Open Side Menu Go to the Top
Register
SAS Log SAS Log

09-20-2010 , 11:16 PM
Will someone look at this for me? Most of these "Trojans" seem ok...My wife's computer just started acting up today, so I thought that I would run this to see. I'm going to go through everything tomorrow in FAQ, but I ran this and MBA tonight. MBA didn't find anything, here is the log from SAS. Thanks.


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/20/2010 at 11:11 PM

Application Version : 4.36.1006

Core Rules Database Version : 5547
Trace Rules Database Version: 3359

Scan type : Complete Scan
Total Scan Time : 00:55:27

Memory items scanned : 622
Memory threats detected : 0
Registry items scanned : 6956
Registry threats detected : 0
File items scanned : 30935
File threats detected : 46

Trojan.Agent/Gen-SVCFake
C:\PROGRAM FILES\AUTOHOTKEY\AUTOHOTKEY.EXE
C:\PROGRAM FILES\AUTOHOTKEY\COMPILER\AHK2EXE.EXE
C:\PROGRAM FILES\INSTALLSHIELD INSTALLATION INFORMATION\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\ISSETUP.DLL
C:\PROGRAM FILES\INSTALLSHIELD INSTALLATION INFORMATION\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}\ISSETUP.DLL
C:\PROGRAM FILES\INSTALLSHIELD INSTALLATION INFORMATION\{DC24971E-1946-445D-8A82-CE685433FA7D}\ISSETUP.DLL
C:\PROGRAM FILES\MICROSOFT WORKS\LNCHTOUR.EXE
C:\PROGRAM FILES\PLAZMIC CDK 4.7\BIN\DISPATCHER.EXE
C:\PROGRAM FILES\PLAZMIC CDK 4.7\BIN\DISPATCHERCLIENT.EXE
C:\PROGRAM FILES\PLAZMIC CDK 4.7\BIN\RAPC_CDK.EXE
C:\PROGRAM FILES\PLAZMIC CDK 4.7\BIN\SVGC.EXE
C:\PROGRAM FILES\PLAZMIC CDK 4.7\BIN\SWFTOSVG.EXE
C:\PROGRAM FILES\PLAZMIC CDK 4.7\BIN\TBBUNDLE.EXE
C:\PROGRAM FILES\PLAZMIC CDK 4.7\UNINSTALL PLAZMIC CDK 4.7 FOR BLACKBERRY\UNINSTALL PLAZMIC CDK 4.7 FOR BLACKBERRY.EXE
C:\PROGRAM FILES\PLAZMIC CDK 4.7 UPDATE PATCH\UNINSTALL_PLAZMIC CONTENT DEVELOPER'S KIT 4.7 UPDATE PATCH\UNINSTALL PLAZMIC CONTENT DEVELOPER'S KIT 4.7 UPDATE PATCH.EXE
C:\PROGRAM FILES\SMINST\RMCTOOLS.DLL
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\HIJACKTHIS.EXE
C:\SWSETUP\DRIVERS\CARDREAD\ISSETUP.DLL
C:\SWSETUP\DRIVERS\MODEM\NETWAITING\ISSETUP.DLL
C:\SWSETUP\DRIVERS\NETWORK\ISSETUP.DLL
C:\SWSETUP\DRIVERS\WLAN\ISSETUP.DLL
C:\SWSETUP\MSWORKS\PFILES\MSWORKS\LNCHTOUR.EXE
C:\SWSETUP\QLB\DISK1\ISSETUP.DLL
C:\SWSETUP\SP46631\ISSETUP.DLL
C:\USERS\JOELANDKATIE\APPDATA\LOCAL\AUTOBAHN\MLB-NEXDEF-AUTOBAHN.EXE
C:\USERS\JOELANDKATIE\DOCUMENTS\DOWNLOADS\ATF-CLEANER.EXE
C:\USERS\JOELANDKATIE\DOCUMENTS\DOWNLOADS\J6LH2NMP .EXE
C:\USERS\JOELANDKATIE\DOCUMENTS\DOWNLOADS\NPOCMK6O .EXE
C:\USERS\JOELANDKATIE\G2MDLHLPX.EXE

Adware.Tracking Cookie
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@andomedia[2].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@rogersmedia[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@ad.yieldmanager[2].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@fastclick[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@casalemedia[2].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@advertising[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@at.atwola[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@analytics.rogersmedia[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@content.yieldmanager[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@tribalfusion[2].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@serving-sys[2].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@stat.onestat[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@atdmt[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@adxpose[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@apmebf[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@doubleclick[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@zedo[1].txt
C:\Users\JoelandKatie\AppData\Roaming\Microsoft\Wi ndows\Cookies\joelandkatie@bs.serving-sys[1].txt
SAS Log Quote
09-20-2010 , 11:40 PM
here is a HiJackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:44:26 PM, on 9/20/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Users\JoelandKatie\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe
C:\Program Files\PdaNet for BlackBerry\PdaNetPC.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Users\JoelandKatie\AppData\Local\Google\Chrome\ Application\chrome.exe
C:\Users\JoelandKatie\AppData\Local\Google\Chrome\ Application\chrome.exe
C:\Users\JoelandKatie\AppData\Local\Google\Chrome\ Application\chrome.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...vilion&pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...vilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...vilion&pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...vilion&pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [RDVCHG] "C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Google Update] "C:\Users\JoelandKatie\AppData\Local\Google\Update \GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-4106239335-2428983455-2669550932-1002\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'postgres')
O4 - Startup: MLB.TV NexDef Plug-in.lnk = C:\Users\JoelandKatie\AppData\Local\Autobahn\mlb-nexdef-autobahn.exe
O4 - Startup: PdaNet Desktop.lnk = C:\Program Files\PdaNet for BlackBerry\PdaNetPC.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{DA504B75-B12C-409B-960A-E79FB255C00B}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Sprint Con App Svc (CASprint) - SmithMicro Inc. - C:\Program Files\Sprint\Sprint SmartView\ConAppsSvc.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PostgreSQL Database Server 8.3 (pgsql-8.3) - PostgreSQL Global Development Group - C:\Program Files\PostgreSQL\8.3\bin\pg_ctl.exe
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - SmithMicro Inc. - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: TetherBerry - Unknown owner - C:\Program Files\TetherBerry\TBService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 8374 bytes
SAS Log Quote
09-21-2010 , 03:09 AM
09-21-2010 , 10:58 AM
lol...thanks, I browse the forums (though not this one much, as I have no expertise to give) all the time from my phone, but find it tedious to post from my EVO, so typically just read.

One problem we've been having as well, is that firefox will no longer open. Any way that I try to open it, it never opens. I'm going to try to uninstall/reinstall it and see if that helps, but otherwise I don't why this would be happening.

Also, in Chrome, my wife (who informed me of all this yesterday) said when she clicked links (from facebook or people, etc.) she got a message that said "aww, snap!" but never showed what she was looking for. I verified that the Facebook links were not external links, but links to, say, her inbox. I haven't been able to recreate it, but that confused me as well.
SAS Log Quote
09-21-2010 , 02:48 PM
SAS is saying HJT, ATF-cleaner and Autohotkey are infected? Seems like that is probably false positives to me.

Download, update and run Malwarebytes Antimalware.
SAS Log Quote

      
m