Computing.Net > Forums > Security and Virus > Stubby.D + DyFuCa - please help!

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Stubby.D + DyFuCa - please help!

Reply to Message Icon

Name: Tug Wilson
Date: January 6, 2005 at 08:09:27 Pacific
OS: WinMe 4.90.3000
CPU/Ram: PII-R400/128OEMRam
Comment:

Sending this on Grandads computer. Can you please help me to get going for exams? I've gone as far as I can.
Any help would be good.
On startup ERROR-Severity5. TrapNo.205.
Product 0ID: 1.3.6.1.4.1.2231.12
Parameters (0)C:\win\SATMAT.exe(1) - Stubby.d
(Whatever this all means!)
Symptoms - Slow/almost dead; Scandisk 50%only;Tesco Virus Check = Action. NONE!!
HighjackThis =
Logfile of HijackThis v1.99.0
Scan saved at 03:32:39, on 05/01/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.exe
C:\WINDOWS\SYSTEM\MPREXE.exe
C:\WINDOWS\SYSTEM\STIMON.exe
C:\WINDOWS\SYSTEM\MSTASK.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\COMMON\FSMA32.exe
C:\WINDOWS\SYSTEM\RESTORE\STMGR.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\BACKWEB\9655419\PROGRAM\FSPEX.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\FWES\PROGRAM\FSDFWD.exe
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\TESCO INTERNET SECURITY\COMMON\FSMB32.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\COMMON\FCH32.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSHTTPS\FSHTTPS.exe
C:\WINDOWS\EXPLORER.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\COMMON\FAMEH32.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\ANTI-VIRUS\FSGK32.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\FWES\PROGRAM\FSDFWD.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPC.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\ANTI-VIRUS\FSSM32.exe
C:\WINDOWS\TASKMON.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\ANTI-VIRUS\FSAV32.exe
C:\MOUSE\POINT32.exe
C:\WINDOWS\SYSTEM\MSWHEEL.exe
C:\PROGRAM FILES\KODAK DIGITAL SCIENCE\PICTURE EASY SOFTWARE\PROGRAM\PEZDOWNLOAD.exe
C:\WINDOWS\SYSTEM\HPZTSB01.exe
C:\WINDOWS\SYSTEM\SPOOL32.exe
C:\PROGRAM FILES\AHEAD\INCD\INCD.exe
C:\WINDOWS\TEMP\YVJNO.exe
C:\WINDOWS\TEMP\DBCQ.exe
C:\WINDOWS\TEMP\IGF3.exe
C:\WINDOWS\SYSTEM\QTTASK.exe
C:\PROGRAM FILES\THOMSON\SPEEDTOUCH USB\DRAGDIAG.exe
C:\PROGRAM FILES\NAVISEARCH\BIN\NLS.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\BACKWEB\9655419\PROGRAM\FSBWSYS.exe
C:\WINDOWS\SYSTEM\SYSTRAY.exe
C:\WINDOWS\SYSTEM\DDHELP.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\COMMON\FSM32.exe
C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSGUI\ISPNEWS.exe
C:\WINDOWS\SYSTEM\WMIEXE.exe
C:\PROGRAM FILES\MSOFFICE\OFFICE\OSA.exe
C:\WINDOWS\SYSTEM\RNAAPP.exe
C:\WINDOWS\SYSTEM\TAPISRV.exe
F:\HIJACKTHIS.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.search-exe.com/nph-search.cgi?tcode=exebar1&look=sbar1_srchbtn
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tesco.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tesco.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.search-exe.com/nph-search.cgi?tcode=exebar1&look=sbar1_srchbtn
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.search-exe.com/nph-search.cgi?tcode=exesrch1&look=stmpl1&fw=
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_19_0.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Setup.Setup1 - {2E65A557-173C-4DE9-860B-28FC5CACA542} - C:\WINDOWS\ALL USERS\APPLICATION DATA\SETUP\SETUP.DLL (file missing)
O2 - BHO: (no name) - {C38496B0-89E0-C50F-D4EA-DDC63E7507A9} - C:\WINDOWS\Uzacuwsp.dll
O2 - BHO: MxTargetObj Class - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\MXTARGET.DLL
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\SYSTEM\NVMS.DLL
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\PROGRAM FILES\SIDEFIND\SFBHO.DLL
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\NEM220.DLL (file missing)
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\WSEM302.DLL (file missing)
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\BXXS5.DLL
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\PROGRAM FILES\SEP\SEP.DLL (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_19_0.DLL
O3 - Toolbar: Search - {77BDA6BE-B514-486F-C1B1-D9C21971F51D} - C:\WINDOWS\Uzacuwsp.dll
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\PROGRA~1\ISTBAR\ISTBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [Disknag] C:\DELL\DISKNAG.exe
O4 - HKLM\..\Run: [POINTER] C:\MOUSE\point32.exe
O4 - HKLM\..\Run: [TIPS] C:\MOUSE\tips\mouse\tips.exe
O4 - HKLM\..\Run: [Picture Easy Download] C:\Program Files\Kodak Digital Science\Picture Easy Software\Program\PezDownload.exe
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TSADBOT.exe"
O4 - HKLM\..\Run: [PCHealth] c:\windows\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb01.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [bxxs5] RunDLL32.exe C:\WINDOWS\BXXS5.DLL,DllRun
O4 - HKLM\..\Run: [YVJNO] C:\WINDOWS\TEMP\YVJNO.exe
O4 - HKLM\..\Run: [DBCQ] C:\WINDOWS\TEMP\DBCQ.exe
O4 - HKLM\..\Run: [IGF3] C:\WINDOWS\TEMP\IGF3.exe
O4 - HKLM\..\Run: [yohpqum] C:\WINDOWS\SYSTEM\grjimwkx.exe
O4 - HKLM\..\Run: [5FS8TZB3X6ME3L] C:\WINDOWS\SYSTEM\Vqxu.exe
O4 - HKLM\..\Run: [WinLogin] win32x.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\SATMAT.exe
O4 - HKLM\..\Run: [switp] C:\WINDOWS\SWITP_BUND_AR3.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.exe" -atboottime
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [¢‰¸ï0 4Ã4}¤Áœ5]C:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\NRWDNPX.exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [2XKBWP@2Y8X#P5] C:\WINDOWS\SYSTEM\Npcs0WLP.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\PROGRAM FILES\TESCO INTERNET SECURITY\Common\FSM32.exe" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\PROGRAM FILES\TESCO INTERNET SECURITY\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [News Service] "C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSGUI\ispnews.exe"
O4 - HKLM\..\RunServices: [Winmodem] C:\WINDOWS\SYSTEM\WINMODEM.101\winmodem.exe
O4 - HKLM\..\RunServices: [V128IID] Rundll32.exe c:\windows\SYSTEM\v128iitw.dll,STB_InitTweak
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\PROGRAM FILES\TESCO INTERNET SECURITY\Common\FSMA32.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Tsa2] C:\PROGRAM FILES\COMMON FILES\TSA\TSM2.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\MSOffice\Office\OSA.exe
O4 - User Startup: Office Startup.lnk = C:\Program Files\MSOffice\Office\OSA.exe
O4 - Global Startup: Tesco Internet Security.lnk = C:\Program Files\Tesco Internet Security\backweb\9655419\Program\fspex.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.exe
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.exe
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\PROGRAM FILES\SIDEFIND\SIDEFIND.DLL
O9 - Extra button: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O9 - Extra 'Tools' menuitem: &Allow this website - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O9 - Extra 'Tools' menuitem: &Deny this website - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O9 - Extra 'Tools' menuitem: &Suspend Webpage Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O9 - Extra 'Tools' menuitem: Show website &list - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\PROGRAM FILES\TESCO INTERNET SECURITY\FSPC\FSPCMSIE.DLL
O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tesco.net
O16 - DPF: {0C98419E-324F-11D3-9A23-00C04FF40D52} (McAfee Clinic AV Installer Control) - http://download.mcafee.com/molbin/clinic/virusscan/mgavinst.cab
O16 - DPF: {DA28C54E-D95C-11D3-9A01-005004677EF4} - http://download.mcafee.com/molbin/clinic/CDM/McCDM.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7.cab
O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab
O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab




Sponsored Link
Ads by Google

Response Number 1
Name: RoadRunner
Date: January 7, 2005 at 15:41:32 Pacific
Reply:

Hi ... I believe before posting a hijackthis log you need to have one of the other members ( a expert ) to ask you for it ... I'm not a expert I did notice you do have many nasty entry in your log ... Also I don't like to turn others to another forum site because I do find this forum site one of the better ones out there , but I do like to help others whenever I can and if no one here helps you with your log you can try going here which is also a very good forum site

http://spywarewarrior.com/index.php


0

Response Number 2
Name: smifff
Date: January 8, 2005 at 11:25:27 Pacific
Reply:

Try an online antivirus scan from any of these first
http://windowsxp.mvps.org/Scanners.htm

You can post your Hijack this log here for an automated analysis
http://www.hijackthis.de./


If any advice helps, please post back as it might help others.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Stubby.D + DyFuCa - please help!

Router opens ports? PLEASE HELP! www.computing.net/answers/security/router-opens-ports-please-help/13009.html

Lycos Sidesearch PLEASE HELP! www.computing.net/answers/security/lycos-sidesearch-please-help/10881.html

please help! Backdoor.Graybird www.computing.net/answers/security/please-help-backdoorgraybird/20273.html