Topic Starter
did my homework "r u infected" stuff first. Picked up a myshovel problem, redirecting my searches. please help.
GMER ran for a while but made my pc go ape, unexpected shutdown, so didnt try that again. here is mbam and dds logs tho. have the "attach" log that i have to zip to attach also.
angie
———————————————-
Malwarebytes' Anti-Malware 1.44
Database version: 3865
Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005
3/13/2010 10:03:18 PM
mbam-log-2010-03-13 (22-03-18).txt
Scan type: Quick Scan
Objects scanned: 105662
Time elapsed: 7 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 10
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\Windows\System32\ug20026.dll (Trojan.BHO) -> Delete on reboot.
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{fe96cc3a-a21c-3ae0-8f48-c7a1715cda49} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{469c7ae5-1e24-3e70-8a01-ea44cc53a4af} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3933e7b5-bb76-3787-9a4d-0d348bb0923e} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\{3933e7b5-bb76-3787-9a4d-0d348bb0923e} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3933e7b5-bb76-3787-9a4d-0d348bb0923e} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3933e7b5-bb76-3787-9a4d-0d348bb0923e} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\D (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\D.1 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe (Security.Hijack) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\ug20026.dll (Trojan.BHO) -> Delete on reboot.
———————————————–
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 22:27:47.69 on Sat 03/13/2010
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.893.263 [GMT -6:00]
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\dldfcoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PSIService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\sttray.exe
C:\Program Files\Dell AIO Printer 948\dldfmon.exe
C:\Program Files\Dell AIO Printer 948\memcard.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\System32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Users\ANGELA FRED\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HCGIXK8C\downloads[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uWindow Title = Internet Explorer provided by Dell
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_8
uRun: [Aim6]
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: []
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [%PROVIDERID%] "bin\sprtcmd.exe" /P %PROVIDERID%
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [dldfmon.exe] "c:\program files\dell aio printer 948\dldfmon.exe"
mRun: [MemoryCardManager] "c:\program files\dell aio printer 948\memcard.exe"
mRun: [Dell AIO Printer 948 Fax Server] "c:\program files\dell aio printer 948\fm3032.exe" /s
mRun: [Corel Photo Downloader] c:\program files\corel\corel snapfire plus\Corel Photo Downloader.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\users\angela~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\480\G2AWinLogon.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
============= SERVICES / DRIVERS ===============
R2 dldf_device;dldf_device;c:\windows\system32\dldfcoms.exe -service –> c:\windows\system32\dldfcoms.exe -service [?]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-8-8 24652]
S2 dldfCATSCustConnectService;dldfCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dldfserv.exe [2007-6-26 98952]
=============== Created Last 30 ================
2010-03-13 21:52 –d—– c:\users\angela~1\appdata\roaming\Malwarebytes
2010-03-13 21:52 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-13 21:52 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-13 21:52 –d—– c:\programdata\Malwarebytes
2010-03-13 21:52 –d—– c:\progra~2\Malwarebytes
2010-03-13 21:52 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-11 22:10 3,600,456 a——- c:\windows\system32\ntkrnlpa.exe
2010-03-11 22:10 3,548,216 a——- c:\windows\system32\ntoskrnl.exe
2010-02-26 23:37 2,048 a——- c:\windows\system32\tzres.dll
2010-02-12 10:05 302,080 a——- c:\windows\system32\drivers\srv.sys
2010-02-12 10:05 98,816 a——- c:\windows\system32\drivers\srvnet.sys
2010-02-12 10:05 904,776 a——- c:\windows\system32\drivers\tcpip.sys
2010-02-12 10:05 30,720 a——- c:\windows\system32\drivers\tcpipreg.sys
2010-02-12 10:04 1,314,816 a——- c:\windows\system32\quartz.dll
2010-02-12 10:04 31,744 a——- c:\windows\system32\msvidc32.dll
2010-02-12 10:04 22,528 a——- c:\windows\system32\msyuv.dll
2010-02-12 10:04 12,288 a——- c:\windows\system32\tsbyuv.dll
2010-02-12 10:04 82,944 a——- c:\windows\system32\mciavi32.dll
2010-02-12 10:04 50,176 a——- c:\windows\system32\iyuv_32.dll
2010-02-12 10:04 13,312 a——- c:\windows\system32\msrle32.dll
2010-02-12 10:04 123,904 a——- c:\windows\system32\msvfw32.dll
2010-02-12 10:04 91,136 a——- c:\windows\system32\avifil32.dll
2010-02-12 10:04 105,984 a——- c:\windows\system32\drivers\mrxsmb.sys
2010-02-12 10:03 212,992 a——- c:\windows\system32\drivers\mrxsmb10.sys
==================== Find3M ====================
2010-02-24 09:16 181,632 ——– c:\windows\system32\MpSigStub.exe
2009-12-18 07:01 78,336 a——- c:\windows\system32\ieencode.dll
2009-12-16 05:44 834,048 a——- c:\windows\system32\wininet.dll
2009-12-16 05:44 9,216 a——- c:\windows\system32\ctfmonnwo.exe
2009-10-19 17:56 51,200 a——- c:\windows\inf\infpub.dat
2009-10-19 17:56 143,360 a——- c:\windows\inf\infstrng.dat
2009-10-19 17:55 86,016 a——- c:\windows\inf\infstor.dat
2009-10-19 17:47 1,377,872 a——- c:\programdata\pswi_preloaded.exe
2009-10-19 17:47 1,377,872 a——- c:\progra~2\pswi_preloaded.exe
2009-09-26 11:07 665,600 a——- c:\windows\inf\drvindex.dat
2008-09-20 19:37 174 a–sh— c:\program files\desktop.ini
2007-11-17 12:11 60,968 a——- c:\users\angela fred\GoToAssistDownloadHelper.exe
2006-11-02 06:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-12-12 22:00 88 —shr– c:\windows\system32\DE4105B61D.sys
2009-12-12 22:00 2,828 a–sh— c:\windows\system32\KGyGaAvL.sys
2007-09-08 08:37 8,192 a–sh— c:\windows\users\default\NTUSER.DAT
============= FINISH: 22:31:38.82 ===============