Anyone...Need your immediate help please ..:-(

Discussion in 'Windows - Virus and spyware problems' started by duday, Sep 3, 2007.

  1. duday

    duday Member

    Joined:
    Sep 2, 2007
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
    Hi

    my computer shutdown automatically 60 sec after reboot .message says "Remote Precedure Call terminated unexpectedly." Really need your help please.

    here is my hijack log history.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:48:00 PM, on 9/3/2007
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\HpMmKbd.exe
    C:\PROGRAM FILES\MOUSEWAREPRO\MWProEng.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
    C:\DMI\Win32\Bin\HPTrayIcon.exe
    C:\WINDOWS\System32\Promon.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\SYSTEM32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\cassandra\Desktop\FxSasser.exe
    C:\Documents and Settings\cassandra\My Documents\background\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
    O2 - BHO: (no name) - {2DA29024-7E86-4B28-B96C-3D17F356EE30} - C:\WINDOWS\Speech\rcc.dll (file missing)
    O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - C:\WINDOWS\System32\umohelxv.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [HpMmKbd] HpMmKbd.exe
    O4 - HKLM\..\Run: [MWProEng] C:\PROGRAM FILES\MOUSEWAREPRO\MWProEng.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] "C:\Program Files\Ahead\InCD\InCD.exe"
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [sysems] C:\WINDOWS\system32\syslem.exe
    O4 - HKLM\..\Run: [stack12] C:\WINDOWS\system32\mfee.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
    O4 - HKLM\..\Run: [ServiceLayer] C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
    O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer\Application\DataLayer.exe
    O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [Virtual Drive] "C:\Program Files\FarStone\VirtualDrive\vdtask.exe"
    O4 - HKLM\..\Run: [McAfeeWebScanX] C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WebScanX.Exe
    O4 - HKLM\..\Run: [HP Tray Icon] C:\DMI\Win32\Bin\HPTrayIcon.exe
    O4 - HKLM\..\Run: [Promon.exe] Promon.exe
    O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
    O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\SYSTEM32\PDESK.EXE /Autolaunch
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM32\STIMON.EXE
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
    O4 - HKUS\S-1-5-21-2052111302-113007714-854245398-1005\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
    O4 - HKUS\S-1-5-21-2052111302-113007714-854245398-1005\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User '?')
    O4 - HKUS\S-1-5-21-2052111302-113007714-854245398-1005\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [Microsoft WinMax Player] winvrn.exe (User '?')
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
    O4 - HKUS\S-1-5-18\..\RunServices: [Microsoft WinMax Player] winvrn.exe (User '?')
    O4 - HKUS\.DEFAULT\..\Run: [Microsoft WinMax Player] winvrn.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunServices: [Microsoft WinMax Player] winvrn.exe (User 'Default user')
    O4 - Global Startup: Reality Fusion GameCam SE.lnk = C:\Program Files\Intel\Createshare\program\PC Camera Games\Program\RFTray.exe
    O4 - Global Startup: Quick Shelf.lnk = C:\Program Files\Microsoft Encarta\Encarta World English Dictionary 2001\QSHLFED.EXE
    O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
    O8 - Extra context menu item: &Define - c:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O8 - Extra context menu item: Look Up in &Encyclopedia - c:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - c:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - c:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Common\yiesrvc.dll
    O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - c:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - c:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O12 - Plugin for .ivs: C:\PROGRA~1\INTERN~1\PLUGINS\Npriff.dll
    O16 - DPF: Win32 Classes -
    O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136508759610
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136510132354
    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712...amai.com/6712/player/install3.0/installer.exe
    O20 - Winlogon Notify: ddcaxwu - ddcaxwu.dll (file missing)
    O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\rvipxmib.dll (file missing)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Advanced Windows Tray - Unknown owner - C:\WINDOWS\system32\vcmon.exe (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
    O23 - Service: Client Debug Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Client Disk Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Config Debug Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Debug Config System - Unknown owner - C:\WINDOWS\system32\lrsys.exe (file missing)
    O23 - Service: DNS Client Service - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: DNS FPHost Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: DNS Support Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: Local Debug Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Logon Task Manager - Unknown owner - C:\WINDOWS\system32\symon.exe (file missing)
    O23 - Service: Logon Terminal Manager - Unknown owner - C:\WINDOWS\system32\spoolsc.exe (file missing)
    O23 - Service: Microsoft BIOS Drivers - Unknown owner - C:\WINDOWS\system32\vcmon.exe (file missing)
    O23 - Service: Microsoft Client Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Microsoft DLL System - Unknown owner - C:\WINDOWS\system32\smsc.exe (file missing)
    O23 - Service: Microsoft Windows System32 - Unknown owner - C:\WINDOWS\zaber.exe (file missing)
    O23 - Service: Monitor Disk Manager - Unknown owner - C:\WINDOWS\system32\spoolcs.exe (file missing)
    O23 - Service: Net Logon Engine - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Net Logon Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Network Location Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Network Logon Engine - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Remote Auther Service - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote Crypt Services - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote FTPD Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote Header Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote Logon Manager - Unknown owner - C:\WINDOWS\system32\smcs.exe (file missing)
    O23 - Service: Remote Map Manager - Unknown owner - C:\WINDOWS\system32\lssc.exe (file missing)
    O23 - Service: Remote PEpng Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote Plesk Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote Print Spooler - Unknown owner - C:\WINDOWS\system32\spoolsc.exe (file missing)
    O23 - Service: Remote Process Manager - Unknown owner - C:\WINDOWS\system32\vcmon.exe (file missing)
    O23 - Service: Remote Public Services - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote Storage Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote TCP Services - Unknown owner - C:\WINDOWS\system32\vcmon.exe (file missing)
    O23 - Service: Remote Transfer Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote Usage Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote vShell Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Remote ZWare Service - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Security Access Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Security Task Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: Shell Code Services - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Shell Plugin Services - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Storage Shell Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: System Restore Manager - Unknown owner - C:\WINDOWS\system32\symon.exe (file missing)
    O23 - Service: System Restore Services - Unknown owner - C:\WINDOWS\system32\lsiss.exe (file missing)
    O23 - Service: Task Client Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Task Restore Service - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: TCP Monitor Manager - Unknown owner - C:\WINDOWS\system32\symon.exe (file missing)
    O23 - Service: Terminal Device Services - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)
    O23 - Service: Web Client Supply - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Win32Sr - Unknown owner - C:\WINDOWS\win32ssr.exe (file missing)
    O23 - Service: Window Boot Services - Unknown owner - C:\WINDOWS\system32\lsiss.exe (file missing)
    O23 - Service: Window Configs Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Windows Access Services - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Windows Browser Application - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Windows Live Config - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Windows Monitor Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Windows PE Debugger - Unknown owner - C:\WINDOWS\system32\lviss.exe (file missing)
    O23 - Service: Windows Process Manager - Unknown owner - C:\WINDOWS\system32\spoolsc.exe (file missing)
    O23 - Service: Windows Reg Service - Unknown owner - C:\WINDOWS\system32\lsyss.exe (file missing)
    O23 - Service: Windows Regedit Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Windows Remote Manager - Unknown owner - C:\WINDOWS\system32\lsiss.exe (file missing)
    O23 - Service: Windows Restore Service - Unknown owner - C:\WINDOWS\system32\spoolcs.exe (file missing)
    O23 - Service: Windows Security Manager - Unknown owner - C:\WINDOWS\system32\vcmon.exe (file missing)
    O23 - Service: Windows SFTP System - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Windows System Host - Unknown owner - C:\WINDOWS\sychost32.exe (file missing)
    O23 - Service: Windows System Tray - Unknown owner - C:\WINDOWS\systay.exe (file missing)
    O23 - Service: Windows Task Manager - Unknown owner - C:\WINDOWS\system32\vcmon.exe (file missing)
    O23 - Service: Windows Terminal Services - Unknown owner - C:\WINDOWS\system32\vcmon.exe (file missing)
    O23 - Service: Wireless Task Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)
    O23 - Service: Washer AutoComplete (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\System32\wwSecure.exe
     
  2. PeaInAPod

    PeaInAPod Active member

    Joined:
    Nov 28, 2005
    Messages:
    3,050
    Likes Received:
    0
    Trophy Points:
    66
    Remove these (lol theres lots of them)....

    O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)

    O2 - BHO: (no name) - {2DA29024-7E86-4B28-B96C-3D17F356EE30} - C:\WINDOWS\Speech\rcc.dll (file missing)

    O2 - BHO: (no name) - {F18F04B0-9CF1-4b93-B004-77A288BEE28B} - C:\WINDOWS\System32\umohelxv.dll (file missing)

    O4 - HKLM\..\Run: [sysems] C:\WINDOWS\system32\syslem.exe

    O16 - DPF: Win32 Classes -

    O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/v...0/installer.exe

    O20 - Winlogon Notify: ddcaxwu - ddcaxwu.dll (file missing)

    O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\rvipxmib.dll (file missing)

    O23 - Service: Advanced Windows Tray - Unknown owner - C:\WINDOWS\system32\vcmon.exe (file missing)

    O23 - Service: Client Debug Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)

    - through -

    O23 - Service: DNS Support Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)

    O23 - Service: Local Debug Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)

    - through -

    O23 - Service: Security Task Manager - Unknown owner - C:\WINDOWS\system32\spoolvc.exe (file missing)

    O23 - Service: Shell Code Services - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)

    - through -

    O23 - Service: Wireless Task Manager - Unknown owner - C:\WINDOWS\system32\svshost.exe (file missing)


    Besides removing these entries also I would advise updating your copy of Internet Explorer. And of course after removing these entries post a new HJT log.
     
  3. hilu

    hilu Member

    Joined:
    Jun 7, 2006
    Messages:
    81
    Likes Received:
    0
    Trophy Points:
    16
    @PeaInAPod

    Now I see your skills

    @duday

    I Have some bad news!

    Your computer is infected by a variant of the SDBot worm. This can give intruders complete control of your computer, logging key strokes, stealing information, etc.

    You are strongly advised to do the following immediately!:


    * Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned.
    * Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    * From a clean computer, change *all* of your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.

    Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

    Because of its backdoor functionality, your PC is very likely compromised and there is no way to be sure it can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

    Danger: Remote Access Trojans.
    When should I re-format? How should I reinstall?
    How Do I Handle Possible Identify Theft, Internet Fraud and Credit Card Fraud?

    Please let me know your decision and we'll get started with clean up if that's what you choose.
     

Share This Page