Once i knew i had a virus i ran malware bytes and AVG Antivirus, both found things so i healed/quarantined/deleted them but it appeared to get worse. It changed registry and start up items and when i tried to disable them they just kept reappearing again. I knew from getting rid of the virtuomonde one that you have to disable system restore before deleting them from the start up so they don't reappear on the next boot but can't remember the exact process so don't want to mess it up any further so need another walkthrough as i'm not very good with this stuff.
I've restored my firewall which was disabled bit still can't restore AVG. Webpages are taking an age to load and if i click a link from say google it tries to redirect me elsewhere so it's easier to go to pages already in my favourites or browser already. I get the odd pop but those are minimal.
Anyway here's the logs required and i look forward to someone helping out. Thanks in advance.
DDS (Ver_09-03-16.01) - NTFSx86
Run by Wayne at 0:39:46.32 on 25/04/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_01
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.446.83 [GMT 1:00]
AV: AVG 7.5.523 *On-access scanning enabled* (Updated)
FW: *disabled*
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\dhcp\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\sopidkc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Wayne\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\tdctxte.exe
C:\WINDOWS\system32\wtukd32.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Wayne\LOCALS~1\Temp\2291010398.exe
C:\WINDOWS\system32\dncyool64.sys
C:\Documents and Settings\Wayne\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
mSearchAssistant = hxxp://www.google.com
BHO: {02af8cd4-6753-4ae4-9f26-751dcbd24434} - c:\windows\system32\bayunivu.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: c:\windows\system32\jksahfo93wjfkd.dll: {b2ba40a2-74f0-42bd-f434-12345a2c8953} - c:\windows\system32\jksahfo93wjfkd.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\wayne\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Diagnostic Manager] c:\docume~1\wayne\locals~1\temp\2291010398.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [905e303e] rundll32.exe "c:\windows\system32\tuzatazo.dll",b
mRun: [CPM936d03a2] Rundll32.exe "c:\windows\system32\gukowema.dll",a
mRun: [VT100 Emulator] c:\windows\system32\VT100.EXE
mRun: [waiting1690] c:\windows\stid1690.exe
mRun: [wamewenafi] Rundll32.exe "c:\windows\system32\buvatolo.dll",s
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
dRun: [svc] c:\program files\thunmail\testabd.exe
StartupFolder: c:\docume~1\wayne\startm~1\programs\startup\imvu.lnk - c:\program files\imvu\IMVUClient.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\wayne\start menu\programs\>imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\PicLens.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw_promo.cab
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} - hxxp://cameras.homeentertainmentinc.com:81/IPV6CAM.CAB
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {2BE6A92D-D51C-4659-B372-BB18C99BC439} - hxxp://www.ppmate.com/search/downcab.jsp
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} - hxxp://smokeybunny.com/activex/AMC.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} - hxxp://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D821DC4A-0814-435E-9820-661C543A4679} - hxxp://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://cafecam.heerenvanbeijerland.nl/activex/AMC.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: jkkIBTLe - jkkIBTLe.dll
AppInit_DLLs: c:\progra~1\thunmail\testabd.dll c:\windows\system32\higibege.dll c:\windows\system32\gukowema.dll
SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gukowema.dll
STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\gukowema.dll
STS: c:\windows\system32\jksahfo93wjfkd.dll: {b2ba40a2-74f0-42bd-f434-12345a2c8953} - c:\windows\system32\jksahfo93wjfkd.dll
SEH: {D6163CD3-DC2A-48A1-A145-02C04FCD1249} - No File
LSA: Authentication Packages = msv1_0 c:\windows\system32\ljJAPJDv
LSA: Notification Packages = scecli c:\windows\system32\higibege.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\wayne\applic~1\mozilla\firefox\profiles\0b2tj0xy.default\
FF - prefs.js: browser.search.selectedEngine - F365
FF - component: c:\documents and settings\wayne\application data\idm\idmmzcc2\components\idmmzcc.dll
============= SERVICES / DRIVERS ===============
R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2007-10-31 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2007-10-31 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2007-10-31 27776]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2007-10-31 10760]
R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2008-3-19 607576]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avg7\avgamsvr.exe [2007-10-31 439296]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avg7\avgupsvc.exe [2007-10-31 70144]
R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avg7\avgemc.exe [2007-10-31 427008]
R2 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2007-10-31 4960]
R2 BCMWLNPF;Broadcom Netgroup Packet Filter;c:\windows\system32\drivers\BCMWLNPF.SYS [2006-11-29 33664]
R2 dhcpsrv;Dhcp server;c:\windows\dhcp\svchost.exe [2009-4-21 255488]
R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;c:\windows\system32\drivers\hnm_wrls_pkt.sys [2006-1-12 13696]
R2 msncache;msncache;c:\windows\system32\svchost.exe -k NetworkService [2004-8-10 34816]
R2 sopidkc;sopidkc Service;c:\windows\system32\sopidkc.exe [2004-8-4 194560]
R2 tdctxte;tdctxte Service;c:\windows\system32\tdctxte.exe [2004-8-4 194560]
R2 wsppkt;Wireless Security Protocol;c:\windows\system32\drivers\wsp_pkt.sys [2006-1-12 13568]
S0 avcrjg;avcrjg;c:\windows\system32\drivers\ylgeusa.sys --> c:\windows\system32\drivers\ylgeusa.sys [?]
S1 a0860f24;a0860f24;c:\windows\system32\drivers\a0860f24.sys [2009-4-21 0]
S3 CAM1690;USB 2.0 Compliance JPEG Video Camera;c:\windows\system32\drivers\cam1690.sys [2008-4-10 177280]
S3 mamotou;mamotou;c:\windows\system32\drivers\mamotou.sys [2007-4-19 49399]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-1-22 7680]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-1-25 42000]
=============== Created Last 30 ================
2009-04-24 20:41 0 a------- c:\windows\system32\C.tmp
2009-04-24 20:41 84 a------- c:\windows\system32\B.tmp
2009-04-24 20:41 15,000 a------- c:\windows\system32\jksahfo93wjfkd.dll
2009-04-24 19:24 132,096 -------- c:\windows\system32\VT100.EXE
2009-04-24 12:46 1,400,156 ---sh--- c:\windows\system32\ozatazut.ini
2009-04-24 01:20 155 a------- c:\windows\system32\SelfDel.bat
2009-04-24 01:19 108,032 a------- c:\windows\system32\ftp_non_crp.exe
2009-04-24 00:48 65,536 a------- c:\windows\system32\ak1.exe
2009-04-24 00:35 1,400,118 ---sh--- c:\windows\system32\agoyafin.ini
2009-04-23 08:30 <DIR> --d----- c:\program files\KoiCompanion
2009-04-23 01:34 1,399,373 ---sh--- c:\windows\system32\agonived.ini
2009-04-22 13:33 2,713 ---sh--- c:\windows\system32\nureyige.exe
2009-04-21 19:36 2,713 ---sh--- c:\windows\system32\vinomisu.dll
2009-04-21 19:36 2,713 ---sh--- c:\windows\system32\fuweyofa.dll
2009-04-21 19:30 232,960 a------- c:\windows\system32\w.exe
2009-04-21 19:30 36,864 a------- c:\windows\system32\dpcxool64.sys
2009-04-21 19:30 <DIR> --d----- c:\windows\system32\3361
2009-04-21 19:29 108,336 a------- c:\windows\system32\MSWINSCK.OCX
2009-04-21 19:29 <DIR> --d----- c:\windows\dhcp
2009-04-21 19:29 <DIR> --dshr-- c:\program files\ThunMail
2009-04-21 19:28 182,656 a------- c:\windows\system32\dllcache\ndis.sys
2009-04-21 19:28 0 a------- c:\windows\system32\drivers\a0860f24.sys
2009-04-21 19:28 <DIR> --d----- c:\docume~1\wayne\applic~1\pidle
2009-04-21 19:27 2 a------- C:\-1872875375
2009-04-21 19:27 114,752 a------- c:\windows\system32\prunnet.exe
2009-04-21 19:10 943,213 a------- c:\windows\system32\rn.tmp
2009-04-12 07:41 <DIR> --d----- C:\FLAV
==================== Find3M ====================
2009-04-25 00:14 98,304 a------- c:\windows\DUMP9d78.tmp
2009-04-24 23:36 2,189,184 ----h--- c:\windows\system32\ntoskrnl.exe
2009-04-24 12:46 88,576 a--sh--- c:\windows\system32\gukowema.dll
2009-04-24 12:46 80,896 a--sh--- c:\windows\system32\tuzatazo.dll
2009-04-24 12:46 75,264 a--sh--- c:\windows\system32\jemitawa.exe
2009-04-24 00:34 74,752 a--sh--- c:\windows\system32\badarizo.exe
2009-04-24 00:34 87,040 a--sh--- c:\windows\system32\tawagifi.dll
2009-04-24 00:32 98,304 a------- c:\windows\DUMPa807.tmp
2009-04-23 01:34 49,152 a--sh--- c:\windows\system32\vadalulu.dll
2009-04-23 01:34 74,752 a--sh--- c:\windows\system32\seretisa.exe
2009-04-23 01:34 88,064 a--sh--- c:\windows\system32\kajekipa.dll
2009-04-22 20:53 98,304 a------- c:\windows\DUMPa095.tmp
2009-04-22 20:51 98,304 a------- c:\windows\DUMPa028.tmp
2009-04-22 20:49 98,304 a------- c:\windows\DUMP9f6c.tmp
2009-04-22 15:49 98,304 a------- c:\windows\DUMPc071.tmp
2009-04-22 05:40 98,304 a------- c:\windows\DUMP8675.tmp
2009-04-21 19:28 182,656 a------- c:\windows\system32\drivers\ndis.sys
2009-04-21 19:27 34,816 a------- c:\windows\system32\svchost.exe
2009-03-07 06:50 218,940 a------- c:\windows\pchealth\helpctr\config\cache\Personal_32_1033.dat
2009-02-06 19:52 49,504 a------- c:\windows\system32\sirenacm.dll
2009-02-01 22:30 324 a------- c:\docume~1\wayne\applic~1\wklnhst.dat
2009-01-25 22:10 179,200 a------- c:\windows\system32\xvidvfw.dll
2007-08-08 18:35 87,608 a------- c:\docume~1\wayne\applic~1\inst.exe
2007-08-08 18:35 47,360 a------- c:\docume~1\wayne\applic~1\pcouffin.sys
2007-04-05 22:54 87,608 a------- c:\docume~1\wayne\applic~1\ezpinst.exe
2007-12-18 14:35 168 ---shr-- c:\windows\system32\92FA225111.sys
2009-01-23 01:34 49,152 a--sh--- c:\windows\system32\bayunivu.dll
2009-01-23 01:34 49,152 a--sh--- c:\windows\system32\buvatolo.dll
2009-01-23 01:34 49,152 a--sh--- c:\windows\system32\higibege.dll
2007-12-18 14:38 5,642 a--sh--- c:\windows\system32\KGyGaAvL.sys
2008-06-14 15:26 192,066 a--sh--- c:\windows\system32\vDJPAJjl.ini2
2008-09-09 09:11 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090920080910\index.dat
============= FINISH: 0:42:01.48 ===============