Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan viruses wont go away!


  • This topic is locked This topic is locked
11 replies to this topic

#1 Johnoh123

Johnoh123

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 28 December 2008 - 01:07 AM

Hello good people . everytime i connect to the web i get popups of virus removal programs and alot of other random things , and i have tried deleting these trojans in safe mode and alot of other ways ive tried. i think its also playing with my computer and its changing settings and its getting pretty annoying please help!

Note: member cannot download DDS-garmanma

this is my "Hijackthis" log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:05:58 PM, on 28/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\NOTEPAD.EXE

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7d4fd48e-6419-4d85-b627-57bd860c24ca} - C:\WINDOWS\system32\jepiliwu.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ALYac] "C:\Program Files\ESTsoft\ALYac\AYUpdate.exe" /run
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [a046bd3a] rundll32.exe "C:\WINDOWS\system32\rugozeko.dll",b
O4 - HKLM\..\Run: [CPMa3758ea6] Rundll32.exe "c:\windows\system32\sonosuje.dll",a
O4 - HKLM\..\Run: [tineyitoru] Rundll32.exe "C:\WINDOWS\system32\bubedena.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O20 - AppInit_DLLs: c:\windows\system32\sonosuje.dll c:\windows\system32\kovihihi.dll,C:\WINDOWS\system32\vurotipe.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sonosuje.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sonosuje.dll
O23 - Service: ALYac_PZSrv - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)

--
End of file - 8133 bytes

Edited by garmanma, 28 December 2008 - 10:21 AM.


BC AdBot (Login to Remove)

 


#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:10:30 PM

Posted 03 January 2009 - 10:26 PM

Hello, Johnoh123
:thumbsup: to BleepingComputer.com

My name is Billy O'Neal and I will be helping you. (Billy or Bill is fine, if you like.)
Please give me some time to look over your computer's log(s).
Please take note of the following:
  • In the meantime, please refrain from making any changes to your computer.
  • Also, even if things appear to be running better, there is no guarantee that everything is finished. Please continue to check this forum post in order to ensure we get your system completely clean. We do not want to clean you part-way up, only to have the system re-infect itself. :)
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Finally, please reply using the Posted Image button in the lower left hand corner of your screen.
We Need to Run ComboFix

Note to readers of this post other than the starter of this thread:
ComboFix is a VERY POWERFUL tool which should NOT BE USED without guidance of an expert.

If this tool helped you, please consider a donation to it's author: Posted Image

How to run ComboFix:
  • Please download ComboFix from one of the following mirrors, and save it to your desktop.
  • Disable any running Anti-Virus or Anti-Malware programs. This includes Firewalls, Anti-Virus, Spyware Scanners, etc. Any or all of them may interfere with the running of ComboFix.
  • Double click Posted Image on your desktop.
  • Read and accept (Press Yes) to the disclaimer.
  • For Windows XP Systems: Install the Recovery Console:
    • If you are using Windows XP and do not already have the Recovery Console installed, please ensure your internet connection is active (if possible), and press Yes. If for some reason your internet is not working, please press No. If you are not using Windows XP, you will not be prompted.
    • When prompted to accept the EULA, press OK.
    • Accept Microsoft's EULA (Press Yes).
    • When you are told that the RC is installed correctly, please press YES to continue scanning for malware.
  • ComboFix will run. Simply wait for it to finish.
  • When it finishes, ComboFix will produce a log. Please post that log in your next reply here :)
NOTE: If ComboFix will not run, please rename it to GlobRemover.exe and try again!

In your next reply, please include the following:
  • ComboFix.txt

BillyIII
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#3 Johnoh123

Johnoh123
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 04 January 2009 - 04:05 AM

Hey bill thanks for coming to my rescue :thumbsup:

one problem i have not got Recovery Console Installed on my Windows XP computer , and i ran the ComboFix without having it installed , is that too much of a problem? and is it essential to install it , if then where can i get it?

And heres the Log thanks again , ill be waiting for the reply! :)


ComboFix 09-01-02.01 - user 2009-01-04 19:52:34.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.949.82.1033.18.502.245 [GMT 11:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
AV: 알약 *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\bemuwafe.dll
c:\windows\system32\beziseno.dll
c:\windows\system32\bizoyuza.dll
c:\windows\system32\bowikiku.dll
c:\windows\system32\dadutiwo.dll
c:\windows\system32\detujedu.dll
c:\windows\system32\dirupahu.dll
c:\windows\system32\fafivolo.dll
c:\windows\system32\fapilizu.dll
c:\windows\system32\faviheki.dll
c:\windows\system32\fawuruvo.dll
c:\windows\system32\fefirifu.dll
c:\windows\system32\feyujafi.dll
c:\windows\system32\gadonesi.dll
c:\windows\system32\hakolike.dll
c:\windows\system32\hegiguve.dll
c:\windows\system32\hilijizi.dll
c:\windows\system32\jadebaji.dll
c:\windows\system32\jakegetu.dll
c:\windows\system32\joredoma.dll
c:\windows\system32\kilatape.dll
c:\windows\system32\kobitaka.dll
c:\windows\system32\kovihihi.dll
c:\windows\system32\kumenelo.dll
c:\windows\system32\kuvarilo.dll
c:\windows\system32\ledanozo.dll
c:\windows\system32\limereju.dll
c:\windows\system32\liwifina.dll
c:\windows\system32\logozama.dll
c:\windows\system32\mapatawa.dll
c:\windows\system32\mayotomo.dll
c:\windows\system32\miluduri.dll
c:\windows\system32\mojeluru.dll
c:\windows\system32\nopihizu.dll
c:\windows\system32\pibovijo.dll
c:\windows\system32\pikumivu.dll
c:\windows\system32\pujosove.dll
c:\windows\system32\puvipezi.dll
c:\windows\system32\rabawehe.dll
c:\windows\system32\raramuge.dll
c:\windows\system32\rerurepo.dll
c:\windows\system32\reyusosu.dll
c:\windows\system32\rimozinu.dll
c:\windows\system32\ririzaki.dll
c:\windows\system32\rogahefa.dll
c:\windows\system32\roloropo.dll
c:\windows\system32\rowopapo.dll
c:\windows\system32\royazava.dll
c:\windows\system32\rudajeki.dll
c:\windows\system32\rugozeko.dll
c:\windows\system32\ruvaluno.dll
c:\windows\system32\senozama.dll
c:\windows\system32\siyojama.dll
c:\windows\system32\subapade.dll
c:\windows\system32\tadebava.dll
c:\windows\system32\tatoluya.dll
c:\windows\system32\telelepu.dll
c:\windows\system32\torazovi.dll
c:\windows\system32\turenugu.dll
c:\windows\system32\tuzakupe.dll
c:\windows\system32\veyopiho.dll
c:\windows\system32\vihokaso.dll
c:\windows\system32\visoboja.dll
c:\windows\system32\vonowiya.dll
c:\windows\system32\vozigoji.dll
c:\windows\system32\wobebupi.dll
c:\windows\system32\yekotafo.dll
c:\windows\system32\yitefuko.dll
c:\windows\system32\yitofoyi.dll
c:\windows\system32\yiyawefo.dll
c:\windows\system32\yizofuyu.dll
c:\windows\system32\yolufeta.dll
c:\windows\system32\yukosiji.dll
c:\windows\system32\zerefugu.dll
c:\windows\system32\zikubupa.dll
c:\windows\system32\zipuhovo.dll
c:\windows\system32\zoyulolu.dll
c:\windows\system32\zukogulu.dll

----- BITS: Possible infected sites -----

hxxp://77.74.48.105
.
((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 )))))))))))))))))))))))))))))))
.

2009-01-04 11:46 . 2009-01-04 11:46 1,266,209 ---hs---- c:\windows\system32\apubukiz.ini
2009-01-03 11:14 . 2009-01-03 11:14 1,266,209 ---hs---- c:\windows\system32\onesizeb.ini
2009-01-03 10:16 . 2009-01-03 10:16 1,266,209 ---hs---- c:\windows\system32\amajoyis.ini
2009-01-02 14:06 . 2009-01-02 14:06 1,266,209 ---hs---- c:\windows\system32\ojivobip.ini
2009-01-02 00:26 . 2009-01-02 00:26 1,266,209 ---hs---- c:\windows\system32\ipubebow.ini
2009-01-01 09:50 . 2009-01-01 09:50 1,266,209 ---hs---- c:\windows\system32\ufirifef.ini
2008-12-31 13:36 . 2008-12-31 13:36 1,266,209 ---hs---- c:\windows\system32\olovifaf.ini
2008-12-31 00:41 . 2008-12-31 00:42 1,266,767 ---hs---- c:\windows\system32\ukikiwob.ini
2008-12-30 12:42 . 2008-12-30 20:41 1,266,776 ---hs---- c:\windows\system32\evosojup.ini
2008-12-30 12:37 . 2008-12-30 12:37 2,713 ---hs---- c:\windows\system32\hagatogo.dll
2008-12-29 23:01 . 2008-12-30 12:41 1,266,767 ---hs---- c:\windows\system32\operurer.ini
2008-12-29 11:02 . 2008-12-29 11:02 1,265,838 ---hs---- c:\windows\system32\odewohis.ini
2008-12-28 16:02 . 2008-12-28 16:02 1,265,838 ---hs---- c:\windows\system32\okezogur.ini
2008-12-27 22:30 . 2008-12-27 22:31 1,258,203 ---hs---- c:\windows\system32\uloluyoz.ini
2008-12-27 20:06 . 2008-12-27 20:06 <DIR> d-------- c:\program files\Trend Micro
2008-12-27 17:37 . 2008-12-31 01:15 <DIR> d-------- c:\documents and settings\user\Application Data\My Battle for Middle-earth™ II Files
2008-12-27 17:04 . 2008-12-27 17:04 <DIR> d-------- c:\program files\Electronic Arts
2008-12-27 10:36 . 2008-12-27 10:37 1,258,186 ---hs---- c:\windows\system32\oliravuk.ini
2008-12-26 21:10 . 2008-12-26 22:07 1,606,281 ---hs---- c:\windows\system32\upelelet.ini
2008-12-26 09:09 . 2008-12-26 09:09 2,713 ---hs---- c:\windows\system32\loyayono.dll
2008-12-26 09:09 . 2008-12-26 09:09 2,713 ---hs---- c:\windows\system32\fukafati.dll
2008-12-25 15:10 . 2008-12-26 17:47 1,606,281 ---hs---- c:\windows\system32\otugebub.ini
2008-12-25 00:11 . 2008-12-25 00:11 1,606,245 ---hs---- c:\windows\system32\ehepegop.ini
2008-12-24 12:09 . 2008-12-24 12:09 1,606,245 ---hs---- c:\windows\system32\iyejuzob.ini
2008-12-24 00:08 . 2008-12-24 00:08 1,606,245 ---hs---- c:\windows\system32\izedobaw.ini
2008-12-23 11:09 . 2008-12-23 11:10 121 ---hs---- c:\windows\system32\ajebufeg.ini
2008-12-22 22:24 . 2008-12-22 22:24 1,606,245 ---hs---- c:\windows\system32\akihiveb.ini
2008-12-22 10:25 . 2008-12-22 10:25 1,606,245 ---hs---- c:\windows\system32\arovugum.ini
2008-12-21 14:48 . 2008-12-21 14:48 1,606,245 ---hs---- c:\windows\system32\olenemuk.ini
2008-12-20 12:47 . 2008-12-20 12:47 1,606,245 ---hs---- c:\windows\system32\aguyinah.ini
2008-12-19 12:05 . 2008-12-19 12:05 1,606,245 ---hs---- c:\windows\system32\etojisay.ini
2008-12-18 11:32 . 2008-12-18 11:33 1,602,497 ---hs---- c:\windows\system32\izebazab.ini
2008-12-17 22:17 . 2008-12-27 18:08 664 --a------ c:\windows\system32\d3d9caps.dat
2008-12-17 18:29 . 2008-12-17 18:29 120 ---hs---- c:\windows\system32\evugigeh.ini
2008-12-17 09:02 . 2008-12-17 09:02 120 ---hs---- c:\windows\system32\atayubig.ini
2008-12-16 08:41 . 2008-12-17 18:29 1,587,388 ---hs---- c:\windows\system32\amazogol.ini
2008-12-15 09:55 . 2008-12-15 09:55 1,588,267 ---hs---- c:\windows\system32\uzewigor.ini
2008-12-14 15:23 . 2008-12-14 15:24 1,588,267 ---hs---- c:\windows\system32\uwikifap.ini
2008-12-13 13:38 . 2008-12-13 13:38 552 --a------ c:\windows\system32\d3d8caps.dat
2008-12-13 13:14 . 2008-12-13 13:14 1,583,225 ---hs---- c:\windows\system32\ugunerut.ini
2008-12-12 21:42 . 2008-12-12 21:42 1,567,958 ---hs---- c:\windows\system32\edihonay.ini
2008-12-12 09:42 . 2008-12-12 09:42 1,565,519 ---hs---- c:\windows\system32\izahadur.ini
2008-12-11 12:01 . 2008-12-11 12:01 <DIR> d-------- c:\program files\EA GAMES
2008-12-11 11:18 . 2008-12-11 11:18 1,527,414 ---hs---- c:\windows\system32\emolusov.ini
2008-12-10 23:15 . 2008-12-10 23:15 1,492,974 ---hs---- c:\windows\system32\ijisokuy.ini
2008-12-10 22:26 . 2008-12-10 22:26 <DIR> d-------- c:\program files\EA SPORTS
2008-12-10 11:14 . 2008-12-10 11:15 1,492,136 ---hs---- c:\windows\system32\ovuruwaf.ini
2008-12-09 23:14 . 2008-12-09 23:14 1,470,836 ---hs---- c:\windows\system32\ovohupiz.ini
2008-12-09 11:15 . 2008-12-09 11:15 1,470,836 ---hs---- c:\windows\system32\uhehojos.ini
2008-12-08 19:29 . 2008-12-08 19:29 1,426,874 ---hs---- c:\windows\system32\ivozarot.ini
2008-12-08 01:09 . 2008-12-08 01:09 1,426,874 ---hs---- c:\windows\system32\uzilipaf.ini
2008-12-07 17:40 . 2008-12-07 17:40 1,364 --a------ c:\windows\16331531.cvr
2008-12-07 13:10 . 2008-12-07 13:10 1,426,874 ---hs---- c:\windows\system32\afosumin.ini
2008-12-06 11:47 . 2008-12-06 11:47 1,428,719 ---hs---- c:\windows\system32\oporolor.ini
2008-12-05 22:50 . 2008-12-05 22:50 1,428,719 ---hs---- c:\windows\system32\otorezun.ini
2008-12-04 21:57 . 2008-12-04 21:57 1,374,462 ---hs---- c:\windows\system32\azihufof.ini
2008-12-04 09:56 . 2008-12-04 09:57 1,385,606 ---hs---- c:\windows\system32\idufatap.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-23 07:17 --------- d-----w c:\program files\Symantec AntiVirus
2008-12-23 07:17 --------- d-----w c:\program files\Symantec
2008-12-23 07:17 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-23 07:17 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-01 10:47 --------- d-----w c:\documents and settings\Administrator\Application Data\EstSoft
2008-11-28 08:07 --------- d-----w c:\program files\Google
2008-11-28 08:05 --------- d-----w c:\program files\Common Files\AVSMedia
2008-11-28 08:05 --------- d-----w c:\program files\AVS4YOU
2008-11-21 11:17 --------- d-----w c:\program files\Common Files\DVDVideoSoft
2008-11-21 11:16 --------- d-----w c:\program files\DVDVideoSoft
2008-11-06 10:56 --------- d-----w c:\documents and settings\user\Application Data\LimeWire
2008-09-10 02:49 5,817,064 ----a-w c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2006-05-03 09:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2008-09-05 23:47 88,064 --sha-w c:\windows\system32\lejorude.dll
2008-08-28 08:00 2,048 --sha-w c:\windows\system32\lenodanu.dll
2008-09-24 13:08 15,360 --sha-w c:\windows\system32\mejeweme.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2008-03-16 12:30 216,064 --sh--r c:\windows\system32\nbDX.dll
1601-01-01 00:12 28,672 --sha-w c:\windows\system32\pajohebu.dll
2008-09-23 12:07 9,216 --sha-w c:\windows\system32\serevudo.dll
2008-09-03 10:56 62,976 --sha-w c:\windows\system32\sesimuvi.dll
2008-09-03 10:56 62,976 --sha-w c:\windows\system32\zidewomi.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"ALYac"="c:\program files\ESTsoft\ALYac\AYUpdate.exe" [2008-01-11 79304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2008-01-11 39792]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2007-05-11 738968]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\ESTsoft\\ALYac\\AYAgent.aye"=
"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\ESTsoft\\ALYac\\AYServiceNT.aye"=
"c:\\WINDOWS\\system32\\imapi.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2967:TCP"= 2967:TCP:Symantec RTVScan
"1024:TCP"= 1024:TCP:Symantec Management

R3 AYDrvSP_ALYAC;AYDrvSP_ALYAC;c:\program files\ESTsoft\ALYac\AYDrvSP.sys [2008-12-04 23288]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2008-08-06 20160]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
\Shell\AutoRun\command - Z:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder

2008-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 18:57]
.
- - - - ORPHANS REMOVED - - - -

BHO-{7d4fd48e-6419-4d85-b627-57bd860c24ca} - c:\windows\system32\pikumivu.dll
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKCU-Run-ares - c:\program files\Ares\Ares.exe
HKLM-Run-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe


.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
.
.
------- File Associations -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-04 19:58:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ALYac_PZSrv]
"ImagePath"="c:\program files\ESTsoft\ALYac\AYServiceNt.aye"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\SUPER *NULL*]
"DisplayName"="SUPER ?Version 2008.bld.33 (Sep 2, 2008)"
"UninstallString"="c:\\PROGRA~1\\ERIGHT~1\\SUPER\\Setup.exe /remove /q0"
"InstallDate"="2008-10-10 21:59:09"
"InstallLocation"="c:\\Program Files\\eRightSoft\\SUPER"
"InstallSource"="c:\\Documents and Settings\\user\\Desktop"
"DisplayIcon"="c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"
"DisplayVersion"="Version 2008.bld.33 (Sep 2, 2008)"
"VersionMajor"=dword:00000000
"VersionMinor"=dword:00000000
"Publisher"="eRightSoft"
"HelpLink"="http://www.eRightSoft.com"
"URLInfoAbout"="http://www.eRightSoft.com"
"URLUpdateInfo"="http://www.eRightSoft.com"
"Contact"="support@eRightSoft.com"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\conime.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Completion time: 2009-01-04 20:00:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-04 09:00:07

Pre-Run: 24,408,723,456 bytes free
Post-Run: 24,709,197,824 bytes free

300 --- E O F --- 2008-12-30 08:13:36


#4 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:10:30 PM

Posted 04 January 2009 - 10:56 AM

Hello, Johnoh123

one problem i have not got Recovery Console Installed on my Windows XP computer , and i ran the ComboFix without having it installed , is that too much of a problem? and is it essential to install it , if then where can i get it?

CF will attempt to install it automaticly.

We need to re-run ComboFix with some additonal directives.
  • Please disable any running anti-virus programs.

    If you are unsure how to do this, see this topic: http://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the quotebox below into it:
    file::
    c:\windows\system32\apubukiz.ini
    c:\windows\system32\onesizeb.ini
    c:\windows\system32\amajoyis.ini
    c:\windows\system32\ojivobip.ini
    c:\windows\system32\ipubebow.ini
    c:\windows\system32\ufirifef.ini
    c:\windows\system32\olovifaf.ini
    c:\windows\system32\ukikiwob.ini
    c:\windows\system32\evosojup.ini
    c:\windows\system32\hagatogo.dll
    c:\windows\system32\operurer.ini
    c:\windows\system32\odewohis.ini
    c:\windows\system32\okezogur.ini
    c:\windows\system32\uloluyoz.ini
    c:\windows\system32\oliravuk.ini
    c:\windows\system32\upelelet.ini
    c:\windows\system32\loyayono.dll
    c:\windows\system32\fukafati.dll
    c:\windows\system32\otugebub.ini
    c:\windows\system32\ehepegop.ini
    c:\windows\system32\iyejuzob.ini
    c:\windows\system32\izedobaw.ini
    c:\windows\system32\ajebufeg.ini
    c:\windows\system32\akihiveb.ini
    c:\windows\system32\arovugum.ini
    c:\windows\system32\olenemuk.ini
    c:\windows\system32\aguyinah.ini
    c:\windows\system32\etojisay.ini
    c:\windows\system32\izebazab.ini
    c:\windows\system32\evugigeh.ini
    c:\windows\system32\atayubig.ini
    c:\windows\system32\amazogol.ini
    c:\windows\system32\uzewigor.ini
    c:\windows\system32\uwikifap.ini
    c:\windows\system32\ugunerut.ini
    c:\windows\system32\edihonay.ini
    c:\windows\system32\izahadur.ini
    c:\windows\system32\emolusov.ini
    c:\windows\system32\ijisokuy.ini
    c:\windows\system32\ovuruwaf.ini
    c:\windows\system32\ovohupiz.ini
    c:\windows\system32\uhehojos.ini
    c:\windows\system32\ivozarot.ini
    c:\windows\system32\uzilipaf.ini
    c:\windows\16331531.cvr
    c:\windows\system32\afosumin.ini
    c:\windows\system32\oporolor.ini
    c:\windows\system32\otorezun.ini
    c:\windows\system32\azihufof.ini
    c:\windows\system32\idufatap.ini
    c:\windows\system32\flvDX.dll
    c:\windows\system32\lejorude.dll
    c:\windows\system32\lenodanu.dll
    c:\windows\system32\mejeweme.dll
    c:\windows\system32\msfDX.dll
    c:\windows\system32\nbDX.dll
    c:\windows\system32\pajohebu.dll
    c:\windows\system32\serevudo.dll
    c:\windows\system32\sesimuvi.dll
    c:\windows\system32\zidewomi.dll
  • Save this as CFScript.txt, in the same location as ComboFix.exe
  • Posted Image
    Refering to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at "C:\ComboFix.txt". Please copy and paste that report here.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

We need to run a Scan with DDS
  • Please download DDS, and save it to your desktop, from one of the following mirrors:
  • Disable any type of "Script Blockers" or "Script Protection" installed on your system.
  • Double click Posted Image on your desktop.
  • If prompted by any script blocking tools, please allow any actions taken by DDS.
  • Two reports will open. Please reply with the generated reports:
    • DDS.txt <-- Copy and paste into your next post
    • Attach.txt <-- Attach to your next post
I would like us to use ESET (NOD32)'s Online Scanner
  • Please go to ESET OnlineScan (NOD32)
  • You will then see the Terms of Use, tick the check-box infront of YES, I accept the Terms of Use
  • Now click Start
  • Should you face a Security Warning that asks if you want to install and run a file called "OnlineScanner.cab", click Yes
  • Click Start
    • Note: (the Onlinescanner will now prepare itself for running on your pc)
  • To do a full-scan, tick: "Remove found threats" and "Scan potentially unwanted applications"
  • Press Scan
  • The Onlinescan will now start and scan your pc (this could take a while)
  • When the scan has finished, it will show a screen with two tabs "overview" and "details" and the option to get information or buy software, just close the window
  • Click Start >> Run... >> type: C:\Program Files\EsetOnlineScanner\log.txt
  • The Scanresults will now open in Notepad
  • Click into the text area, right-click and chose "select all" (or use +A)
  • Right-click again and chose "Copy" (or +C)
  • Close/Exit Notepad
  • Navigate to this thread and post your log along with anything else requested from us, by right-clicking and "paste" (or ctrl+v) in the text area of the reply post you just created.
Note: For Vista Users: Eset is compatible but Internet Explorer must be run as Administrator. To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.)

In your next reply, please include the following:
  • ComboFix.txt
  • DDS.txt
  • Attach.txt
  • ESET OnlineScan's Log

BillyIII
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#5 Johnoh123

Johnoh123
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 04 January 2009 - 08:00 PM

Hello again bill thanks for the reply :thumbsup:

Combofix Log

ComboFix 09-01-02.01 - user 2009-01-05 10:20:13.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.949.82.1033.18.502.267 [GMT 11:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
AV: 알약 *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\windows\16331531.cvr
c:\windows\system32\afosumin.ini
c:\windows\system32\aguyinah.ini
c:\windows\system32\ajebufeg.ini
c:\windows\system32\akihiveb.ini
c:\windows\system32\amajoyis.ini
c:\windows\system32\amazogol.ini
c:\windows\system32\apubukiz.ini
c:\windows\system32\arovugum.ini
c:\windows\system32\atayubig.ini
c:\windows\system32\azihufof.ini
c:\windows\system32\edihonay.ini
c:\windows\system32\ehepegop.ini
c:\windows\system32\emolusov.ini
c:\windows\system32\etojisay.ini
c:\windows\system32\evosojup.ini
c:\windows\system32\evugigeh.ini
c:\windows\system32\flvDX.dll
c:\windows\system32\fukafati.dll
c:\windows\system32\hagatogo.dll
c:\windows\system32\idufatap.ini
c:\windows\system32\ijisokuy.ini
c:\windows\system32\ipubebow.ini
c:\windows\system32\ivozarot.ini
c:\windows\system32\iyejuzob.ini
c:\windows\system32\izahadur.ini
c:\windows\system32\izebazab.ini
c:\windows\system32\izedobaw.ini
c:\windows\system32\lejorude.dll
c:\windows\system32\lenodanu.dll
c:\windows\system32\loyayono.dll
c:\windows\system32\mejeweme.dll
c:\windows\system32\msfDX.dll
c:\windows\system32\nbDX.dll
c:\windows\system32\odewohis.ini
c:\windows\system32\ojivobip.ini
c:\windows\system32\okezogur.ini
c:\windows\system32\olenemuk.ini
c:\windows\system32\oliravuk.ini
c:\windows\system32\olovifaf.ini
c:\windows\system32\onesizeb.ini
c:\windows\system32\operurer.ini
c:\windows\system32\oporolor.ini
c:\windows\system32\otorezun.ini
c:\windows\system32\otugebub.ini
c:\windows\system32\ovohupiz.ini
c:\windows\system32\ovuruwaf.ini
c:\windows\system32\pajohebu.dll
c:\windows\system32\serevudo.dll
c:\windows\system32\sesimuvi.dll
c:\windows\system32\ufirifef.ini
c:\windows\system32\ugunerut.ini
c:\windows\system32\uhehojos.ini
c:\windows\system32\ukikiwob.ini
c:\windows\system32\uloluyoz.ini
c:\windows\system32\upelelet.ini
c:\windows\system32\uwikifap.ini
c:\windows\system32\uzewigor.ini
c:\windows\system32\uzilipaf.ini
c:\windows\system32\zidewomi.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\16331531.cvr
c:\windows\system32\afosumin.ini
c:\windows\system32\aguyinah.ini
c:\windows\system32\ajebufeg.ini
c:\windows\system32\akihiveb.ini
c:\windows\system32\amajoyis.ini
c:\windows\system32\amazogol.ini
c:\windows\system32\apubukiz.ini
c:\windows\system32\arovugum.ini
c:\windows\system32\atayubig.ini
c:\windows\system32\azihufof.ini
c:\windows\system32\edihonay.ini
c:\windows\system32\ehepegop.ini
c:\windows\system32\emolusov.ini
c:\windows\system32\etojisay.ini
c:\windows\system32\evosojup.ini
c:\windows\system32\evugigeh.ini
c:\windows\system32\flvDX.dll
c:\windows\system32\fukafati.dll
c:\windows\system32\hagatogo.dll
c:\windows\system32\idufatap.ini
c:\windows\system32\ijisokuy.ini
c:\windows\system32\ipubebow.ini
c:\windows\system32\ivozarot.ini
c:\windows\system32\iyejuzob.ini
c:\windows\system32\izahadur.ini
c:\windows\system32\izebazab.ini
c:\windows\system32\izedobaw.ini
c:\windows\system32\lejorude.dll
c:\windows\system32\lenodanu.dll
c:\windows\system32\loyayono.dll
c:\windows\system32\mejeweme.dll
c:\windows\system32\msfDX.dll
c:\windows\system32\nbDX.dll
c:\windows\system32\odewohis.ini
c:\windows\system32\ojivobip.ini
c:\windows\system32\okezogur.ini
c:\windows\system32\olenemuk.ini
c:\windows\system32\oliravuk.ini
c:\windows\system32\olovifaf.ini
c:\windows\system32\onesizeb.ini
c:\windows\system32\operurer.ini
c:\windows\system32\oporolor.ini
c:\windows\system32\otorezun.ini
c:\windows\system32\otugebub.ini
c:\windows\system32\ovohupiz.ini
c:\windows\system32\ovuruwaf.ini
c:\windows\system32\pajohebu.dll
c:\windows\system32\serevudo.dll
c:\windows\system32\sesimuvi.dll
c:\windows\system32\ufirifef.ini
c:\windows\system32\ugunerut.ini
c:\windows\system32\uhehojos.ini
c:\windows\system32\ukikiwob.ini
c:\windows\system32\uloluyoz.ini
c:\windows\system32\upelelet.ini
c:\windows\system32\uwikifap.ini
c:\windows\system32\uzewigor.ini
c:\windows\system32\uzilipaf.ini
c:\windows\system32\zidewomi.dll

.
((((((((((((((((((((((((( Files Created from 2008-12-04 to 2009-01-04 )))))))))))))))))))))))))))))))
.

2009-01-04 22:28 . 2009-01-04 22:28 <DIR> d-------- c:\program files\Windows Media Connect 2
2009-01-04 22:26 . 2009-01-04 22:27 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-01-04 21:01 . 2009-01-04 21:01 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-04 21:01 . 2009-01-04 21:01 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-27 20:06 . 2008-12-27 20:06 <DIR> d-------- c:\program files\Trend Micro
2008-12-27 17:37 . 2008-12-31 01:15 <DIR> d-------- c:\documents and settings\user\Application Data\My Battle for Middle-earth™ II Files
2008-12-27 17:04 . 2008-12-27 17:04 <DIR> d-------- c:\program files\Electronic Arts
2008-12-17 22:17 . 2008-12-27 18:08 664 --a------ c:\windows\system32\d3d9caps.dat
2008-12-13 13:38 . 2008-12-13 13:38 552 --a------ c:\windows\system32\d3d8caps.dat
2008-12-11 12:01 . 2008-12-11 12:01 <DIR> d-------- c:\program files\EA GAMES
2008-12-10 22:26 . 2008-12-10 22:26 <DIR> d-------- c:\program files\EA SPORTS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-04 12:35 --------- d-----w c:\documents and settings\user\Application Data\LimeWire
2009-01-04 10:01 --------- d-----w c:\program files\Java
2008-12-23 07:17 --------- d-----w c:\program files\Symantec AntiVirus
2008-12-23 07:17 --------- d-----w c:\program files\Symantec
2008-12-23 07:17 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-23 07:17 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-12-01 10:47 --------- d-----w c:\documents and settings\Administrator\Application Data\EstSoft
2008-11-28 08:07 --------- d-----w c:\program files\Google
2008-11-28 08:05 --------- d-----w c:\program files\Common Files\AVSMedia
2008-11-28 08:05 --------- d-----w c:\program files\AVS4YOU
2008-11-21 11:17 --------- d-----w c:\program files\Common Files\DVDVideoSoft
2008-11-21 11:16 --------- d-----w c:\program files\DVDVideoSoft
2008-11-20 02:22 274,432 ----a-w c:\windows\system32\TubeFinder.exe
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 03:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 03:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 03:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 03:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 03:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 03:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 03:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 03:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 03:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 03:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-09-10 02:49 5,817,064 ----a-w c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-04_19.59.28.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-14 00:12:38 208,896 ----a-w c:\windows\inf\unregmp2.exe
+ 2006-11-01 07:31:34 315,904 ----a-w c:\windows\inf\unregmp2.exe
- 2008-04-13 17:23:38 8,192 ----a-w c:\windows\system32\asferror.dll
+ 2006-10-18 10:47:08 7,168 ----a-w c:\windows\system32\asferror.dll
+ 2006-10-18 10:47:08 276,992 ------w c:\windows\system32\audiodev.dll
- 2004-08-10 15:45:04 233,472 ----a-w c:\windows\system32\blackbox.dll
+ 2006-10-18 10:47:10 542,720 ----a-w c:\windows\system32\blackbox.dll
- 2004-08-10 15:45:04 161,792 ----a-w c:\windows\system32\cewmdm.dll
+ 2006-10-18 10:47:10 229,376 ----a-w c:\windows\system32\cewmdm.dll
- 2008-04-13 17:23:38 8,192 -c--a-w c:\windows\system32\dllcache\asferror.dll
+ 2006-10-18 10:47:08 7,168 -c--a-w c:\windows\system32\dllcache\asferror.dll
- 2004-08-10 15:45:04 233,472 -c--a-w c:\windows\system32\dllcache\blackbox.dll
+ 2006-10-18 10:47:10 542,720 -c--a-w c:\windows\system32\dllcache\blackbox.dll
- 2004-08-10 15:45:04 161,792 -c--a-w c:\windows\system32\dllcache\cewmdm.dll
+ 2006-10-18 10:47:10 229,376 -c--a-w c:\windows\system32\dllcache\cewmdm.dll
- 2004-08-10 15:45:04 527,360 -c--a-w c:\windows\system32\dllcache\drmv2clt.dll
+ 2006-10-18 10:47:10 991,744 -c--a-w c:\windows\system32\dllcache\drmv2clt.dll
- 2004-08-10 15:45:04 6,656 -c--a-w c:\windows\system32\dllcache\laprxy.dll
+ 2006-10-18 10:47:14 11,264 -c--a-w c:\windows\system32\dllcache\LAPRXY.dll
- 2008-06-09 22:17:42 96,768 -c--a-w c:\windows\system32\dllcache\logagent.exe
+ 2006-10-18 09:03:58 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe
- 2008-04-14 00:11:57 310,272 -c--a-w c:\windows\system32\dllcache\mp43dmod.dll
+ 2006-10-18 10:47:14 4,096 -c--a-w c:\windows\system32\dllcache\MP43DMOD.dll
- 2008-04-14 00:11:57 384,512 -c--a-w c:\windows\system32\dllcache\mp4sdmod.dll
+ 2006-10-18 10:47:14 4,096 -c--a-w c:\windows\system32\dllcache\MP4SDMOD.dll
- 2008-04-14 00:11:57 240,640 -c--a-w c:\windows\system32\dllcache\mpg4dmod.dll
+ 2006-10-18 10:47:14 4,096 -c--a-w c:\windows\system32\dllcache\MPG4DMOD.dll
- 2008-04-14 00:11:57 368,640 -c--a-w c:\windows\system32\dllcache\mpvis.dll
+ 2006-10-18 10:47:14 243,712 -c--a-w c:\windows\system32\dllcache\mpvis.dll
- 2004-08-10 15:45:04 141,312 -c--a-w c:\windows\system32\dllcache\msnetobj.dll
+ 2006-10-18 10:47:16 179,712 -c--a-w c:\windows\system32\dllcache\msnetobj.dll
- 2004-08-10 15:45:04 25,088 -c--a-w c:\windows\system32\dllcache\mspmsnsv.dll
+ 2006-10-18 10:47:16 27,136 -c--a-w c:\windows\system32\dllcache\mspmsnsv.dll
- 2004-08-10 15:45:04 169,472 -c--a-w c:\windows\system32\dllcache\mspmsp.dll
+ 2006-10-18 10:47:16 175,616 -c--a-w c:\windows\system32\dllcache\mspmsp.dll
- 2004-08-10 15:45:04 360,176 -c--a-w c:\windows\system32\dllcache\msscp.dll
+ 2006-10-18 10:47:16 414,208 -c--a-w c:\windows\system32\dllcache\msscp.dll
- 2004-08-10 15:45:04 311,296 -c--a-w c:\windows\system32\dllcache\mswmdm.dll
+ 2006-10-18 10:47:16 321,536 -c--a-w c:\windows\system32\dllcache\mswmdm.dll
- 2004-08-10 15:45:04 221,184 -c--a-w c:\windows\system32\dllcache\qasf.dll
+ 2006-10-18 10:47:18 211,456 -c--a-w c:\windows\system32\dllcache\qasf.dll
- 2008-04-14 00:12:35 774,144 -c--a-w c:\windows\system32\dllcache\setup_wm.exe
+ 2006-11-01 07:31:38 1,669,120 -c--a-w c:\windows\system32\dllcache\setup_wm.exe
- 2008-04-14 00:12:38 208,896 -c--a-w c:\windows\system32\dllcache\unregmp2.exe
+ 2006-11-01 07:31:34 315,904 -c--a-w c:\windows\system32\dllcache\unregmp2.exe
- 2004-08-10 15:45:04 380,144 -c--a-w c:\windows\system32\dllcache\wmadmod.dll
+ 2006-10-18 10:47:18 757,248 -c--a-w c:\windows\system32\dllcache\WMADMOD.dll
- 2004-08-10 15:45:04 712,704 -c--a-w c:\windows\system32\dllcache\wmadmoe.dll
+ 2006-10-18 10:47:18 1,117,696 -c--a-w c:\windows\system32\dllcache\WMADMOE.dll
- 2007-10-27 07:40:06 227,328 -c--a-w c:\windows\system32\dllcache\wmasf.dll
+ 2006-10-18 10:47:18 222,208 -c--a-w c:\windows\system32\dllcache\WMASF.dll
- 2004-08-10 15:45:04 30,208 -c--a-w c:\windows\system32\dllcache\wmdmlog.dll
+ 2006-10-18 10:47:18 33,792 -c--a-w c:\windows\system32\dllcache\wmdmlog.dll
- 2004-08-10 15:45:04 34,304 -c--a-w c:\windows\system32\dllcache\wmdmps.dll
+ 2006-10-18 10:47:18 37,376 -c--a-w c:\windows\system32\dllcache\wmdmps.dll
- 2008-04-13 17:23:24 168,448 -c--a-w c:\windows\system32\dllcache\wmerror.dll
+ 2006-10-18 10:47:20 227,328 -c--a-w c:\windows\system32\dllcache\wmerror.dll
- 2004-08-10 15:45:04 150,016 -c--a-w c:\windows\system32\dllcache\wmidx.dll
+ 2006-10-18 10:47:20 157,184 -c--a-w c:\windows\system32\dllcache\wmidx.dll
- 2008-06-10 00:37:02 1,026,048 -c--a-w c:\windows\system32\dllcache\WMNetmgr.dll
+ 2006-10-18 10:47:20 937,984 -c--a-w c:\windows\system32\dllcache\WMNetMgr.dll
- 2008-04-14 00:12:09 4,874,240 -c--a-w c:\windows\system32\dllcache\wmp.dll
+ 2006-10-18 10:47:20 10,834,432 -c--a-w c:\windows\system32\dllcache\wmp.dll
- 2008-04-14 00:12:09 114,688 -c--a-w c:\windows\system32\dllcache\wmpasf.dll
+ 2006-10-18 10:47:20 242,688 -c--a-w c:\windows\system32\dllcache\wmpasf.dll
- 2008-04-14 00:12:09 98,304 -c--a-w c:\windows\system32\dllcache\wmpband.dll
+ 2006-10-18 10:47:20 96,256 -c--a-w c:\windows\system32\dllcache\wmpband.dll
- 2008-04-14 00:12:09 233,472 -c--a-w c:\windows\system32\dllcache\wmpdxm.dll
+ 2006-10-18 10:47:20 314,880 -c--a-w c:\windows\system32\dllcache\wmpdxm.dll
- 2008-04-14 00:12:40 73,728 -c--a-w c:\windows\system32\dllcache\wmplayer.exe
+ 2006-10-18 10:46:20 64,000 -c--a-w c:\windows\system32\dllcache\wmplayer.exe
- 2008-04-13 17:28:21 2,940,928 -c--a-w c:\windows\system32\dllcache\wmploc.dll
+ 2006-10-18 10:47:20 8,231,936 -c--a-w c:\windows\system32\dllcache\wmploc.dll
- 2008-04-14 00:12:09 102,400 -c--a-w c:\windows\system32\dllcache\wmpshell.dll
+ 2006-10-18 10:47:20 99,840 -c--a-w c:\windows\system32\dllcache\wmpshell.dll
- 2004-08-10 15:45:04 773,368 -c--a-w c:\windows\system32\dllcache\wmsdmod.dll
+ 2006-10-18 10:47:22 4,096 -c--a-w c:\windows\system32\dllcache\wmsdmod.dll
- 2004-08-10 15:45:04 1,116,160 -c--a-w c:\windows\system32\dllcache\wmsdmoe2.dll
+ 2006-10-18 10:47:22 4,096 -c--a-w c:\windows\system32\dllcache\wmsdmoe2.dll
- 2004-08-10 15:45:06 531,192 -c--a-w c:\windows\system32\dllcache\wmspdmod.dll
+ 2006-10-18 10:47:22 603,648 -c--a-w c:\windows\system32\dllcache\WMSPDMOD.dll
- 2004-08-10 15:45:06 936,960 -c--a-w c:\windows\system32\dllcache\wmspdmoe.dll
+ 2006-10-18 10:47:22 1,329,152 -c--a-w c:\windows\system32\dllcache\WMSPDMOE.dll
- 2008-06-10 00:57:40 2,364,472 -c--a-w c:\windows\system32\dllcache\WMVCore.dll
+ 2006-10-18 10:47:22 2,450,944 -c--a-w c:\windows\system32\dllcache\wmvcore.dll
- 2004-08-10 15:45:06 871,160 -c--a-w c:\windows\system32\dllcache\wmvdmod.dll
+ 2006-10-18 10:47:22 4,096 -c--a-w c:\windows\system32\dllcache\wmvdmod.dll
- 2004-08-10 15:45:06 999,424 -c--a-w c:\windows\system32\dllcache\wmvdmoe2.dll
+ 2006-10-18 10:47:22 4,096 -c--a-w c:\windows\system32\dllcache\wmvdmoe2.dll
+ 2006-10-18 10:47:22 671,232 ------w c:\windows\system32\drivers\UMDF\wpdmtpdr.dll
- 2004-08-10 15:45:06 18,944 ----a-w c:\windows\system32\drivers\wpdusb.sys
+ 2006-10-18 09:00:00 38,528 ----a-w c:\windows\system32\drivers\wpdusb.sys
+ 2006-09-28 07:55:50 77,568 ------w c:\windows\system32\drivers\WudfPf.sys
+ 2006-09-28 08:00:34 82,944 ------w c:\windows\system32\drivers\WudfRd.sys
+ 2006-10-18 09:00:46 249,856 ------w c:\windows\system32\drmupgds.exe
- 2004-08-10 15:45:04 527,360 ----a-w c:\windows\system32\drmv2clt.dll
+ 2006-10-18 10:47:10 991,744 ----a-w c:\windows\system32\drmv2clt.dll
+ 2009-01-04 10:01:30 144,792 ----a-w c:\windows\system32\java.exe
+ 2009-01-04 10:01:30 144,792 ----a-w c:\windows\system32\javaw.exe
+ 2009-01-04 10:01:30 148,888 ----a-w c:\windows\system32\javaws.exe
- 2004-08-10 15:45:04 6,656 ----a-w c:\windows\system32\laprxy.dll
+ 2006-10-18 10:47:14 11,264 ----a-w c:\windows\system32\LAPRXY.dll
- 2008-06-09 22:17:42 96,768 ----a-w c:\windows\system32\logagent.exe
+ 2006-10-18 09:03:58 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2006-10-18 10:47:14 212,992 ------w c:\windows\system32\MFPLAT.dll
+ 2006-10-18 10:47:14 259,072 ------w c:\windows\system32\MP43DECD.dll
- 2008-04-14 00:11:57 310,272 ----a-w c:\windows\system32\mp43dmod.dll
+ 2006-10-18 10:47:14 4,096 ----a-w c:\windows\system32\MP43DMOD.dll
+ 2006-10-18 10:47:14 317,440 ------w c:\windows\system32\MP4SDECD.dll
- 2008-04-14 00:11:57 384,512 ----a-w c:\windows\system32\mp4sdmod.dll
+ 2006-10-18 10:47:14 4,096 ----a-w c:\windows\system32\MP4SDMOD.dll
+ 2006-10-18 10:47:14 259,072 ------w c:\windows\system32\MPG4DECD.dll
- 2008-04-14 00:11:57 240,640 ----a-w c:\windows\system32\mpg4dmod.dll
+ 2006-10-18 10:47:14 4,096 ----a-w c:\windows\system32\MPG4DMOD.dll
+ 2008-12-09 04:24:38 17,593,280 ----a-w c:\windows\system32\MRT.exe
+ 2006-10-02 04:28:42 312,128 ------w c:\windows\system32\msdelta.dll
- 2004-08-10 15:45:04 141,312 ----a-w c:\windows\system32\msnetobj.dll
+ 2006-10-18 10:47:16 179,712 ----a-w c:\windows\system32\msnetobj.dll
- 2004-08-10 15:45:04 25,088 ----a-w c:\windows\system32\MsPMSNSv.dll
+ 2006-10-18 10:47:16 27,136 ----a-w c:\windows\system32\mspmsnsv.dll
- 2004-08-10 15:45:04 169,472 ----a-w c:\windows\system32\MsPMSP.dll
+ 2006-10-18 10:47:16 175,616 ----a-w c:\windows\system32\mspmsp.dll
- 2004-08-10 15:45:04 360,176 ----a-w c:\windows\system32\MSSCP.dll
+ 2006-10-18 10:47:16 414,208 ----a-w c:\windows\system32\msscp.dll
- 2004-08-10 15:45:04 311,296 ----a-w c:\windows\system32\MSWMDM.dll
+ 2006-10-18 10:47:16 321,536 ----a-w c:\windows\system32\mswmdm.dll
+ 2006-10-18 10:47:18 284,160 ------w c:\windows\system32\PortableDeviceApi.dll
+ 2006-10-18 10:47:18 101,888 ------w c:\windows\system32\PortableDeviceClassExtension.dll
+ 2006-10-18 10:47:18 166,912 ------w c:\windows\system32\PortableDeviceTypes.dll
+ 2006-10-18 10:47:18 132,096 ------w c:\windows\system32\PortableDeviceWiaCompat.dll
+ 2006-10-18 10:47:18 199,168 ------w c:\windows\system32\PortableDeviceWMDRM.dll
- 2004-08-10 15:45:04 221,184 ----a-w c:\windows\system32\qasf.dll
+ 2006-10-18 10:47:18 211,456 ----a-w c:\windows\system32\qasf.dll
- 2007-07-26 22:41:40 16,760 ------w c:\windows\system32\spmsg.dll
+ 2006-09-25 06:58:48 14,640 ------w c:\windows\system32\spmsg.dll
- 2004-08-10 15:45:04 47,104 ----a-w c:\windows\system32\uwdf.exe
+ 2006-10-18 10:58:00 8,704 ----a-w c:\windows\system32\uwdf.exe
- 2004-08-10 15:45:04 15,872 ----a-w c:\windows\system32\wdfapi.dll
+ 2006-10-18 10:47:18 4,096 ----a-w c:\windows\system32\wdfapi.dll
- 2004-08-10 15:45:04 38,912 ----a-w c:\windows\system32\wdfmgr.exe
+ 2006-10-18 10:58:00 8,704 ----a-w c:\windows\system32\wdfmgr.exe
- 2004-08-10 15:45:04 380,144 ----a-w c:\windows\system32\wmadmod.dll
+ 2006-10-18 10:47:18 757,248 ----a-w c:\windows\system32\wmadmod.dll
- 2004-08-10 15:45:04 712,704 ----a-w c:\windows\system32\wmadmoe.dll
+ 2006-10-18 10:47:18 1,117,696 ----a-w c:\windows\system32\WMADMOE.dll
- 2007-10-27 07:40:06 227,328 ----a-w c:\windows\system32\wmasf.dll
+ 2006-10-18 10:47:18 222,208 ----a-w c:\windows\system32\wmasf.dll
- 2004-08-10 15:45:04 30,208 ----a-w c:\windows\system32\WMDMLOG.dll
+ 2006-10-18 10:47:18 33,792 ----a-w c:\windows\system32\wmdmlog.dll
- 2004-08-10 15:45:04 34,304 ----a-w c:\windows\system32\WMDMPS.dll
+ 2006-10-18 10:47:18 37,376 ----a-w c:\windows\system32\wmdmps.dll
- 2004-08-10 15:45:04 344,064 ----a-w c:\windows\system32\WMDRMdev.dll
+ 2006-10-18 10:47:18 429,056 ----a-w c:\windows\system32\wmdrmdev.dll
- 2004-08-10 15:45:04 290,816 ----a-w c:\windows\system32\WMDRMNet.dll
+ 2006-10-18 10:47:20 348,672 ----a-w c:\windows\system32\wmdrmnet.dll
+ 2006-10-18 10:47:20 535,040 ------w c:\windows\system32\wmdrmsdk.dll
- 2008-04-13 17:23:24 168,448 ----a-w c:\windows\system32\wmerror.dll
+ 2006-10-18 10:47:20 227,328 ----a-w c:\windows\system32\wmerror.dll
- 2004-08-10 15:45:04 150,016 ----a-w c:\windows\system32\wmidx.dll
+ 2006-10-18 10:47:20 157,184 ----a-w c:\windows\system32\wmidx.dll
- 2008-06-10 00:37:02 1,026,048 ----a-w c:\windows\system32\WMNetmgr.dll
+ 2006-10-18 10:47:20 937,984 ----a-w c:\windows\system32\wmnetmgr.dll
- 2008-04-14 00:12:09 4,874,240 ----a-w c:\windows\system32\wmp.dll
+ 2006-10-18 10:47:20 10,834,432 ----a-w c:\windows\system32\wmp.dll
- 2008-04-14 00:12:09 114,688 ----a-w c:\windows\system32\wmpasf.dll
+ 2006-10-18 10:47:20 242,688 ----a-w c:\windows\system32\wmpasf.dll
- 2008-04-14 00:12:09 233,472 ----a-w c:\windows\system32\wmpdxm.dll
+ 2006-10-18 10:47:20 314,880 ----a-w c:\windows\system32\wmpdxm.dll
+ 2006-10-18 10:47:20 295,936 ------w c:\windows\system32\wmpeffects.dll
+ 2006-10-18 10:47:20 1,661,440 ------w c:\windows\system32\wmpencen.dll
- 2008-04-13 17:28:21 2,940,928 ----a-w c:\windows\system32\wmploc.dll
+ 2006-10-18 10:47:20 8,231,936 ----a-w c:\windows\system32\wmploc.dll
+ 2006-10-18 10:47:20 613,376 ------w c:\windows\system32\wmpmde.dll
+ 2006-10-18 10:47:20 130,048 ------w c:\windows\system32\wmpps.dll
- 2008-04-14 00:12:09 102,400 ----a-w c:\windows\system32\wmpshell.dll
+ 2006-10-18 10:47:20 99,840 ----a-w c:\windows\system32\wmpshell.dll
+ 2006-10-18 10:47:20 204,288 ------w c:\windows\system32\wmpsrcwp.dll
- 2004-08-10 15:45:04 773,368 ----a-w c:\windows\system32\wmsdmod.dll
+ 2006-10-18 10:47:22 4,096 ----a-w c:\windows\system32\wmsdmod.dll
- 2004-08-10 15:45:04 1,116,160 ----a-w c:\windows\system32\wmsdmoe2.dll
+ 2006-10-18 10:47:22 4,096 ----a-w c:\windows\system32\wmsdmoe2.dll
- 2004-08-10 15:45:06 531,192 ----a-w c:\windows\system32\wmspdmod.dll
+ 2006-10-18 10:47:22 603,648 ----a-w c:\windows\system32\WMSPDMOD.dll
- 2004-08-10 15:45:06 936,960 ----a-w c:\windows\system32\wmspdmoe.dll
+ 2006-10-18 10:47:22 1,329,152 ----a-w c:\windows\system32\WMSPDMOE.dll
- 2004-08-10 15:45:06 1,181,944 ----a-w c:\windows\system32\wmvadvd.dll
+ 2006-10-18 10:47:22 4,096 ----a-w c:\windows\system32\WMVADVD.dll
- 2004-08-10 15:45:06 1,509,376 ----a-w c:\windows\system32\WMVADVE.DLL
+ 2006-10-18 10:47:22 4,096 ----a-w c:\windows\system32\WMVADVE.DLL
- 2008-06-10 00:57:40 2,364,472 ----a-w c:\windows\system32\WMVCore.dll
+ 2006-10-18 10:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll
+ 2006-10-18 10:47:22 1,543,680 ------w c:\windows\system32\WMVDECOD.dll
- 2004-08-10 15:45:06 871,160 ----a-w c:\windows\system32\wmvdmod.dll
+ 2006-10-18 10:47:22 4,096 ----a-w c:\windows\system32\wmvdmod.dll
- 2004-08-10 15:45:06 999,424 ----a-w c:\windows\system32\wmvdmoe2.dll
+ 2006-10-18 10:47:22 4,096 ----a-w c:\windows\system32\wmvdmoe2.dll
+ 2006-10-18 10:47:22 1,574,912 ------w c:\windows\system32\WMVENCOD.dll
+ 2006-10-18 10:47:22 1,382,912 ------w c:\windows\system32\WMVSDECD.dll
+ 2006-10-18 10:47:22 767,488 ------w c:\windows\system32\WMVSENCD.dll
+ 2006-10-18 10:47:22 656,896 ------w c:\windows\system32\WMVXENCD.dll
- 2004-08-10 15:45:06 38,912 ----a-w c:\windows\system32\wpd_ci.dll
+ 2006-10-18 10:47:22 629,760 ----a-w c:\windows\system32\wpd_ci.dll
- 2004-08-10 15:45:06 61,952 ----a-w c:\windows\system32\wpdconns.dll
+ 2006-10-18 10:47:22 35,840 ----a-w c:\windows\system32\wpdconns.dll
- 2004-08-10 15:45:06 114,176 ----a-w c:\windows\system32\wpdmtp.dll
+ 2006-10-18 10:47:22 154,624 ----a-w c:\windows\system32\wpdmtp.dll
- 2004-08-10 15:45:06 66,560 ----a-w c:\windows\system32\wpdmtpus.dll
+ 2006-10-18 10:47:22 63,488 ----a-w c:\windows\system32\wpdmtpus.dll
+ 2006-10-18 10:47:22 2,603,008 ------w c:\windows\system32\WpdShext.dll
+ 2006-10-18 09:00:14 17,408 ------w c:\windows\system32\wpdshextautoplay.exe
+ 2006-10-18 10:47:22 38,400 ------w c:\windows\system32\wpdshextres.dll
+ 2006-10-18 10:47:22 133,632 ------w c:\windows\system32\WPDShServiceObj.dll
- 2004-08-10 15:45:06 327,680 ----a-w c:\windows\system32\wpdsp.dll
+ 2006-10-18 10:47:22 356,352 ----a-w c:\windows\system32\wpdsp.dll
+ 2006-09-28 09:13:26 95,344 ------w c:\windows\system32\WUDFCoinstaller.dll
+ 2006-09-28 07:56:38 146,432 ------w c:\windows\system32\WudfHost.exe
+ 2006-09-28 07:56:16 165,376 ------w c:\windows\system32\WudfPlatform.dll
+ 2006-09-28 07:56:14 55,808 ------w c:\windows\system32\WudfSvc.dll
+ 2006-09-28 07:56:38 316,416 ------w c:\windows\system32\WUDFx.dll
+ 2009-01-04 23:02:20 16,384 ----atw c:\windows\temp\Perflib_Perfdata_64c.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-03-23 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-23 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-23 77824]
"ALYac"="c:\program files\ESTsoft\ALYac\AYUpdate.exe" [2008-01-11 79304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-04 136600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2008-01-11 39792]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2007-05-11 738968]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\ESTsoft\\ALYac\\AYAgent.aye"=
"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\igfxsrvc.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\ESTsoft\\ALYac\\AYServiceNT.aye"=
"c:\\WINDOWS\\system32\\imapi.exe"=
"c:\\Program Files\\Electronic Arts\\The Battle for Middle-earth ™ II\\game.dat"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2967:TCP"= 2967:TCP:Symantec RTVScan
"1024:TCP"= 1024:TCP:Symantec Management

R3 AYDrvSP_ALYAC;AYDrvSP_ALYAC;c:\program files\ESTsoft\ALYac\AYDrvSP.sys [2008-12-04 23288]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2008-08-06 20160]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
\Shell\AutoRun\command - Z:\Autorun.exe
.
Contents of the 'Scheduled Tasks' folder

2008-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 18:57]
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-05 10:21:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\ALYac_PZSrv]
"ImagePath"="c:\program files\ESTsoft\ALYac\AYServiceNt.aye"
.
Completion time: 2009-01-05 10:22:21
ComboFix-quarantined-files.txt 2009-01-04 23:22:19
ComboFix2.txt 2009-01-04 09:00:11

Pre-Run: 23,232,073,728 bytes free
Post-Run: 23,166,373,888 bytes free

486 --- E O F --- 2009-01-04 12:45:20


DDS text


DDS (Version 1.1.0) - NTFSx86
Run by user at 10:13:57.46 on 05/01/2009 Mon
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.949.82.1033.18.502.189 [GMT 11:00]

AV: 알약 *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESTsoft\ALYac\AYServiceNt.aye
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\ESTsoft\ALYac\AYAgent.aye
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\user\Desktop\dds.scr
C:\WINDOWS\system32\conime.exe

============== Pseudo HJT Report ===============

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [ALYac] "c:\program files\estsoft\alyac\AYUpdate.exe" /run
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\oaqxrzly.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/

============= SERVICES / DRIVERS ===============

S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2008-8-6 20160]
S3 AYDrvSP_ALYAC;AYDrvSP_ALYAC;\??\c:\program files\estsoft\alyac\AYDrvSP.sys [2008-12-4 23288]

============== File Associations ===============

inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"

=============== Created Last 30 ================

2009-01-04 22:28 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-01-04 21:01 410,984 a------- c:\windows\system32\deploytk.dll
2009-01-04 21:01 73,728 a------- c:\windows\system32\javacpl.cpl
2009-01-04 19:51 161,792 a------- c:\windows\SWREG.exe
2009-01-04 19:51 98,816 a------- c:\windows\sed.exe
2009-01-04 11:46 1,266,209 ---sh--- c:\windows\system32\apubukiz.ini
2009-01-03 11:14 1,266,209 ---sh--- c:\windows\system32\onesizeb.ini
2009-01-03 10:16 1,266,209 ---sh--- c:\windows\system32\amajoyis.ini
2009-01-02 14:06 1,266,209 ---sh--- c:\windows\system32\ojivobip.ini
2009-01-02 00:26 1,266,209 ---sh--- c:\windows\system32\ipubebow.ini
2009-01-01 09:50 1,266,209 ---sh--- c:\windows\system32\ufirifef.ini
2008-12-31 13:36 1,266,209 ---sh--- c:\windows\system32\olovifaf.ini
2008-12-31 00:41 1,266,767 ---sh--- c:\windows\system32\ukikiwob.ini
2008-12-30 12:42 1,266,776 ---sh--- c:\windows\system32\evosojup.ini
2008-12-30 12:37 2,713 ---sh--- c:\windows\system32\hagatogo.dll
2008-12-29 23:01 1,266,767 ---sh--- c:\windows\system32\operurer.ini
2008-12-29 11:02 1,265,838 ---sh--- c:\windows\system32\odewohis.ini
2008-12-28 16:02 1,265,838 ---sh--- c:\windows\system32\okezogur.ini
2008-12-27 22:30 1,258,203 ---sh--- c:\windows\system32\uloluyoz.ini
2008-12-27 20:06 <DIR> --d----- c:\program files\Trend Micro
2008-12-27 17:37 <DIR> --d----- c:\docume~1\user\applic~1\My Battle for Middle-earth™ II Files
2008-12-27 10:36 1,258,186 ---sh--- c:\windows\system32\oliravuk.ini
2008-12-26 21:10 1,606,281 ---sh--- c:\windows\system32\upelelet.ini
2008-12-26 09:09 2,713 ---sh--- c:\windows\system32\loyayono.dll
2008-12-26 09:09 2,713 ---sh--- c:\windows\system32\fukafati.dll
2008-12-25 15:10 1,606,281 ---sh--- c:\windows\system32\otugebub.ini
2008-12-25 00:11 1,606,245 ---sh--- c:\windows\system32\ehepegop.ini
2008-12-24 12:09 1,606,245 ---sh--- c:\windows\system32\iyejuzob.ini
2008-12-24 00:08 1,606,245 ---sh--- c:\windows\system32\izedobaw.ini
2008-12-23 11:09 121 ---sh--- c:\windows\system32\ajebufeg.ini
2008-12-22 22:24 1,606,245 ---sh--- c:\windows\system32\akihiveb.ini
2008-12-22 10:25 1,606,245 ---sh--- c:\windows\system32\arovugum.ini
2008-12-21 14:48 1,606,245 ---sh--- c:\windows\system32\olenemuk.ini
2008-12-20 12:47 1,606,245 ---sh--- c:\windows\system32\aguyinah.ini
2008-12-19 12:05 1,606,245 ---sh--- c:\windows\system32\etojisay.ini
2008-12-18 11:32 1,602,497 ---sh--- c:\windows\system32\izebazab.ini
2008-12-17 22:17 664 a------- c:\windows\system32\d3d9caps.dat
2008-12-17 18:29 120 ---sh--- c:\windows\system32\evugigeh.ini
2008-12-17 09:02 120 ---sh--- c:\windows\system32\atayubig.ini
2008-12-16 08:41 1,587,388 ---sh--- c:\windows\system32\amazogol.ini
2008-12-15 09:55 1,588,267 ---sh--- c:\windows\system32\uzewigor.ini
2008-12-14 15:23 1,588,267 ---sh--- c:\windows\system32\uwikifap.ini
2008-12-13 13:38 552 a------- c:\windows\system32\d3d8caps.dat
2008-12-13 13:14 1,583,225 ---sh--- c:\windows\system32\ugunerut.ini
2008-12-12 21:42 1,567,958 ---sh--- c:\windows\system32\edihonay.ini
2008-12-12 09:42 1,565,519 ---sh--- c:\windows\system32\izahadur.ini
2008-12-11 12:01 <DIR> --d----- c:\program files\EA GAMES
2008-12-11 11:18 1,527,414 ---sh--- c:\windows\system32\emolusov.ini
2008-12-10 23:15 1,492,974 ---sh--- c:\windows\system32\ijisokuy.ini
2008-12-10 22:26 <DIR> --d----- c:\program files\EA SPORTS
2008-12-10 11:14 1,492,136 ---sh--- c:\windows\system32\ovuruwaf.ini
2008-12-09 23:14 1,470,836 ---sh--- c:\windows\system32\ovohupiz.ini
2008-12-09 11:15 1,470,836 ---sh--- c:\windows\system32\uhehojos.ini
2008-12-08 19:29 1,426,874 ---sh--- c:\windows\system32\ivozarot.ini
2008-12-08 01:09 1,426,874 ---sh--- c:\windows\system32\uzilipaf.ini
2008-12-07 17:40 1,364 a------- c:\windows\16331531.cvr
2008-12-07 13:10 1,426,874 ---sh--- c:\windows\system32\afosumin.ini
2008-12-06 11:47 1,428,719 ---sh--- c:\windows\system32\oporolor.ini

==================== Find3M ====================

2008-11-20 13:22 274,432 a------- c:\windows\system32\TubeFinder.exe
2008-10-23 23:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-17 07:38 826,368 a------- c:\windows\system32\wininet.dll
2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
2006-05-03 20:06 163,328 ---shr-- c:\windows\system32\flvDX.dll
2008-09-06 10:47 88,064 a--sh--- c:\windows\system32\lejorude.dll
2008-08-28 19:00 2,048 a--sh--- c:\windows\system32\lenodanu.dll
2008-09-25 00:08 15,360 a--sh--- c:\windows\system32\mejeweme.dll
2007-02-21 21:47 31,232 ---shr-- c:\windows\system32\msfDX.dll
2008-03-16 23:30 216,064 ---shr-- c:\windows\system32\nbDX.dll
1601-01-01 11:12 28,672 a--sh--- c:\windows\system32\pajohebu.dll
2008-09-23 23:07 9,216 a--sh--- c:\windows\system32\serevudo.dll
2008-09-03 21:56 62,976 a--sh--- c:\windows\system32\sesimuvi.dll
2008-09-03 21:56 62,976 a--sh--- c:\windows\system32\zidewomi.dll

============= FINISH: 10:14:30.92 ===============



ESET Online Scans Log

# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3735 (20090104)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=1683aa43cd242643b39d2f2d01472b43
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2009-01-05 12:32:51
# local_time=2009-01-05 11:32:51 (+1000, AUS Eastern Daylight Time)
# country="Australia"
# osver=5.1.2600 NT Service Pack 3
# scanned=279201
# found=20
# scan_time=2379
C:\Documents and Settings\user\Desktop\how lovely are they dwellings.mp3 WMA/TrojanDownloader.GetCodec.C trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Documents and Settings\user\My Documents\LimeWire\Incomplete\T-3545425-how lovely brahms.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned) A66B046C155533B8BB0E20C4703797F1
C:\Documents and Settings\user\My Documents\LimeWire\Incomplete\T-3877629-trees oscar rasbach.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned) 63BBBCA0394EDB6D1899012044D8EA90
C:\Documents and Settings\user\My Documents\LimeWire\Incomplete\T-5745425-blues shuffle backing track.mp3 a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned) 9C44CA58466D33CC499F651DCCC32E48
C:\Documents and Settings\user\My Documents\LimeWire\Saved\G3 - Joe Satriani - Steve Vai - John Petrucci - Live in Tokyo 2005-BY SCELMONT.avi a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned) 0A0A0B47E35D557D949DC5288E100D51
C:\Documents and Settings\user\My Documents\LimeWire\Saved\how lovely are they dwellings.mp3 WMA/TrojanDownloader.GetCodec.C trojan (unable to clean - deleted) 00000000000000000000000000000000
C:\Qoobox\Quarantine\C\WINDOWS\system32\kovihihi.dll.vir Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\Qoobox\Quarantine\C\WINDOWS\system32\kumenelo.dll.vir Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\Qoobox\Quarantine\C\WINDOWS\system32\ledanozo.dll.vir Win32/Adware.Agent.NKB application (unable to clean - deleted) 00000000000000000000000000000000
C:\Qoobox\Quarantine\C\WINDOWS\system32\nopihizu.dll.vir Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\Qoobox\Quarantine\C\WINDOWS\system32\puvipezi.dll.vir Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\Qoobox\Quarantine\C\WINDOWS\system32\rowopapo.dll.vir Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\Qoobox\Quarantine\C\WINDOWS\system32\ruvaluno.dll.vir Win32/Adware.Agent.NKE application (unable to clean - deleted) 00000000000000000000000000000000
C:\Qoobox\Quarantine\C\WINDOWS\system32\vihokaso.dll.vir Win32/Adware.Agent.NKB application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\bizoyuza.dll.tmp Win32/Adware.Agent.NKE application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\bubedena.dll.tmp Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\jepiliwu.dll.tmp Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\vurotipe.dll.tmp Win32/Adware.Virtumonde application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\zaregabi.dll.tmp Win32/Adware.Agent.NKE application (unable to clean - deleted) 00000000000000000000000000000000
C:\WINDOWS\system32\zebeduwi.dll.tmp Win32/Adware.Agent.NKE application (unable to clean - deleted) 00000000000000000000000000000000



And i have attatched the dds attach log

Attached Files



#6 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:10:30 PM

Posted 04 January 2009 - 08:42 PM

Hello, Johnoh123
Should be the last one :thumbsup:

Please do an online scan with Kaspersky WebScanner.
  • Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
In your next reply, please include the following:
  • Kaspersky's Log

BillyIII
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#7 Johnoh123

Johnoh123
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 05 January 2009 - 12:07 AM

hey bill

the log is attatched

thanks :thumbsup:

Attached Files



#8 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:10:30 PM

Posted 05 January 2009 - 11:03 PM

Hello, Johnoh123
We need to execute an OTMoveIt3 script
  • Please download OTMoveIt3 by OldTimer and save it to your desktop.
  • Double click the Posted Image icon on your desktop.
  • Paste the following code under the Posted Image area. Do not include the word "Code".
    DO NOT FORGET TO INCLUDE THE :files PART :)
    :files
    C:\Documents and Settings\user\My Documents\LimeWire\Incomplete\T-3515161-trees oscar rasbach - greatest hits.wma
    C:\Windows\system32\*.tmp
    :commands
    [EmptyTemp]
  • Push the large Posted Image button.
  • OTMI3 may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the Posted Image line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Congratulations! You now appear clean! :thumbsup:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware
We Need to Remove ComboFix
  • Please go to Start -> Run
  • Enter "ComboFix /u" (without quotes). Note the space betwen "ComboFix" and "/u", it needs to be there.
    Posted Image
  • Press OK (Or hit enter).
  • Allow ComboFix to remove itself.
We Need to Clean Up Our Mess
  • Please reopen Posted Image on your desktop.
  • Push the large "Cleanup" button
  • Allow your system to reboot
Recommendations
Below are some recommendations to lower your chances of (re)infection.
  • Install Spyware Blaster and update it regularly
    If you wish, the commercial version provides automatic updating.
  • Install the MVPs hosts file, and update it regularly
    You can use the HostMan host file manager to do this automaticly if you wish.
    For more information on the hosts file, and what it can do for you, you can view the Tutorial on the Hosts file
  • Install an Anti-Spyware program, and update it regularly
    Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
    SUPERAntiSpyware is another good scanner with high detection and removal rates.
    Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

    If you are using Windows XP or earlier
    Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

    If you are using Windows Vista
    • Click the "Start Menu" (or Windows Orb)
    • Click "All Programs"
    • Click "Windows Update"
    • On the left, choose "Change Settings"
    • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
    • Press OK and accept the UAC prompt.
      Note: You shouldn't need to check this checkbox every single time you update, only the first time.
    • Click "Check for Updates" in the upper left corner.
    • Follow the instructions to install the latest updates.
    • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on your machine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing :).
In your next reply, please include the following:
  • OTMoveIt3's Log

BillyIII
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#9 Johnoh123

Johnoh123
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 06 January 2009 - 02:45 AM

thanks for everything bill the pop ups have stopped and i everything strange has stopped happening .

this is the log from the "move it" program

========== FILES ==========
C:\Documents and Settings\user\My Documents\LimeWire\Incomplete\T-3515161-trees oscar rasbach - greatest hits.wma moved successfully.
C:\Windows\system32\CONFIG.TMP moved successfully.
C:\Windows\system32\dogubina.dll.tmp moved successfully.
C:\Windows\system32\gefuwami.dll.tmp moved successfully.
C:\Windows\system32\kavumefe.dll.tmp moved successfully.
C:\Windows\system32\kegezadu.dll.tmp moved successfully.
C:\Windows\system32\kisukipe.dll.tmp moved successfully.
C:\Windows\system32\kofidutu.dll.tmp moved successfully.
C:\Windows\system32\kunokeja.dll.tmp moved successfully.
C:\Windows\system32\laroheya.dll.tmp moved successfully.
C:\Windows\system32\lehelojo.dll.tmp moved successfully.
C:\Windows\system32\magagovi.dll.tmp moved successfully.
C:\Windows\system32\nebazifi.dll.tmp moved successfully.
C:\Windows\system32\rijavuza.dll.tmp moved successfully.
C:\Windows\system32\rorivano.dll.tmp moved successfully.
C:\Windows\system32\SET10A.tmp moved successfully.
C:\Windows\system32\SET10C.tmp moved successfully.
C:\Windows\system32\SET111.tmp moved successfully.
C:\Windows\system32\SET118.tmp moved successfully.
C:\Windows\system32\SET160.tmp moved successfully.
C:\Windows\system32\tijayefe.dll.tmp moved successfully.
C:\Windows\system32\tipukuvu.dll.tmp moved successfully.
C:\Windows\system32\vodesome.dll.tmp moved successfully.
C:\Windows\system32\vubuwide.dll.tmp moved successfully.
C:\Windows\system32\yitofoyi.dll.tmp moved successfully.
C:\Windows\system32\zipubara.dll.tmp moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\etilqs_kVrEDWrUoXzch1TS6Npy scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\~DF57D4.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\~DF57E6.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\~DF6FD7.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\~DF71C5.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\user\LOCALS~1\Temp\~DF71D0.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_654.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01062009_183636

Files moved on Reboot...
File C:\DOCUME~1\user\LOCALS~1\Temp\etilqs_kVrEDWrUoXzch1TS6Npy not found!
File C:\DOCUME~1\user\LOCALS~1\Temp\~DF57D4.tmp not found!
File C:\DOCUME~1\user\LOCALS~1\Temp\~DF57E6.tmp not found!
C:\DOCUME~1\user\LOCALS~1\Temp\~DF6FD7.tmp moved successfully.
File C:\DOCUME~1\user\LOCALS~1\Temp\~DF71C5.tmp not found!
File C:\DOCUME~1\user\LOCALS~1\Temp\~DF71D0.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_654.dat not found!
C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\user\Local Settings\Application Data\Mozilla\Firefox\Profiles\oaqxrzly.default\XUL.mfl moved successfully.


is everthing gone ?

thanks again

#10 Johnoh123

Johnoh123
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:04:30 PM

Posted 06 January 2009 - 03:07 AM

sorry one more question , for the programs you listed for anti-spyware programs and stuff , do you think i should install more than one of them or just one . and which one/ones do you think are best to install . ive already installed spyware blaster .

thankyou :thumbsup:

#11 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:10:30 PM

Posted 06 January 2009 - 08:16 PM

Hello :thumbsup:

The hosts file is passive protection which is nice because it doesn't slow your system down yet is still effective, because it's only modifying settings, not running software.

I would install either Malware Bytes OR Super Anti Spyware. Both would be overkill.

Spyware Blaster is like the hosts file in that it works without slowing the machine, because it does not run in the background.

This is why I recommended the programs listed above.

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#12 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:10:30 PM

Posted 09 January 2009 - 07:05 PM

Hello, Johnoh123
Since this issue appears resolved, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

BillyIII
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users