Welcome, Guest. Please login or register.
September 08, 2010, 09:15:01 PM
Home Help Search Donations Login Register
News: Protecting your online financial transactions

+  SpywareHammer.com
|-+  SpywareHammer Malware Removal Forums
| |-+  Completed Malware and Rootkit Removal Topics
| | |-+  [Resolved] Strange happenings after malware infection
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] 2 Go Down Print
Author Topic: [Resolved] Strange happenings after malware infection  (Read 560 times)
nevar23
Bronze Member

Offline Offline

Posts: 14


« on: February 08, 2010, 12:50:08 PM »

I've been trying to get rid of some malware for a few days now and thought I may have finally gotten rid of it, but today my internet connection went limited. I rebooted in Safe Mode with Network and it worked fine. The connection seems to be better now, but I'm feeling paranoid.

Malwarebytes first reported infection with a Rogue Installer called Y03hPCom.exe.part and 2 Trojan.Agents - mm2048.dat and mm256.dat. Another weird thing is that since this all started AVG Resident Shield keeps popping up during every start up with a hit on a cookie file in the \Roaming\Mozilla\Firefox\Profiles directory called cookies.sqlite.

Thanks in advance!

My Hijack This log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:18:08 PM, on 2/8/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\Intuit\QuickBooks Customer Manager\QBCM.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuSchd2.exe
C:\itunes\iTunesHelper.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Intuit\QuickBooks Customer Manager\QBDBMgr.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://stage.bookcrossing.com/mybookshelf
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Sonia\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files (x86)\openoffice.org1.1.4\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: QBCM.exe - Shortcut.lnk = C:\Program Files (x86)\Intuit\QuickBooks Customer Manager\QBCM.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ComcastHSI - {1CFD173E-9A56-4CF6-B331-3C7B84126882} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {25F18074-BD0D-48B3-858A-DED9B3183988} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {639AEB9E-6BE3-452D-9F05-B75C3B491681} - http://www.comcastsupport.com (file missing) (HKCU)
O13 - Gopher Prefix:
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Business\quickbooks\HelpAsyncPluggableProtocol.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - (no file)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Games\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9aa4ffd0f5ab0) (gupdate1c9aa4ffd0f5ab0) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10503 bytes
« Last Edit: February 08, 2010, 11:16:41 PM by Hoov » Logged
Hoov
Malware Removal Mentors
Global Moderator

Offline Offline

Posts: 9367


Unwilling part owner of Gov't. Motors and Chrysler


WWW
« Reply #1 on: February 08, 2010, 11:24:43 PM »

Hello, welcome to SpywareHammer.

I go by Hoov, and I will be helping you with your problem. I must ask you to do a few things for me.

First, tell me everything that you have done, if anything, to try and fix this problem.

Second, please only use 1 forum to help clear up your problem. Posting on more than 1 and following instructions from more than 1 forum will cause those helping you to pull out thier hair.

Third, follow my instructions - If you can't for some reason, or if you don't understand something, please tell me. If you deviate from my instructions, tell me, it may make a difference on where we go.

Fourth, Have faith. I will do all I can to get your computer working, and if I can't - someone else here will know something else to try.

Before we start trying to fix your computer, you need to make sure your data is backed up. Also let me know of any software you have running that encrypts your harddrive.

Now onto trying to fix your computer.


First thing I notice is you are using AVG8, and Vista SP1. Is there a reason you have not updated either program?

About the connection, the most common reason for a limited connection is a corrupted browser cache. Run ccleaner to take care of that.

Download and scan with CCleaner
1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:
  • Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
  • Clean all the entries in the "Windows Explorer" section.
  • Clean all entries in the "System" section.
  • Clean all entries in the "Advanced" section.
  • Clean any others that you choose.[/COLOR]
In the Applications Tab:
  • Clean all except cookies in the Firefox/Mozilla section if you use it.
  • Clean all in the Opera section if you use it.
  • Clean Sun Java in the Internet Section.
  • Clean any others that you choose.[/COLOR]
4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

Next, cookies.sqlite is actually where FireFox stores the cookies. If you are getting a warning about it, then close Firefox, and then delete the file. The next time you start FireFox, it will be recreated and populated again. It will delete all your cookies.

About any other problems you are having, can you tell me the name of the malware that you already removed?

Once you have run the above, test out your system and let me know of any change for the better or for the worse.
Logged

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Be wary of strong drink. It can make you shoot at tax collectors -- and miss. 
      -From the Notebooks of Lazarus Long
      -Senior of The Howard Families
nevar23
Bronze Member

Offline Offline

Posts: 14


« Reply #2 on: February 09, 2010, 01:45:58 PM »

Thanks for the welcome and the assistance!

I was an idiot and didn't keep a log of what steps I tried, so this is from memory. As soon as I got the red fake virus popup - "Your PC is not protected! Do you want to start your antivirus?" - I was locked out of AVG, so without clicking on anything, I quickly rebooted into safe mode with networking and downloaded Malwarebytes and ran it. It reported the following:

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\****\AppData\Local\Temp\Y03hPCom.exe.part (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\****\Cookies\MM2048.DAT (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\****\Cookies\MM256.DAT (Trojan.Agent) -> Quarantined and deleted successfully.

Then I ran AVG and it reported that several important files were locked and couldn't be scanned. I'm the only user on this computer and had disabled UAC a while back (it's back on now), so I'm not sure why AVG couldn't access them.

After that I ran Malwarebytes again and it came back clean so I tried rebooting in normal mode. Things were ok for a while, then I got the fake virus thing again. Back to safe mode, ran Malwarebytes and it came up clean twice more.

I ran msconfig and didn't see any suspicious services, but  found something called mswraute in my startup queue. I tried googling to see if I could identify the program it was associated with -  cyyhsftav.exe - but could not, so I unchecked it and deleted the folder - ovmyrk - and program file. It's still listed in the startup queue, though.

I tried to update Windows Defender and wasn't able to do so. I keep getting an error code. Got the same result when trying to use Windows Update. Ashamed to say I wasn't aware it hadn't been updating. Looked for a straight answer/something to correct the issue from the Microsoft site, quickly got frustrated and gave up. Bad, I know.

My internet speed then suddenly dropped to limited and I couldn't access the web. Checked the modem and router and found no problems. Rebooted in safe mode and was able to connect just fine, so it raised my suspicions that something was amiss.

Trying to tidy up and hopefully prevent a reinfection, I ran Tweaknow Regclean, then downloaded Zone Alarm Firewall since I was not confident with Windows Firewall.

Things seem to be alright now, virus scans and malware scans are clean, but this whole thing was so weird that I worry the problem is just waiting to pop up again.

That brings us up to today. I just ran CCleaner and followed your instructions, and so far, so good.
Logged
Hoov
Malware Removal Mentors
Global Moderator

Offline Offline

Posts: 9367


Unwilling part owner of Gov't. Motors and Chrysler


WWW
« Reply #3 on: February 09, 2010, 01:53:32 PM »

Can you run updates now?

* Anyone other than the originator of this thread, you would be best advised to not run combofix without guidance from someone trained in its use. It is a very powerful tool that can cause damage to your computer if used wrong.

Run comboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Also make sure you close all your browsers just before the instructions tell you to start the scanner.

Please include the C:\ComboFix.txt in your next reply for further review.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
Logged

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Be wary of strong drink. It can make you shoot at tax collectors -- and miss. 
      -From the Notebooks of Lazarus Long
      -Senior of The Howard Families
nevar23
Bronze Member

Offline Offline

Posts: 14


« Reply #4 on: February 09, 2010, 02:28:42 PM »

No, I can't run updates. I'm still getting Error 80072efd. Unfortunately I also got an error when trying to start Combofix: Error - Win32 only, incompatible OS.
Logged
Hoov
Malware Removal Mentors
Global Moderator

Offline Offline

Posts: 9367


Unwilling part owner of Gov't. Motors and Chrysler


WWW
« Reply #5 on: February 09, 2010, 02:43:45 PM »

Sorry, that is what I get for focusing on the tiny details and not the big picture.

Try turning off ZoneAlarm and running the update. If it fails turn ZA back on and let me know.

Please perform a BitDefender Online Virus and Malware Scan here:
http://www.bitdefender.com/scan8/ie.html
    * Click on I Agree.
    * An ActiveX warning box will appear, click on Install.
    * Under Select What You Want To Check For Viruses.
    * Please Check My Computer and Click Ok
    * Now Click On Click Here To Scan
    * Next, Click on Click here to export the scan report
    * Save it to your Desktop.
    * In your next reply, please include the BitDefender log and a fresh HijackThis log.
Logged

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Be wary of strong drink. It can make you shoot at tax collectors -- and miss. 
      -From the Notebooks of Lazarus Long
      -Senior of The Howard Families
nevar23
Bronze Member

Offline Offline

Posts: 14


« Reply #6 on: February 09, 2010, 05:38:09 PM »

The BitDefender scan got to 90% and stopped. I tried shutting down Zone Alarm and ran it again but got the same result. The log:

BitDefender QuickScan Beta 32-bit v0.9.9.0
------------------------------------------

Scan date:  Tue Feb 09 19:30:01 2010
Machine ID: 72F8C2F3

Warning: Only 32-bit processes scanned.


Scan failed! Couldn't access QuickScan server.
------------------------------------------------


Processes
---------
<unsigned>   hpwuSchd Application                               3976    C:\Program Files (x86)\hp\HP Software Update\hpwuSchd2.exe
<unsigned>  GPCore COM object                                   4976    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
<unsigned>  hp digital imaging - hp all-in-one series           4928    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
<unsigned>  hp digital imaging - hp all-in-one series           4884    C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
<unsigned>  Last.fm                                             2240    C:\Program Files (x86)\Last.fm\LastFM.exe

<verified>  Firefox                                             4832    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
<verified>  hp digital imaging - hp all-in-one series           2136    C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
<verified>  iTunes                                              3520    C:\itunes\iTunesHelper.exe
<verified>  Microsoft® Windows® Operating System                1628    C:\Windows\SysWOW64\NOTEPAD.EXE
<verified>  QuickBooks Automatic Update                         3664    C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe


Network activity
----------------
Process firefox.exe (4832) connected on port 1935 - 209.107.220.103



Autoruns and critical files
---------------------------
<unsigned>   hpwuSchd Application                               C:\Program Files (x86)\hp\HP Software Update\hpwuSchd2.exe
<unsigned>  Catalyst® Control Center                            C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
<unsigned>  QuickTime                                           C:\Program Files (x86)\QuickTime\QTTask.exe

<verified>  AVG Internet Security                               C:\Program Files (x86)\AVG\AVG8\avgtray.exe
<verified>  Google Update                                       C:\Users\Sonia\AppData\Local\Google\Update\GoogleUpdate.exe
<verified>  hp digital imaging - hp all-in-one series           C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
<verified>  IntuitSyncManager                                   C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe
<verified>  iTunes                                              C:\itunes\iTunesHelper.exe
<verified>  Launcher Application                                E:\autorun.exe
<verified>  Microsoft® Windows® Operating System                C:\Windows\ehome\ehTray.exe
<verified>  Microsoft® Windows® Operating System                c:\windows\system32\browseui.dll
<verified>  Microsoft® Windows® Operating System                c:\windows\system32\userinit.exe
<verified>  QuickBooks Automatic Update                         C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
<verified>  QuickBooks Customer/Client Manager                  C:\Program Files (x86)\Intuit\QuickBooks Customer Manager\QBCM.exe
<verified>  Windows® Internet Explorer                          c:\windows\syswow64\webcheck.dll
<verified>  ZoneAlarm Client                                    C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe


Browser plugins
---------------
<unsigned>  Bonjour                                             C:\Program Files (x86)\Bonjour\mdnsNSP.dll
<unsigned>  Google Earth Plugin                                 C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
<unsigned>  IE Tab Plug-in                                      C:\Users\Sonia\AppData\Roaming\Mozilla\Firefox\Profiles/23hmkwyt.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
<unsigned>  npitunes.dll                                        C:\itunes\Mozilla Plugins\npitunes.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll

<verified>  AcroIEHelperShim Library                            c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
<verified>  Adobe Acrobat                                       C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll
<verified>  Adobe Acrobat                                       C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
<verified>  AVG Internet Security                               c:\program files (x86)\avg\avg8\avgssie.dll
<verified>  AVG Security Toolbar                                c:\program files (x86)\avg\avg8\toolbar\ietoolbar.dll
<verified>  BitDefender QuickScan                               C:\Users\Sonia\AppData\Roaming\Mozilla\Firefox\Profiles/23hmkwyt.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
<verified>  BitDefender QuickScan                               C:\Users\Sonia\AppData\Roaming\Mozilla\Firefox\Profiles/23hmkwyt.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
<verified>  Google Update                                       C:\Program Files (x86)\Google\Update\1.2.183.13\npGoogleOneClick8.dll
<verified>  Google Updater                                      C:\Program Files (x86)\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
<verified>  GoogleToolbarNotifier                               c:\program files (x86)\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
<verified>  HP Smart Web Printing                               c:\program files (x86)\hp\digital imaging\smart web printing\hpswp_bho.dll
<verified>  InstallShield Update Service                        C:\Windows\Downloaded Program Files\dwusplay.dll
<verified>  InstallShield Update Service                        C:\Windows\Downloaded Program Files\dwusplay.exe
<verified>  Java Deployment Toolkit 6.0.160.1                   C:\Program Files (x86)\Mozilla Firefox\plugins\npdeploytk.dll
<verified>  Microsoft® Windows Media Player Firefox Plugin      C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\System32\mswsock.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\system32\napinsp.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\system32\NLAapi.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\system32\pnrpnsp.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\System32\winrnr.dll
<verified>  Mozilla Default Plug-in                             C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
<verified>  NPSWF32.dll                                         C:\Windows\system32\Macromed\Flash\NPSWF32.dll
<verified>  Silverlight Plug-In                                 c:\Program Files (x86)\Microsoft Silverlight\3.0.40818.0\npctrl.dll
<verified>  Software Manager                                    C:\Windows\Downloaded Program Files\isusweb.dll
<verified>  Windows Presentation Foundation                     c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
<verified>  ZoneAlarm ForceField                                c:\program files\checkpoint\zaforcefield\wow64\trustchecker\bin\trustcheckerieplugin.dll


Scan
----

Scan finished - communication took 2 sec
Total traffic - 0.00 MB sent, 0.00 KB recvd
Scanned 556 files and modules - 27 seconds


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:32:56 PM, on 2/9/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuSchd2.exe
C:\itunes\iTunesHelper.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Windows\SysWOW64\NOTEPAD.EXE
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://stage.bookcrossing.com/mybookshelf
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Sonia\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files (x86)\openoffice.org1.1.4\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: QBCM.exe - Shortcut.lnk = C:\Program Files (x86)\Intuit\QuickBooks Customer Manager\QBCM.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ComcastHSI - {1CFD173E-9A56-4CF6-B331-3C7B84126882} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {25F18074-BD0D-48B3-858A-DED9B3183988} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {639AEB9E-6BE3-452D-9F05-B75C3B491681} - http://www.comcastsupport.com (file missing) (HKCU)
O13 - Gopher Prefix:
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Business\quickbooks\HelpAsyncPluggableProtocol.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - (no file)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Games\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9aa4ffd0f5ab0) (gupdate1c9aa4ffd0f5ab0) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10310 bytes



Logged
Hoov
Malware Removal Mentors
Global Moderator

Offline Offline

Posts: 9367


Unwilling part owner of Gov't. Motors and Chrysler


WWW
« Reply #7 on: February 09, 2010, 06:13:55 PM »

Please try booting to safe mode with networking and then try the same scan.
Logged

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Be wary of strong drink. It can make you shoot at tax collectors -- and miss. 
      -From the Notebooks of Lazarus Long
      -Senior of The Howard Families
nevar23
Bronze Member

Offline Offline

Posts: 14


« Reply #8 on: February 10, 2010, 11:34:00 AM »

Was locked out of the internet again, and this time it wouldn't work in Safe Mode with networking either. I disconnected the router and ran the connection directly to my computer and am running in safe mode now.

Here's the BitDefender log. I shut down Zone Alarm but still get the same error:

BitDefender QuickScan Beta 32-bit v0.9.9.0
------------------------------------------

Scan date:  Wed Feb 10 13:31:51 2010
Machine ID: 72F8C2F3

Warning: Only 32-bit processes scanned.


Scan failed! Couldn't access QuickScan server.
------------------------------------------------


Processes
---------
<verified>  Firefox                                              688    C:\Program Files (x86)\Mozilla Firefox\firefox.exe


Network activity
----------------


Autoruns and critical files
---------------------------
<unsigned>   hpwuSchd Application                               C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
<unsigned>  Catalyst® Control Center                            C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
<unsigned>  QuickTime                                           C:\Program Files (x86)\QuickTime\QTTask.exe

<verified>  AVG Internet Security                               C:\Program Files (x86)\AVG\AVG8\avgtray.exe
<verified>  Google Update                                       C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
<verified>  Google Update                                       C:\Users\Sonia\AppData\Local\Google\Update\GoogleUpdate.exe
<verified>  Google Updater                                      C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
<verified>  hp digital imaging - hp all-in-one series           C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
<verified>  IntuitSyncManager                                   C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe
<verified>  iTunes                                              C:\itunes\iTunesHelper.exe
<verified>  Launcher Application                                E:\autorun.exe
<verified>  Microsoft® Windows® Operating System                C:\Windows\ehome\ehTray.exe
<verified>  Microsoft® Windows® Operating System                c:\windows\system32\browseui.dll
<verified>  Microsoft® Windows® Operating System                c:\windows\system32\userinit.exe
<verified>  QuickBooks Automatic Update                         C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
<verified>  QuickBooks Customer/Client Manager                  C:\Program Files (x86)\Intuit\QuickBooks Customer Manager\QBCM.exe
<verified>  Windows® Internet Explorer                          c:\windows\syswow64\webcheck.dll
<verified>  ZoneAlarm Client                                    C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe


Browser plugins
---------------
<unsigned>  Bonjour                                             C:\Program Files (x86)\Bonjour\mdnsNSP.dll
<unsigned>  Google Earth Plugin                                 C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
<unsigned>  IE Tab Plug-in                                      C:\Users\Sonia\AppData\Roaming\Mozilla\Firefox\Profiles/23hmkwyt.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
<unsigned>  npitunes.dll                                        C:\itunes\Mozilla Plugins\npitunes.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
<unsigned>  QuickTime Plug-in 7.6                               C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll

<verified>  AcroIEHelperShim Library                            c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
<verified>  Adobe Acrobat                                       C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll
<verified>  Adobe Acrobat                                       C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
<verified>  AVG Internet Security                               c:\program files (x86)\avg\avg8\avgssie.dll
<verified>  AVG Security Toolbar                                c:\program files (x86)\avg\avg8\toolbar\ietoolbar.dll
<verified>  BitDefender QuickScan                               C:\Users\Sonia\AppData\Roaming\Mozilla\Firefox\Profiles/23hmkwyt.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
<verified>  BitDefender QuickScan                               C:\Users\Sonia\AppData\Roaming\Mozilla\Firefox\Profiles/23hmkwyt.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
<verified>  Google Update                                       C:\Program Files (x86)\Google\Update\1.2.183.13\npGoogleOneClick8.dll
<verified>  Google Updater                                      C:\Program Files (x86)\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
<verified>  GoogleToolbarNotifier                               c:\program files (x86)\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
<verified>  HP Smart Web Printing                               c:\program files (x86)\hp\digital imaging\smart web printing\hpswp_bho.dll
<verified>  InstallShield Update Service                        C:\Windows\Downloaded Program Files\dwusplay.dll
<verified>  InstallShield Update Service                        C:\Windows\Downloaded Program Files\dwusplay.exe
<verified>  Java Deployment Toolkit 6.0.160.1                   C:\Program Files (x86)\Mozilla Firefox\plugins\npdeploytk.dll
<verified>  Microsoft® Windows Media Player Firefox Plugin      C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\System32\mswsock.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\system32\napinsp.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\system32\NLAapi.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\system32\pnrpnsp.dll
<verified>  Microsoft® Windows® Operating System                C:\Windows\System32\winrnr.dll
<verified>  Mozilla Default Plug-in                             C:\Program Files (x86)\Mozilla Firefox\plugins\npnul32.dll
<verified>  NPSWF32.dll                                         C:\Windows\system32\Macromed\Flash\NPSWF32.dll
<verified>  Silverlight Plug-In                                 c:\Program Files (x86)\Microsoft Silverlight\3.0.40818.0\npctrl.dll
<verified>  Software Manager                                    C:\Windows\Downloaded Program Files\isusweb.dll
<verified>  Windows Presentation Foundation                     c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
<verified>  ZoneAlarm ForceField                                c:\program files\checkpoint\zaforcefield\wow64\trustchecker\bin\trustcheckerieplugin.dll


Scan
----

Scan finished - communication took 1 sec
Total traffic - 0.00 MB sent, 0.00 KB recvd
Scanned 344 files and modules - 15 seconds



And I ran HijackThis before rebooting to safe mode:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:19:36 PM, on 2/10/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files (x86)\AVG\AVG8\avgtray.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuSchd2.exe
C:\itunes\iTunesHelper.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://stage.bookcrossing.com/mybookshelf
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe  startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Sonia\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files (x86)\openoffice.org1.1.4\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: QBCM.exe - Shortcut.lnk = C:\Program Files (x86)\Intuit\QuickBooks Customer Manager\QBCM.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ComcastHSI - {1CFD173E-9A56-4CF6-B331-3C7B84126882} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {25F18074-BD0D-48B3-858A-DED9B3183988} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {639AEB9E-6BE3-452D-9F05-B75C3B491681} - http://www.comcastsupport.com (file missing) (HKCU)
O13 - Gopher Prefix:
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Business\quickbooks\HelpAsyncPluggableProtocol.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - (no file)
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - C:\Games\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9aa4ffd0f5ab0) (gupdate1c9aa4ffd0f5ab0) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10196 bytes
Logged
Hoov
Malware Removal Mentors
Global Moderator

Offline Offline

Posts: 9367


Unwilling part owner of Gov't. Motors and Chrysler


WWW
« Reply #9 on: February 10, 2010, 03:31:17 PM »

I need you to go to the administration tools in Vista. They are in the Control Panel. Open the Admin tools, then open the event viewer. Over on the left hand side expand the window category and then click on  System. Then up at the top click on Action and then click on Save Events As, type in system as the file name,  make sure file type EVTX is selected, and then navigate so it will save the file to your desktop, then click save. Over on the left hand side and click on Application. Then up at the top click on Action and then click on Save Events As, type in application as the file name,  make sure file type EVTX is selected, and then navigate so it will save the file to your desktop, then click save. Zip them both up into a single zip file, post them back here in your next reply as attachments.

Logged

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Be wary of strong drink. It can make you shoot at tax collectors -- and miss. 
      -From the Notebooks of Lazarus Long
      -Senior of The Howard Families
nevar23
Bronze Member

Offline Offline

Posts: 14


« Reply #10 on: February 10, 2010, 05:48:36 PM »

Ok, hope I attached them correctly. I had to filter the dates since the files were too large to upload. I went back to Feb. 1st. Trouble started on the 5th.
Logged
Hoov
Malware Removal Mentors
Global Moderator

Offline Offline

Posts: 9367


Unwilling part owner of Gov't. Motors and Chrysler


WWW
« Reply #11 on: February 10, 2010, 06:40:46 PM »

Do you have your windows vista install DVD?
Logged

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Be wary of strong drink. It can make you shoot at tax collectors -- and miss. 
      -From the Notebooks of Lazarus Long
      -Senior of The Howard Families
nevar23
Bronze Member

Offline Offline

Posts: 14


« Reply #12 on: February 10, 2010, 06:44:17 PM »

Yes, I do.
Logged
Hoov
Malware Removal Mentors
Global Moderator

Offline Offline

Posts: 9367


Unwilling part owner of Gov't. Motors and Chrysler


WWW
« Reply #13 on: February 10, 2010, 06:45:45 PM »

Please stick the DVD in the drive and then go to the run command and type in sfc /scannow  and then follow the instructions.
Logged

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Be wary of strong drink. It can make you shoot at tax collectors -- and miss. 
      -From the Notebooks of Lazarus Long
      -Senior of The Howard Families
nevar23
Bronze Member

Offline Offline

Posts: 14


« Reply #14 on: February 10, 2010, 07:03:55 PM »

Ok, it ran the verification scan, then the window closed with no report. Is that bad?
Logged
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  


Login with username, password and session length

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.295 seconds with 27 queries.