Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspect Winfixer, Don't Really Know


  • Please log in to reply
11 replies to this topic

#1 Kong

Kong

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 24 April 2007 - 12:52 PM

I have gone through the suggested procedure from this site concerning pop-ups and malware infection. I have tried many different programs, including Adware SE Personal, CCleaner, SpyBot Search and Destroy, Registry Fix, Vundo Fix, McAfee Stinger and have had no success in removing whatever it is. Just now while I am typing this, it freezes at times and I have to wait several seconds before the letters begin again. Even the cursor doesn't look right, it blinks but it flickers in between blinks. Concerning pop-ups, they are random and wide range of topics. This only happens when surfing with IE - 7, in the internet options section I have noticed that under the privacy tab it always goes back to accept all cookies. I have changed it serval times but it always goes back. I have also noticed under the Manage Add Ons section there are some mysterious entries, such as insicbuy.dll, yhntjoje.dll, fcccd.dll, iiijg.dll, iifdday.dll .. This has really got me stumpped, the programs mentioned above have always fixed things before. This time, I believe, I have gotten myself in deep water and I'm sinking. Here is my HJT log. Hope you can help. Thanks in advance..

Logfile of HijackThis v1.99.1
Scan saved at 1:13:20 PM, on 4/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

BC AdBot (Login to Remove)

 


m

#2 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:13 PM

Posted 24 April 2007 - 03:12 PM

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Kong :thumbsup:

Please download Combofix and save to the desktop:
http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe
Note:
It is important that it is saved directly to your desktop

Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the C:\ComboFix.txt into your next reply.
Note:
Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.


****************************

Please go to:
C:\Program Files\HijackThis\HijackThis.exe
Right click on Hijackthis.exe and select 'Rename', rename it to abc.bat
Double click on abc.bat(which is still Hijackthis.exe),post that log into your next reply please.
Also post the C:\ComboFix.txt

Posted Image
Posted Image

#3 Kong

Kong
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 25 April 2007 - 10:37 AM

Hello RichieUK, thanks for the help. I really need it. Here is what you requested.

"RJP" - 07-04-25 11:17:36 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\RJP\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\cfvyyiyu.dll
C:\WINDOWS\system32\phmphqow.dll
C:\WINDOWS\system32\ymjedmde.dll
C:\WINDOWS\system32\xjihhyfu.dll
C:\WINDOWS\system32\efcbxwv.dll
C:\WINDOWS\system32\woqhpmhp.ini
C:\WINDOWS\system32\gjiii.bak1
C:\WINDOWS\system32\gjiii.bak2
C:\WINDOWS\system32\gjiii.ini
C:\WINDOWS\system32\gjiii.ini2
C:\WINDOWS\system32\gjiii.tmp
C:\WINDOWS\system32\iiijg.dll
C:\WINDOWS\system32\iifdday.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((( Files Created from 2007-03-25 to 2007-04-25 ))))))))))))))))))))))))))))))))))


2007-04-23 19:57 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-04-23 18:38 <DIR> d-------- C:\DOCUME~1\RJP\.housecall6.6
2007-04-23 16:57 <DIR> d-------- C:\VundoFix Backups
2007-04-18 20:57 <DIR> d-------- C:\Program Files\Windows Defender
2007-04-16 12:50 <DIR> d-------- C:\Program Files\RegistryFix
2007-04-13 15:30 <DIR> d-------- C:\DOCUME~1\RJP\APPLIC~1\Help
2007-04-09 10:56 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-04-06 19:59 45,056 --a------ C:\WINDOWS\NCUNINST.EXE
2007-04-06 19:57 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2007-04-06 19:21 212 -ra------ C:\WINDOWS\system32\HPBVNSTP.DAT
2007-04-06 19:21 196,608 -ra------ C:\WINDOWS\system32\HPBVNSTP.DLL
2007-04-06 19:19 23,808 --a------ C:\WINDOWS\system32\drivers\Dot4usb.sys
2007-04-06 19:19 207,360 --a------ C:\WINDOWS\system32\drivers\Dot4.sys
2007-04-06 19:19 12,928 --a------ C:\WINDOWS\system32\drivers\Dot4Prt.sys
2007-04-04 11:05 8,704 --a------ C:\WINDOWS\system32\fxsperf.dll
2007-04-04 11:05 72,192 --a------ C:\WINDOWS\system32\fxscom.dll
2007-04-04 11:05 6,656 --a------ C:\WINDOWS\system32\fxsres.dll
2007-04-04 11:05 562,176 --a------ C:\WINDOWS\system32\fxsst.dll
2007-04-04 11:05 55,296 --a------ C:\WINDOWS\system32\fxsevent.dll
2007-04-04 11:05 452,096 --a------ C:\WINDOWS\system32\fxsapi.dll
2007-04-04 11:05 400,384 --a------ C:\WINDOWS\system32\fxsxp32.dll
2007-04-04 11:05 397,312 --a------ C:\WINDOWS\system32\fxstiff.dll
2007-04-04 11:05 31,744 --a------ C:\WINDOWS\system32\fxsroute.dll
2007-04-04 11:05 285,184 --a------ C:\WINDOWS\system32\fxscomex.dll
2007-04-04 11:05 27,136 --a------ C:\WINDOWS\system32\fxsdrv.dll
2007-04-04 11:05 267,776 --a------ C:\WINDOWS\system32\fxssvc.exe
2007-04-04 11:05 246,272 --a------ C:\WINDOWS\system32\fxst30.dll
2007-04-04 11:05 23,552 --a------ C:\WINDOWS\system32\fxsmon.dll
2007-04-04 11:05 23,552 --a------ C:\WINDOWS\system32\fxsext32.dll
2007-04-04 11:05 229,376 --a------ C:\WINDOWS\system32\fxscover.exe
2007-04-04 11:05 192,512 --a------ C:\WINDOWS\system32\fxswzrd.dll
2007-04-04 11:05 154,112 --a------ C:\WINDOWS\system32\fxsui.dll
2007-04-04 11:05 143,360 --a------ C:\WINDOWS\system32\fxsclnt.exe
2007-04-04 11:05 132,608 --a------ C:\WINDOWS\system32\fxsclntR.dll
2007-04-04 11:05 111,104 --a------ C:\WINDOWS\system32\fxscfgwz.dll
2007-04-04 11:05 11,264 --a------ C:\WINDOWS\system32\fxssend.exe
2007-04-04 11:05 <DIR> d-------- C:\WINDOWS\system32\FxsTmp


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-20 22:36 -------- d-------- C:\Program Files\k-lite
2007-04-06 21:26 -------- d-------- C:\Program Files\hewlett-packard
2007-03-21 13:57 -------- d-------- C:\Program Files\p2player
2007-03-20 15:44 -------- d-------- C:\Program Files\Common Files\installshield
2007-03-17 09:45 292864 --a------ C:\WINDOWS\system32\winsrv.dll
2007-03-08 11:48 578048 --a------ C:\WINDOWS\system32\user32.dll
2007-03-08 11:48 40960 --a------ C:\WINDOWS\system32\mf3216.dll
2007-03-08 11:48 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-03-08 09:49 1843968 --a------ C:\WINDOWS\system32\win32k.sys
2007-03-06 19:05 -------- d-------- C:\DOCUME~1\RJP\APPLIC~1\epson
2007-02-23 08:04 201 --a------ C:\WINDOWS\powerreg.dat
2007-02-22 23:16 81920 -r------- C:\WINDOWS\bwunin-6.1.4.61-8876480l.exe
2007-02-22 20:56 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-02-22 19:56 0 -rahs---- C:\MSDOS.SYS
2007-02-22 19:56 0 -rahs---- C:\IO.SYS
2007-02-22 19:56 0 --a------ C:\CONFIG.SYS
2007-02-22 19:56 0 --a------ C:\AUTOEXEC.BAT
2007-02-22 15:48 62 --ahs---- C:\DOCUME~1\RJP\APPLIC~1\desktop.ini
2007-02-13 20:49 86073 --a------ C:\WINDOWS\system32\usrfaxa.dll
2007-02-13 20:49 8192 --a------ C:\WINDOWS\system32\tsbyuv.dll
2007-02-13 20:49 8192 --a------ C:\WINDOWS\system32\streamci.dll
2007-02-13 20:49 77891 --a------ C:\WINDOWS\system32\usrmlnka.exe
2007-02-13 20:49 77890 --a------ C:\WINDOWS\system32\usrdpa.dll
2007-02-13 20:49 77883 --a------ C:\WINDOWS\system32\usrrtosa.dll
2007-02-13 20:49 72192 --a------ C:\WINDOWS\system32\sprio800.dll
2007-02-13 20:49 70656 --a------ C:\WINDOWS\system32\sprio600.dll
2007-02-13 20:49 69700 --a------ C:\WINDOWS\system32\usrshuta.exe
2007-02-13 20:49 69699 --a------ C:\WINDOWS\system32\usrcoina.dll
2007-02-13 20:49 69632 --a------ C:\WINDOWS\system32\spnike.dll
2007-02-13 20:49 61508 --a------ C:\WINDOWS\system32\usrprbda.exe
2007-02-13 20:49 61500 --a------ C:\WINDOWS\system32\usrcntra.dll
2007-02-13 20:49 55296 --a------ C:\WINDOWS\system32\dvdplay.exe
2007-02-13 20:49 53305 --a------ C:\WINDOWS\system32\usrlbva.dll
2007-02-13 20:49 52736 --a------ C:\WINDOWS\system32\wzcsapi.dll
2007-02-13 20:49 52224 --a------ C:\WINDOWS\system32\dmutil.dll
2007-02-13 20:49 49211 --a------ C:\WINDOWS\system32\usrvpa.dll
2007-02-13 20:49 49211 --a------ C:\WINDOWS\system32\usrsdpia.dll
2007-02-13 20:49 49209 --a------ C:\WINDOWS\system32\usrv80a.dll
2007-02-13 20:49 476160 --a------ C:\WINDOWS\system32\wzcsvc.dll
2007-02-13 20:49 47616 --a------ C:\WINDOWS\system32\iyuv_32.dll
2007-02-13 20:49 47104 --a------ C:\WINDOWS\system32\cnbjmon.dll
2007-02-13 20:49 45116 --a------ C:\WINDOWS\system32\usrvoica.dll
2007-02-13 20:49 41019 --a------ C:\WINDOWS\system32\usrsvpia.dll
2007-02-13 20:49 35328 --a------ C:\WINDOWS\system32\pid.dll
2007-02-13 20:49 323641 --a------ C:\WINDOWS\system32\usrdtea.dll
2007-02-13 20:49 3200 --a------ C:\WINDOWS\system32\wowfax.dll
2007-02-13 20:49 20992 --a------ C:\WINDOWS\system32\hid.dll
2007-02-13 20:49 17408 --a------ C:\WINDOWS\system32\msyuv.dll
2007-02-13 20:49 157696 --a------ C:\WINDOWS\system32\paqsp.dll
2007-02-13 20:49 15360 --a------ C:\WINDOWS\system32\pjlmon.dll
2007-02-13 20:49 147968 --a------ C:\WINDOWS\system32\mdwmdmsp.dll
2007-02-13 20:49 13824 --a------ C:\WINDOWS\system32\wowfaxui.dll
2007-02-13 20:49 102457 --a------ C:\WINDOWS\system32\usrv42a.dll
2007-02-13 20:22 331776 --a------ C:\WINDOWS\system32\wpdmtpdr.dll
2007-02-13 20:22 20480 --a------ C:\WINDOWS\system32\wmpui.dll
2007-02-13 20:22 10752 --a------ C:\WINDOWS\system32\wpdtrace.dll
2007-02-13 20:21 96768 --a------ C:\WINDOWS\system32\drmstor.dll
2007-02-13 20:21 258296 --a------ C:\WINDOWS\system32\drmclien.dll
2007-02-13 20:21 23040 --a------ C:\WINDOWS\kb913800.exe
2007-02-13 20:21 20480 --a------ C:\WINDOWS\system32\wmpcore.dll
2007-02-13 20:21 20480 --a------ C:\WINDOWS\system32\wmpcd.dll
2007-02-13 20:20 68888 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-02-13 20:20 62744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-02-13 20:20 3426072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-02-13 20:20 251672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2007-02-13 20:20 2414360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2007-02-13 20:20 237848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2007-02-13 20:20 236824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-02-13 20:20 2297552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2007-02-13 20:20 15128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2007-02-13 20:19 946448 --a------ C:\WINDOWS\system32\calc.exe
2007-02-13 20:19 8636 --a------ C:\WINDOWS\modifype.exe
2007-02-13 20:19 80896 --a------ C:\WINDOWS\system32\wscsvc.dll
2007-02-13 20:19 68096 --a------ C:\WINDOWS\system32\webclnt.dll
2007-02-13 20:19 65536 --a------ C:\WINDOWS\system32\wshext.dll
2007-02-13 20:19 61440 --a------ C:\WINDOWS\system32\copytosendto.dll
2007-02-13 20:19 49152 --a------ C:\WINDOWS\system32\wdigest.dll
2007-02-13 20:19 465368 --a------ C:\WINDOWS\system32\wuapi.dll
2007-02-13 20:19 43520 --a------ C:\WINDOWS\system32\makecab.exe
2007-02-13 20:19 41432 --a------ C:\WINDOWS\system32\wups.dll
2007-02-13 20:19 394240 --a------ C:\WINDOWS\system32\hmtcd.dll
2007-02-13 20:19 383488 --a------ C:\WINDOWS\system32\wzcdlg.dll
2007-02-13 20:19 28672 --a------ C:\WINDOWS\system32\wshcon.dll
2007-02-13 20:19 28672 --a------ C:\WINDOWS\system32\verclsid.exe
2007-02-13 20:19 26624 --a------ C:\WINDOWS\system32\verifier.dll
2007-02-13 20:19 200192 --a------ C:\WINDOWS\upx.exe
2007-02-13 20:19 194520 --a------ C:\WINDOWS\system32\wuaueng1.dll
2007-02-13 20:19 18392 --a------ C:\WINDOWS\system32\wups2.dll
2007-02-13 20:19 18392 --a------ C:\WINDOWS\system32\wuauserv.dll
2007-02-13 20:19 174040 --a------ C:\WINDOWS\system32\wuweb.dll
2007-02-13 20:19 172504 --a------ C:\WINDOWS\system32\wuauclt1.exe
2007-02-13 20:19 1353688 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-02-13 20:19 132096 --a------ C:\WINDOWS\system32\wkssvc.dll
2007-02-13 20:19 127448 --a------ C:\WINDOWS\system32\wucltui.dll
2007-02-13 20:19 124376 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-02-13 20:19 11776 --a------ C:\WINDOWS\system32\xolehlp.dll
2007-02-13 20:19 114688 --a------ C:\WINDOWS\system32\wscript.exe
2007-02-13 20:19 114688 --a------ C:\WINDOWS\system32\cabarc.exe
2007-02-13 20:18 96768 --a------ C:\WINDOWS\system32\srvsvc.dll
2007-02-13 20:18 713216 --a------ C:\WINDOWS\system32\sxs.dll
2007-02-13 20:18 59392 --a------ C:\WINDOWS\system32\stclient.dll
2007-02-13 20:18 57856 --a------ C:\WINDOWS\system32\spoolsv.exe
2007-02-13 20:18 55808 --a------ C:\WINDOWS\system32\twext.dll
2007-02-13 20:18 50176 --a------ C:\WINDOWS\system32\utilman.exe
2007-02-13 20:18 36352 --a------ C:\WINDOWS\system32\tsgqec.dll
2007-02-13 20:18 35840 --a------ C:\WINDOWS\system32\umandlg.dll
2007-02-13 20:18 295424 --a------ C:\WINDOWS\system32\termsrv.dll
2007-02-13 20:18 249344 --a------ C:\WINDOWS\system32\tapisrv.dll
2007-02-13 20:18 246814 --a------ C:\WINDOWS\system32\strmdll.dll
2007-02-13 20:18 218624 --a------ C:\WINDOWS\system32\uxtheme.dll
2007-02-13 20:18 123392 --a------ C:\WINDOWS\system32\umpnpmgr.dll
2007-02-13 20:18 117760 --a------ C:\WINDOWS\system32\t2embed.dll
2007-02-13 20:18 101376 --a------ C:\WINDOWS\system32\txflog.dll
2007-02-13 20:17 985088 --a------ C:\WINDOWS\system32\setupapi.dll
2007-02-13 20:17 91648 --a------ C:\WINDOWS\system32\mtxoci.dll
2007-02-13 20:17 86728 --a------ C:\WINDOWS\system32\msxml6r.dll
2007-02-13 20:17 84480 --a------ C:\WINDOWS\system32\pintool.exe
2007-02-13 20:17 74752 --a------ C:\WINDOWS\system32\olecli32.dll
2007-02-13 20:17 66560 --a------ C:\WINDOWS\system32\mtxclu.dll
2007-02-13 20:17 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2007-02-13 20:17 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2007-02-13 20:17 58880 --a------ C:\WINDOWS\system32\pnrpnsp.dll
2007-02-13 20:17 582144 --a------ C:\WINDOWS\system32\rpcrt4.dll
2007-02-13 20:17 553984 --a------ C:\WINDOWS\system32\p2psvc.dll
2007-02-13 20:17 53760 --a------ C:\WINDOWS\system32\narrator.exe
2007-02-13 20:17 531568 --a------ C:\WINDOWS\system32\rmactivate_isv.exe
2007-02-13 20:17 523376 --a------ C:\WINDOWS\system32\rmactivate.exe
2007-02-13 20:17 519280 --a------ C:\WINDOWS\system32\secproc_isv.dll
2007-02-13 20:17 518768 --a------ C:\WINDOWS\system32\secproc.dll
2007-02-13 20:17 43520 --a------ C:\WINDOWS\system32\ntlanman.dll
2007-02-13 20:17 399360 --a------ C:\WINDOWS\system32\rpcss.dll
2007-02-13 20:17 386048 --a------ C:\WINDOWS\system32\qdvd.dll
2007-02-13 20:17 37376 --a------ C:\WINDOWS\system32\olecnv32.dll
2007-02-13 20:17 35840 --a------ C:\WINDOWS\system32\qfecheck.exe
2007-02-13 20:17 358000 --a------ C:\WINDOWS\system32\rmactivate_ssp.exe
2007-02-13 20:17 354416 --a------ C:\WINDOWS\system32\rmactivate_ssp_isv.exe
2007-02-13 20:17 313344 --a------ C:\WINDOWS\system32\p2pgraph.dll
2007-02-13 20:17 288768 --a------ C:\WINDOWS\system32\rhttpaa.dll
2007-02-13 20:17 270336 --a------ C:\WINDOWS\system32\oakley.dll
2007-02-13 20:17 247808 --a------ C:\WINDOWS\system32\newdev.dll
2007-02-13 20:17 215552 --a------ C:\WINDOWS\system32\osk.exe
2007-02-13 20:17 197632 --a------ C:\WINDOWS\system32\netman.dll
2007-02-13 20:17 192624 --a------ C:\WINDOWS\system32\secproc_ssp_isv.dll
2007-02-13 20:17 192624 --a------ C:\WINDOWS\system32\secproc_ssp.dll
2007-02-13 20:17 192512 --a------ C:\WINDOWS\system32\qcap.dll
2007-02-13 20:17 178408 --a------ C:\WINDOWS\system32\muweb.dll
2007-02-13 20:17 1705472 --a------ C:\WINDOWS\system32\netshell.dll
2007-02-13 20:17 153088 --a------ C:\WINDOWS\system32\p2p.dll
2007-02-13 20:17 151552 --a------ C:\WINDOWS\system32\scrrun.dll
2007-02-13 20:17 151552 --a------ C:\WINDOWS\system32\scrobj.dll
2007-02-13 20:17 1435648 --a------ C:\WINDOWS\system32\query.dll
2007-02-13 20:17 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
2007-02-13 20:17 1321744 --a------ C:\WINDOWS\system32\msxml6.dll
2007-02-13 20:17 1287680 --a------ C:\WINDOWS\system32\quartz.dll
2007-02-13 20:17 1286656 --a------ C:\WINDOWS\system32\ole32.dll
2007-02-13 20:17 115712 --a------ C:\WINDOWS\system32\p2pnetsh.dll
2007-02-13 20:17 10752 --a------ C:\WINDOWS\system32\rspndr.exe
2007-02-13 20:17 104960 --a------ C:\WINDOWS\system32\p2pgasvc.dll
2007-02-13 20:16 956928 --a------ C:\WINDOWS\system32\msdtctm.dll
2007-02-13 20:16 884736 --a------ C:\WINDOWS\system32\msimsg.dll
2007-02-13 20:16 838360 --a------ C:\WINDOWS\system32\mswdat10.dll
2007-02-13 20:16 82432 --a------ C:\WINDOWS\system32\msxml4r.dll
2007-02-13 20:16 78848 --a------ C:\WINDOWS\system32\msiexec.exe
2007-02-13 20:16 73728 --a------ C:\WINDOWS\system32\mscms.dll
2007-02-13 20:16 701440 --a------ C:\WINDOWS\system32\msxml2.dll
2007-02-13 20:16 621272 --a------ C:\WINDOWS\system32\mswstr10.dll
2007-02-13 20:16 600576 --a------ C:\WINDOWS\system32\mstsc.exe
2007-02-13 20:16 58880 --a------ C:\WINDOWS\system32\msdtclog.dll
2007-02-13 20:16 427520 --a------ C:\WINDOWS\system32\msdtcprx.dll
2007-02-13 20:16 323696 --a------ C:\WINDOWS\system32\msdrm.dll
2007-02-13 20:16 297472 --a------ C:\WINDOWS\system32\msctf.dll
2007-02-13 20:16 2890240 --a------ C:\WINDOWS\system32\msi.dll
2007-02-13 20:16 271360 --a------ C:\WINDOWS\system32\msihnd.dll
2007-02-13 20:16 1866240 --a------ C:\WINDOWS\system32\mstscax.dll
2007-02-13 20:16 161792 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2007-02-13 20:16 15360 --a------ C:\WINDOWS\system32\msisip.dll
2007-02-13 20:16 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2007-02-13 20:16 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2007-02-13 20:15 72704 --a------ C:\WINDOWS\system32\magnify.exe
2007-02-13 20:15 726528 --a------ C:\WINDOWS\system32\lsasrv.dll
2007-02-13 20:15 61440 --a------ C:\WINDOWS\system32\mmcshext.dll
2007-02-13 20:15 586240 --a------ C:\WINDOWS\system32\mlang.dll
2007-02-13 20:15 397312 --a------ C:\WINDOWS\system32\mmcex.dll
2007-02-13 20:15 33792 --a------ C:\WINDOWS\system32\mmcperf.exe
2007-02-13 20:15 298496 --a------ C:\WINDOWS\system32\kerberos.dll
2007-02-13 20:15 19968 --a------ C:\WINDOWS\system32\linkinfo.dll
2007-02-13 20:15 198616 --a------ C:\WINDOWS\system32\iuengine.dll
2007-02-13 20:15 1913344 --a------ C:\WINDOWS\system32\mmcndmgr.dll
2007-02-13 20:15 184320 --a------ C:\WINDOWS\system32\microsoft.managementconsole.dll
2007-02-13 20:15 163328 --a------ C:\WINDOWS\system32\mmcbase.dll
2007-02-13 20:15 137216 --a------ C:\WINDOWS\system32\itss.dll
2007-02-13 20:15 1354752 --a------ C:\WINDOWS\system32\mmc.exe
2007-02-13 20:15 106496 --a------ C:\WINDOWS\system32\mmcfxcommon.dll
2007-02-13 20:14 98304 --a------ C:\WINDOWS\system32\cscript.exe
2007-02-13 20:14 97792 --a------ C:\WINDOWS\system32\comrepl.dll
2007-02-13 20:14 80896 --a------ C:\WINDOWS\system32\fontsub.dll
2007-02-13 20:14 77824 --a------ C:\WINDOWS\system32\browser.dll
2007-02-13 20:14 75736 --a------ C:\WINDOWS\system32\cdm.dll
2007-02-13 20:14 72704 --a------ C:\WINDOWS\system32\hlink.dll
2007-02-13 20:14 69120 --a------ C:\WINDOWS\system32\ciodm.dll
2007-02-13 20:14 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-02-13 20:14 625152 --a------ C:\WINDOWS\system32\catsrvut.dll
2007-02-13 20:14 62464 --a------ C:\WINDOWS\system32\cryptsvc.dll
2007-02-13 20:14 61952 --a------ C:\WINDOWS\system32\hdashcut.exe
2007-02-13 20:14 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2007-02-13 20:14 60416 --a------ C:\WINDOWS\system32\colbact.dll
2007-02-13 20:14 539648 --a------ C:\WINDOWS\system32\comuid.dll
2007-02-13 20:14 5120 --a------ C:\WINDOWS\system32\hdaudres.dll
2007-02-13 20:14 498742 --a------ C:\WINDOWS\system32\dxmasf.dll
2007-02-13 20:14 498688 --a------ C:\WINDOWS\system32\clbcatq.dll
2007-02-13 20:14 42496 --a------ C:\WINDOWS\system32\ftp.exe
2007-02-13 20:14 41472 --a------ C:\WINDOWS\system32\hhsetup.dll
2007-02-13 20:14 36921 --a------ C:\WINDOWS\system32\imeshare.dll
2007-02-13 20:14 347136 --a------ C:\WINDOWS\system32\hypertrm.dll
2007-02-13 20:14 28672 --a------ C:\WINDOWS\system32\dispex.dll
2007-02-13 20:14 254976 --a------ C:\WINDOWS\system32\icm32.dll
2007-02-13 20:14 25088 --a------ C:\WINDOWS\system32\hdaprop.dll
2007-02-13 20:14 243200 --a------ C:\WINDOWS\system32\es.dll
2007-02-13 20:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2007-02-13 20:14 225792 --a------ C:\WINDOWS\system32\catsrv.dll
2007-02-13 20:14 2068480 --a------ C:\WINDOWS\system32\cdosys.dll
2007-02-13 20:14 183808 --a------ C:\WINDOWS\system32\ipsecsvc.dll
2007-02-13 20:14 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2007-02-13 20:14 155136 --a------ C:\WINDOWS\system32\itircl.dll
2007-02-13 20:14 151552 --a------ C:\WINDOWS\system32\ifxcardm.dll
2007-02-13 20:14 148480 --a------ C:\WINDOWS\system32\cic.dll
2007-02-13 20:14 1269248 --a------ C:\WINDOWS\system32\comsvcs.dll
2007-02-13 20:14 123392 --a------ C:\WINDOWS\system32\input.dll
2007-02-13 20:14 110080 --a------ C:\WINDOWS\system32\clbcatex.dll
2007-02-13 20:14 1082368 --a------ C:\WINDOWS\system32\esent.dll
2007-02-13 20:14 10752 --a------ C:\WINDOWS\hh.exe
2007-02-13 20:14 1033216 --a------ C:\WINDOWS\explorer.exe
2007-02-13 20:13 96792 --a------ C:\WINDOWS\system32\basecsp.dll
2007-02-13 20:13 62464 --a------ C:\WINDOWS\system32\authz.dll
2007-02-13 20:13 25600 --a------ C:\WINDOWS\system32\bcsprsrc.dll
2007-02-13 20:13 133120 --a------ C:\WINDOWS\system32\axaltocm.dll
2007-02-13 20:13 116736 --a------ C:\WINDOWS\system32\aaclient.dll
2007-02-13 20:13 100352 --a------ C:\WINDOWS\system32\6to4svc.dll
2007-02-05 16:17 185344 --a------ C:\WINDOWS\system32\upnphost.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{1557B435-8242-4686-9AA3-9265BF7525A4} C:\WINDOWS\system32\yhntjoje.dll [x]
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{65BD0B3B-9F52-4069-83D1-47777C83CB07} C:\WINDOWS\system32\xjihhyfu.dll [x]
{AD68A30A-5C27-4B07-BCE2-9666F9E2ACA7} C:\WINDOWS\system32\fcccd.dll [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Logitech Utility"="Logi_MwX.Exe"
"Windows Defender"="C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb07.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"=dword:00000000
"NoToolbarCustomize"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"=dword:00000000
"NoToolbarCustomize"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{2188CEDE-B239-484C-8EA6-B84DC1001001}"="bjnlxbxtuusg"
"{CEDE2188-484C-B239-A68E-DC1B84001001}"="qwfuhbegnife"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\bjnlxbxtuusg
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qwfuhbegnife

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-04-25 11:24:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 07-04-25 11:25:10 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 07-04-25 11:25

Logfile of HijackThis v1.99.1
Scan saved at 11:27:51 AM, on 4/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\Abc.bat.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\yhntjoje.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {65BD0B3B-9F52-4069-83D1-47777C83CB07} - C:\WINDOWS\system32\xjihhyfu.dll (file missing)
O2 - BHO: (no name) - {AD68A30A-5C27-4B07-BCE2-9666F9E2ACA7} - C:\WINDOWS\system32\fcccd.dll (file missing)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O20 - Winlogon Notify: bjnlxbxtuusg - C:\WINDOWS\
O20 - Winlogon Notify: qwfuhbegnife - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

#4 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:13 PM

Posted 25 April 2007 - 10:51 AM

Download/install AVG Anti-Spyware 7.5.

Please follow these instructions very carefully.

Launch/start up AVG Anti-Spyware.
On the main page click the 'Update' tab,and then 'Start Update'.
Note:
If you have any problems running the update process prior to running the scan,download/install the 'Full Database' from here:
http://download.ewido.net/avgas-signatures-full-current.exe

Once the updates have been installed,do the following:
Select the 'Scanner' icon at the top of the screen, then select the 'Settings' tab.
Once in the 'Settings' screen,under 'How to act?',then under 'Set default action for detected malware to:', click on 'Recommended actions',then click on 'Quarantine'.
Under 'Reports' select 'Automatically generate report after every scan' and unselect 'Only if threats were found'.
Exit AVG Anti-Spyware,don't run the scan just yet.

You might want to print/copy the following as you need to be in Safe Mode from here on.

Reboot your computer into SAFE MODE using the F8 method.
To do this,restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly.
A menu will appear with several options.
Use the arrow keys on your keyboard to navigate and select the option to run Windows in "Safe Mode".

Have Hijack This fix the following [If still present], by placing a check in the appropriate boxes and selecting 'Fix checked'.
Make sure all browser and all Windows Explorer windows are closed before fixing:

O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\yhntjoje.dll (file missing)
O2 - BHO: (no name) - {65BD0B3B-9F52-4069-83D1-47777C83CB07} - C:\WINDOWS\system32\xjihhyfu.dll (file missing)
O2 - BHO: (no name) - {AD68A30A-5C27-4B07-BCE2-9666F9E2ACA7} - C:\WINDOWS\system32\fcccd.dll (file missing)
O20 - Winlogon Notify: bjnlxbxtuusg - C:\WINDOWS\
O20 - Winlogon Notify: qwfuhbegnife - C:\WINDOWS\


If you're not aware of these following restrictions,then fix them as well:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present


Still in Safe Mode launch AVG Anti-Spyware.
Click the 'Scanner' icon at the top.
To start the scan click on 'Complete System Scan'.
Please be patient,it takes a while for the scan to finish.

Once the scan is complete,do the following.
If AVG Anti-Spyware detected any infected objects:,click on 'Apply All Actions'.

Next click on 'Save Report'.
Copy and paste that report into your next reply.
The report can be found under the 'Reports' tab at the top.
Close AVG Anti-Spyware when you've done.
Reboot normally.

Post the AVG Anti Spyware report and a new Hijackthis log into your next reply.
Let me know how your pc is running now please.
Posted Image
Posted Image

#5 Kong

Kong
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 25 April 2007 - 02:49 PM

Hi Richie. It seems that my computer is working better. I noticed the Add-ons are not there anymore. The cursor is still flickering between blinks but it hasn't frozen yet, so that is good. When I first rebooted after running the Avg Spyware the folders and programs were having a little trouble opening. It took longer than usual, then I noticed it took a while for the actual Avg Spyware icon to show up. Maybe that had something to do with it. I haven't had a pop-up yet, so that is good. Here is the logs you wanted. Hope they look good. By the way, what was the reason for changing the name of the Hijackthis application. Can I change it back or should I run it like that from now on?


AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 3:19:34 PM 4/25/2007

+ Scan result:



C:\QooBox\Quarantine\C\WINDOWS\system32\efcbxwv.dll.vir -> Adware.Virtumonde : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\iifdday.dll.vir -> Adware.Virtumonde : Cleaned.
C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001222.dll -> Adware.Virtumonde : Cleaned.
C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001230.dll -> Adware.Virtumonde : Cleaned.
G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001247.exe -> Adware.Virtumonde : Cleaned.
C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000100.exe -> Downloader.Small.edb : Cleaned.
G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0001125.exe -> Downloader.Small.edb : Cleaned.
C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000101.exe -> Not-A-Virus.Monitor.Win32.Perflogger.be : Cleaned.
G:\Downloads\XoftSpy\XoftspybyGoldocrack.zip/crackxoftspybyGoldocrack.exe -> Not-A-Virus.Monitor.Win32.Perflogger.be : Cleaned.
G:\Downloads\XoftSpy\crackxoftspybyGoldocrack.exe -> Not-A-Virus.Monitor.Win32.Perflogger.be : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@buzznet.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@getmusicfree.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@www.abcsearch[1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@rotator.its.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@ehg-pcsecurityshield.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\RJP\Cookies\rjp@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000099.exe -> Trojan.Agent.qt : Cleaned.
G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0001126.exe -> Trojan.Agent.qt : Cleaned.


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 3:45:02 PM, on 4/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\Abc.bat.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

#6 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:13 PM

Posted 25 April 2007 - 02:54 PM

Run 'BitDefender Online Scanner' using Internet Explorer:
http://www.bitdefender.com/scan8/ie.html
Read the 'END USER SOFTWARE LICENSE AGREEMENT' then click 'I agree'.
You'll be prompted to install the activex control,please do so.
Once installed,disable your current antivirus program,then click the 'Click here to scan' button.
The virus signatures will then load.
Once loaded the scan will start.
The scan will take quite some time so please be patient.
Once the scan has finished select the 'Detected Problems' tab.
Click on 'Click here to export scan'.
Save the file as an HTML file to your desktop.
Then click on the saved file and allow it to open with your browser.
Go to 'Edit'/'Select All' then copy and paste that log into your next reply.
*Note*
Don't forget to re-enable your antivirus program.
Posted Image
Posted Image

#7 Kong

Kong
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 25 April 2007 - 05:47 PM

Sorry, I scanned the Bitdefender twice. The first time the update failed and it asked me if I wanted to scan anyway. I hit OK, don't ask me why. I went back and tried a second time and the update took. So I have two scans, both picked up a good bit. Wow, I'm impressed. This must be a good program. Here are the logs.

BitDefender Online Scanner



Scan report generated at: Wed, Apr 25, 2007 - 17:15:47





Scan path: A:\;C:\;D:\;E:\;F:\;G:\;H:\;







Statistics

Time
00:25:12

Files
230440

Folders
1896

Boot Sectors
6

Archives
1018

Packed Files
102




Results

Identified Viruses
3

Infected Files
5

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
5




Engines Info

Virus Definitions
449645

Engine build
AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

Scan plugins
2

Archive plugins
10

Unpack plugins
2

E-mail plugins
1

System plugins
1




Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions


Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes




Scanned File
Status

C:\QooBox\Quarantine\C\WINDOWS\system32\xjihhyfu.dll.vir
Infected with: Trojan.BHO.AR

C:\QooBox\Quarantine\C\WINDOWS\system32\xjihhyfu.dll.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\system32\xjihhyfu.dll.vir
Deleted

G:\Chris' extras\Spamwasher\SpamWasher.exe
Infected with: MemScan:Win32.Worm.Gael.A

G:\Chris' extras\Spamwasher\SpamWasher.exe
Disinfection failed

G:\Chris' extras\Spamwasher\SpamWasher.exe
Deleted

G:\Chris' extras\VisualBusinessCards\vbc3.exe
Infected with: Win32.Worm.Gael.A

G:\Chris' extras\VisualBusinessCards\vbc3.exe
Disinfection failed

G:\Chris' extras\VisualBusinessCards\vbc3.exe
Deleted

G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001299.exe
Infected with: MemScan:Win32.Worm.Gael.A

G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001299.exe
Disinfection failed

G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001299.exe
Deleted

G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001300.exe
Infected with: Win32.Worm.Gael.A

G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001300.exe
Disinfection failed

G:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001300.exe
Deleted



*********************************************


BitDefender Online Scanner



Scan report generated at: Wed, Apr 25, 2007 - 18:25:41





Scan path: A:\;C:\;D:\;E:\;F:\;G:\;H:\;







Statistics

Time
00:58:12

Files
522253

Folders
1896

Boot Sectors
6

Archives
1844

Packed Files
79412




Results

Identified Viruses
3

Infected Files
27

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
27




Engines Info

Virus Definitions
487717

Engine build
AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

Scan plugins
14

Archive plugins
38

Unpack plugins
6

E-mail plugins
6

System plugins
1




Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions


Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes




Scanned File
Status

C:\QooBox\Quarantine\C\WINDOWS\system32\cfvyyiyu.dll.vir
Infected with: Trojan.Vundo.AN

C:\QooBox\Quarantine\C\WINDOWS\system32\cfvyyiyu.dll.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\system32\cfvyyiyu.dll.vir
Deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\iiijg.dll.vir
Infected with: MemScan:Trojan.Vundo.AP

C:\QooBox\Quarantine\C\WINDOWS\system32\iiijg.dll.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\system32\iiijg.dll.vir
Deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\phmphqow.dll.vir
Infected with: Trojan.Vundo.AN

C:\QooBox\Quarantine\C\WINDOWS\system32\phmphqow.dll.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\system32\phmphqow.dll.vir
Deleted

C:\QooBox\Quarantine\C\WINDOWS\system32\ymjedmde.dll.vir
Infected with: Trojan.Vundo.AN

C:\QooBox\Quarantine\C\WINDOWS\system32\ymjedmde.dll.vir
Disinfection failed

C:\QooBox\Quarantine\C\WINDOWS\system32\ymjedmde.dll.vir
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000085.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000085.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000085.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000086.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000086.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000086.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000087.dll
Infected with: MemScan:Trojan.Vundo.AP

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000087.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000087.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000088.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000088.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000088.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000089.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000089.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000089.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000090.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000090.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000090.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000091.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000091.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000091.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000092.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000092.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000092.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000093.dll
Infected with: MemScan:Trojan.BHO.AU

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000093.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000093.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000094.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000094.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP4\A0000094.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001219.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001219.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001219.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001220.dll
Infected with: Trojan.Vundo.AN

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001220.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001220.dll
Deleted

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001229.dll
Infected with: MemScan:Trojan.Vundo.AP

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001229.dll
Disinfection failed

C:\System Volume Information\_restore{7A4893C8-73D0-4AEC-9392-13099EE1A0FC}\RP5\A0001229.dll
Deleted

C:\VundoFix Backups\bhemrpef.dll.bad
Infected with: Trojan.Vundo.AN

C:\VundoFix Backups\bhemrpef.dll.bad
Disinfection failed

C:\VundoFix Backups\bhemrpef.dll.bad
Deleted

C:\VundoFix Backups\dpwwbbto.dll.bad
Infected with: Trojan.Vundo.AN

C:\VundoFix Backups\dpwwbbto.dll.bad
Disinfection failed

C:\VundoFix Backups\dpwwbbto.dll.bad
Deleted

C:\VundoFix Backups\fcccd.dll.bad
Infected with: MemScan:Trojan.Vundo.AP

C:\VundoFix Backups\fcccd.dll.bad
Disinfection failed

C:\VundoFix Backups\fcccd.dll.bad
Deleted

C:\VundoFix Backups\gheihwcy.dll.bad
Infected with: Trojan.Vundo.AN

C:\VundoFix Backups\gheihwcy.dll.bad
Disinfection failed

C:\VundoFix Backups\gheihwcy.dll.bad
Deleted

C:\VundoFix Backups\jrvuhruh.dll.bad
Infected with: Trojan.Vundo.AN

C:\VundoFix Backups\jrvuhruh.dll.bad
Disinfection failed

C:\VundoFix Backups\jrvuhruh.dll.bad
Deleted

C:\VundoFix Backups\kuxyxuya.dll.bad
Infected with: Trojan.Vundo.AN

C:\VundoFix Backups\kuxyxuya.dll.bad
Disinfection failed

C:\VundoFix Backups\kuxyxuya.dll.bad
Deleted

C:\VundoFix Backups\ntulwodq.dll.bad
Infected with: Trojan.Vundo.AN

C:\VundoFix Backups\ntulwodq.dll.bad
Disinfection failed

C:\VundoFix Backups\ntulwodq.dll.bad
Deleted

C:\VundoFix Backups\twimfnpn.dll.bad
Infected with: Trojan.Vundo.AN

C:\VundoFix Backups\twimfnpn.dll.bad
Disinfection failed

C:\VundoFix Backups\twimfnpn.dll.bad
Deleted

C:\VundoFix Backups\ufjfumux.dll.bad
Infected with: MemScan:Trojan.BHO.AU

C:\VundoFix Backups\ufjfumux.dll.bad
Disinfection failed

C:\VundoFix Backups\ufjfumux.dll.bad
Deleted

C:\VundoFix Backups\ypoiaobu.dll.bad
Infected with: Trojan.Vundo.AN

C:\VundoFix Backups\ypoiaobu.dll.bad
Disinfection failed

C:\VundoFix Backups\ypoiaobu.dll.bad
Deleted

#8 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:13 PM

Posted 25 April 2007 - 06:10 PM

If all's ok,please do the following:

Find and delete:
C:\VundoFix Backups
C:\QooBox


Click on Start/All Programs/Accessories/System Tools/System Restore.
In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'.
In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'.
The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.
The 'Select Drive' box will appear,click on Ok.
The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.
At the bottom in the 'System Restore' window,click on the 'Clean up...' button.
A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.
Click on 'Yes' at 'Are you sure you want to perform these actions?'.
Now wait until 'Disk Cleanup' finishes and the box disappears.

Read through the information found here,to help you prevent any possible future infections.
'How to prevent Malware' by miekiemoes:
http://users.telenet.be/bluepatchy/miekiem...prevention.html
Posted Image
Posted Image

#9 Kong

Kong
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 25 April 2007 - 08:15 PM

Thanks for all your help. Things are working much better than they were. Can I change the name of the Hijack exe file back to its original name? What do you think about these programs like Registry Fix, Registry Boost, or Registry Mechanic. They all say it can speed things up and fix registry problems, is this true or just crap? Should I be running them?

#10 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:13 PM

Posted 26 April 2007 - 03:51 AM

Can I change the name of the Hijack exe file back to its original name?

Hijackthis can be a dangerous tool if used by someone who does'nt know what they're doing,it could render your operating system inoperable.I suggest you remove it via Add or Remove Programs.

What do you think about these programs like Registry Fix, Registry Boost, or Registry Mechanic. They all say it can speed things up and fix registry problems, is this true or just crap? Should I be running them?

Personally i think they're a complete waste of time,remove them all via Add or Remove Programs.
:thumbsup:
Posted Image
Posted Image

#11 Kong

Kong
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:13 PM

Posted 26 April 2007 - 01:19 PM

I know you are busy, this web site seems to be booming. A reflection on the job you're doing. One question, in the IE options under Privacy, what should the setting be? My is set at accept all cookies, is that right?? Thanks

#12 RichieUK

RichieUK

    Malware Assassin


  • Malware Response Team
  • 13,614 posts
  • OFFLINE
  •  
  • Local time:11:13 PM

Posted 26 April 2007 - 01:32 PM

Blocking Unwanted Cookies with IE7:
http://www.mvps.org/winhelp2002/cookies.htm
Scroll down to Recommended Settings.
Posted Image
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users