Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93100 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

HELP Sndc.A worm


  • This topic is locked This topic is locked
8 replies to this topic

#1 krome8800

krome8800

    Silver Member

  • Authentic Member
  • PipPipPip
  • 359 posts
  • Interests:Gaming (COD PC), Football, Sportbike riding, Computers

Posted 09 January 2006 - 09:10 AM

Hello first off how is everybody. My name is Keith R. I just builted a nice gaming computer since I play a lot of games COD2 is my favor.... Well anyways this weekend i was playing Half-life 2 and notice my computer was messing up a little on the video side so i decided to run Ad-ware, Spy sweeper, S&D 1.4. Nothing in those programs seem to find anything...Come to find out my little sister was over at my house this weekend and my gf and her were downloading music from imesh(ssshhh don't tell the record companies lol) So i checked the log of what they were downloading to see if it came from there and sure enough it was...After doing some reach on the files downloaded I found it to be the SNDC.A WORM. Now being a kinda computer person I like to read alot about things first before looking for help..I am drained of reading about this worm.I ran a few programs Panda and they comfirm it there. List of program it keep putting in folder such and My Music, My Downloads, And a few other folders: Ad-aware Pro Crack.exe Adobe Acrobat Reader crack.exe Adobe Golive v6.0 Keygen.exe Adobe Illustrator v10.0 Time Limit Crack.exe Adobe ImageReady v1.0 crack.exe Adobe PageMaker v7.0 Keygen.exe Adobe Photoshop 7 keygen.exe Adobe Photoshop all.exe Adobe Serial Generator v2.0.exe Age of Empires II The Age of Kings NO CD crack.exe Age Of Mythology - The Titans no cd crack.exe Age Of Mythology no cd crack.exe Alias Acclaim crack.exe All Macromedia Products Keygen.exe Anti-Trojan 4.0.exe Avant Browser.exe Backyard Baseball 2003 no cd crack.exe Backyard Wrestling 2 - There Goes the Neighborhood Eidos Interactive crack.exe Battlefield 1942 no cd crack.exe Battlefield Vietnam EA Games crack.exe Battlefield Vietnam Multiplayer Online Crack.exe Besieger Strategy DreamCatcher Interactive crack.exe Blinx 2 - Masters of Time & Space Microsoft crack.exe Blitzkrieg - Burning Horizon Strategy CDV Software GmbH crack.exe Call of Duty Activision crack.exe Call Of Duty no cd crack.exe City of Heroes Role-Playing NCsoft crack.exe Civilization III crack.exe Classic NES Series - The Legend of Zelda GBA Role-Playing Nintendo crack.exe CloneDVD v1.x crack.exe Command & Conquer - Generals no cd crack.exe Command & Conquer - Generals Zero Hour no cd crack.exe Command & Conquer - Generals Zero Hour Strategy EA Games crack.exe Counter-Strike Condition Zero Keygen.exe Credit card generator.exe Crusader Kings Strategy Paradox Entertainment crack.exe Cubase Audio XT 3.X crack.exe Dark Age Of Camelot - Trials Of Atlantis no cd crack.exe Dark Matter - The Baryon Proj crack.exe Deus Ex Invisible War NO CD Crack.exe Diablo 2 no cd crack.exe Diablo 2 NO CD crack.exe DivX Player and Codec.exe Doom 3 Activision crack.exe Doom 3 NO CD Crack.exe Download Accelerator Plus (spyware free).exe Dragon Ball Z - Budokai 3 Atari crack.exe Dragon Ball Z - Supersonic Warriors GBA Atari crack.exe Dragon Warrior VIII Role-Playing Square Enix crack.exe DRIV3R Atari crack.exe Dungeon Lords Role-Playing DreamCatcher Interactive crack.exe Dungeon Siege no cd crack.exe Enter the Matrix Atari crack.exe ESPN NFL 2K5 Sega crack.exe F.E.A.R. VU Games crack.exe Fable Role-Playing Microsoft crack.exe Far Cry Ubisoft crack.exe Final Fantasy VII - Advent Children PSP Role-Playing Square Enix crack.exe Final Fantasy XI - Square Enix USA no cd crack.exe Final Fantasy XII Role-Playing Square Enix crack.exe Fire Emblem - Seima no Kouseki GBA Role-Playing Nintendo crack.exe FlashFXP 2 RC2 Crack.exe FlashFXP v1.4.1 Crack.exe FlashFXP v1.4.3 Crack.exe FlashFXP v2.0 Crack.exe FlashFXP v2.1 crack.exe FlashFXP v2.2 crack.exe FlashGet.exe Forgotten Realms - Demon Stone Atari crack.exe Forgotten Realms - Demon Stone crack.exe Freedom Force no cd crack.exe Front Mission 4 Strategy Square Enix crack.exe Full Spectrum Warrior Strategy THQ crack.exe Geist GC Nintendo crack.exe Goblin Commander - Unleash the Horde Strategy Jaleco Entertainment crack.exe Gran Turismo 4 SCEA crack.exe Grand Theft Auto - San Andreas Rockstar Games crack.exe Grand Theft Auto 3 no cd crack.exe Grand Theft Auto III no cd crack.exe Grand Theft Auto San Andreas NO CD crack.exe Grand Theft Auto Vice City NO CD crack.exe GTA crack.exe Half-Life 2 Keygen.exe Half-Life 2 NO CD Crack.exe Half-Life 2 VU Games crack.exe Halo - Combat Evolved - Microsoft no cd crack.exe Halo 2 crack.exe Harry Potter & The Sorcerers Stone no cd crack.exe Harry Potter and the Prisoner of Azkaban Adventure EA Games crack.exe Harry Potter and the Sorcerers Stone no cd crack.exe Heroes of Might & Magic IV no cd crack.exe Hidden & Dangerous 2 NO CD Crack.exe Icewind Dale 2 no cd crack.exe ICQ 4.exe ICQ Pro 2003b.exe iMesh patch.exe Jedi Academy NO CD Crack.exe Joint Operations - Typhoon Rising NovaLogic crack.exe Juiced Acclaim crack.exe Kingdom Hearts II Role-Playing Square Enix crack.exe Knights Apprentice Memoricks Adventures Games crack.exe LimeWire server scanner.exe Macromedia ColdFusion MX crack.exe Macromedia Contribute v2.0 crack.exe Macromedia Director 8 Crack.exe Macromedia Dreamweaver 4.0 Patch.exe Macromedia Dreamweaver MX v6.0 crack.exe Macromedia Dreamweaver UltraDev 4.0 Patch.exe Macromedia Fireworks 4.0 Patch.exe Macromedia Flash All Versions keygen.exe Macromedia Flash MX v6.0 crack.exe Macromedia Flash SWF-Unprotect v2.0.exe Macromedia FreeHand v10 Loader.exe Madden NFL 2003 no cd crack.exe Madden NFL 2005 EA crack.exe Mafia no cd crack.exe Malice Mud Duck Productions crack.exe Mario Pinball Land GBA Puzzle Nintendo crack.exe Mario Tennis GC Nintendo crack.exe Matrix Screensaver.exe Max Payne 2 Fall Of Max Payne no cd crack.exe Max Payne 2 NO CD Crack.exe Max Payne 2 The Fall of Max Payne NO CD crack.exe MaxPayne 2 The Fall Of Max Payne Crack.exe McFarlanes Evil Prophecy Konami crack.exe Medal Of Honor - Allied Assault no cd crack.exe Medal Of Honor - Allied Assault BreakThrough no cd crack.exe Medal Of Honor - Allied Assault no cd crack.exe Medal of Honor Pacific Assault EA Games crack.exe Medal of Honor- Allied Assault no cd crack.exe Medieval - Total War no cd crack.exe Mega Man Anniversary Collection GC Capcom crack.exe Metal Gear Acid PSP Strategy Konami crack.exe Metal Gear Solid 3 - Snake Eater Konami crack.exe Microsoft Flight Simulator 2004 - A Century Of Flight no cd crack.exe Microsoft Office 2000 Regmaker.exe Microsoft Office XP Activation Crack.exe Microsoft Office XP Activation Killer.exe Microsoft Office XP Professional Crack.exe Microsoft Office XP Professional Serial.exe Microsoft Office XP Universal Activator v1.0.exe Midnight Club 3 - DUB Edition Rockstar Games crack.exe mirc 6.1x reg entries.exe mIRC 6.X crack.exe Morpheus patch.exe MS Office XP Activation Crack.exe MS Zoo Tycoon no cd crack.exe MSN advert remover.exe MSN Toolbar advert remover.exe MVP Baseball 2004 EA crack.exe NBA Live 2003 crack.exe NBA Live 2004 crack.exe NCAA Football 2005 EA crack.exe Need For Speed 5 - no cd.exe Need for Speed Hot Pursuit 2 CD KeyGenerator.exe Need for speed underground - nocd.exe Need for Speed Underground 2 crack.exe Need for Speed Underground 2 Electronic Arts crack.exe Need for Speed Underground 2 NO CD crack.exe Need for Speed Underground NO CD crack.exe Need for Speed4 - NOCD.exe NeedforspeedUnderground-nocd.exe Nero Burning ROM v6.x crack.exe Ninja Gaiden Tecmo crack.exe Norton AntiVirus 2004 crack.exe Onimusha 3 - Demon Siege Adventure Capcom crack.exe Psi-Ops - The Mindgate Conspiracy Midway crack.exe Purge Jihad Freeform Interactive LLC crack.exe RealPlayer crack (keygen).exe Red Dead Revolver Rockstar Games crack.exe Resident Evil 4 GC Adventure Capcom crack.exe Rise of Nations - Thrones & Patriots Strategy Microsoft crack.exe RoboForm crack.exe Roller Coaster Tycoon no cd crack.exe RYL crack.exe Second Life Role-Playing Linden Lab crack.exe Shadow Ops - Red Mercury Atari crack.exe ShellShock - Nam 67 Eidos Interactive crack.exe Silent Storm - Sentinels Strategy _No Company crack.exe Sim City 4 - Rush Hour no cd crack.exe Sim City 4 Deluxe no cd crack.exe Sim Theme Park World no cd crack.exe Singles - Flirt Up Your Life Strategy Eidos Interactive crack.exe Snood crack.exe Snowblind Eidos Interactive crack.exe Soldier of Fortune II- Double Helix no cd crack.exe SolSuite 2004 - Solitaire Card Games Suite crack.exe Sonic the Hedgehog 3 crack.exe Spider-Man 2 Activision crack.exe Spider-Man 2 GC Activision crack.exe Sponge Bob Square Pants - Operation Krabby Patty no cd crack.exe Spybot Search and Destroy.exe Star Wars - Jedi Knight - Jedi Academy no cd crack.exe Star Wars - Knights of the Old Republic Role-Playing LucasArts crack.exe Star Wars Galactic Battlegrounds- Clone Campaigns no cd crack.exe Star Wars Jedi Knight II - Jedi Outcast no cd crack.exe Star Wars Jedi Knight II- Jedi Outcast no cd crack.exe Star Wars Knights of the Old Republic II - The Sith Lords Role-Playing LucasArts crack.exe Starcraft - Battlechest no cd crack.exe The Chronicles of Riddick - Escape From Butcher Bay VU Games crack.exe The Elder Scrolls III - Morrowind Game of the Year Edition Role-Playing Bethesda Softworks crack.exe The Legend of Zelda (working title) GC Nintendo crack.exe The Legend of Zelda - Four Swords Adventures GC Nintendo crack.exe The Legend of Zelda - The Minish Cap GBA Nintendo crack.exe The Lord of the Rings The Battle for Middle-earth Strategy EA Games crack.exe The Lord of the Rings The Return of The King crack.exe The Sims no cd crack.exe The Sims - Hot Date Expansion Pack no cd crack.exe The Sims - Makin Magic Expansion Pack no cd crack.exe The Sims - Superstar Expansion Pack no cd crack.exe The Sims - Unleashed Expansion Pack no cd crack.exe The Sims - Vacation Expansion Pack no cd crack.exe The Sims - Hot Date Expansion Pack no cd crack.exe The Sims - Vacation Expansion Pack no cd crack.exe The Sims 2 crack.exe The Sims Deluxe no cd crack.exe The Sims Deluxe no cd crack.exe The Sims Double Deluxe no cd crack.exe The Sims no cd crack.exe The Sims- Vacation no cd crack.exe The Suffering Encore Software Inc. crack.exe The Suffering Midway crack.exe Thief - Deadly Shadows Eidos Interactive crack.exe Tiger Woods PGA Tour 2004 crack.exe Tom Clancy's Splinter Cell Pandora Tomorrow crack.exe Tom Clancys Ghost Recon - Desert Siege no cd crack.exe Tom Clancys Splinter Cell Pandora Tomorrow Ubisoft crack.exe Tom Clancys Splinter Cell Ubisoft crack.exe Tony Hawks Underground crack.exe Trillian crasher.exe Unreal Tournament 2003 no cd crack.exe Unreal Tournament 2004 Atari crack.exe Unreal Tournament 2004 crack (keygen).exe Unreal Tournament 2004 NO CD crack.exe Vampire - The Masquerade - Bloodlines Role-Playing Activision crack.exe VirtualLab Data Recovery crack.exe Warcraft III - Reign Of Chaos no cd crack.exe Warez P2P.exe Webroot Spy Sweeper.exe windows server 2003 crack.exe Windows XP Activation Crack.exe Windows XP home edition Activation.exe Windows XP Professional crack.exe WinRAR crack (keygen).exe WinZip All Versions keygen.exe Winzip keygen.exe WinZip Self-Extractor v2.2 keygen.exe WinZip Self-Extractor v2.2 Patch.exe WinZip v8.0 Keygen.exe WinZip v8.x - v9.x patch.exe WinZIP v9.0 Keygen.exe WinZip v9.0 Registration.exe World of Warcraft Role-Playing Blizzard Entertainment crack.exe Worms Armageddon NO CD crack.exe WWE Day of Reckoning GC THQ crack.exe WWE SmackDown! vs. Raw THQ crack.exe XBOX X-Fer Ripper and Transfer.exe Yoshinoya Success crack.exe ZoneAlarm crack (keygen).exe Zoo Tycoon - Complete Collection no cd crack.exe Zoo Tycoon no cd crack.exe Zoo Tycoon- Dinosaur Digs no cd crack.exe What is the best way to remove this worm without buying any programs...Are is there a way...I tryed to look in C:\Windows\System32 but I couldn't find it.. Anyone have any ideas... Thanks for any help...
Individual commitment to a group effort - that is what makes a team work, a company work, a society work, a civilization work. ~VINCE LOMBARDI~

    Advertisements

Register to Remove


#2 krome8800

krome8800

    Silver Member

  • Authentic Member
  • PipPipPip
  • 359 posts
  • Interests:Gaming (COD PC), Football, Sportbike riding, Computers

Posted 09 January 2006 - 09:19 AM

Right now I am at work so I will check back about 4 or so when I get home. THANKSAGAIN FOR ANY HELP.
Individual commitment to a group effort - that is what makes a team work, a company work, a society work, a civilization work. ~VINCE LOMBARDI~

#3 krome8800

krome8800

    Silver Member

  • Authentic Member
  • PipPipPip
  • 359 posts
  • Interests:Gaming (COD PC), Football, Sportbike riding, Computers

Posted 09 January 2006 - 05:54 PM

I ran Regcleaner and thought I found it but I was wrong.I ran Panda program and this is what came up C:\WINDOWS\lbbho.dll Not disinfected C:\WINDOWS\NDNuninstall4_85.exe Not disinfected C:\WINDOWS\NDNuninstall6_98.exe Not disinfected C:\WINDOWS\NDNuninstall7_14.exe Not disinfected C:\WINDOWS\system32\actskn45.ocx Not disinfected What does this mean and how can i get rid of it? When i ran Regcleaner I found sndcfg16.exe in the start up menu and removed them. What else would I may need as for as imformation to get help on this thanks.
Individual commitment to a group effort - that is what makes a team work, a company work, a society work, a civilization work. ~VINCE LOMBARDI~

#4 krome8800

krome8800

    Silver Member

  • Authentic Member
  • PipPipPip
  • 359 posts
  • Interests:Gaming (COD PC), Football, Sportbike riding, Computers

Posted 09 January 2006 - 06:18 PM

HijackThis log if it helps.

Logfile of HijackThis v1.99.1
Scan saved at 6:17:18 PM, on 1/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\AOL\1134851420\ee\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\keith\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: - {B590180F-2078-4622-8D42-398366976800} - C:\WINDOWS\lbbho.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
Individual commitment to a group effort - that is what makes a team work, a company work, a society work, a civilization work. ~VINCE LOMBARDI~

#5 therock247uk

therock247uk

    247fixes Owner/Admin/Teacher, MVP

  • Visiting Fellow
  • PipPipPipPip
  • 681 posts
  • Interests:Killing Malware.

Posted 09 January 2006 - 06:31 PM

Please download ewido anti-malware it is a trial version of the program.
  • Install ewido anti-malware
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

Boot into safemode to do this keep tapping F8 on your keyboard while your PC is starting up you will get a menu select safemode.

Open Ewido again
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido anti-malware.

While still in safemode open Hijackthis and click scan. Then tick and fix the following in Hijackthis with all windows closed except Hijackthis.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll (file missing)
O2 - BHO: - {B590180F-2078-4622-8D42-398366976800} - C:\WINDOWS\lbbho.dll

Delete the files. (if present)

C:\WINDOWS\lbbho.dll

Reboot and Post the report Ewido made and a new Hijackthis log here in a reply.

#6 krome8800

krome8800

    Silver Member

  • Authentic Member
  • PipPipPip
  • 359 posts
  • Interests:Gaming (COD PC), Football, Sportbike riding, Computers

Posted 09 January 2006 - 07:10 PM

OK I did what I was told but I couldn't find O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll (file missing)

here is the logs that i saved:

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 7:00:43 PM, 1/9/2006
+ Report-Checksum: 3E4F86B2

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{00000000-6CB0-410C-8C3D-8FA8D2011D0A} -> Spyware.iMesh : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-6CB0-410C-8C3D-8FA8D2011D0A} -> Spyware.iMesh : Cleaned with backup
HKU\S-1-5-21-1801674531-562591055-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6CB0-410C-8C3D-8FA8D2011D0A} -> Spyware.iMesh : Cleaned with backup
HKU\S-1-5-21-1801674531-562591055-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0494D0D1-F8E0-41AD-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKU\S-1-5-21-1801674531-562591055-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\lbbho.dll -> Spyware.RelatedLinks : Cleaned with backup
C:\WINDOWS\NDNuninstall4_85.exe -> Spyware.NewDotNet : Cleaned with backup
C:\WINDOWS\NDNuninstall6_98.exe -> Adware.NewDotNet : Cleaned with backup


::Report End



_________________________________________________________________________________


Logfile of HijackThis v1.99.1
Scan saved at 7:06:20 PM, on 1/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\DOCUME~1\keith\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
Individual commitment to a group effort - that is what makes a team work, a company work, a society work, a civilization work. ~VINCE LOMBARDI~

#7 therock247uk

therock247uk

    247fixes Owner/Admin/Teacher, MVP

  • Visiting Fellow
  • PipPipPipPip
  • 681 posts
  • Interests:Killing Malware.

Posted 09 January 2006 - 07:19 PM

Your log is clean :)

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
I also suggest that you delete any files from "temp", "tmp" folders. In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". These steps should be done on a regular basis.

#8 krome8800

krome8800

    Silver Member

  • Authentic Member
  • PipPipPip
  • 359 posts
  • Interests:Gaming (COD PC), Football, Sportbike riding, Computers

Posted 09 January 2006 - 07:30 PM

OK I LOVE YOU...LOL J/K....A BIG THANKS TO ANYONE AND EVERYONE FROM TOM COYOTE......NOW MY GIRLFREIND IS LIMITED TO HER TIME ON THE INTERNET.. NOW I DO DOWLOAD THINGS MYSELF FROM IMESH SINCE I DRIVE 2 HRS A DAY TO WORK (MUSIC MAINLY) IS THERE ANYTHING I CAN DO TO KEEP THIS PROBLEM FROM HAPPENING AGAIN..... I DOWNLOADED ALL THE REMENDED PROGRAM TO SAID TO USE.. THANKS AGAIN
Individual commitment to a group effort - that is what makes a team work, a company work, a society work, a civilization work. ~VINCE LOMBARDI~

#9 therock247uk

therock247uk

    247fixes Owner/Admin/Teacher, MVP

  • Visiting Fellow
  • PipPipPipPip
  • 681 posts
  • Interests:Killing Malware.

Posted 09 January 2006 - 07:31 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users