BleepingComputer.com: I need help with removing viruses

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

I need help with removing viruses I have found Wekenupo.dll , folonefo.dll and others

#1 User is offline   jzarate 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 25-May 09

Posted 25 May 2009 - 01:42 AM

Hi,

It seems that i have really messed up my computer. I have tried to clean it my self, but i'm not that efficient at it. The symptoms I get include: Fatal error and the computer just turning into a blue screen, the computer freezes, when i click on a google link it takes me to a site completely different from what it should be and pop-ups.
Here is the DDS log.
and the Attached file


DDS (Ver_09-05-14.01) - NTFSx86
Run by Administrator at 23:29:36.79 on Sun 05/24/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_05
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.61 [GMT -7:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator.PARTSCOMPUTER\Desktop\dds.scr
C:\WINDOWS\System32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://msn.com/
uSearch Bar = hxxp://www.yahoo.com/search/ie.html
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
mSearchAssistant = hxxp://www.google.com/ie
BHO: {6ced5bad-6afb-44f1-90ce-451e61b9b8c9} - c:\windows\system32\zopiwahe.dll
BHO: : {a8302ad3-ba36-4987-8b6b-9fa04d1a9cd9} - c:\windows\system32\wrtoxyq.dll
BHO: c:\windows\system32\jkshfuiehi.dll: {c2ba40a1-74f3-42bd-f434-12345a2c8953} - c:\windows\system32\jkshfuiehi.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll
TB: {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - No File
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /S
mRun: [avg8_tray] c:\progra~1\avg\avg8\avgtray.exe
mRun: [bimafupika] Rundll32.exe "c:\windows\system32\gezokije.dll",s
mRun: [CPMa7fcf994] Rundll32.exe "c:\windows\system32\mihamake.dll",a
mRun: [a4cfca08] rundll32.exe "c:\windows\system32\foponiga.dll",b
dRun: [Diagnostic Manager] c:\windows\temp\1631420488.exe
dRunOnce: [RunNarrator] Narrator.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
dPolicies-explorer: NoFolderOptions = 1 (0x1)
dPolicies-system: DisableRegistryTools = 1 (0x1)
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon%20FiOS%20Installer.cab
TCP: NameServer = 85.255.112.211,85.255.112.149
TCP: {59BCE8B2-9F24-4D24-A0F4-310507C6E7BC} = 85.255.112.211,85.255.112.149
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: eeekp - eeekp.dll
Notify: igfxcui - igfxsrvc.dll
Notify: imod3 - imod3.dll
Notify: smnlmwep - wrtoxyq.dll
Notify: vhexejhu - wrtoxyq.dll
Notify: __c00b6fa - c:\windows\system32\__c00B6FA.dat
AppInit_DLLs: c:\windows\system32\mokosuha.dll c:\windows\system32\fojawuka.dll c:\windows\system32\rutunisi.dll c:\windows\system32\yisiwusu.dll c:\windows\system32\lenozafi.dll c:\windows\system32\jitabine.dll c:\windows\system32\fokonefo.dll c:\windows\system32\rutobuki.dll c:\windows\system32\kunobesi.dll c:\windows\system32\mihamake.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mihamake.dll
STS: c:\windows\system32\jkshfuiehi.dll: {c2ba40a1-74f3-42bd-f434-12345a2c8953} - c:\windows\system32\jkshfuiehi.dll
STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\mihamake.dll
LSA: Notification Packages = scecli c:\windows\system32\mokosuha.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1.par\applic~1\mozilla\firefox\profiles\t2d7wq9d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll
FF - component: c:\program files\mozilla firefox\components\dfff.dll
FF - component: c:\program files\mozilla firefox\components\WWShow.dll
FF - plugin: c:\documents and settings\administrator.partscomputer\application data\mozilla\firefox\profiles\t2d7wq9d.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071102000005.dll

============= SERVICES / DRIVERS ===============

R?2 sunvxnec;Linksys Home Wireless-G USB Adapter Helper;c:\windows\system32\svchost.exe -k netsvcs [2003-7-16 14336]
R0 dfbbnyth;dfbbnyth;c:\windows\system32\drivers\dfbbnyth.sys [2003-7-16 23424]
R0 jmbniqxb;jmbniqxb;c:\windows\system32\drivers\jmbniqxb.sys [2003-7-16 23424]
R1 avgldx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-8 325896]
R1 avgmfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-8 27784]
R1 avgtdix;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-8 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-8 298776]
R2 enankaki;NDIS System Monitor;c:\windows\system32\svchost.exe -k netsvcs [2003-7-16 14336]
S1 77c211ee;77c211ee;c:\windows\system32\drivers\77c211ee.sys [2009-5-9 0]
S4 bndmss;Windows Network Data Management System Service;c:\windows\system32\bndmss.exe --> c:\windows\system32\bndmss.exe [?]
S4 fci;FCI;c:\windows\system32\svchost.exe:ext.exe --> c:\windows\system32\svchost.exe:ext.exe [?]

=============== Created Last 30 ================

2009-05-24 23:03 121 ---sh--- c:\windows\system32\aginopof.ini
2009-05-22 14:05 121 ---sh--- c:\windows\system32\igurohib.ini
2009-05-21 15:29 121 ---sh--- c:\windows\system32\upogekad.ini
2009-05-20 22:33 121 ---sh--- c:\windows\system32\egiyelim.ini
2009-05-20 10:33 121 ---sh--- c:\windows\system32\oponekew.ini
2009-05-19 22:33 121 ---sh--- c:\windows\system32\afutebuj.ini
2009-05-19 10:34 121 ---sh--- c:\windows\system32\ivuzaleg.ini
2009-05-18 21:37 121 ---sh--- c:\windows\system32\agutusub.ini
2009-05-18 08:31 121 ---sh--- c:\windows\system32\olenepam.ini
2009-05-17 10:36 121 ---sh--- c:\windows\system32\oyiladab.ini
2009-05-16 22:12 121 ---sh--- c:\windows\system32\apurabaf.ini
2009-05-16 10:13 121 ---sh--- c:\windows\system32\otutayiw.ini
2009-05-15 09:41 121 ---sh--- c:\windows\system32\obopadag.ini
2009-05-14 21:43 121 ---sh--- c:\windows\system32\ekimugor.ini
2009-05-13 11:41 121 ---sh--- c:\windows\system32\oyeyotol.ini
2009-05-12 23:30 <DIR> --d----- c:\windows\pss
2009-05-12 23:05 121 ---sh--- c:\windows\system32\awizuwoz.ini
2009-05-12 11:09 121 ---sh--- c:\windows\system32\eviriyiw.ini
2009-05-11 17:25 121 ---sh--- c:\windows\system32\esiyijab.ini
2009-05-11 14:38 1,589 a------- c:\windows\_DETMP.1
2009-05-10 13:33 121 ---sh--- c:\windows\system32\uwihumoz.ini
2009-05-10 12:33 <DIR> --d----- c:\docume~1\admini~1.par\applic~1\aAvgApi
2009-05-10 04:50 2,713 ---sh--- c:\windows\system32\towowuwo.exe
2009-05-09 13:15 1 ----h--- c:\windows\msmark2.dat
2009-05-09 13:15 1 ----h--- c:\windows\f23567.dat
2009-05-09 13:15 2 ----h--- c:\windows\t55ft2695f44.dat
2009-05-09 13:15 2 ----h--- c:\windows\t55ft2668f44.dat
2009-05-09 11:17 1 a------- c:\windows\9g2234wesdf3dfgjf23
2009-05-09 11:15 2 ----h--- c:\windows\t55ft2692f44.dat
2009-05-09 11:15 <DIR> --d----- c:\windows\system32\796525
2009-05-09 11:12 0 a------- c:\windows\system32\drivers\77c211ee.sys
2009-05-09 11:12 190,976 a------- C:\vfmf.exe
2009-05-09 11:12 14,336 a------- c:\windows\system32\OLD82.tmp
2009-05-09 11:12 577,536 a------- c:\windows\system32\ookthfvib
2009-05-09 11:11 182,912 ac------ c:\windows\system32\dllcache\ndis.sys
2009-05-09 10:57 0 a------- c:\windows\mqcd.dbt
2009-05-09 10:40 95,484 a------- c:\windows\system32\drivers\30c52d7c.sys
2009-05-09 10:39 190,976 a------- C:\kinkerc.exe
2009-05-09 10:39 32,768 a------- c:\windows\system32\fairy.an
2009-05-09 10:39 79,360 a------- c:\windows\system32\ashl.nq
2009-05-09 10:39 28,672 a------- c:\windows\system32\dolman.zt
2009-05-09 10:39 262,144 a------- c:\windows\system32\nvrsk.dll
2009-05-09 10:39 15,000 a------- c:\windows\system32\jkshfuiehi.dll
2009-05-09 09:32 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-05-08 23:05 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-05-08 23:05 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-08 23:05 325,896 a------- c:\windows\system32\drivers\avgldx86.sys
2009-05-08 23:05 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-05-08 23:05 <DIR> --d----- c:\docume~1\admini~1.par\applic~1\AVGTOOLBAR
2009-05-08 22:39 1,406,518 ---sh--- c:\windows\system32\umigadip.ini
2009-05-08 22:24 <DIR> --d----- c:\program files\AVG
2009-05-08 10:38 1,433,831 ---sh--- c:\windows\system32\umeyanol.ini
2009-05-07 22:38 1,406,509 ---sh--- c:\windows\system32\iwehesaw.ini
2009-05-07 16:54 <DIR> --d----- c:\docume~1\admini~1.par\applic~1\sifglfva
2009-05-07 15:41 <DIR> --d----- c:\docume~1\admini~1.par\applic~1\Twain
2009-05-07 15:36 <DIR> --d----- c:\program files\WWShow
2009-05-07 15:31 <DIR> --d----- c:\program files\Jcore
2009-05-07 10:38 1,406,496 ---sh--- c:\windows\system32\atatigot.ini
2009-05-06 15:18 87,164 a------- c:\windows\system32\drivers\c356b783.sys
2009-05-06 15:18 2 a------- C:\-1529886041
2009-05-05 11:57 1,433,128 ---sh--- c:\windows\system32\amesujaj.ini
2009-05-05 11:52 <DIR> --d----- c:\docume~1\admini~1.par\applic~1\ptidle

==================== Find3M ====================

2009-05-24 23:02 81,920 a--sh--- c:\windows\system32\mihamake.dll
2009-05-24 23:02 78,848 a--sh--- c:\windows\system32\foponiga.dll
2009-05-09 11:11 182,912 a------- c:\windows\system32\drivers\ndis.sys
2009-05-09 10:39 577,536 a------- c:\windows\system32\user32.DLL
2009-04-02 14:44 724,992 a------- c:\windows\iun6002.exe
2009-02-24 12:34 90,112 a------- c:\windows\system32\dpl100.dll
2009-02-24 12:34 823,296 a------- c:\windows\system32\divx_xx0c.dll
2009-02-24 12:34 823,296 a------- c:\windows\system32\divx_xx07.dll
2009-02-24 12:34 815,104 a------- c:\windows\system32\divx_xx0a.dll
2009-02-24 12:34 802,816 a------- c:\windows\system32\divx_xx11.dll
2009-02-24 12:34 684,032 a------- c:\windows\system32\DivX.dll
2008-07-22 23:12 809,661,888 a------- c:\documents and settings\administrator.partscomputer\imagefile.bin
2008-07-22 23:06 136 a------- c:\documents and settings\administrator.partscomputer\cueSheet.bin
2008-07-22 23:06 11 a------- c:\documents and settings\administrator.partscomputer\info.bin
2005-12-19 11:01 33,408 a------- c:\documents and settings\administrator.partscomputer\g2mdlhlpx.exe
2009-02-06 15:19 49,664 a--sh--- c:\windows\system32\mokosuha.dll

============= FINISH: 23:30:53.92 ===============

Attached File(s)



#2 User is offline   shelf life 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 1,366
  • Joined: 06-November 08
  • Gender:Male
  • Location:@localhost

Posted 31 May 2009 - 08:06 AM

hi,

sorry for delay, no shortage of posters. Your log is several days old, if you still need help reply to my post.
Is It Real or ScareWare?
How Can I Reduce My Risk.

#3 User is offline   jzarate 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 25-May 09

Posted 01 June 2009 - 01:52 PM

Hi,

Thanks for your reply. I still haven't messed around with the system for a while. A few days ago I did some work on it and managed to get it working somewhat ok, but if you can help me get it virus free I will definitely appreciate it. The log might still be the same since the computer hasn't been used much lately.

#4 User is offline   shelf life 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 1,366
  • Joined: 06-November 08
  • Gender:Male
  • Location:@localhost

Posted 01 June 2009 - 05:44 PM

Hi,

ok your welcome. we will get a download to use. There is a guide you need to read first. It will explain everything. You can read it on another computer.
Then do the downloading on the computer that has the malware on it. Read the guide, download combofix to the desktop. Disable any AV, anti-malware that might be running, double click the combofix icon and follow the prompts. The guide to read:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Is It Real or ScareWare?
How Can I Reduce My Risk.

#5 User is offline   jzarate 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 25-May 09

Posted 15 June 2009 - 02:02 AM

Hi,
Sorry for the late response. Finals week was a priority over fixing the computer. Here is the log from ComboFix.

Thank you for your time.

ComboFix 09-06-14.02 - Administrator 06/14/2009 23:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.251 [GMT -7:00]
Running from: c:\documents and settings\Administrator.PARTSCOMPUTER\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator.PARTSCOMPUTER\Start Menu\Programs\System Security
c:\program files\Jcore
c:\program files\podmena
c:\program files\WWShow
c:\windows\system32\drivers\dfbbnyth.sys
c:\windows\system32\drivers\gxvxcbnrsblxaiwqwmkypdwkvtmbftuuthesr.sys
c:\windows\system32\drivers\yoesinad.sys
c:\windows\system32\gxvxcriqmoewsuwbbuxvhxvebqhipfjmiqjpt.dll
c:\windows\system32\rbrhvig.dll
c:\windows\system32\rnufmxri.dll
c:\windows\system32\towowuwo.exe
c:\windows\system32\wrtoxyq.dll
c:\windows\Tasks\At1.job
c:\windows\Tasks\At2.job
C:\-1529886041
c:\documents and settings\Administrator.PARTSCOMPUTER\Desktop\System Security 2009.lnk
c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Temporary Internet Files\Cpvff.stt
c:\documents and settings\Administrator.PARTSCOMPUTER\Start Menu\Programs\System Security\System Security 2009 Support.lnk
c:\documents and settings\Administrator.PARTSCOMPUTER\Start Menu\Programs\System Security\System Security 2009.lnk
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\1361538659.exe
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\1458931097.exe
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\615289520.exe
c:\program files\Internet Explorer\setupapi.dll
c:\program files\Mozilla Firefox\setupapi.dll
c:\program files\podmena\podmena.dll
c:\program files\podmena\podmena.sys
c:\windows\9g2234wesdf3dfgjf23
c:\windows\f23567.dat
c:\windows\IE4 Error Log.txt
c:\windows\ld09.exe
c:\windows\mqcd.dbt
c:\windows\msmark2.dat
c:\windows\system32\_000000_.tmp.dll
c:\windows\system32\_000001_.tmp.dll
c:\windows\system32\a9k.bin
c:\windows\system32\afetazil.ini
c:\windows\system32\afutebuj.ini
c:\windows\system32\aginopof.ini
c:\windows\system32\agofufuh.ini
c:\windows\system32\agutusub.ini
c:\windows\system32\ajewitab.ini
c:\windows\system32\akimajur.ini
c:\windows\system32\amesujaj.ini
c:\windows\system32\amevamey.ini
c:\windows\system32\apurabaf.ini
c:\windows\system32\ashl.nq
c:\windows\system32\atatigot.ini
c:\windows\system32\avast!Antivirus.exe
c:\windows\system32\avast!AVSControlService.exe
c:\windows\system32\awizuwoz.ini
c:\windows\system32\awoyibid.ini
c:\windows\system32\ayevopid.ini
c:\windows\system32\B.tmp
c:\windows\system32\dolman.zt
c:\windows\system32\drivers\gxvxcbnrsblxaiwqwmkypdwkvtmbftuuthesr.sys
c:\windows\system32\drivers\jmbniqxb.sys
c:\windows\system32\drivers\razeanle.sys
c:\windows\system32\egiyelim.ini
c:\windows\system32\ehazerom.ini
c:\windows\system32\ekimugor.ini
c:\windows\system32\epuhilah.ini
c:\windows\system32\erelipij.ini
c:\windows\system32\esiyijab.ini
c:\windows\system32\esujofij.ini
c:\windows\system32\eviriyiw.ini
c:\windows\system32\eyayagay.ini
c:\windows\system32\fairy.an
c:\windows\system32\fupipivo.exe
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcriqmoewsuwbbuxvhxvebqhipfjmiqjpt.dll
c:\windows\system32\himepuka.dll
c:\windows\system32\ibahizuf.ini
c:\windows\system32\igurohib.ini
c:\windows\system32\ilafigap.ini
c:\windows\system32\iledagoz.ini
c:\windows\system32\ivuzaleg.ini
c:\windows\system32\iwehesaw.ini
c:\windows\system32\iwivajuz.ini
c:\windows\system32\iyiyogos.ini
c:\windows\system32\izevayef.ini
c:\windows\system32\jbnmcd.dll
c:\windows\system32\kenahapu.dll
c:\windows\system32\nvrsk.dll
c:\windows\system32\obopadag.ini
c:\windows\system32\ohijawim.ini
c:\windows\system32\olenepam.ini
c:\windows\system32\oponekew.ini
c:\windows\system32\otutayiw.ini
c:\windows\system32\oyeyotol.ini
c:\windows\system32\oyiladab.ini
c:\windows\system32\sebodume.dll
c:\windows\system32\sft.res
c:\windows\system32\ufatebab.ini
c:\windows\system32\uhafawep.ini
c:\windows\system32\ulibujam.ini
c:\windows\system32\umeyanol.ini
c:\windows\system32\umigadip.ini
c:\windows\system32\upogekad.ini
c:\windows\system32\usevuyov.ini
c:\windows\system32\uwihumoz.ini
c:\windows\system32\vanabesa.dll
c:\windows\t55ft2668f44.dat
c:\windows\t55ft2692f44.dat
c:\windows\t55ft2695f44.dat
c:\windows\Temp\1347840288.exe
c:\windows\Temp\3160547362.exe
c:\windows\Temp\3503051052.exe
c:\windows\Temp\996543066.exe

Infected copy of c:\windows\system32\drivers\ndis.sys was found and disinfected
Restored copy from - The cat ate it :thumbup2:
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_GXVXCSERV.SYS
-------\Legacy_AVAST!ANTIVIRUS
-------\Legacy_bndmss
-------\Legacy_dfbbnyth
-------\Legacy_enankaki
-------\Legacy_FCI
-------\Legacy_jmbniqxb
-------\Legacy_podmena
-------\Legacy_podmenadrv
-------\Legacy_sunvxnec
-------\Service_avast!Antivirus
-------\Service_bndmss
-------\Service_dfbbnyth
-------\Service_enankaki
-------\Service_fci
-------\Service_jmbniqxb
-------\Service_podmena
-------\Service_podmenadrv
-------\Service_sunvxnec
-------\Legacy_avast!AVSControlService
-------\Service_avast!AVSControlService


((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.

2009-06-15 06:22 . 2009-06-15 06:22 2 ---h--w- c:\windows\zaponce53290.dat
2009-06-15 06:22 . 2009-06-15 06:22 159 ----a-w- C:\d45.bat
2009-06-15 06:12 . 2009-06-15 06:45 99422 ----a-w- c:\windows\system32\drivers\e21c929a.sys
2009-06-12 01:37 . 2009-06-12 01:37 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\ghanorhd
2009-06-12 01:37 . 2009-06-12 01:37 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\ghanorhd
2009-06-08 20:18 . 2009-06-08 21:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\91888116
2009-06-08 20:18 . 2009-06-08 21:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\11878124

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 06:38 . 2003-07-16 16:43 577536 ----a-w- c:\windows\system32\user32.dll
2009-06-15 06:31 . 2003-07-16 16:31 182912 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-06-15 06:22 . 2009-03-15 06:22 81408 --sha-w- c:\windows\system32\dofoferu.dll
2009-06-15 06:22 . 2009-03-15 06:22 15360 --sha-w- c:\windows\system32\fobunayi.exe
2009-06-15 06:22 . 2009-03-15 06:22 79360 --sha-w- c:\windows\system32\hufufoga.dll
2009-06-15 06:09 . 2009-04-22 18:29 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2009-06-13 00:01 . 2009-03-13 00:01 81920 --sha-w- c:\windows\system32\yuwehosu.dll
2009-06-13 00:01 . 2009-03-13 00:01 79360 ------w- c:\windows\system32\rujamika.dll
2009-06-10 23:25 . 2009-03-10 23:25 49664 --sha-w- c:\windows\system32\maremapa.dll
2009-06-08 06:07 . 2004-06-18 16:57 24272 ----a-w- c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-06 06:59 . 2006-08-18 17:24 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\LimeWire
2009-06-05 18:06 . 2009-05-06 22:18 0 ----a-w- c:\windows\system32\drivers\c356b783.sys
2009-06-04 17:40 . 2004-05-20 14:22 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\MSN6
2009-05-25 21:30 . 2009-04-22 18:34 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-05-21 05:45 . 2009-05-09 18:12 0 ----a-w- c:\windows\system32\drivers\77c211ee.sys
2009-05-11 21:33 . 2006-12-07 17:05 -------- d-----w- c:\program files\DDBPlayer
2009-05-11 21:31 . 2004-11-02 16:27 -------- d-----w- c:\program files\Real
2009-05-11 21:31 . 2004-11-02 16:27 -------- d-----w- c:\program files\Common Files\Real
2009-05-11 21:24 . 2008-04-11 06:06 -------- d-----w- c:\program files\Microsoft Games
2009-05-11 21:22 . 2004-05-20 18:04 -------- d-----w- c:\program files\Almyta
2009-05-11 21:19 . 2004-05-21 19:10 -------- d-----w- c:\program files\ACT
2009-05-11 21:18 . 2007-06-12 21:09 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\Yahoo!
2009-05-11 21:18 . 2007-06-04 20:41 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Yahoo!
2009-05-11 21:12 . 2006-11-07 23:30 -------- d-----w- c:\program files\Yahoo!
2009-05-11 20:02 . 2004-05-18 18:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-10 19:33 . 2009-05-10 19:33 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\aAvgApi
2009-05-09 18:12 . 2009-05-09 18:12 14336 ----a-w- c:\windows\system32\OLD82.tmp
2009-05-09 17:53 . 2009-05-07 22:41 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\Twain
2009-05-09 17:53 . 2009-05-05 18:52 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\ptidle
2009-05-09 06:07 . 2009-05-09 06:05 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\AVGTOOLBAR
2009-05-09 06:05 . 2009-05-09 06:05 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-09 06:05 . 2009-05-09 06:05 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-09 06:05 . 2009-05-09 06:05 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-09 06:05 . 2009-05-09 06:05 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-09 05:24 . 2009-05-09 05:24 -------- d-----w- c:\program files\AVG
2009-05-08 00:07 . 2009-05-08 00:07 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\sifglfva
2009-05-07 23:54 . 2009-05-07 23:54 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\sifglfva
2009-05-06 23:49 . 2004-12-14 20:23 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-05-06 23:49 . 2004-12-14 20:23 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-01 15:29 . 2004-05-19 22:26 -------- d-----w- c:\program files\Print Server
2009-04-22 19:58 . 2009-04-22 19:58 -------- d-----w- c:\program files\XP Codec Pack
2009-04-22 19:38 . 2009-04-22 19:38 -------- d-----w- c:\program files\Xvid
2009-04-22 19:38 . 2009-04-22 19:38 390664 ----a-w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-04-22 19:16 . 2008-06-24 16:43 -------- d-----w- c:\program files\DivX
2009-04-22 19:15 . 2009-04-22 19:15 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-04-22 18:49 . 2009-04-22 18:49 -------- d-----w- c:\program files\IObit
2009-04-22 18:49 . 2009-04-22 18:49 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\IObit
2009-04-22 18:45 . 2009-04-22 18:45 -------- d-----w- c:\program files\YouTube Downloader
2009-04-21 20:29 . 2009-04-21 20:29 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\Uniblue
2009-04-21 20:29 . 2009-04-21 20:28 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\WinZip
2009-04-21 20:13 . 2009-04-02 23:00 -------- d-----w- c:\program files\Audacity
2009-04-21 20:09 . 2009-04-21 20:06 -------- d-----w- c:\program files\Lame for Audacity
2009-04-19 17:28 . 2006-05-19 22:01 -------- d-----w- c:\program files\PartyGaming.Net
2009-04-14 21:07 . 2009-04-14 21:07 75048 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-02 21:44 . 2009-04-02 21:45 724992 ----a-w- c:\windows\iun6002.exe
2009-03-30 18:43 . 2009-03-30 18:43 0 ----a-w- C:\VDM101.tmp
2009-03-30 18:43 . 2009-03-30 18:43 0 ----a-w- C:\VDM100.tmp
2009-03-19 23:32 . 2009-03-19 23:32 23400 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 23:32 . 2008-01-29 19:01 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-18 20:53 . 2009-03-18 20:53 1421449 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\NeoEdge Networks\Yahoo_Monopoly\IAF.dll
2009-03-18 05:05 . 2009-02-22 04:50 7 ----a-w- c:\windows\system32\nar.bin
2009-04-22 07:12 . 2009-04-22 07:12 90624 ----a-w- c:\program files\mozilla firefox\components\WWShow.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-03-10 23:26 . 2009-03-10 23:26 49664 --sha-w- c:\windows\SYSTEM32\ruvaluno.dll
2009-03-10 23:26 . 2009-03-10 23:26 49664 --sha-w- c:\windows\SYSTEM32\vuvimuwe.dll
.
Infected c:\windows\system32\user32.dll hex repaired


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6ced5bad-6afb-44f1-90ce-451e61b9b8c9}]
2009-03-10 23:26 49664 --sha-w- c:\windows\SYSTEM32\ruvaluno.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avg8_tray"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-09 1947928]
"bimafupika"="c:\windows\system32\vuvimuwe.dll" [2009-03-10 49664]
"a4cfca08"="c:\windows\system32\hufufoga.dll" [2009-06-15 79360]
"CPMa7fcf994"="c:\windows\system32\dofoferu.dll" [2009-06-15 81408]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\SYSTEM32\narrator.exe [2004-08-04 53760]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\dofoferu.dll" [2009-06-15 81408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\dofoferu.dll [2009-06-15 81408]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-09 06:05 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKLM\~\startupfolder\c:^documents and settings^all users.windows^start menu^programs^startup^acrobat assistant.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\c:^documents and settings^all users.windows^start menu^programs^startup^hp digital imaging monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"MDM"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"fci"=2 (0x2)
"bndmss"=2 (0x2)
"BITS"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Adobe LM Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires\\EMPIRESX.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\SYSTEM32\\hpzipm12.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\explorer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:podmena

R1 avgldx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [5/8/2009 11:05 PM 325896]
R1 avgtdix;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [5/8/2009 11:05 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/8/2009 11:04 PM 298776]
S1 4127bab8;4127bab8;c:\windows\system32\drivers\4127bab8.sys --> c:\windows\system32\drivers\4127bab8.sys [?]
S1 77c211ee;77c211ee;c:\windows\SYSTEM32\DRIVERS\77c211ee.sys [5/9/2009 11:12 AM 0]
S1 b40de6f4;b40de6f4;c:\windows\system32\drivers\b40de6f4.sys --> c:\windows\system32\drivers\b40de6f4.sys [?]
S1 b4689307;b4689307;c:\windows\system32\drivers\b4689307.sys --> c:\windows\system32\drivers\b4689307.sys [?]
S1 c33b18e9;c33b18e9;c:\windows\system32\drivers\c33b18e9.sys --> c:\windows\system32\drivers\c33b18e9.sys [?]
S1 c356b783;c356b783;c:\windows\SYSTEM32\DRIVERS\c356b783.sys [5/6/2009 3:18 PM 0]
S1 d058583c;d058583c;c:\windows\system32\drivers\d058583c.sys --> c:\windows\system32\drivers\d058583c.sys [?]
S1 d170b3c1;d170b3c1;c:\windows\system32\drivers\d170b3c1.sys --> c:\windows\system32\drivers\d170b3c1.sys [?]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - DFBBNYTH
*Deregistered* - dfbbnyth
.
Contents of the 'Scheduled Tasks' folder

2009-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 19:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0feb365c-dce7-47d2-a5a7-763fa116869a} - c:\windows\system32\rnufmxri.dll
Notify-__c00b6fa - c:\windows\system32\__c00B6FA.dat
Notify-eeekp - eeekp.dll
Notify-imod3 - imod3.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://msn.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-14 23:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\system32\agofufuh.ini 1406496 bytes

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\e21c929a]
"ImagePath"="\SystemRoot\System32\drivers\e21c929a.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2036)
c:\windows\system32\hufufoga.dll
c:\windows\system32\ruvaluno.dll
c:\windows\system32\dofoferu.dll
c:\windows\system32\vuvimuwe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Microsoft Shared\OFFICE11\MSOXEV.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\SYSTEM32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-06-15 23:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-15 06:51

Pre-Run: 9,642,938,368 bytes free
Post-Run: 9,625,784,320 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

358 --- E O F --- 2009-03-25 10:00

#6 User is offline   shelf life 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 1,366
  • Joined: 06-November 08
  • Gender:Male
  • Location:@localhost

Posted 15 June 2009 - 06:06 PM

hi jzarate,

You had a large load of malware. You still have malware onboard.

You had core system files that were infected. I would no longer trust the computer. I would use the computer as little as possible until its cleaned up. When not in use pull the plug so you have no network connectivity.

You should seriously consider reformatting and reinstalling Windows but i leave that up to you.
let me know how you want to proceed.

this is several years old but still holds true:

http://technet.microsoft.com/en-us/library/cc512587.aspx
Is It Real or ScareWare?
How Can I Reduce My Risk.

#7 User is offline   jzarate 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 25-May 09

Posted 20 June 2009 - 12:07 AM

Thanks for your advise. I'll just have to buy a new copy of XP and format the computer. :thumbup2:

#8 User is offline   shelf life 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 1,366
  • Joined: 06-November 08
  • Gender:Male
  • Location:@localhost

Posted 20 June 2009 - 03:18 PM

Commercial computers should have either a reinstall or restore disk or a restore partition on the hard drive.
If you dont have these options then we can attempt to clean it using combofix and other tools if you want.
Is It Real or ScareWare?
How Can I Reduce My Risk.

#9 User is offline   jzarate 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 25-May 09

Posted 27 June 2009 - 11:16 PM

If you have other programs that might help clean it I would like to give those a chance. I already ran Combofix and the computer seems to be working much better. I'm still getting a lot of pop-ups but overall the computer is running faster and AVG seems to be doing a decent job of getting rid off some suspicious items.

#10 User is offline   shelf life 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 1,366
  • Joined: 06-November 08
  • Gender:Male
  • Location:@localhost

Posted 28 June 2009 - 05:27 AM

ok. We will get two downloads to start with. the first one is SDfix. it only runs in safe mode. Use if first, followed by combofix. Link and directions for SDFix:

Download SDFix and save it to your Desktop.

http://downloads.andymanchesta.com/RemovalTools/SDFix.exe


Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, the Advanced Options Menu should appear;
* Select the first option, to run Windows in Safe Mode, then press Enter.
* Choose your usual account.

* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
* Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
* Finally paste the contents of the Report.txt in your reply.



Run combofix next, most likely you will have to download a new copy first. Please disable AVG before running it. Combofix links:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Guide to using Combofix

Post the Sdfix log and the combofix log
Is It Real or ScareWare?
How Can I Reduce My Risk.

#11 User is offline   jzarate 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 25-May 09

Posted 10 July 2009 - 02:52 AM

Hi,

Here are the reports for SDFix and Combo Fix.

SDFix: Version 1.240
Run by Administrator on Thu 07/09/2009 at 11:50 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Name :
Driver

Path :
C:\WINDOWS\system32\svchost.exe -k driver

Driver - Deleted



Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-10 00:04:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"NoPopUpsOnBoot"=dword:00000001
"AppInit_DLLs"="C:\WINDOWS\system32\kenahapu.dll c:\windows\system32\yelosuso.dll c:\windows\system32\vemumise.dll c:\windows\system32\fujehone.dll c:\windows\system32\mejiyuwo.dll c:\windows\system32\nehakite.dll"
"LoadAppInit_DLLs"=dword:00000001

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Microsoft Games\\Age of Empires\\EMPIRESX.EXE"="C:\\Program Files\\Microsoft Games\\Age of Empires\\EMPIRESX.EXE:*:Enabled:Age of Empires, the Rise of Rome"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe:*:Enabled:Age of Empires 3"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\SYSTEM32\\hpzipm12.exe"="C:\\WINDOWS\\SYSTEM32\\hpzipm12.exe:*:Enabled:HPZipm12"
"C:\\Program Files\\iPod\\bin\\iPodService.exe"="C:\\Program Files\\iPod\\bin\\iPodService.exe:*:Enabled:iPodService"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\AVG\\AVG8\\avgtray.exe"="C:\\Program Files\\AVG\\AVG8\\avgtray.exe:*:Enabled:avgtray"
"C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\explorer.exe:*:Enabled:explorer"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Wed 8 Jul 2009 83,456 A.SH. --- "C:\WINDOWS\SYSTEM32\fabapufu.dll"
Thu 9 Jul 2009 83,456 A.SH. --- "C:\WINDOWS\SYSTEM32\fajohiti.dll"
Sun 5 Jul 2009 80,384 A.SH. --- "C:\WINDOWS\SYSTEM32\feyimupa.dll"
Wed 8 Jul 2009 2,713 ..SH. --- "C:\WINDOWS\SYSTEM32\gimowave.dll"
Sun 5 Jul 2009 84,480 A.SH. --- "C:\WINDOWS\SYSTEM32\juyarono.dll"
Wed 10 Jun 2009 49,664 A.SH. --- "C:\WINDOWS\SYSTEM32\maremapa.dll"
Thu 9 Jul 2009 84,480 A.SH. --- "C:\WINDOWS\SYSTEM32\nehakite.dll"
Thu 9 Jul 2009 79,360 A.SH. --- "C:\WINDOWS\SYSTEM32\redivipo.dll"
Sun 28 Jun 2009 2,713 ..SH. --- "C:\WINDOWS\SYSTEM32\rimuwuka.dll"
Sat 4 Jul 2009 83,456 A.SH. --- "C:\WINDOWS\SYSTEM32\robudiki.dll"
Mon 6 Jul 2009 84,480 A.SH. --- "C:\WINDOWS\SYSTEM32\rurimita.dll"
Tue 10 Mar 2009 49,664 A.SH. --- "C:\WINDOWS\SYSTEM32\ruvaluno.dll"
Sat 27 Jun 2009 2,713 ..SH. --- "C:\WINDOWS\SYSTEM32\sisazibo.exe"
Sun 28 Jun 2009 2,713 ..SH. --- "C:\WINDOWS\SYSTEM32\sosafuji.dll"
Tue 10 Mar 2009 49,664 A.SH. --- "C:\WINDOWS\SYSTEM32\vuvimuwe.dll"
Sun 5 Jul 2009 84,480 A.SH. --- "C:\WINDOWS\SYSTEM32\wegureju.dll"
Sun 5 Jul 2009 83,456 A.SH. --- "C:\WINDOWS\SYSTEM32\wifowigu.dll"
Fri 26 Jun 2009 2,713 ..SH. --- "C:\WINDOWS\SYSTEM32\wonupago.exe"
Sun 28 Jun 2009 2,713 ..SH. --- "C:\WINDOWS\SYSTEM32\wuleluzu.exe"
Mon 6 Jul 2009 79,360 A.SH. --- "C:\WINDOWS\SYSTEM32\yedibufo.dll"
Mon 15 Jun 2009 19,914 ..SH. --- "C:\WINDOWS\SYSTEM32\yukojuni.exe"
Tue 7 Jul 2009 714,789 A.SH. --- "C:\WINDOWS\SYSTEM32\zodofigu.exe"
Wed 11 Oct 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv1.bak"
Sat 4 Jul 2009 83,456 A.SH. --- "C:\System Volume Information\_restore{A62102F1-27F1-4831-8FC3-56DBFCD1262A}\RP11\A0002846.dll"
Sun 5 Jul 2009 83,968 A.SH. --- "C:\System Volume Information\_restore{A62102F1-27F1-4831-8FC3-56DBFCD1262A}\RP12\A0002885.dll"
Mon 6 Jul 2009 84,480 A.SH. --- "C:\System Volume Information\_restore{A62102F1-27F1-4831-8FC3-56DBFCD1262A}\RP12\A0002943.dll"
Mon 6 Jul 2009 83,456 A.SH. --- "C:\System Volume Information\_restore{A62102F1-27F1-4831-8FC3-56DBFCD1262A}\RP12\A0002944.dll"
Mon 6 Jul 2009 79,872 A.SH. --- "C:\System Volume Information\_restore{A62102F1-27F1-4831-8FC3-56DBFCD1262A}\RP12\A0002945.dll"
Tue 7 Jul 2009 79,872 A.SH. --- "C:\System Volume Information\_restore{A62102F1-27F1-4831-8FC3-56DBFCD1262A}\RP12\A0002968.dll"
Tue 7 Jul 2009 84,480 A.SH. --- "C:\System Volume Information\_restore{A62102F1-27F1-4831-8FC3-56DBFCD1262A}\RP12\A0002969.dll"
Wed 28 May 2008 35,328 ...H. --- "C:\Documents and Settings\Administrator.PARTSCOMPUTER\My Documents\Jose\~WRL4068.tmp"
Wed 23 Apr 2008 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"
Thu 7 Dec 2006 3,096,576 A..H. --- "C:\Documents and Settings\Administrator.PARTSCOMPUTER\Application Data\U3\temp\Launchpad Removal.exe"
Tue 12 May 2009 22,528 ...H. --- "C:\Documents and Settings\Administrator.PARTSCOMPUTER\My Documents\Jose\Maria Caruso Homework\~WRL2969.tmp"
Wed 23 Apr 2008 20 A..H. --- "C:\Documents and Settings\Administrator.PARTSCOMPUTER\Application Data\Real\rhapsody\wmlicbackup\drmv1lic.bak"
Mon 20 Jun 2005 8 A..H. --- "C:\Documents and Settings\All Users.WINDOWS\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Mon 20 Jun 2005 8 A..H. --- "C:\Documents and Settings\All Users.WINDOWS\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"

Finished!



Combo Fix--------------------------------------------------


ComboFix 09-07-09.07 - Administrator 07/10/2009 0:21.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.177 [GMT -7:00]
Running from: c:\documents and settings\Administrator.PARTSCOMPUTER\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\{767132FF-FABD-4B74-9FB8-6F9A1A5D220A}
c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\{767132FF-FABD-4B74-9FB8-6F9A1A5D220A}\chrome.manifest
c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\{767132FF-FABD-4B74-9FB8-6F9A1A5D220A}\chrome\content\_cfg.js
c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\{767132FF-FABD-4B74-9FB8-6F9A1A5D220A}\chrome\content\c.js
c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\{767132FF-FABD-4B74-9FB8-6F9A1A5D220A}\chrome\content\overlay.xul
c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\{767132FF-FABD-4B74-9FB8-6F9A1A5D220A}\install.rdf
c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Temporary Internet Files\Cpvff.stt
c:\documents and settings\All Users.WINDOWS\Application Data\91888116.ini
c:\program files\ACT
c:\program files\ACT\Layout\Accounts640x480.gly
c:\program files\ACT\Layout\bluea1.bmp
c:\program files\ACT\Layout\Default52.cly
c:\program files\ACT\Layout\Default54.gly
c:\program files\ACT\Layout\Default640x480.cly
c:\program files\ACT\Layout\Default640x480.gly
c:\program files\ACT\Layout\Default800x600.cly
c:\program files\ACT\Layout\DefaultBarBG.bmp
c:\program files\ACT\Layout\deflt16.cly
c:\program files\ACT\Layout\Dflt5bg.BMP
c:\program files\ACT\Layout\Essentials.cly
c:\program files\ACT\Layout\Essentials1024x768.cly
c:\program files\ACT\Layout\Essentials2.gly
c:\program files\ACT\Layout\Essentials800x600.cly
c:\program files\ACT\Layout\GroupsAccount52.gly
c:\program files\ACT\Layout\GroupsDefault52.gly
c:\program files\ACT\Layout\GroupsEssentials.gly
c:\program files\ACT\Layout\Layout Tools\Layout Shapes.cly
c:\program files\ACT\Layout\modernbk.bmp
c:\program files\ACT\Layout\Watermark071.bmp
c:\program files\ACT\NetLinks\50001dic.web
c:\program files\ACT\NetLinks\Interact\actlogo.gif
c:\program files\ACT\NetLinks\Interact\CompanyProfile.ini
c:\program files\ACT\NetLinks\Interact\connect.gif
c:\program files\ACT\NetLinks\Interact\makecontact.gif
c:\program files\ACT\NetLinks\Interact\offline.htm
c:\program files\ACT\Report\10.env
c:\program files\ACT\Report\11.env
c:\program files\ACT\Report\12.env
c:\program files\ACT\Report\2160.lbl
c:\program files\ACT\Report\2162.lbl
c:\program files\ACT\Report\2163.lbl
c:\program files\ACT\Report\4014.lbl
c:\program files\ACT\Report\4143.lbl
c:\program files\ACT\Report\4144.lbl
c:\program files\ACT\Report\4145.lbl
c:\program files\ACT\Report\4146.lbl
c:\program files\ACT\Report\4161.lbl
c:\program files\ACT\Report\5160.lbl
c:\program files\ACT\Report\5161.lbl
c:\program files\ACT\Report\5162.lbl
c:\program files\ACT\Report\5163.lbl
c:\program files\ACT\Report\5164.lbl
c:\program files\ACT\Report\5385.lbl
c:\program files\ACT\Report\6.env
c:\program files\ACT\Report\9.env
c:\program files\ACT\Report\ACCCOMP6.REP
c:\program files\ACT\Report\ACCLIST6.REP
c:\program files\ACT\Report\ACCMEMB6.REP
c:\program files\ACT\Report\ACCSUMM6.REP
c:\program files\ACT\Report\activit6.rep
c:\program files\ACT\Report\contact6.rep
c:\program files\ACT\Report\custom.lbl
c:\program files\ACT\Report\directr6.rep
c:\program files\ACT\Report\group6.rep
c:\program files\ACT\Report\grplst6.rep
c:\program files\ACT\Report\grpmemb6.rep
c:\program files\ACT\Report\Histcla6.rep
c:\program files\ACT\Report\history6.rep
c:\program files\ACT\Report\Hsallex6.rep
c:\program files\ACT\Report\monarch.env
c:\program files\ACT\Report\notehis6.rep
c:\program files\ACT\Report\Other Reports\callmtgsum.rep
c:\program files\ACT\Report\Other Reports\countgroupmem.rep
c:\program files\ACT\Report\Other Reports\emaillist.rep
c:\program files\ACT\Report\Other Reports\faxlist.rep
c:\program files\ACT\Report\phonels6.rep
c:\program files\ACT\Report\referra6.rep
c:\program files\ACT\Report\slsbymg6.rep
c:\program files\ACT\Report\slscntc6.rep
c:\program files\ACT\Report\slsdtai6.rep
c:\program files\ACT\Report\slsFrcs6.rep
c:\program files\ACT\Report\slspipeline6.rep
c:\program files\ACT\Report\slstota6.rep
c:\program files\ACT\Report\status6.rep
c:\program files\ACT\Report\tasklis6.rep
c:\program files\ACT\Template\emailbody.gmt
c:\program files\ACT\Template\faxcover.adt
c:\program files\ACT\Template\faxcover.tpl
c:\program files\ACT\Template\Letter.adt
c:\program files\ACT\Template\Letter.tpl
c:\program files\ACT\Template\lttrela.adt
c:\program files\ACT\Template\lttrela.tpl
c:\program files\ACT\Template\lttruka.adt
c:\program files\ACT\Template\lttruka.tpl
c:\program files\ACT\Template\lttrusc.adt
c:\program files\ACT\Template\lttrusc.tpl
c:\program files\ACT\Template\memo.adt
c:\program files\ACT\Template\memo.tpl
c:\program files\ACT\Template\Other Templates\anniv.gmt
c:\program files\ACT\Template\Other Templates\anniversary.adt
c:\program files\ACT\Template\Other Templates\anniversary.tpl
c:\program files\ACT\Template\Other Templates\anniversary_backgroud.gif
c:\program files\ACT\Template\Other Templates\anniversary_background_l1.gif
c:\program files\ACT\Template\Other Templates\anniversary_l1.gif
c:\program files\ACT\Template\Other Templates\anniversary_l1b.gif
c:\program files\ACT\Template\Other Templates\anniversary_ln.gif
c:\program files\ACT\Template\Other Templates\anniversary1_header.gif
c:\program files\ACT\Template\Other Templates\anniversary1_slice.gif
c:\program files\ACT\Template\Other Templates\bday.gmt
c:\program files\ACT\Template\Other Templates\bdaygroup.gmt
c:\program files\ACT\Template\Other Templates\birthday.adt
c:\program files\ACT\Template\Other Templates\birthday.tpl
c:\program files\ACT\Template\Other Templates\birthdayfromgroup.adt
c:\program files\ACT\Template\Other Templates\birthdayfromgroup.tpl
c:\program files\ACT\Template\Other Templates\enews.gmt
c:\program files\ACT\Template\Other Templates\enews1_header.gif
c:\program files\ACT\Template\Other Templates\enews1_slice.gif
c:\program files\ACT\Template\Other Templates\enews2.gmt
c:\program files\ACT\Template\Other Templates\enews2_bg.gif
c:\program files\ACT\Template\Other Templates\enews2_header.gif
c:\program files\ACT\Template\Other Templates\enews2_l1.gif
c:\program files\ACT\Template\Other Templates\enews2_r1.gif
c:\program files\ACT\Template\Other Templates\enews3_footer.gif
c:\program files\ACT\Template\Other Templates\enews3_header.gif
c:\program files\ACT\Template\Other Templates\enews3_slice_mid.gif
c:\program files\ACT\Template\Other Templates\enews3_slice_mid2.gif
c:\program files\ACT\Template\Other Templates\envlp10.adt
c:\program files\ACT\Template\Other Templates\envlp10.tpl
c:\program files\ACT\Template\Other Templates\file_01.jpg
c:\program files\ACT\Template\Other Templates\file_02.jpg
c:\program files\ACT\Template\Other Templates\file_03.jpg
c:\program files\ACT\Template\Other Templates\file_04.jpg
c:\program files\ACT\Template\Other Templates\file_05.jpg
c:\program files\ACT\Template\Other Templates\followup.adt
c:\program files\ACT\Template\Other Templates\followup.tpl
c:\program files\ACT\Template\Other Templates\followup_1_left.gif
c:\program files\ACT\Template\Other Templates\followup_1_right.gif
c:\program files\ACT\Template\Other Templates\followup_1_top.gif
c:\program files\ACT\Template\Other Templates\followup_1ln.gif
c:\program files\ACT\Template\Other Templates\followup_1lnl.gif
c:\program files\ACT\Template\Other Templates\followup_1lnr.gif
c:\program files\ACT\Template\Other Templates\followup_backup.gif
c:\program files\ACT\Template\Other Templates\group_background-v1.gif
c:\program files\ACT\Template\Other Templates\group_bday-_1_header.gif
c:\program files\ACT\Template\Other Templates\group_bday-_1_left slice.gif
c:\program files\ACT\Template\Other Templates\group_bday-_1_lines.gif
c:\program files\ACT\Template\Other Templates\group_bday-l1.gif
c:\program files\ACT\Template\Other Templates\group_bday-l1bg.gif
c:\program files\ACT\Template\Other Templates\group_bday-v1.gif
c:\program files\ACT\Template\Other Templates\ind_bday_1_left.jpg
c:\program files\ACT\Template\Other Templates\ind_bday_hor.gif
c:\program files\ACT\Template\Other Templates\ind_bday_horizontal1.gif
c:\program files\ACT\Template\Other Templates\newsletter.adt
c:\program files\ACT\Template\Other Templates\newsletter.tpl
c:\program files\ACT\Template\Other Templates\order_2_footer.gif
c:\program files\ACT\Template\Other Templates\order_2_header.gif
c:\program files\ACT\Template\Other Templates\order_2_l1.gif
c:\program files\ACT\Template\Other Templates\order_2_ln.gif
c:\program files\ACT\Template\Other Templates\order_2_r1.gif
c:\program files\ACT\Template\Other Templates\order_2_slice.gif
c:\program files\ACT\Template\Other Templates\order_2_title.gif
c:\program files\ACT\Template\Other Templates\orderconf.adt
c:\program files\ACT\Template\Other Templates\orderconf.gmt
c:\program files\ACT\Template\Other Templates\orderconf.tpl
c:\program files\ACT\Template\Other Templates\prospect.adt
c:\program files\ACT\Template\Other Templates\prospect.gmt
c:\program files\ACT\Template\Other Templates\prospect.tpl
c:\program files\ACT\Template\Other Templates\prospect_3_COMP_01.gif
c:\program files\ACT\Template\Other Templates\prospect_3_COMP_02.gif
c:\program files\ACT\Template\Other Templates\prospect_3_COMP_02b.gif
c:\program files\ACT\Template\Other Templates\prospect_3_COMP_03.gif
c:\program files\ACT\Template\Other Templates\prospect_3_COMP_04.gif
c:\program files\ACT\Template\Other Templates\prospect_3_COMP_07.gif
c:\program files\ACT\Template\Other Templates\prospect_background.gif
c:\program files\ACT\Template\Other Templates\renvlp10.adt
c:\program files\ACT\Template\Other Templates\renvlp10.tpl
c:\program files\ACT\Template\Other Templates\special-offer-4-ln.gif
c:\program files\ACT\Template\Other Templates\special-offer-4-ln2.gif
c:\program files\ACT\Template\Other Templates\special_3_background.gif
c:\program files\ACT\Template\Other Templates\special_3_bullet.gif
c:\program files\ACT\Template\Other Templates\special_3_header.gif
c:\program files\ACT\Template\Other Templates\special_3_ln.gif
c:\program files\ACT\Template\Other Templates\special_3_sl1.gif
c:\program files\ACT\Template\Other Templates\special_3_slice.gif
c:\program files\ACT\Template\Other Templates\special_4_bottomline.gif
c:\program files\ACT\Template\Other Templates\special_4_footer.gif
c:\program files\ACT\Template\Other Templates\special_4_header.gif
c:\program files\ACT\Template\Other Templates\special_4_slice.gif
c:\program files\ACT\Template\Other Templates\specialoffer.adt
c:\program files\ACT\Template\Other Templates\specialoffer.gmt
c:\program files\ACT\Template\Other Templates\specialoffer.tpl
c:\program files\ACT\Template\Other Templates\specialoffer2.gmt
c:\program files\ACT\Template\Other Templates\specialoffer3.gmt
c:\program files\ACT\Template\Other Templates\thankyou.gmt
c:\program files\ACT\Template\Other Templates\title_ordrcon.gif
c:\program files\driver
c:\windows\010112010146118114.dat
c:\windows\0101120101465452.dat
c:\windows\0101120101465749.dat
c:\windows\desktop
c:\windows\system32\adawetaz.ini
c:\windows\system32\agofufuh.ini
c:\windows\system32\apumiyef.ini
c:\windows\system32\egotisel.ini
c:\windows\system32\eguloyih.ini
c:\windows\system32\esonibaz.ini
c:\windows\system32\etemitav.ini
c:\windows\system32\etonuvih.ini
c:\windows\system32\gimowave.dll
c:\windows\system32\ifobabiy.ini
c:\windows\system32\ifomofon.ini
c:\windows\system32\ikuvawub.ini
c:\windows\system32\ilufazok.ini
c:\windows\system32\imiremez.ini
c:\windows\system32\inadamon.ini
c:\windows\system32\inojukeg.ini
c:\windows\system32\itafakuf.ini
c:\windows\system32\iyadiken.ini
c:\windows\system32\ofubidey.ini
c:\windows\system32\oganerew.ini
c:\windows\system32\opinomab.ini
c:\windows\system32\opivider.ini
c:\windows\system32\oruyofid.ini
c:\windows\system32\osusoley.ini
c:\windows\system32\ozivujef.ini
c:\windows\system32\redivipo.dll
c:\windows\system32\rimuwuka.dll
c:\windows\system32\sisazibo.exe
c:\windows\system32\sosafuji.dll
c:\windows\system32\ukajebor.ini
c:\windows\system32\umogevog.ini
c:\windows\system32\utejedoy.ini
c:\windows\system32\uwimufez.ini
c:\windows\system32\uzuleluw.ini
c:\windows\system32\wonupago.exe
c:\windows\system32\wuleluzu.exe
c:\windows\zaponce53290.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_driverdrv
-------\Service_driverdrv


((((((((((((((((((((((((( Files Created from 2009-06-10 to 2009-07-10 )))))))))))))))))))))))))))))))
.

2009-07-10 06:44 . 2009-07-10 06:44 -------- d-----w- c:\windows\ERUNT
2009-07-10 06:33 . 2009-07-10 07:12 -------- d-----w- C:\SDFix
2009-06-29 03:45 . 2009-06-14 23:07 1004800 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-29 02:02 . 2009-06-29 02:02 -------- d-----w- c:\program files\uTorrent
2009-06-29 02:00 . 2009-07-10 07:32 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\uTorrent
2009-06-28 04:03 . 2009-06-28 04:03 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\AVG Security Toolbar
2009-06-27 17:07 . 2009-06-27 17:05 832144 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-27 17:06 . 2009-06-29 03:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2009-06-27 17:06 . 2009-06-27 17:06 -------- d-----w- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\AVGTOOLBAR
2009-06-17 18:42 . 2009-06-17 18:42 1 ---h--w- c:\windows\jmmark2.dat
2009-06-17 18:41 . 2009-06-17 18:41 1 ---h--w- c:\windows\bf23567.dat
2009-06-17 18:40 . 2009-06-17 18:40 2 ----a-w- c:\windows\104116116112584747.dat
2009-06-15 18:39 . 2009-06-15 18:39 19914 --sh--w- c:\windows\system32\yukojuni.exe
2009-06-15 06:22 . 2009-06-15 06:22 159 ----a-w- C:\d45.bat
2009-06-12 01:37 . 2009-06-12 01:37 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\ghanorhd
2009-06-12 01:37 . 2009-06-12 01:37 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\ghanorhd

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-10 05:04 . 2009-04-10 05:04 84480 --sha-w- c:\windows\system32\nehakite.dll
2009-07-09 17:04 . 2009-04-09 17:04 83456 --sha-w- c:\windows\system32\fajohiti.dll
2009-07-09 05:04 . 2009-04-09 05:04 83456 --sha-w- c:\windows\system32\fabapufu.dll
2009-07-07 16:58 . 2009-04-07 16:58 714789 --sha-w- c:\windows\system32\zodofigu.exe
2009-07-06 23:41 . 2006-08-18 17:24 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\LimeWire
2009-07-06 19:28 . 2009-04-22 18:29 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2009-07-06 07:56 . 2009-04-06 07:56 84480 --sha-w- c:\windows\system32\rurimita.dll
2009-07-06 07:56 . 2009-04-06 07:56 79360 --sha-w- c:\windows\system32\yedibufo.dll
2009-07-06 06:51 . 2009-04-06 06:51 79360 ------w- c:\windows\system32\gekujoni.dll
2009-07-06 06:51 . 2009-04-06 06:51 84480 --sha-w- c:\windows\system32\juyarono.dll
2009-07-06 06:28 . 2009-04-06 06:28 84480 --sha-w- c:\windows\system32\wegureju.dll
2009-07-06 06:28 . 2009-04-06 06:28 79360 ------w- c:\windows\system32\yodejetu.dll
2009-07-06 06:06 . 2009-04-06 06:06 79360 ------w- c:\windows\system32\nofomofi.dll
2009-07-06 06:06 . 2009-04-06 06:06 83456 --sha-w- c:\windows\system32\wifowigu.dll
2009-07-05 17:47 . 2009-04-05 17:47 80384 --sha-w- c:\windows\system32\feyimupa.dll
2009-07-05 03:59 . 2009-04-05 03:59 83456 --sha-w- c:\windows\system32\robudiki.dll
2009-06-27 17:05 . 2009-05-09 06:05 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-27 17:05 . 2009-05-09 06:05 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-27 17:05 . 2009-05-09 06:05 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-17 04:52 . 2009-05-09 06:05 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\AVGTOOLBAR
2009-06-15 06:38 . 2003-07-16 16:43 577536 ----a-w- c:\windows\system32\user32.dll
2009-06-15 06:31 . 2003-07-16 16:31 182912 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-06-10 23:25 . 2009-03-10 23:25 49664 --sha-w- c:\windows\system32\maremapa.dll
2009-06-08 21:49 . 2009-06-08 20:18 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\91888116
2009-06-08 21:49 . 2009-06-08 20:18 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\11878124
2009-06-08 06:07 . 2004-06-18 16:57 24272 ----a-w- c:\documents and settings\Administrator.PARTSCOMPUTER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-05 18:06 . 2009-05-06 22:18 0 ----a-w- c:\windows\system32\drivers\c356b783.sys
2009-06-04 17:40 . 2004-05-20 14:22 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\MSN6
2009-05-25 21:30 . 2009-04-22 18:34 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-05-21 05:45 . 2009-05-09 18:12 0 ----a-w- c:\windows\system32\drivers\77c211ee.sys
2009-05-11 21:33 . 2006-12-07 17:05 -------- d-----w- c:\program files\DDBPlayer
2009-05-11 21:31 . 2004-11-02 16:27 -------- d-----w- c:\program files\Real
2009-05-11 21:31 . 2004-11-02 16:27 -------- d-----w- c:\program files\Common Files\Real
2009-05-11 21:24 . 2008-04-11 06:06 -------- d-----w- c:\program files\Microsoft Games
2009-05-11 21:22 . 2004-05-20 18:04 -------- d-----w- c:\program files\Almyta
2009-05-11 21:18 . 2007-06-12 21:09 -------- d-----w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\Yahoo!
2009-05-11 21:18 . 2007-06-04 20:41 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Yahoo!
2009-05-11 21:12 . 2006-11-07 23:30 -------- d-----w- c:\program files\Yahoo!
2009-05-11 20:02 . 2004-05-18 18:47 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-09 18:12 . 2009-05-09 18:12 14336 ----a-w- c:\windows\system32\OLD82.tmp
2009-05-09 06:05 . 2009-05-09 06:05 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-22 19:38 . 2009-04-22 19:38 390664 ----a-w- c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-04-14 21:07 . 2009-04-14 21:07 75048 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-03-10 23:26 . 2009-03-10 23:26 49664 --sha-w- c:\windows\SYSTEM32\ruvaluno.dll
2009-03-10 23:26 . 2009-03-10 23:26 49664 --sha-w- c:\windows\SYSTEM32\vuvimuwe.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-15_06.42.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-31 16:56 . 2009-03-06 06:59 36864 c:\windows\SYSTEM32\DRIVERS\usbaapl.sys
+ 2004-05-15 00:08 . 2009-07-05 17:46 49152 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2004-05-15 00:08 . 2009-06-15 06:22 49152 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2005-06-20 18:00 . 2005-06-20 18:00 84992 c:\windows\Installer\641162.msi
+ 2006-01-28 16:24 . 2006-01-28 16:24 20480 c:\windows\Installer\3687e98.msi
- 2004-05-15 00:08 . 2009-06-15 06:22 868352 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-05-15 00:08 . 2009-07-05 17:46 868352 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-05-15 00:08 . 2009-07-05 17:46 245760 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-05-15 00:08 . 2009-06-15 06:22 245760 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-22 02:20 . 2008-04-22 02:20 130560 c:\windows\Installer\f8c2c0.msi
+ 2008-04-22 02:19 . 2008-04-22 02:19 130048 c:\windows\Installer\f8c2bb.msi
+ 2008-04-22 02:19 . 2008-04-22 02:19 133632 c:\windows\Installer\f8c2b6.msi
+ 2008-04-22 02:19 . 2008-04-22 02:19 327680 c:\windows\Installer\f8c2b1.msi
+ 2007-10-25 16:23 . 2007-10-25 16:23 131072 c:\windows\Installer\e811.msi
+ 2007-10-25 16:23 . 2007-10-25 16:23 131072 c:\windows\Installer\e80c.msi
+ 2007-10-25 16:22 . 2007-10-25 16:22 130048 c:\windows\Installer\e807.msi
+ 2007-10-25 16:22 . 2007-10-25 16:22 327680 c:\windows\Installer\e802.msi
+ 2007-03-02 17:44 . 2007-03-02 17:44 344064 c:\windows\Installer\dfe9a71.msi
+ 2008-06-22 07:16 . 2008-06-22 07:16 289792 c:\windows\Installer\c6a385.msi
+ 2006-11-29 22:11 . 2006-11-29 22:11 312320 c:\windows\Installer\b9cf808.msi
+ 2008-09-03 23:17 . 2008-09-03 23:17 184832 c:\windows\Installer\a9648.msi
+ 2005-10-18 22:41 . 2005-10-18 22:41 509952 c:\windows\Installer\6d397e8.msi
+ 2005-06-20 18:00 . 2005-06-20 18:00 123904 c:\windows\Installer\641158.msi
+ 2005-06-20 17:59 . 2005-06-20 17:59 249344 c:\windows\Installer\641153.msi
+ 2005-06-20 17:59 . 2005-06-20 17:59 309248 c:\windows\Installer\64114e.msi
+ 2005-06-20 17:59 . 2005-06-20 17:59 193024 c:\windows\Installer\641116.msi
+ 2005-06-20 17:58 . 2005-06-20 17:58 394752 c:\windows\Installer\6410fe.msi
+ 2005-06-20 17:58 . 2005-06-20 17:58 265216 c:\windows\Installer\6410f6.msi
+ 2005-06-20 17:58 . 2005-06-20 17:58 130048 c:\windows\Installer\6410f1.msi
+ 2005-06-20 17:58 . 2005-06-20 17:58 363520 c:\windows\Installer\6410ec.msi
+ 2005-06-20 17:58 . 2005-06-20 17:58 445440 c:\windows\Installer\6410e7.msi
+ 2005-07-01 15:47 . 2005-07-01 15:47 375296 c:\windows\Installer\54bf647.msi
+ 2005-07-01 15:47 . 2005-07-01 15:47 377344 c:\windows\Installer\54bf63f.msi
+ 2007-05-03 17:20 . 2007-05-03 17:20 188928 c:\windows\Installer\51287d83.msi
+ 2008-07-17 17:52 . 2008-07-17 17:52 532992 c:\windows\Installer\5121950.msi
+ 2007-10-24 16:15 . 2007-10-24 16:15 129024 c:\windows\Installer\3f41d.msi
+ 2007-10-24 16:15 . 2007-10-24 16:15 502784 c:\windows\Installer\3f3ff.msi
+ 2007-10-24 16:14 . 2007-10-24 16:14 540672 c:\windows\Installer\3f3fa.msi
+ 2007-10-24 16:14 . 2007-10-24 16:14 501248 c:\windows\Installer\3f3f5.msi
+ 2007-10-24 16:14 . 2007-10-24 16:14 130560 c:\windows\Installer\3f3f0.msi
+ 2007-10-24 16:14 . 2007-10-24 16:14 501248 c:\windows\Installer\3f3eb.msi
+ 2007-10-24 16:14 . 2007-10-24 16:14 339968 c:\windows\Installer\3f3e3.msi
+ 2007-10-24 16:12 . 2007-10-24 16:12 209920 c:\windows\Installer\3f20c.msi
+ 2008-09-04 00:06 . 2008-09-04 00:06 184832 c:\windows\Installer\380dce.msi
+ 2009-04-22 19:15 . 2009-04-22 19:15 152576 c:\windows\Installer\352750.msi
+ 2004-05-19 17:32 . 2004-05-19 17:32 621056 c:\windows\Installer\2fafec.msi
+ 2009-05-09 05:24 . 2009-05-09 05:24 337408 c:\windows\Installer\28e40c9.msi
+ 2008-12-02 21:56 . 2008-12-02 21:56 891392 c:\windows\Installer\26ca9d.msi
+ 2005-10-06 15:41 . 2005-10-06 15:41 313856 c:\windows\Installer\242ac65c.msi
+ 2006-04-24 15:24 . 2006-04-24 15:24 258048 c:\windows\Installer\1d274224.msi
+ 2004-05-15 00:09 . 2004-05-15 00:09 264704 c:\windows\Installer\10783.msi
+ 2009-07-10 06:44 . 2009-07-10 06:44 266240 c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2009-07-10 06:44 . 2008-08-07 22:27 163328 c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2009-07-10 06:45 . 2009-07-10 06:45 266240 c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2009-07-10 06:45 . 2008-08-07 22:27 163328 c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2006-01-13 18:09 . 2005-04-04 09:07 982016 c:\windows\Downloaded Installations\{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5}\ISScript11.Msi
+ 2003-07-16 16:44 . 2004-07-17 18:35 1326080 c:\windows\SYSTEM32\webfldrs.msi
+ 2009-03-14 16:37 . 2009-03-06 06:59 1900544 c:\windows\SYSTEM32\usbaaplrc.dll
+ 2004-09-21 21:34 . 2004-07-17 18:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2007-05-25 19:08 . 2007-05-25 19:08 9609728 c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp
+ 2008-04-11 04:47 . 2008-04-11 04:47 3620864 c:\windows\Installer\b9ea.msi
+ 2009-01-06 23:22 . 2009-01-06 23:22 1013248 c:\windows\Installer\b511c5.msi
+ 2009-03-14 16:41 . 2009-03-14 16:41 8992256 c:\windows\Installer\aa8ec.msi
+ 2009-04-21 20:29 . 2009-04-21 20:29 1541120 c:\windows\Installer\978699.msi
+ 2004-05-20 00:25 . 2004-10-26 20:44 3777536 c:\windows\Installer\6d45fc.msi
+ 2004-05-20 00:13 . 2004-05-20 00:13 4408832 c:\windows\Installer\6d4409.msi
+ 2006-01-28 18:20 . 2006-01-28 18:20 5864960 c:\windows\Installer\64184a.msp
+ 2005-06-20 17:59 . 2005-06-20 17:59 1217536 c:\windows\Installer\641139.msi
+ 2005-06-20 17:55 . 2005-06-20 17:55 3443712 c:\windows\Installer\6410b7.msi
+ 2009-04-14 21:29 . 2009-04-14 21:29 3966976 c:\windows\Installer\5c9c9d6.msi
+ 2009-04-14 21:26 . 2009-04-14 21:26 3293696 c:\windows\Installer\5c9c69d.msi
+ 2007-10-24 16:15 . 2007-10-24 16:15 1179648 c:\windows\Installer\3f404.msi
+ 2008-08-13 19:06 . 2008-08-13 19:06 1549312 c:\windows\Installer\2c2a76.msi
+ 2007-11-02 17:54 . 2007-11-02 17:54 3558912 c:\windows\Installer\2985537c.msi
+ 2009-01-21 06:59 . 2009-01-21 06:59 1602560 c:\windows\Installer\289d767.msi
+ 2009-04-06 05:34 . 2009-04-06 05:34 5885952 c:\windows\Installer\26d1ff2.msi
+ 2008-12-27 05:01 . 2008-12-27 05:01 2109440 c:\windows\Installer\24f858e.msi
+ 2005-06-20 17:53 . 2005-06-20 17:53 2220544 c:\windows\Hewlett-Packard\Setup Files\HP Software Update\{BB4EE741-CA46-4345-A3B7-1AECBFAB0AFE}\HP Software Update.msi
+ 2009-07-10 06:44 . 2009-07-10 06:44 7749632 c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2009-07-10 06:44 . 2009-07-10 06:45 7749632 c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2006-01-13 18:09 . 2005-12-21 19:57 9934848 c:\windows\Downloaded Installations\{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5}\iTunes.msi
+ 2007-11-02 17:51 . 2007-11-02 17:51 8581632 c:\windows\Downloaded Installations\{3E547985-AA94-4B1B-8ADD-21E060E5E31F}\Adobe Photoshop Album 3.2 SE.msi
+ 2004-09-21 21:27 . 2003-07-16 16:44 1325568 c:\windows\$NtServicePackUninstall$\webfldrs.msi
+ 2005-09-23 15:48 . 2005-09-23 15:48 24863744 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\netfx.msi
+ 2005-06-20 17:57 . 2005-06-20 17:57 16367616 c:\windows\Installer\6410d1.msi
+ 2007-07-17 15:10 . 2007-07-17 15:10 15256576 c:\windows\Installer\47bd20dd.msp
+ 2007-10-24 16:14 . 2007-10-24 16:14 16309248 c:\windows\Installer\3f3d0.msi
+ 2006-01-28 16:29 . 2006-01-28 16:29 19210240 c:\windows\Installer\3687ee1.msp
+ 2003-11-04 07:41 . 2003-11-04 07:41 19963904 c:\windows\Installer\1438e1d.msp
+ 2004-05-21 15:15 . 2004-05-21 15:15 19479040 c:\windows\Downloaded Installations\{E83562AD-CFFD-4E8B-841F-6B60B5AC2496}\iTunes.msi
+ 2006-01-27 16:22 . 2006-01-27 16:22 33979904 c:\windows\Downloaded Installations\{00C2E789-F948-4BE1-8167-6E6447DC4CE2}\iPod for Windows 2006-01-10.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6ced5bad-6afb-44f1-90ce-451e61b9b8c9}]
2009-03-10 23:26 49664 --sha-w- c:\windows\SYSTEM32\ruvaluno.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 23:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-06-29 288048]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-19 2356088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avg8_tray"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-27 1948440]
"bimafupika"="c:\windows\system32\vuvimuwe.dll" [2009-03-10 49664]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"CPMa7fcf994"="c:\windows\system32\nehakite.dll" [2009-07-10 84480]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\SYSTEM32\narrator.exe [2004-08-04 53760]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\nehakite.dll" [2009-07-10 84480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\nehakite.dll [2009-07-10 84480]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-27 17:05 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKLM\~\startupfolder\c:^documents and settings^all users.windows^start menu^programs^startup^acrobat assistant.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\c:^documents and settings^all users.windows^start menu^programs^startup^hp digital imaging monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"MDM"=2 (0x2)
"iPod Service"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"fci"=2 (0x2)
"bndmss"=2 (0x2)
"BITS"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Adobe LM Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires\\EMPIRESX.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\SYSTEM32\\hpzipm12.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgtray.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\SYSTEM32\\wscntfy.exe"=
"c:\\WINDOWS\\explorer.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:driver

R1 avgldx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [5/8/2009 11:05 PM 327688]
R1 avgtdix;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [5/8/2009 11:05 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/8/2009 11:04 PM 298776]
S1 4127bab8;4127bab8;c:\windows\system32\drivers\4127bab8.sys --> c:\windows\system32\drivers\4127bab8.sys [?]
S1 77c211ee;77c211ee;c:\windows\SYSTEM32\DRIVERS\77c211ee.sys [5/9/2009 11:12 AM 0]
S1 b40de6f4;b40de6f4;c:\windows\system32\drivers\b40de6f4.sys --> c:\windows\system32\drivers\b40de6f4.sys [?]
S1 b4689307;b4689307;c:\windows\system32\drivers\b4689307.sys --> c:\windows\system32\drivers\b4689307.sys [?]
S1 c33b18e9;c33b18e9;c:\windows\system32\drivers\c33b18e9.sys --> c:\windows\system32\drivers\c33b18e9.sys [?]
S1 c356b783;c356b783;c:\windows\SYSTEM32\DRIVERS\c356b783.sys [5/6/2009 3:18 PM 0]
S1 d058583c;d058583c;c:\windows\system32\drivers\d058583c.sys --> c:\windows\system32\drivers\d058583c.sys [?]
S1 d170b3c1;d170b3c1;c:\windows\system32\drivers\d170b3c1.sys --> c:\windows\system32\drivers\d170b3c1.sys [?]
S1 e21c929a;e21c929a;c:\windows\system32\drivers\e21c929a.sys --> c:\windows\system32\drivers\e21c929a.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 19:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{0feb365c-dce7-47d2-a5a7-763fa116869a} - (no file)
HKLM-Run-a4cfca08 - c:\windows\system32\redivipo.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://msn.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
FF - ProfilePath - c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\Mozilla\Firefox\Profiles\t2d7wq9d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Administrator.PARTSCOMPUTER\Application Data\Mozilla\Firefox\Profiles\t2d7wq9d.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071102000005.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-10 00:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3136)
c:\windows\system32\vuvimuwe.dll
c:\windows\system32\nehakite.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Completion time: 2009-07-10 0:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-10 07:42
ComboFix2.txt 2009-06-15 06:51

Pre-Run: 5,429,927,936 bytes free
Post-Run: 5,391,306,752 bytes free

547 --- E O F --- 2009-03-25 10:00

#12 User is offline   shelf life 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 1,366
  • Joined: 06-November 08
  • Gender:Male
  • Location:@localhost

Posted 10 July 2009 - 06:34 PM

hi,

ok thanks for all the info. I would still consider a reformat/reinstall. this may take several attempts to get the machine clean. We will use combofix again, then get another download which you can keep and use as a anti-malware solution. your torrent client and limewire are potential sources of malware. FYI: there is plenty of malware distributed via p2p networks that one can download and install.

Click Start, then Run and type Notepad and click OK.
Copy/paste the text in the code box below into notepad:

File::
c:\windows\system32\yukojuni.exe
C:\d45.bat
c:\windows\system32\nehakite.dll
c:\windows\system32\fajohiti.dll
c:\windows\system32\fabapufu.dll
c:\windows\system32\zodofigu.exe
c:\windows\system32\rurimita.dll
c:\windows\system32\yedibufo.dll
c:\windows\system32\gekujoni.dll
c:\windows\system32\juyarono.dll
c:\windows\system32\wegureju.dll
c:\windows\system32\yodejetu.dll
c:\windows\system32\nofomofi.dll
c:\windows\system32\wifowigu.dll
c:\windows\system32\feyimupa.dll
c:\windows\system32\robudiki.dll
c:\windows\system32\maremapa.dl
c:\windows\SYSTEM32\ruvaluno.dll
c:\windows\SYSTEM32\vuvimuwe.dll
c:\windows\system32\nehakite.dll

Driver::
4127bab8
77c211ee
b40de6f4
b4689307
c33b18e9
c356b783
d058583c
d170b3c1
e21c929a

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6ced5bad-6afb-44f1-90ce-451e61b9b8c9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"bimafupika"="-
"CPMa7fcf994"=-


Name the Notepad file CFScript.txt and Save it to your desktop.
now locate the file you just saved and the combofix icon, both on your desktop
using your mouse drag the CFScript right on top of the combofix icon and release, combofix will run and produce a new log.
Please post the new combofix log.

After combofix is done download and run Malwarebytes. Link and directions:


Please download Malwarebytes' Anti-Malware (MBAM) to your desktop:

http://www.malwarebytes.org/mbam.php

Double-click mbam-setup.exe and follow the prompts to install the program.

Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded, select Perform FULL SCAN, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.

Be sure that everything is checked, and click **Remove Selected.**

**A restart of your computer most likely will be required to remove some items.**

When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

Post the log in your reply.
Is It Real or ScareWare?
How Can I Reduce My Risk.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users