Jump to content

I'm infected


Recommended Posts

protection-log-2010-07-30.txt:

00:16:33 Owner IP-BLOCK 91.212.226.179

00:16:36 Owner IP-BLOCK 91.212.226.179

00:16:42 Owner IP-BLOCK 91.212.226.179

00:16:54 Owner IP-BLOCK 85.12.46.156

00:16:57 Owner IP-BLOCK 85.12.46.156

00:17:03 Owner IP-BLOCK 85.12.46.156

00:17:15 Owner IP-BLOCK 85.12.46.157

00:17:18 Owner IP-BLOCK 85.12.46.157

00:17:24 Owner IP-BLOCK 85.12.46.157

00:17:36 Owner IP-BLOCK 91.212.226.182

00:17:39 Owner IP-BLOCK 91.212.226.182

00:17:45 Owner IP-BLOCK 91.212.226.182

00:17:57 Owner IP-BLOCK 85.12.46.158

00:18:00 Owner IP-BLOCK 85.12.46.158

00:18:06 Owner IP-BLOCK 85.12.46.158

00:18:18 Owner IP-BLOCK 85.12.46.157

00:18:21 Owner IP-BLOCK 85.12.46.157

00:18:27 Owner IP-BLOCK 85.12.46.157

00:18:39 Owner IP-BLOCK 85.12.46.155

00:18:42 Owner IP-BLOCK 85.12.46.155

00:18:48 Owner IP-BLOCK 85.12.46.155

00:19:00 Owner IP-BLOCK 85.12.46.155

00:19:03 Owner IP-BLOCK 85.12.46.155

00:19:09 Owner IP-BLOCK 85.12.46.155

00:19:21 Owner IP-BLOCK 85.12.46.158

00:19:24 Owner IP-BLOCK 85.12.46.158

00:19:30 Owner IP-BLOCK 85.12.46.158

dds.txt:

DDS (Ver_10-03-17.01) - NTFSx86

Run by Owner at 21:06:51.57 on Thu 07/29/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.702 [GMT -4:00]

AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

C:\WINDOWS\Explorer.EXE

svchost.exe

svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

C:\WINDOWS\system32\svchost.exe -k imgsvc

c:\WINDOWS\system32\ZuneBusEnum.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://www.google.com/ie

uStart Page = hxxp://www.douglas1.com/

uInternet Settings,ProxyOverride = <local>

uInternet Settings,ProxyServer = http=127.0.0.1:5577

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File

uRun: [XtraRichi] c:\program files\richi\Richi_Skype_Com.exe /OnStartUp

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

mRun: [soundMan] SOUNDMAN.EXE

mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min

IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab

DPF: {0122955E-1FB0-11D2-A238-006097FAEE8B} - hxxp://205.159.125.199/central/02030106/cccabs/CleverContent.cab

DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204

DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab

DPF: {6414512B-B978-451D-A0D8

Link to post
Share on other sites

attach.zip

dds.txt:

DDS (Ver_10-03-17.01) - NTFSx86

Run by Owner at 21:06:51.57 on Thu 07/29/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.702 [GMT -4:00]

AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

C:\WINDOWS\Explorer.EXE

svchost.exe

svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\WINDOWS\System32\svchost.

Link to post
Share on other sites

protection-log-2010-07-30.txt:

00:16:33 Owner IP-BLOCK 91.212.226.179

00:16:36 Owner IP-BLOCK 91.212.226.179

00:16:42 Owner IP-BLOCK 91.212.226.179

00:16:54 Owner IP-BLOCK 85.12.46.156

00:16:57 Owner IP-BLOCK 85.12.46.156

00:17:03 Owner IP-BLOCK 85.12.46.156

00:17:15 Owner IP-BLOCK 85.12.46.157

00:17:18 Owner IP-BLOCK 85.12.46.157

00:17:24 Owner IP-BLOCK 85.12.46.157

00:17:36 Owner IP-BLOCK 91.212.226.182

00:17:39 Owner IP-BLOCK 91.212.226.182

00:17:45 Owner IP-BLOCK 91.212.226.182

00:17:57 Owner IP-BLOCK 85.12.46.158

00:18:00 Owner IP-BLOCK 85.12.46.158

00:18:06 Owner IP-BLOCK 85.12.46.158

00:18:18 Owner IP-BLOCK 85.12.46.157

00:18:21 Owner IP-BLOCK 85.12.46.157

00:18:27 Owner IP-BLOCK 85.12.46.157

00:18:39 Owner IP-BLOCK 85.12.46.155

00:18:42 Owner IP-BLOCK 85.12.46.155

00:18:48 Owner IP-BLOCK 85.12.46.155

00:19:00 Owner IP-BLOCK 85.12.46.155

00:19:03 Owner IP-BLOCK 85.12.46.155

00:19:09 Owner IP-BLOCK 85.12.46.155

00:19:21 Owner IP-BLOCK 85.12.46.158

00:19:24 Owner IP-BLOCK 85.12.46.158

00:19:30 Owner IP-BLOCK 85.12.46.158

00:31:49 Owner IP-BLOCK 94.228.209.214

01:22:55 Owner IP-BLOCK 91.212.226.67

01:22:58 Owner IP-BLOCK 91.212.226.67

01:23:04 Owner IP-BLOCK 91.212.226.67

01:33:16 Owner IP-BLOCK 91.212.226.59

01:33:19 Owner IP-BLOCK 91.212.226.59

01:33:25 Owner IP-BLOCK 91.212.226.59

02:27:33 Owner IP-BLOCK 121.11.153.242

02:27:36 Owner IP-BLOCK 121.11.153.242

03:24:02 Owner IP-BLOCK 91.212.226.67

03:24:05 Owner IP-BLOCK 91.212.226.67

03:24:11 Owner IP-BLOCK 91.212.226.67

03:34:23 Owner IP-BLOCK 91.212.226.59

03:34:26 Owner IP-BLOCK 91.212.226.59

03:34:32 Owner IP-BLOCK 91.212.226.59

04:00:00 Owner MESSAGE Scheduled scan executed successfully

05:24:15 Owner IP-BLOCK 91.212.226.67

05:24:18 Owner IP-BLOCK 91.212.226.67

05:24:24 Owner IP-BLOCK 91.212.226.67

05:34:36 Owner IP-BLOCK 91.212.226.59

05:34:39 Owner IP-BLOCK 91.212.226.59

05:34:45 Owner IP-BLOCK 91.212.226.59

05:53:06 Owner IP-BLOCK 188.124.18.8

07:24:24 Owner IP-BLOCK 91.212.226.67

07:24:27 Owner IP-BLOCK 91.212.226.67

07:24:33 Owner IP-BLOCK 91.212.226.67

07:34:45 Owner IP-BLOCK 91.212.226.59

07:34:48 Owner IP-BLOCK 91.212.226.59

07:34:54 Owner IP-BLOCK 91.212.226.59

DDS.TXT:

DDS (Ver_10-03-17.01) - NTFSx86

Run by Owner at 21:06:51.57 on Thu 07/29/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.702 [GMT -4:00]

AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

C:\WINDOWS\Explorer.EXE

svchost.exe

svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

C:\WINDOWS\system32\svchost.exe -k imgsvc

c:\WINDOWS\system32\ZuneBusEnum.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://www.google.com/ie

uStart Page = hxxp://www.douglas1.com/

uInternet Settings,ProxyOverride = <local>

uInternet Settings,ProxyServer = http=127.0.0.1:5577

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File

uRun: [XtraRichi] c:\program files\richi\Richi_Skype_Com.exe /OnStartUp

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

mRu

Link to post
Share on other sites

protection-log-2010-07-30.txt:

00:16:33 Owner IP-BLOCK 91.212.226.179

00:16:36 Owner IP-BLOCK 91.212.226.179

00:16:42 Owner IP-BLOCK 91.212.226.179

00:16:54 Owner IP-BLOCK 85.12.46.156

00:16:57 Owner IP-BLOCK 85.12.46.156

00:17:03 Owner IP-BLOCK 85.12.46.156

00:17:15 Owner IP-BLOCK 85.12.46.157

00:17:18 Owner IP-BLOCK 85.12.46.157

00:17:24 Owner IP-BLOCK 85.12.46.157

00:17:36 Owner IP-BLOCK 91.212.226.182

00:17:39 Owner IP-BLOCK 91.212.226.182

00:17:45 Owner IP-BLOCK 91.212.226.182

00:17:57 Owner IP-BLOCK 85.12.46.158

00:18:00 Owner IP-BLOCK 85.12.46.158

00:18:06 Owner IP-BLOCK 85.12.46.158

00:18:18 Owner IP-BLOCK 85.12.46.157

00:18:21 Owner IP-BLOCK 85.12.46.157

00:18:27 Owner IP-BLOCK 85.12.46.157

00:18:39 Owner IP-BLOCK 85.12.46.155

00:18:42 Owner IP-BLOCK 85.12.46.155

00:18:48 Owner IP-BLOCK 85.12.46.155

00:19:00 Owner IP-BLOCK 85.12.46.155

00:19:03 Owner IP-BLOCK 85.12.46.155

00:19:09 Owner IP-BLOCK 85.12.46.155

00:19:21 Owner IP-BLOCK 85.12.46.158

00:19:24 Owner IP-BLOCK 85.12.46.158

00:19:30 Owner IP-BLOCK 85.12.46.158

00:31:49 Owner IP-BLOCK 94.228.209.214

01:22:55 Owner IP-BLOCK 91.212.226.67

01:22:58 Owner IP-BLOCK 91.212.226.67

01:23:04 Owner IP-BLOCK 91.212.226.67

01:33:16 Owner IP-BLOCK 91.212.226.59

01:33:19 Owner IP-BLOCK 91.212.226.59

01:33:25 Owner IP-BLOCK 91.212.226.59

02:27:33 Owner IP-BLOCK 121.11.153.242

02:27:36 Owner IP-BLOCK 121.11.153.242

03:24:02 Owner IP-BLOCK 91.212.226.67

03:24:05 Owner IP-BLOCK 91.212.226.67

03:24:11 Owner IP-BLOCK 91.212.226.67

03:34:23 Owner IP-BLOCK 91.212.226.59

03:34:26 Owner IP-BLOCK 91.212.226.59

03:34:32 Owner IP-BLOCK 91.212.226.59

04:00:00 Owner MESSAGE Scheduled scan executed successfully

05:24:15 Owner IP-BLOCK 91.212.226.67

05:24:18 Owner IP-BLOCK 91.212.226.67

05:24:24 Owner IP-BLOCK 91.212.226.67

05:34:36 Owner IP-BLOCK 91.212.226.59

05:34:39 Owner IP-BLOCK 91.212.226.59

05:34:45 Owner IP-BLOCK 91.212.226.59

05:53:06 Owner IP-BLOCK 188.124.18.8

07:24:24 Owner IP-BLOCK 91.212.226.67

07:24:27 Owner IP-BLOCK 91.212.226.67

07:24:33 Owner IP-BLOCK 91.212.226.67

07:34:45 Owner IP-BLOCK 91.212.226.59

07:34:48 Owner IP-BLOCK 91.212.226.59

07:34:54 Owner IP-BLOCK 91.212.226.59

DDS.TXT:

DDS (Ver_10-03-17.01) - NTFSx86

Run by Owner at 21:06:51.57 on Thu 07/29/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.702 [GMT -4:00]

AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

C:\WINDOWS\Explorer.EXE

svchost.exe

svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

C:\WINDOWS\system32\svchost.exe -k imgsvc

c:\WINDOWS\system32\ZuneBusEnum.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://www.google.com/ie

uStart Page = hxxp://www.douglas1.com/

uInternet Settings,ProxyOverride = <local>

uInternet Settings,ProxyServer = http=127.0.0.1:5577

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File

uRun: [XtraRichi] c:\program files\richi\Richi_Skype_Com.exe /OnStartUp

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

mRun:

Link to post
Share on other sites

attach.zip

00:16:33 Owner IP-BLOCK 91.212.226.179

00:16:36 Owner IP-BLOCK 91.212.226.179

00:16:42 Owner IP-BLOCK 91.212.226.179

00:16:54 Owner IP-BLOCK 85.12.46.156

00:16:57 Owner IP-BLOCK 85.12.46.156

00:17:03 Owner IP-BLOCK 85.12.46.156

00:17:15 Owner IP-BLOCK 85.12.46.157

00:17:18 Owner IP-BLOCK 85.12.46.157

00:17:24 Owner IP-BLOCK 85.12.46.157

00:17:36 Owner IP-BLOCK 91.212.226.182

00:17:39 Owner IP-BLOCK 91.212.226.182

00:17:45 Owner IP-BLOCK 91.212.226.182

00:17:57 Owner IP-BLOCK 85.12.46.158

00:18:00 Owner IP-BLOCK 85.12.46.158

00:18:06 Owner IP-BLOCK 85.12.46.158

00:18:18 Owner IP-BLOCK 85.12.46.157

00:18:21 Owner IP-BLOCK 85.12.46.157

00:18:27 Owner IP-BLOCK 85.12.46.157

00:18:39 Owner IP-BLOCK 85.12.46.155

00:18:42 Owner IP-BLOCK 85.12.46.155

00:18:48 Owner IP-BLOCK 85.12.46.155

00:19:00 Owner IP-BLOCK 85.12.46.155

00:19:03 Owner IP-BLOCK 85.12.46.155

00:19:09 Owner IP-BLOCK 85.12.46.155

00:19:21 Owner IP-BLOCK 85.12.46.158

00:19:24 Owner IP-BLOCK 85.12.46.158

00:19:30 Owner IP-BLOCK 85.12.46.158

00:31:49 Owner IP-BLOCK 94.228.209.214

01:22:55 Owner IP-BLOCK 91.212.226.67

01:22:58 Owner IP-BLOCK 91.212.226.67

01:23:04 Owner IP-BLOCK 91.212.226.67

01:33:16 Owner IP-BLOCK 91.212.226.59

01:33:19 Owner IP-BLOCK 91.212.226.59

01:33:25 Owner IP-BLOCK 91.212.226.59

02:27:33 Owner IP-BLOCK 121.11.153.242

02:27:36 Owner IP-BLOCK 121.11.153.242

03:24:02 Owner IP-BLOCK 91.212.226.67

03:24:05 Owner IP-BLOCK 91.212.226.67

03:24:11 Owner IP-BLOCK 91.212.226.67

03:34:23 Owner IP-BLOCK 91.212.226.59

03:34:26 Owner IP-BLOCK 91.212.226.59

03:34:32 Owner IP-BLOCK 91.212.226.59

04:00:00 Owner MESSAGE Scheduled scan executed successfully

05:24:15 Owner IP-BLOCK 91.212.226.67

05:24:18 Owner IP-BLOCK 91.212.226.67

05:24:24 Owner IP-BLOCK 91.212.226.67

05:34:36 Owner IP-BLOCK 91.212.226.59

05:34:39 Owner IP-BLOCK 91.212.226.59

05:34:45 Owner IP-BLOCK 91.212.226.59

05:53:06 Owner IP-BLOCK 188.124.18.8

07:24:24 Owner IP-BLOCK 91.212.226.67

07:24:27 Owner IP-BLOCK 91.212.226.67

07:24:33 Owner IP-BLOCK 91.212.226.67

07:34:45 Owner IP-BLOCK 91.212.226.59

07:34:48 Owner IP-BLOCK 91.212.226.59

07:34:54 Owner IP-BLOCK 91.212.226.59

DDS (Ver_10-03-17.01) - NTFSx86

Run by Owner at 21:06:51.57 on Thu 07/29/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.702 [GMT -4:00]

AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}

AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup

C:\WINDOWS\Explorer.EXE

svchost.exe

svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\LEXPPS.EXE

C:\Program Files\Avira\AntiVir Desktop\sched.exe

svchost.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

C:\WINDOWS\system32\svchost.exe -k imgsvc

c:\WINDOWS\system32\ZuneBusEnum.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://www.google.com/ie

uStart Page = hxxp://www.douglas1.com/

uInternet Settings,ProxyOverride = <local>

uInternet Settings,ProxyServer = http=127.0.0.1:5577

BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File

BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll

TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File

uRun: [XtraRichi] c:\program files\richi\Richi_Skype_Com.exe /OnStartUp

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [MSMSGS] "c:\program files\messenge

Link to post
Share on other sites

  • 5 weeks later...
  • 5 weeks later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.