Help - Search - Members - Calendar
Full Version: Im pretty sure im infected with something.
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
Stevenson1
I think im infected with something..
I have a hard time accessing my web browsers.. mozilla, verizon, IE..
And my computer is da** slow

well here is my HiJackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 4:27:42 PM, on 4/1/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HiJackThis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearflix.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: XBTP01621 - {D0285C32-F09A-49bd-BA67-FDAB0A58675E} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [{A0BC7B14-07CF-1033-0902-040804030001}] "C:\Program Files\Common Files\{A0BC7B14-07CF-1033-0902-040804030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [{A0BC7B14-07D0-1033-0902-040804030001}] "C:\Program Files\Common Files\{A0BC7B14-07D0-1033-0902-040804030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [BearFlix] "C:\Program Files\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.CPL,CMICtrlWnd
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
teacup61
Hello Stevenson1,

I strongly suggest you uninstall everything BearShare. There are better P2P programs, such as the newer version of Limewire, or KazaaLite. BearShare is notorious for infecting its users.

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

Thanks,
tea
Stevenson1
Alright I will do that when I get home from school. which will be in about an hour or so.

One quick question.. how can I uninstall and delete both Bearflix and Bearshare without going into "Add/Remove programs" because everytime I try it, it says that the install.log cannot be found.

Also, I am having problems deleting Bit Defender as well.
teacup61
Hello,

Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"

Scroll down until you see what you want to uninstall, choose it, then click "delete this entry" Reboot when you're done.
Stevenson1
Here is the ComboFix Log::::::::::::

"scott stevenson sr" - 07-04-02 12:39:59 Service Pack 1
ComboFix 07-03-27.4.2 - Running from: "C:\Program Files\Mozilla Firefox"

/wow section - STAGE #3

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\Common Files\{30BC7~1\toolbardll.lzma
C:\Program Files\Common Files\{A0BC7~1\directordll.lzma
C:\Program Files\Common Files\{A0BC7~1\directorexe.lzma
C:\WINDOWS\system32\svchosts.lzma
C:\WINDOWS\system32\unsvchosts.lzma
C:\WINDOWS\system32\wnsintsv.exe
C:\Program Files\outerinfo
C:\Program Files\winupdates
C:\Program Files\Common Files\{30BC7~1
C:\Program Files\Common Files\{A0BC7~1
C:\Program Files\Common Files\{A0BC7~2
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\SCOTTS~2
C:\qoobox\purity\DOCUME~1\SCOTTS~2\Application Data
C:\qoobox\purity\DOCUME~1\SCOTTS~2\My Documents
C:\qoobox\purity\DOCUME~1\SCOTTS~2\Application Data\from.txt
C:\qoobox\purity\DOCUME~1\SCOTTS~2\Application Data\RACLE~1
C:\qoobox\purity\DOCUME~1\SCOTTS~2\My Documents\from.txt
C:\qoobox\purity\DOCUME~1\SCOTTS~2\My Documents\ICROSO~1.NET
C:\qoobox\purity\Program Files\DOBE~2
C:\qoobox\purity\Program Files\PPPATC~1
C:\qoobox\purity\Program Files\SKS~1
C:\qoobox\purity\Program Files\YMANTE~1
C:\qoobox\purity\Program Files\Common Files\ASEMBL~1
C:\qoobox\purity\Program Files\Common Files\RACLE~1
C:\qoobox\purity\WINDOWS\ASEMBL~1
C:\qoobox\purity\WINDOWS\SMANTE~1
C:\qoobox\purity\WINDOWS\WNSXS~1
C:\qoobox\purity\WINDOWS\system32\FNTS~1
C:\qoobox\purity\WINDOWS\system32\RACLE~1
C:\qoobox\purity\WINDOWS\system32\SCURIT~1
C:\qoobox\purity\WINDOWS\WNSXS~1\WNSXS~1
C:\qoobox\purity\WINDOWS\WNSXS~1\WNSXS~1\ctxad-527.0000
C:\qoobox\purity\WINDOWS\WNSXS~1\WNSXS~1\ctxad-527.0001
C:\qoobox\purity\WINDOWS\WNSXS~1\WNSXS~1\ctxad-527.0002
C:\qoobox\purity\WINDOWS\WNSXS~1\WNSXS~1\ctxad-527.0003
C:\qoobox\purity\WINDOWS\WNSXS~1\WNSXS~1\ctxad-527.0004
C:\qoobox\purity\WINDOWS\WNSXS~1\WNSXS~1\ctxad-527.0005
C:\qoobox\purity\WINDOWS\WNSXS~1\WNSXS~1\ctxad-527.0006


((((((((((((((((((((((((((((((( Files Created from 2007-03-02 to 2007-04-02 ))))))))))))))))))))))))))))))))))


2007-04-01 16:18 <DIR> d-------- C:\WINDOWS\LastGood
2007-03-31 14:58 <DIR> d-------- C:\DOCUME~1\SCOTTS~2\APPLIC~1\Motive
2007-03-28 23:35 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2007-03-28 23:29 <DIR> d-------- C:\DOCUME~1\SCOTTS~2\APPLIC~1\Sony
2007-03-28 23:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Sony
2007-03-28 23:25 <DIR> d-------- C:\Program Files\Sony Setup
2007-03-26 20:45 3,440,640 --a------ C:\DOCUME~1\SCOTTS~2\ntuser.dat
2007-03-18 14:43 <DIR> d-------- C:\WINDOWS\system32\bits
2007-03-18 14:42 <DIR> d-------- C:\WINDOWS\system32\PreInstall
2007-03-15 12:25 2,973,696 --------- C:\WINDOWS\UNMRW.exe
2007-03-15 12:24 8,704 --------- C:\WINDOWS\system32\drivers\InCDrec.sys
2007-03-15 12:24 29,696 --------- C:\WINDOWS\system32\drivers\InCDpass.sys
2007-03-15 12:24 28,672 --------- C:\WINDOWS\system32\drivers\InCDrm.sys
2007-03-15 12:24 2,973,696 --------- C:\WINDOWS\NuNinst.exe
2007-03-15 12:24 101,504 --------- C:\WINDOWS\system32\drivers\InCDfs.sys
2007-03-15 12:24 <DIR> d-------- C:\WINDOWS\InCD
2007-03-15 12:23 2,916,352 --------- C:\WINDOWS\UNNMP.exe
2007-03-15 12:22 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-03-15 12:20 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-03-15 12:20 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-03-15 12:20 38,912 --------- C:\WINDOWS\system32\picn20.dll
2007-03-15 12:20 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2007-03-15 12:20 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-03-15 12:20 2,977,792 --------- C:\WINDOWS\UNNeroVision.exe
2007-03-15 12:20 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-03-15 12:20 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-03-15 11:50 89,360 --a------ C:\WINDOWS\system32\VB5DB.DLL
2007-03-15 11:50 81,920 --a------ C:\WINDOWS\system32\viscomwave.dll
2007-03-15 11:50 643,072 --a------ C:\WINDOWS\system32\DVDProX2.dll
2007-03-15 11:50 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2007-03-15 11:50 339,968 --a------ C:\WINDOWS\system32\MP3EncX.dll
2007-03-15 11:50 28,672 --a------ C:\WINDOWS\system32\SmartMenuXP.dll
2007-03-15 11:50 139,264 --a------ C:\WINDOWS\system32\voltoCDX.dll
2007-03-15 11:50 1,110,016 --a------ C:\WINDOWS\system32\NMSDVDXU.dll
2007-03-15 11:50 <DIR> d-------- C:\Program Files\Cheetah Burner


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-01 20:12 -------- d-------- C:\Program Files\full tilt poker
2007-04-01 14:06 81984 --a------ C:\WINDOWS\system32\bdod.bin
2007-03-31 14:40 -------- d-------- C:\Program Files\sony
2007-03-29 15:15 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-03-15 12:11 -------- d--h----- C:\Program Files\installshield installation information
2007-03-12 17:59 -------- d-------- C:\Program Files\pokerstars
2007-03-02 23:18 -------- d-------- C:\Program Files\google
2007-03-02 20:59 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-26 16:21 -------- d-------- C:\Program Files\java
2007-02-26 15:30 -------- d-------- C:\Program Files\Common Files\nero
2007-02-25 19:00 -------- d-------- C:\Program Files\project64 1.6
2007-02-22 19:25 -------- d-------- C:\Program Files\nba video central v3
2007-02-15 00:51 -------- d-------- C:\Program Files\limewire
2007-02-13 19:55 18816 --a------ C:\WINDOWS\system32\drivers\dvd43llh.sys
2007-02-13 19:55 -------- d-------- C:\Program Files\dvd43
2007-02-13 15:30 34 --a------ C:\DOCUME~1\SCOTTS~2\APPLIC~1\pcouffin.log
2007-02-13 15:30 -------- d-------- C:\DOCUME~1\SCOTTS~2\APPLIC~1\vso
2007-02-13 15:29 87608 --a------ C:\DOCUME~1\SCOTTS~2\APPLIC~1\ezpinst.exe
2007-02-13 15:29 7824 --a------ C:\DOCUME~1\SCOTTS~2\APPLIC~1\pcouffin.cat
2007-02-13 15:29 47360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
2007-02-13 15:29 47360 --a------ C:\DOCUME~1\SCOTTS~2\APPLIC~1\pcouffin.sys
2007-02-13 15:29 1144 --a------ C:\DOCUME~1\SCOTTS~2\APPLIC~1\pcouffin.inf
2007-02-13 15:29 -------- d-------- C:\Program Files\lg software innovations
2007-02-13 15:11 -------- d-------- C:\Program Files\bearshare applications
2007-02-11 21:47 -------- d-------- C:\Program Files\symantec
2007-02-11 21:36 -------- d-------- C:\Program Files\àdobe
2007-02-11 21:36 -------- d-------- C:\Program Files\Common Files\symantec shared
2007-02-11 21:35 -------- d-------- C:\Program Files\norton antivirus
2007-02-11 14:59 -------- d--h----- C:\Program Files\windowsupdate
2007-02-10 13:23 -------- d-------- C:\Program Files\yahoo!
2007-02-09 21:45 -------- d-------- C:\Program Files\Common Files\pestpatrol
2007-02-09 21:29 -------- d-------- C:\Program Files\bearflix
2007-02-09 21:27 -------- d-------- C:\Program Files\spyware terminator
2007-02-09 21:27 -------- d-------- C:\Program Files\outerinfo(2)
2007-02-09 21:27 -------- d-------- C:\Program Files\mcafee
2007-02-09 21:27 -------- d-------- C:\DOCUME~1\SCOTTS~2\APPLIC~1\webroot(2)
2007-02-09 21:27 -------- d-------- C:\DOCUME~1\SCOTTS~2\APPLIC~1\spyware terminator
2007-02-09 21:13 -------- d-------- C:\Program Files\enigma software group
2007-02-09 19:35 -------- d-------- C:\DOCUME~1\SCOTTS~2\APPLIC~1\bitdefender
2007-02-09 18:20 -------- d-------- C:\Program Files\kaspersky lab
2007-02-03 15:17 187 --a------ C:\DOCUME~1\SCOTTS~2\APPLIC~1\g-force prefs (windowsmediaplayer).txt
2007-01-28 18:50 95744 --a-s---- C:\WINDOWS\system32\monterreya_redux.exe
2007-01-28 18:50 95744 --a------ C:\WINDOWS\system32\drivera.exe
2007-01-20 15:11 286720 --a------ C:\WINDOWS\iun506.exe
2007-01-15 23:16 1168 --a------ C:\WINDOWS\mozver.dat
2007-01-11 19:56 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-01-08 15:29 1087216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-01-07 22:30 335 --a------ C:\WINDOWS\nsreg.dat
2007-01-07 19:17 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-01-07 10:49 62 --ahs---- C:\DOCUME~1\SCOTTS~2\APPLIC~1\desktop.ini


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"VerizonServicepoint.exe"="\"C:\\Program Files\\Verizon\\Servicepoint\\VerizonServicepoint.exe\""
"Motive SmartBridge"="C:\\PROGRA~1\\Verizon\\SMARTB~1\\MotiveSB.exe"
"YBrowser"="C:\\PROGRA~1\\Yahoo!\\browser\\ybrwicon.exe"
"{A0BC7B14-07CF-1033-0902-040804030001}"="\"C:\\Program Files\\Common Files\\{A0BC7B14-07CF-1033-0902-040804030001}\\Update.exe\" te-110-12-0000213"
"{A0BC7B14-07D0-1033-0902-040804030001}"="\"C:\\Program Files\\Common Files\\{A0BC7B14-07D0-1033-0902-040804030001}\\Update.exe\" te-110-12-0000213"
"ISUSPM Startup"="\"C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe\" -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"BearFlix"="\"C:\\Program Files\\BearFlix\\BearFlix.exe\" /pause"
"CmPCIaudio"="RunDll32 CMICNFG3.CPL,CMICtrlWnd"
"BDMCon"="\"C:\\Program Files\\Softwin\\BitDefender10\\bdmcon.exe\" /reg"
"BDAgent"="\"C:\\Program Files\\Softwin\\BitDefender10\\bdagent.exe\""
"dvd43"="C:\\Program Files\\dvd43\\dvd43_tray.exe"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="sockspy.dll"


[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c9b8f8b-9e5b-11db-a974-806d6172696f}]
Shell\AutoRun\command RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480


********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-04-02 12:49:04
C:\ComboFix2.txt ... 07-02-13 13:03



AND HERE IS THE NEW HIJACKTHIS LOG:::::::::


Logfile of HijackThis v1.99.1
Scan saved at 12:56:55 PM, on 4/2/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HiJackThis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearflix.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: XBTP01621 - {D0285C32-F09A-49bd-BA67-FDAB0A58675E} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [{A0BC7B14-07CF-1033-0902-040804030001}] "C:\Program Files\Common Files\{A0BC7B14-07CF-1033-0902-040804030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [{A0BC7B14-07D0-1033-0902-040804030001}] "C:\Program Files\Common Files\{A0BC7B14-07D0-1033-0902-040804030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [BearFlix] "C:\Program Files\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.CPL,CMICtrlWnd
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
teacup61
Hello,

Did you try to uninstall BearShare and Bit Defender in the way I mentioned?
Stevenson1
Yea I tried to uninstall both programs through HiJackThis..
it says that they are gone..
but both programs still come up on startup and everything.
teacup61
Hello,

Well, I don't know why they won't uninstall. This may leave some remnants, but we'll give it a go and see. ;)

Please run HijackThis! and click "Scan." Place checks next to the following entries, if present:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.bearshare.com/sidebar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearflix.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb
R3 - URLSearchHook: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O2 - BHO: XBTP01621 - {D0285C32-F09A-49bd-BA67-FDAB0A58675E} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O4 - HKLM\..\Run: [{A0BC7B14-07CF-1033-0902-040804030001}] "C:\Program Files\Common Files\{A0BC7B14-07CF-1033-0902-040804030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [{A0BC7B14-07D0-1033-0902-040804030001}] "C:\Program Files\Common Files\{A0BC7B14-07D0-1033-0902-040804030001}\Update.exe" te-110-12-0000213
O4 - HKLM\..\Run: [BearFlix] "C:\Program Files\BearFlix\BearFlix.exe" /pause
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)


Close all browsers and other windows except for HijackThis!, and click "Fix checked".

Delete the following folders:

C:\Program Files\Common Files\Softwin
C:\Program Files\BearFlix
C:\Program Files\Common Files\{A0BC7B14-07D0-1033-0902-040804030001}
C:\Program Files\BearShare applications

Reboot your computer and post a new log. Let me know how it went, and how it's running now.

Thanks,
tea
Stevenson1
when i try to delete softwin folders.. it says::::

ERROR DELETING FILE.
cannot delete xcommsvr.exe: access is denied.

the bearshare ones went smooth..
and I cant find the other one. or the search is taking way too long
Stevenson1
Logfile of HijackThis v1.99.1
Scan saved at 11:35:35 PM, on 4/3/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe
C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HiJackThis\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.CPL,CMICtrlWnd
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
teacup61
Well, you should not have to delete thast file. I asked you to delete the folder it resides in "Softwin". In any case, we'll do it another way. :)

Delete an NT Service
  • Open HiJackThis
  • Click on the "Config..." button on the bottom right
  • Click on the tab "Misc Tools"
  • click on "delete an NT service"
  • Copy and paste this in: XCOMM
  • Click "ok", then reboot

Let me know if that went easier.
Stevenson1
Well how do you disabled it from running? Becuase I get an error when I try to delete it that says XCOMM is running or is enabled.
teacup61
More than one way to get rid of stuff we don't want. ;)

Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the quote to Notepad. Save it as "All Files" and name it FixServices.bat Please save it on your desktop.

QUOTE
@echo off
sc stop XCOMM
sc delete XCOMM
exit


Double click FixServices.bat. A window will open and close. This is normal.

Let me know.
Stevenson1
Ok, I did that.. and a window did pop up and close.. but i didnt catch what it said.
teacup61
Can you uninstall Softwin now? That was the whole purpose of getting rid of that service.
Stevenson1
Now it says..

Cannot delete bdagent.exe
access is denied.

But I was able to delete the Common Files folder of Softwin.. just not the one in Program Files.
teacup61
Well I'll be....I've never seen this be this stubborn. :furious: I'm not that familiar with BitDefender either, so I don't know if this is common. Can I see a new HijackThis log, please? That way I can see what's left. If it's going to be this stubborn we'll just go for it all at once, not one file at a time.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.