| 
			
			
			
		 | 
	
												  
												
													
														
															
															
	
			
			
				| 
					Problems with lagacy_tdssserv
				 | 
				
				
					
				 | 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						| 
							
								 jimrush51 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						27. October 2008 @ 21:04 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							I have been having problems with the legacy_tdssserv trojan. my anti virus (CA anti-virus, and spyware) can't seem to kick it. worse it has now stopped me from downloading updates for my anti-virus and windows. it has stopped me from being able to use any search engines, and today i found out that i cant download your atf cleaner. its telling me that there is a problem with the internet connection, which only happens when i try to get a program of this type, or to update one like it. i have hijack this already, and any help would be greatly appreciated.
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
					
						| 
							 Advertisement 
							 
						 | 
						   | 
					 
					
						| 
							
							
						 | 
					 
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						27. October 2008 @ 23:16 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
						
						
   
 There are three kinds of men:  The ones that learn by reading; The few who learn by observation;  
 The rest of them have to pee on the electric fence and find out for themselves... 
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 jimrush51 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						28. October 2008 @ 00:23 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							sorry about the mistake. i tried to get a jump on the problem by downloading the first program early. but as i said i cant get it, and now ive noticed that i cant get your super anti-spyware either. all i can give is my hijackthis and its not yours, its one i got a few days ago....
 
 Logfile of HijackThis v1.99.1
 Scan saved at 11:20:31 PM, on 10/27/2008
 Platform: Windows XP SP3 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16735)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
 C:\WINDOWS\arservice.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
 C:\WINDOWS\eHome\ehRecvr.exe
 C:\WINDOWS\eHome\ehSched.exe
 C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
 C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
 C:\Program Files\Viewpoint\Common\ViewpointService.exe
 C:\WINDOWS\system32\dllhost.exe
 C:\Program Files\Stardock\Object Desktop\ThemeManager\wbload.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
 C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
 C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
 C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\AIM6\aim6.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
 C:\Program Files\AIM6\aolsoftware.exe
 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
 C:\HP\KBD\KBD.EXE
 C:\WINDOWS\ALCXMNTR.EXE
 c:\windows\system\hpsysdrv.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Documents and Settings\HP_Administrator\My Documents\My Library\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
 O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
 O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
 O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
 O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
 O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
 O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
 O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
 O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
 O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
 O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/2006...ex/qtplugin.cab
 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
 O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
 O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resourc...lscbase5036.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupd...b?1154434908785
 O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/v...l/installer.exe
 O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
 O20 - Winlogon Notify: WB - C:\Program Files\Stardock\Object Desktop\ThemeManager\fastload.dll
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
 O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
 O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
 O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
 O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
 O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
 O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
 O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						28. October 2008 @ 01:15 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							Hummm?  There is nothing in your HJT Log to indicate the presents of malware but that doesn?t mean you don?t have any..   
 
 EDIT  Please see my next post..  we may be able to skip this one..  2og
 
 Let?s try to sidestep it?..
 
 Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode ? with networking". 
 
 If, hopefully, you can get into Safe Mode then follow my instructions and download and run ATF and SAS..
 
 Post the SAS Log and we will go from there..
 
 P.S.  while there, go ahead and download the newer version of HijackThis..
 
 Thanks,
 2OG 
							
						 
						
						
   
 There are three kinds of men:  The ones that learn by reading; The few who learn by observation;  
 The rest of them have to pee on the electric fence and find out for themselves... 
						
							This message has been edited since posting. Last time this message was edited on 28. October 2008 @ 05:10 
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						28. October 2008 @ 05:07 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							@jimrush51,
 
 
 UPDATE!!!!
 
 I have been doing some research on your problem and discovered that it?s probably the Trojan that downloads the Rogue Micro Antivirus 2009 that is messing with your ability to download from the Anti-Malware Sites?
 
 SDFix should be able to remove this Trojan.  If you have trouble downloading it in Normal Mode then go to Safe Mode ? with Networking and download it there..
 
 
 Download SDFix and save it to your Desktop.
 
 Double click SDFix.exe and it will extract the files to the drive that contains the Windows Directory, typically C:\SDFix
 
 Please then reboot your computer in Safe Mode by doing the following :
 ?	Restart your computer
 ?	After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
 ?	Instead of Windows loading as normal, the Advanced Options Menu should appear;
 ?	Select the first option, to run Windows in Safe Mode, then press Enter.
 ?	Choose your usual account.
 ?	Open the extracted SDFix folder and double click RunThis.bat to start the script.
 ?	Type Y to begin the cleanup process.
 ?	It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
 ?	Press any Key and it will restart the PC.
 ?	When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
 ?	Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt 
 (Report.txt will also be copied to Clipboard ready for posting back on the forum).
 ?	Finally paste the contents of the Report.txt back on the forum with a new Hijack This log
 
 2OG 
							
						 
						
						
   
 There are three kinds of men:  The ones that learn by reading; The few who learn by observation;  
 The rest of them have to pee on the electric fence and find out for themselves... 
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 jimrush51 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						28. October 2008 @ 08:19 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							ok, i just got done with the other stuff so i will go ahead a paste them then get right on the other thing. 
 here is the hijack_Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 7:15:04 AM, on 10/28/2008
 Platform: Windows XP SP3 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16735)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
 C:\WINDOWS\arservice.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
 C:\WINDOWS\eHome\ehRecvr.exe
 C:\WINDOWS\eHome\ehSched.exe
 C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
 C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
 C:\Program Files\Viewpoint\Common\ViewpointService.exe
 C:\Program Files\Stardock\Object Desktop\ThemeManager\wbload.exe
 C:\WINDOWS\system32\dllhost.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
 C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
 C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\AIM6\aim6.exe
 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Program Files\AIM6\aolsoftware.exe
 C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
 O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
 O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
 O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
 O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
 O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
 O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
 O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
 O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
 O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
 O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
 O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/2006...ex/qtplugin.cab
 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
 O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
 O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resourc...lscbase5036.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupd...b?1154434908785
 O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/v...l/installer.exe
 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
 O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
 O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
 O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
 O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
 O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
 O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
 O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
 
 --
 End of file - 9953 bytes
 
 and then the superanti-spyware SUPERAntiSpyware Scan Log
 http://www.superantispyware.com
 
 Generated 10/28/2008 at 03:42 AM
 
 Application Version : 4.21.1004
 
 Core Rules Database Version : 3555
 Trace Rules Database Version: 1543
 
 Scan type       : Complete Scan
 Total Scan Time : 02:38:24
 
 Memory items scanned      : 160
 Memory threats detected   : 0
 Registry items scanned    : 6541
 Registry threats detected : 29
 File items scanned        : 29369
 File threats detected     : 4
 
 Trojan.Unclassified/Helper-DD
 	HKLM\Software\Classes\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}#AppID
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\InprocServer32
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\InprocServer32#ThreadingModel
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\ProgID
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\Programmable
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\TypeLib
 	HKCR\CLSID\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}\VersionIndependentProgID
 	HKCR\main.BHO.1
 	HKCR\main.BHO.1\CLSID
 	HKCR\main.BHO
 	HKCR\main.BHO\CLSID
 	HKCR\main.BHO\CurVer
 	HKCR\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}
 	HKCR\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0
 	HKCR\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\0
 	HKCR\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\0\win32
 	HKCR\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\FLAGS
 	HKCR\TypeLib\{8E3C68CD-F500-4A2A-8CB9-132BB38C3573}\1.0\HELPDIR
 	C:\PROGRAM FILES\COMMON\HELPER.DLL
 	HKCR\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}
 	HKCR\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\ProxyStubClsid
 	HKCR\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\ProxyStubClsid32
 	HKCR\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\TypeLib
 	HKCR\Interface\{986A8AC1-AB4D-4F41-9068-4B01C0197867}\TypeLib#Version
 
 Trojan.DNSChanger-Codec
 	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck
 	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck#DisplayName
 	HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iCheck#UninstallString
 
 Trojan.ErrorSafe
 	C:\DOCUMENTS AND SETTINGS\HP_ADMINISTRATOR\APPLICATION DATA\ERRORSAFENEWRELEASEINSTALL[1].EXE
 
 Trojan.Dropper/CPX
 	C:\WINDOWS\SYSTEM32\WPV003.CPX
 	C:\WINDOWS\SYSTEM32\WPV233.CPX
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 jimrush51 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						28. October 2008 @ 19:44 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							sdx report -
 SDFix: Version 1.238 
 Run by HP_Administrator on Tue 10/28/2008 at 07:45 AM
 
 Microsoft Windows XP [Version 5.1.2600]
 Running From: C:\SDFix
 
 Checking Services :
 
 Rootkit Found :
 C:\WINDOWS\system32\drivers\TDSSmxot.sys - Rootkit.Win32.Agent.cku
 
 Name : 
 tdssserv
 
 Path :
 \systemroot\system32\drivers\TDSSmxot.sys 
 
 tdssserv - Deleted
 
 
 
 Restoring Default Security Values
 Restoring Default Hosts File
 Resetting SecurityProviders Value 
 
 Rebooting
 
 
 Checking Files : 
 
 Trojan Files Found:
 
 C:\WINDOWS\system32\TDSSoipa.dll - Deleted
 C:\WINDOWS\system32\TDSSirxy.dll - Deleted
 C:\WINDOWS\system32\TDSSyavu.dll - Deleted
 C:\WINDOWS\system32\TDSSncur.dll - Deleted
 C:\WINDOWS\system32\TDSSqxnr.dll - Deleted
 C:\WINDOWS\system32\TDSSmupe.dat - Deleted
 C:\WINDOWS\system32\TDSSnmxh.log - Deleted
 C:\WINDOWS\SYSTEM32\WINDOW~1.EXE - Deleted
 C:\Documents and Settings\HP_Administrator\Application Data\Facegame\Facegame.exe - Deleted
 C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\TDSS8004.tmp - Deleted
 C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\TDSS8014.tmp - Deleted
 C:\WINDOWS\system32\wini10803.exe - Deleted
 C:\WINDOWS\default.htm - Deleted
 C:\WINDOWS\system32\brastk.exe - Deleted
 C:\WINDOWS\system32\msansspc.dll - Deleted
 C:\WINDOWS\system32\windows_update.exe - Deleted
 C:\WINDOWS\wiaservv.log - Deleted
 C:\WINDOWS\system32\drivers\TDSSmxot.sys - Deleted
 
 
 
 Folder C:\Documents and Settings\HP_Administrator\Application Data\Facegame - Removed
 
 
 Removing Temp Files
 
 ADS Check :
  
 
 
                                  Final Check :
 
 catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
 Rootkit scan 2008-10-28 09:26:39
 Windows 5.1.2600 Service Pack 3 NTFS
 
 scanning hidden processes ...
 
 scanning hidden services & system hive ...
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
 "s1"=dword:0c88e833
 "s2"=dword:ddd88bd7
 "h0"=dword:00000001
 
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
 "h0"=dword:00000000
 "ujdew"=hex:0b,3d,cd,be,2f,0d,1e,cc,64,7a,f6,88,75,ef,9c,39,30,2c,a8,50,cb,..
 "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
 "h0"=dword:00000000
 "ujdew"=hex:0b,3d,cd,be,2f,0d,1e,cc,64,7a,f6,88,75,ef,9c,39,30,2c,a8,50,cb,..
 "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
 "h0"=dword:00000000
 "ujdew"=hex:0b,3d,cd,be,2f,0d,1e,cc,64,7a,f6,88,75,ef,9c,39,30,2c,a8,50,cb,..
 "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
 
 scanning hidden registry entries ...
 
 scanning hidden files ...
 
 scan completed successfully
 hidden processes: 0
 hidden services: 0
 hidden files: 0
 
 
 Remaining Services :
 
 
 
 
 Authorized Application Key Export:
 
 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
 "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
 "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
 "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
 "C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares"
 "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
 "C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
 "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
 "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
 "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
 "C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Disabled:Earthlink"
 "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Disabled:iTunes"
 "C:\\Program Files\\Starcraft\\StarCraft.exe"="C:\\Program Files\\Starcraft\\StarCraft.exe:*:Enabled:Starcraft"
 "C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III"
 "C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
 "C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.7.6383-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.7.6383-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
 "C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
 "C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
 "C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
 "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
 "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Run a DLL as an App"
 "C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
 "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
 "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
 "C:\\Program Files\\DISC\\DISCover.exe"="C:\\Program Files\\DISC\\DISCover.exe:*:Enabled:DISCover Drop & Play System"
 "C:\\Program Files\\DISC\\DiscStreamHub.exe"="C:\\Program Files\\DISC\\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub"
 "C:\\Program Files\\DISC\\myFTP.exe"="C:\\Program Files\\DISC\\myFTP.exe:*:Enabled:DISCover FTP"
 "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
 "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpace Instant Messenger"
 "C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
 "C:\\Program Files\\LucasArts\\Galactic Battlegrounds Saga\\Game\\Battlegrounds.exe"="C:\\Program Files\\LucasArts\\Galactic Battlegrounds Saga\\Game\\Battlegrounds.exe:*:Disabled:Star Wars Galactic Battlegrounds"
 "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
 
 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
 "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
 "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
 "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
 
 Remaining Files :
 
 
 File Backups: - C:\SDFix\backups\backups.zip
 
 Files with Hidden Attributes :
 
 Fri 28 Jul 2006           211 A.SHR --- "C:\BOOT.BAK"
 Mon 31 Jul 2006         4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
 Tue 31 Jul 2007             0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
 Wed 14 Dec 2005       200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\ACST4.DLL"
 Tue 22 Nov 2005        81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLFIREWALLMGR.DLL"
 Tue 22 Nov 2005        73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLINSTALLERFW.DLL"
 Wed 14 Dec 2005        88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\INSTPH.DLL"
 Wed 14 Dec 2005       200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\ACST4.DLL"
 Tue 22 Nov 2005        81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLFIREWALLMGR.DLL"
 Tue 22 Nov 2005        73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLINSTALLERFW.DLL"
 Wed 14 Dec 2005        88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\INSTPH.DLL"
 
 Finished!
 
 new hijack - Logfile of Trend Micro HijackThis v2.0.2
 Scan saved at 6:42:50 PM, on 10/28/2008
 Platform: Windows XP SP3 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16735)
 Boot mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
 C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
 C:\Program Files\Stardock\Object Desktop\ThemeManager\wbload.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
 C:\WINDOWS\arservice.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
 C:\WINDOWS\eHome\ehRecvr.exe
 C:\WINDOWS\eHome\ehSched.exe
 C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
 C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
 C:\Program Files\Viewpoint\Common\ViewpointService.exe
 C:\WINDOWS\system32\dllhost.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
 C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
 C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
 C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\AIM6\aim6.exe
 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
 C:\Program Files\AIM6\aolsoftware.exe
 c:\program files\common files\installshield\updateservice\isuspm.exe
 c:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
 C:\HP\KBD\KBD.EXE
 C:\WINDOWS\ALCXMNTR.EXE
 C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 c:\windows\system\hpsysdrv.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
 O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
 O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
 O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
 O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
 O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
 O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
 O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
 O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
 O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
 O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
 O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
 O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/2006...ex/qtplugin.cab
 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
 O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
 O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resourc...lscbase5036.cab
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupd...b?1154434908785
 O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
 O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/v...l/installer.exe
 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
 O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
 O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
 O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
 O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
 O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
 O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
 O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
 O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
 
 --
 End of file - 10217 bytes
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						28. October 2008 @ 22:49 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							@jimrush51,
 
 Well, it looks like that took care of the Trojan?  How?s your internet now?
 
 Do you have any other problems??
 
 2OG 
							
						 
						
						
   
 There are three kinds of men:  The ones that learn by reading; The few who learn by observation;  
 The rest of them have to pee on the electric fence and find out for themselves... 
						
						 | 
					 
				
				
			
				
				
				
				
				
					
						| 
							
								 jimrush51 
							
							
								Newbie
								
									
								
							
							 
							 
						 | 
						28. October 2008 @ 23:00 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						| 
						
						 
							
							seems to have taken care of it...i have full access to my search engine again and everything is back to speed! thank you very much!
							
						 
						
						
						
						 | 
					 
				
				
			
				
				
				
					
						| 
							 Advertisement 
							 
						 | 
						   | 
					 
					
						
							
							  
								
							
						 | 
					 
				
				
				
					
						
							
								
							
							
								AfterDawn Addict
								
									
								
							
							 
							 
						 | 
						28. October 2008 @ 23:25 | 
						 
							
								Link to this message
								  
								 
								  
							
							
						 | 
					 
					
					
					
						
						
						
							
							@jimrush51,
 
 Great!    
 
 Here is just one little piece of advice.
 Download and use Comodo BOClean (free) to keep these Trojans out of your machine.. It will not conflict with anything and uses very little resources.
 
  Comodo BOClean protects your computer against trojans, malware and other threats. It constantly scans your system in the background and intercepts any recognized trojan activity. The program can ask the user what to do, or run in unattended mode and automatically shutdown and remove any suspected trojan application. Comodo BOClean currently supports more than 60,000 malware items and offers automatic daily updates. Other features include updating via network share, tamper protection and stealth mode. 
 
 2OG 
							
						 
						
						
   
 There are three kinds of men:  The ones that learn by reading; The few who learn by observation;  
 The rest of them have to pee on the electric fence and find out for themselves... 
						
						 | 
					 
				
				
			
			
			
			
			
		 
		
	
			
			
		
	 |