![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 1
OS: Windows XP
|
Please help. Bad viruses, probably from P2P sadly...
After using P2P (like i shouldnt have...) i got some nasty viruses.
I'm not sure what they are and my virus software stopped working so I uninstalled it for now (will reinstall after this whole mess is cleaned up). Anyways, the viruses/trojans/spyware is causing my computer to crash, random programs to shut down, and is running some sort of audio in the background (I.E. i hear mouse clicks in the background then random audio will start playing like the fanta song for example and some random story about a guy and a dog, they skip as if they are buffering). Any and all help is very much appreciated! Note: The GMER program wouldn't run so I do not have that file, but please help! DDS (Ver_09-06-26.01) - NTFSx86 Run by Administrator at 1:45:03.13 on Wed 07/22/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_05 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1408 [GMT -5:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Internet Explorer\Iexplore.exe c:\program files\aim toolbar\aimtbServer.exe C:\Program Files\Xtras\VisualTaskTips\VisualTaskTips.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\AOL\1223104298\ee\AOLSoftware.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\NETGEAR\WPN111\wpn111.exe C:\DOCUME~1\ADMINI~1.SIR\LOCALS~1\Temp\b.exe C:\WINDOWS\msa.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CD-R\CDBurnerXP Pro\Tools\NMSAccess.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\AIM6\aolsoftware.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\WgaTray.exe C:\Documents and Settings\Administrator.SIRSYSTEM\Desktop\dds.scr C:\WINDOWS\system32\wuauclt.exe ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uStart Page = hxxp://www.daemon-search.com/startpage mDefault_Page_URL = hxxp://www.uwininstaller.tk uInternet Connection Wizard,ShellNext = hxxp://www.uwininstaller.tk/ uInternet Settings,ProxyOverride = *.local mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aol search\AOLSearch.dll uURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aim toolbar 5.0\aoltb.dll uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll mURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aim toolbar 5.0\aoltb.dll mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll BHO: Seekmo: {07aa283a-43d7-4cbe-a064-32a21112d94d} - c:\program files\seekmo\bin\10.0.424.0\HostIE.dll BHO: ShoppingReport: {100eb1fd-d03e-47fd-81f3-ee91287f9465} - c:\program files\shoppingreport\bin\2.5.0\ShoppingReport.dll BHO: XML Class: {500bca15-57a7-4eaf-8143-8c619470b13d} - c:\windows\system32\msxml71.dll BHO: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aol search\AOLSearch.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: mysidesearch search enhancer: {5c7368fb-d033-ce70-4757-e3b62547b82c} - c:\windows\system32\rnqbuctnbrd.dll BHO: {667675cf-b246-41eb-a1c4-5d8c6231bd49} - c:\windows\system32\cabine.dll BHO: dcads: {733716e1-76d2-4003-ac39-845281c0ef85} - c:\windows\system32\nsy18.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aim toolbar 5.0\aoltb.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll BHO: dcads: {f7e5f38b-3105-3aa1-4519-bd2d7e219a76} - c:\windows\system32\nsk39.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll TB: AIM Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll TB: Seekmo: {07aa283a-43d7-4cbe-a064-32a21112d94d} - c:\program files\seekmo\bin\10.0.424.0\HostIE.dll TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll EB: Seekmo Information Window: {93b0fa7b-50f6-41b4-ac7e-612a72ce8c3c} - c:\program files\seekmo\bin\10.0.424.0\HostIE.dll EB: ShopperReports: {a7cddcdc-beeb-4685-a062-978f5e07ceee} - c:\program files\shoppingreport\bin\2.5.0\ShoppingReport.dll EB: Search panel: {b97cab15-5926-1794-f64c-f570399cf0b1} - c:\windows\system32\rnqbuctnbrd.dll EB: Search panel: {fb6fe8d0-7d8c-b0bb-35c3-46c9c04b085d} - c:\windows\system32\ozunxgvjpnsoioviq.dll uRun: [googletalk] "c:\program files\google\google talk\googletalk.exe" /autostart uRun: [ATnotes.exe] c:\program files\atnotes\ATnotes.exe uRun: [Free Download Manager] c:\program files\free download manager\fdm.exe -autorun uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [EA Core] c:\program files\electronic arts\eadm\Core.exe -silent uRun: [AOL Fast Start] "c:\program files\aol 9.1\AOL.EXE" -b uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Cognac] c:\docume~1\admini~1.sir\locals~1\temp\b.exe mRun: [LClock] c:\program files\lclock\LClock.exe mRun: [VisualTaskTips] c:\program files\xtras\visualtasktips\VisualTaskTips.exe mRun: [YCentral] c:\program files\yahoo!\ycentral\YahooCentral.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe" mRun: [SeekmoOE] c:\program files\seekmo\bin\10.0.424.0\OEAddOn.exe mRun: [SeekmoSA] "c:\program files\seekmo\bin\10.0.424.0\SeekmoSA.exe" mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [HostManager] c:\program files\common files\aol\1223104298\ee\AOLSoftware.exe mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k dRun: [RAM Medic] c:\program files\iomatic\ram medic\RAMMedic.exe dRun: [googletalk] "c:\program files\google\google talk\googletalk.exe" /autostart dRun: [ATnotes.exe] c:\program files\atnotes\ATnotes.exe dRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet dRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized dRun: [Free Download Manager] c:\program files\free download manager\fdm.exe -autorun StartupFolder: c:\docume~1\admini~1.sir\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\admini~1.sir\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wpn111\wpn111.exe StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\rainle~1.lnk - c:\program files\xtras\rainlendar\Rainlendar.exe IE: &AIM Toolbar Search - c:\documents and settings\all users.windows\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-us\local\search.html IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm IE: Download web site with Free Download Manager - file://c:\program files\free download manager\dlpage.htm IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll IE: {C5428486-50A0-4a02-9D20-520B59A9F9B2} - {C9CCBB35-D123-4a31-AFFC-9B2933132116} - c:\program files\shoppingreport\bin\2.5.0\ShoppingReport.dll IE: {C5428486-50A0-4a02-9D20-520B59A9F9B3} - {A16AD1E9-F69A-45af-9462-B1C286708842} - c:\program files\shoppingreport\bin\2.5.0\ShoppingReport.dll DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1.sir\applic~1\mozilla\firefox\profiles\r4dgqfwq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www2.yoog.com/search.php?q= FF - prefs.js: browser.search.selectedEngine - Yoog Search FF - prefs.js: keyword.URL - hxxp://www2.yoog.com/search.php?q= FF - component: c:\documents and settings\administrator.sirsystem\application data\mozilla\firefox\profiles\r4dgqfwq.default\extensions\piclens@cooliris.com\components\coolirisstub.dll FF - component: c:\program files\mozilla firefox\components\bdc61f1e-176a-c0da-9a19-f0b9626731ce.dll FF - component: c:\program files\mozilla firefox\components\nsBrowserOpt.dll FF - component: c:\program files\mozilla firefox\components\nsdcads.dll FF - component: c:\program files\mozilla firefox\components\ozunxgvjpnsoioviq.dll FF - component: c:\program files\mozilla firefox\components\rnqbuctnbrd.dll FF - component: c:\program files\mozilla firefox\extensions\browserhighlighter@ebay.com\components\Shim.dll FF - plugin: c:\documents and settings\administrator.sirsystem\application data\mozilla\firefox\profiles\r4dgqfwq.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll FF - plugin: c:\documents and settings\administrator.sirsystem\application data\mozilla\firefox\profiles\r4dgqfwq.default\extensions\solidstateion@solidstatenetworks.com\plugins\npssn.dll FF - plugin: c:\program files\mozilla firefox\plugins\npclntax_SeekmoSA.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- FF - user.js: google.toolbar.linkdoctor.enabled - false FF - user.js: browser.search.selectedEngine - Yoog Search FF - user.js: keyword.URL - hxxp://www2.yoog.com/search.php?q= FF - user.js: keyword.enabled - true FF - user.js: browser.search.defaultenginename - Yoog Search FF - user.js: browser.search.defaulturl - hxxp://www2.yoog.com/search.php?q= ============= SERVICES / DRIVERS =============== R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2008-1-27 2368] R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2008-1-27 17149] R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2008-1-27 362944] S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-1-26 24652] S3 GarenaPEngine;GarenaPEngine;c:\docume~1\admini~1.sir\locals~1\temp\ZMZ7.tmp [2009-7-21 18704] S3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [2008-5-2 7548] S3 XDva037;XDva037;\??\c:\windows\system32\xdva037.sys --> c:\windows\system32\XDva037.sys [?] S3 XDva186;XDva186;\??\c:\windows\system32\xdva186.sys --> c:\windows\system32\XDva186.sys [?] S3 XDva189;XDva189;\??\c:\windows\system32\xdva189.sys --> c:\windows\system32\XDva189.sys [?] S3 XDva219;XDva219;\??\c:\windows\system32\xdva219.sys --> c:\windows\system32\XDva219.sys [?] =============== Created Last 30 ================ 2009-07-22 00:46 65,536 a------- c:\windows\system32\drivers\geyekrsrbpqpjw.sys 2009-07-22 00:39 143,360 a------- c:\windows\msa.exe 2009-07-22 00:38 142,852 a------- c:\windows\system32\msxml71.dll 2009-07-20 18:22 <DIR> --d----- c:\program files\Garena 2009-07-17 09:12 523,776 a------- c:\windows\system32\rnqbuctnbrd.dll 2009-07-16 02:49 <DIR> --d--r-- c:\program files\Skype 2009-07-04 02:14 <DIR> --d----- c:\windows\system32\wbem\Repository 2009-07-04 01:49 <DIR> --d----- c:\windows\system32\AGEIA 2009-07-04 00:34 <DIR> --d----- c:\windows\Logs 2009-07-04 00:16 <DIR> --d----- C:\Root 2009-07-04 00:16 <DIR> --d----- c:\program files\Activision 2009-07-03 14:06 116,736 a------- c:\windows\system32\drivers\mcdbus.sys 2009-07-03 14:06 <DIR> --d----- c:\program files\MagicDisc 2009-07-03 14:01 <DIR> --d----- c:\docume~1\alluse~1.win\applic~1\DAEMON Tools Pro 2009-07-03 11:22 <DIR> --d----- c:\docume~1\admini~1.sir\applic~1\DAEMON Tools Pro ==================== Find3M ==================== 2009-07-21 19:42 58,738 a------- c:\windows\system32\rnqbuctnbrd.dll-uninst.exe 2009-07-03 11:22 721,904 a------- c:\windows\system32\drivers\sptd.sys 2009-06-23 13:44 79,266 a------- c:\windows\War3Unin.dat 2009-06-10 06:03 1,580,550 a------- c:\windows\system32\nvdata.bin 2008-12-30 02:48 919,260,488 a------- c:\program files\2MOONSExpedition.exe 2007-08-24 13:46 35,947 a------- c:\program files\decoy_source_ct.jpg 2006-02-11 03:54 94,208 a------- c:\program files\W3XMapHack12006.exe ============= FINISH: 1:45:42.47 =============== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) | |
|
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
Join Date: Oct 2007
Location: Georgia
Posts: 10,592
OS: XP SP3
|
Re: Please help. Bad viruses, probably from P2P sadly...
Quote:
Even a single click on the site can drop multiple forms of very serious malware, many of which disable your onboard protection, and System Restore. If you install the cracked software, you are running executable files from these dubious, unknown sources. You are in effect giving these sources access to information on your hard disk, and potential control over the operation of your computer. Additionally, cracked programs are illegal. Before posting for help, uninstall any such applications. Referring to the Forum Rules which you should have read at the time of Registering at this forum, TSF does not support illegal activity. As such, be advised that any request for assistance in removing malware may go unanswered, or may be discontinued, if the cracked (illegal) software is still present on the machine. In 2006, a study revealed that 59% of keygens and crack tools downloaded from peer-to-peer networks contained malicious or "unwanted" software. ------------------------------------------------------ |
|
|
|
![]() |
| Thread Tools | |
|
|