Thanks Syler. Here are the files:
Malwarebytes' Anti-Malware 1.39
Database version: 2494
Windows 5.1.2600 Service Pack 2
7/24/2009 6:02:42 PM
mbam-log-2009-07-24 (18-02-42).txt
Scan type: Full Scan (C:\|)
Objects scanned: 283521
Time elapsed: 1 hour(s), 21 minute(s), 22 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 47
Registry Values Infected: 2
Registry Data Items Infected: 2
Folders Infected: 1
Files Infected: 37
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{09de17b0-a527-4eee-9c6e-2d7c2e9b505f} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f4fe513-e22f-4f1f-bb77-b1ed95e434cf} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{222f56e3-3116-4066-91d4-c3874e71e5dd} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{23e150c2-00c7-46e6-a968-724d41b051d6} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3124ad41-99ee-4e18-a605-ed5ee59466bc} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{37735f70-d4aa-4aed-99d0-88955c4bd74b} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4a2b9ad8-5540-46a3-bbb4-8ded5fb09de8} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4e79578b-5f0f-4594-90f9-2c309e59c2bc} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5484d9fa-6c4f-4c0b-8946-1b8ef15897a4} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{661b35ba-6035-4f06-a22a-c4cb19f873b2} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{66df69b7-ad8d-48dd-a4fe-23d336c621a9} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6d9a6231-1550-4652-a353-48e2c9194b19} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90fd4b8b-ce76-48b8-909e-e4d3844727ab} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{910c1d35-55b3-4956-a4f9-1460d06f33d4} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b87e031d-7b2a-4721-873e-c9be9962d64a} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d2a630e4-1ba7-4012-8672-35adbb47aa86} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0b68791-936d-490e-8cd9-a31022b55b35} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d445895c-b621-4d33-9898-4078cd171186} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8755ce6e-0bf7-4441-8751-fb728941b0b4} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8755ce6e-0bf7-4441-8751-fb728941b0b4} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{8755ce6e-0bf7-4441-8751-fb728941b0b4} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{afb06512-6247-4819-98ca-94fa19c734d7} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8ab8528f-ac8b-416d-9b84-92d97729c195} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{a4566604-f73b-4dd5-8a21-87e7a808d426} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0ca51d02-7739-43ea-8d9a-1e8ad4327b03} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ca51d02-7739-43ea-8d9a-1e8ad4327b03} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0ca51d02-7739-43ea-8d9a-1e8ad4327b03} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{5478d59a-b281-4f58-ad2e-103474434377} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{4ffb0262-eb74-461f-bbc8-7818df633687} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{08b13a8e-eb71-4421-b417-4ec0995d5bfc} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5aa23b9d-99c0-4a41-a25d-58e806766680} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7fd094e7-c8b9-40bd-9f80-f20a7194d2e6} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{81b9a3d6-d79f-403e-939b-4f2be8fd2a34} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d977d6a9-be13-496d-9be4-175dfac12628} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{dbbb7978-af21-4ef4-9ad1-b2f4bc75696c} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{dbbb7978-af21-4ef4-9ad1-b2f4bc75696c} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{deee7fe9-3e06-43ee-b04d-18866cd0ad9c} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{deee7fe9-3e06-43ee-b04d-18866cd0ad9c} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e03667bc-5eda-4fd8-992c-ed73265afaa0} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f4fb516e-8f16-44fd-ab1d-260c32b7cf9a} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{201e93ea-c7e1-4849-9985-0d2207a3f528} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bab1ac41-6ff7-4f2e-a04e-5c592ccfea7d} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\p4p service (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\p4p service (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\p4p service (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\addressbarexpress (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Sohu R&D (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{dbbb7978-af21-4ef4-9ad1-b2f4bc75696c} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{bab1ac41-6ff7-4f2e-a04e-5c592ccfea7d} (Adware.BHO) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Adware.BHO) -> Data: c:\windows\system32\sodahk.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Adware.BHO) -> Data: system32\sodahk.dll -> Quarantined and deleted successfully.
Folders Infected:
C:\Program Files\Common Files\Sogou PXP (Adware.BHO) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\P4P\rss.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Program Files\P4P\autolink.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Program Files\P4P\sodaie.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comploader.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\Program Files\P4P\ToolBar.dll (Adware.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\socul.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\common files\sogou pxp\p2psvr.exe (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\P4P\dlmgr.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\P4P\feed.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\P4P\p4pipc.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\P4P\skinpacker.exe (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\P4P\soda.exe (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\P4P\sodalib.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\P4P\strmfea.exe (Adware.BHO) -> Quarantined and deleted successfully.
c:\program files\P4P\tbupdate.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP554\A0103081.old (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP555\A0104079.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP555\A0104081.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP555\A0104083.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP555\A0104084.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP557\A0106449.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP558\A0106451.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP560\A0107711.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP560\A0108121.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP560\A0108123.ocx (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP560\A0108124.tlb (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP560\A0108125.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP560\A0108126.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP560\A0108129.sys (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{b7affc1a-8ab3-4141-aa3d-bd2df76a1666}\RP560\A0108131.dll (Spyware.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\Fonts\windef.Log (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\SODAHK.DLL (Adware.BHO) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\unsocul.exe (Adware.BHO) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\tmp0_782598125154.bk.old (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\WINDOWS\Temp\txpxr_374101370566.b1k (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
Edited DDS logs per member request ~ rigel
Edited by rigel, 09 August 2009 - 11:42 AM.