It is currently Tue Sep 01, 2026 12:12 pm


Random Letter Virus

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Random Letter Virus

Postby Robbington » Sun Jan 06, 2008 11:49 am

Hey, I recently installed a virus onto my computer. Not very clever, but its done now and I would really appreciate some help as its a tricky little gimp.
Have tried anti Virus programs, notably AVG which actually makes it worse if run. Would try programs like smitrem, but my comp now seems to crash every time i boot in safe mode.

If any one could help I would be very greatful as Im pretty sure that My privacy is being comprised.


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 10:28:51, on 06/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Netscape\Navigator 9\navigator.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Compaq_Owner\Desktop\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.virgin.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Virgin.net
O2 - BHO: {817ca3e3-c197-baa8-3c44-79a0210c09e8} - {8e90c012-0a97-44c3-8aab-791c3e3ac718} - C:\WINDOWS\system32\ghpgqhwb.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\htlvxzlc.dll
O2 - BHO: (no name) - {E4AF4207-C99D-49C6-B740-693E5BBA4725} - C:\WINDOWS\system32\awvvt.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\htlvxzlc.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [4842d3dc] rundll32.exe "C:\WINDOWS\system32\mawsndub.dll",b
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: NetEraser v1.0 - {41691540-0BFB-4992-9D7D-89D30DD09E9A} - C:\Program Files\NetEraserTrial\NetEraserDemo.exe (file missing)
O9 - Extra 'Tools' menuitem: NetEraser - {41691540-0BFB-4992-9D7D-89D30DD09E9A} - C:\Program Files\NetEraserTrial\NetEraserDemo.exe (file missing)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.securesoftwarefeed.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.securesoftwarefeed.com/redirect.php (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-U ... E_UNO1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Fac ... loader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_2 ... lashAX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer = 62.24.128.5 62.24.128.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer = 62.24.128.5 62.24.128.69
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00752BC.dat
O20 - Winlogon Notify: htlvxzlc - C:\WINDOWS\SYSTEM32\htlvxzlc.dll
O20 - Winlogon Notify: wineil32 - C:\WINDOWS\SYSTEM32\wineil32.dll
O21 - SSODL: E404Helper - {069e4792-ee19-48a9-ae3b-170f0b86b14e} - (no file)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

Thanks
Robbington
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 11:31 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Sun Jan 06, 2008 11:57 am

Hello Robbington, and welcome to our forum.

Please download and save it to your desktop.

Double-click VundoFix.exe to run it.
When VundoFixopens, click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
Scan for Vundo button." when VundoFix appears at reboot.

After the reboot(s) post a new Hijackthis log in your reply.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Re: Vundofix

Postby Robbington » Sun Jan 06, 2008 12:55 pm

Just posting the HJthis log after I ran Vundofix, can you tell me what you are looking for in it? Just for future reference.


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:53:28, on 06/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Compaq_Owner\Desktop\HiJackThis_v2.exe
C:\Program Files\Netscape\Navigator 9\navigator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.virgin.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Virgin.net
O2 - BHO: {817ca3e3-c197-baa8-3c44-79a0210c09e8} - {8e90c012-0a97-44c3-8aab-791c3e3ac718} - C:\WINDOWS\system32\ghpgqhwb.dll
O2 - BHO: (no name) - {E4AF4207-C99D-49C6-B740-693E5BBA4725} - C:\WINDOWS\system32\awvvt.dll (file missing)
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: NetEraser v1.0 - {41691540-0BFB-4992-9D7D-89D30DD09E9A} - C:\Program Files\NetEraserTrial\NetEraserDemo.exe (file missing)
O9 - Extra 'Tools' menuitem: NetEraser - {41691540-0BFB-4992-9D7D-89D30DD09E9A} - C:\Program Files\NetEraserTrial\NetEraserDemo.exe (file missing)
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.securesoftwarefeed.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.securesoftwarefeed.com/redirect.php (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-U ... E_UNO1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Fac ... loader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_2 ... lashAX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer = 62.24.128.69 62.24.128.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer = 62.24.128.69 62.24.128.5
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00752BC.dat
O21 - SSODL: E404Helper - {069e4792-ee19-48a9-ae3b-170f0b86b14e} - (no file)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

--
End of file - 5804 bytes
Robbington
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 11:31 am

Thanks given:0
Thanks received:0
Top

Re: Vundofix

Postby Gecko » Sun Jan 06, 2008 1:11 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Robbington » Sun Jan 06, 2008 1:32 pm

Here you go.

ComboFix 08-01-04.1 - Compaq_Owner 2008-01-06 12:21:20.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.198 [GMT 0:00]
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Compaq_Owner\Application Data.\Ultimate Cleaner
C:\Documents and Settings\Compaq_Owner\Application Data.\Ultimate Cleaner\settings.dat
C:\Documents and Settings\Compaq_Owner\Application Data\Ultimate Cleaner\settings.dat
C:\Documents and Settings\Compaq_Owner\Desktop\Find Spyware Remover.lnk
C:\Documents and Settings\Compaq_Owner\Favorites\Online Security Guide.lnk
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\E404 Helper
C:\Program Files\E404 Helper\e404.v1.dll
C:\Program Files\E404 Helper\e404.v5.dll
C:\Program Files\E404 Helper\e404.v6.dll
C:\Program Files\Hammer.dll
C:\Program Files\Helper
C:\Program Files\Helper\findsiteonline.dll
C:\Program Files\Helper\Helper6.dll
C:\Program Files\lsass.exe
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe.bak
C:\WINDOWS\Casino.ico
C:\WINDOWS\cookies.ini
C:\WINDOWS\Free Online Dating.ico
C:\WINDOWS\hosts
C:\WINDOWS\pack.epk
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\system32\ajhevlwa.dll
C:\WINDOWS\system32\anvctpxr.ini
C:\WINDOWS\system32\aonctkwg.ini
C:\WINDOWS\system32\avjxfeja.ini
C:\WINDOWS\system32\baqpdoro.ini
C:\WINDOWS\system32\bgeyrkec.ini
C:\WINDOWS\system32\bhcnqxfl.ini
C:\WINDOWS\system32\bmicdhix.ini
C:\WINDOWS\system32\bqkibqqw.ini
C:\WINDOWS\system32\cbqoxkbu.ini
C:\WINDOWS\system32\ddwbpyxc.ini
C:\WINDOWS\system32\din.ip
C:\WINDOWS\system32\dnqkeadx.ini
C:\WINDOWS\system32\dothvnmx.ini
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drvhux.dll
C:\WINDOWS\system32\dxdymuwe.ini
C:\WINDOWS\system32\e404d.dll
C:\WINDOWS\system32\eebpxyuj.ini
C:\WINDOWS\system32\eldimvin.ini
C:\WINDOWS\system32\eomvpnsj.ini
C:\WINDOWS\system32\eqbkyayo.ini
C:\WINDOWS\system32\fhgxlpit.ini
C:\WINDOWS\system32\frwirwfd.ini
C:\WINDOWS\system32\fsiugrgc.ini
C:\WINDOWS\system32\ftofbotj.ini
C:\WINDOWS\system32\fxtxmftr.ini
C:\WINDOWS\system32\gjmsseab.ini
C:\WINDOWS\system32\gnjsjc.dll
C:\WINDOWS\system32\hesfehjo.ini
C:\WINDOWS\system32\hutrasap.ini
C:\WINDOWS\system32\ijascoce.ini
C:\WINDOWS\system32\imhctchp.ini
C:\WINDOWS\system32\ipostyvx.ini
C:\WINDOWS\system32\ipxoueef.ini
C:\WINDOWS\system32\irofvryi.ini
C:\WINDOWS\system32\isdxhnyb.ini
C:\WINDOWS\system32\ivgvttey.ini
C:\WINDOWS\system32\jrmswwxp.ini
C:\WINDOWS\system32\jrvvpjuu.ini
C:\WINDOWS\system32\kbtypfrq.ini
C:\WINDOWS\system32\llermiqq.ini
C:\WINDOWS\system32\lodwhbpr.ini
C:\WINDOWS\system32\lrqagagr.ini
C:\WINDOWS\system32\lxwqjshx.ini
C:\WINDOWS\system32\mmqamjwj.ini
C:\WINDOWS\system32\niwpmobr.ini
C:\WINDOWS\system32\ocsnfnyn.ini
C:\WINDOWS\system32\onpqgcfw.ini
C:\WINDOWS\system32\ostawhit.ini
C:\WINDOWS\system32\pkrtjfpq.ini
C:\WINDOWS\system32\pvftnfwe.ini
C:\WINDOWS\system32\qkasqelo.ini
C:\WINDOWS\system32\qtsamkfh.ini
C:\WINDOWS\system32\qynqrxoa.ini
C:\WINDOWS\system32\rbqrvqdx.ini
C:\WINDOWS\system32\rbswpvwn.ini
C:\WINDOWS\system32\rdklvltp.ini
C:\WINDOWS\system32\rdkvulan.ini
C:\WINDOWS\system32\rhljncuy.ini
C:\WINDOWS\system32\rlftsvah.ini
C:\WINDOWS\system32\suiqiwof.dll
C:\WINDOWS\system32\tbljjryw.ini
C:\WINDOWS\system32\tuskqlnq.ini
C:\WINDOWS\system32\ubltbpwa.ini
C:\WINDOWS\system32\ufyfpikq.ini
C:\WINDOWS\system32\uibhpyuy.ini
C:\WINDOWS\system32\umfgteca.ini
C:\WINDOWS\system32\upwwxnpu.ini
C:\WINDOWS\system32\vddfvqdb.ini
C:\WINDOWS\system32\vhpailad.dll
C:\WINDOWS\system32\vjyapxoj.dll
C:\WINDOWS\system32\vlwkysgo.ini
C:\WINDOWS\system32\wepxjhaf.ini
C:\WINDOWS\system32\whglqbdw.ini
C:\WINDOWS\system32\wvjbcaoh.ini
C:\WINDOWS\system32\wwulcegf.ini
C:\WINDOWS\system32\wynkqwrh.ini
C:\WINDOWS\system32\xntmhdds.ini
C:\WINDOWS\system32\xuqlhoyk.ini
C:\WINDOWS\system32\xvudkudi.ini
C:\WINDOWS\system32\ymlaibbn.ini
C:\WINDOWS\system32\yuujxbwc.ini
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.

2008-01-06 12:20 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-06 11:43 . 2008-01-06 11:43 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-01-06 11:18 . 2008-01-06 11:18 <DIR> d-------- C:\VundoFix Backups
2008-01-06 10:15 . 2008-01-06 10:15 1,043,920 ---hs---- C:\WINDOWS\system32\budnswam.ini
2008-01-06 10:12 . 2008-01-06 10:12 75,840 --a------ C:\WINDOWS\system32\ghpgqhwb.dll
2008-01-05 18:55 . 2008-01-06 10:06 1,043,860 ---hs---- C:\WINDOWS\system32\flvbtukx.ini
2008-01-05 17:18 . 2008-01-05 17:44 <DIR> d-------- C:\Poker
2008-01-05 00:26 . 2008-01-05 13:40 1,043,980 ---hs---- C:\WINDOWS\system32\udwuvefa.ini
2008-01-04 18:44 . 2008-01-05 00:18 1,043,860 ---hs---- C:\WINDOWS\system32\qavvpqyb.ini
2008-01-03 13:21 . 2008-01-04 07:52 1,036,462 ---hs---- C:\WINDOWS\system32\bcceioyt.ini
2008-01-03 07:07 . 2008-01-03 13:13 1,031,873 ---hs---- C:\WINDOWS\system32\daxfntnt.ini
2008-01-02 22:22 . 2008-01-03 06:58 1,031,458 ---hs---- C:\WINDOWS\system32\osapbbsp.ini
2008-01-02 19:44 . 2008-01-02 19:45 1,031,398 ---hs---- C:\WINDOWS\system32\bsoyuqos.ini
2008-01-02 13:00 . 2008-01-02 13:00 1,031,878 ---hs---- C:\WINDOWS\system32\tmxnvpop.ini
2008-01-01 18:18 . 2008-01-02 11:51 1,031,559 ---hs---- C:\WINDOWS\system32\hviiylwd.ini
2008-01-01 14:35 . 2008-01-01 17:13 1,031,319 ---hs---- C:\WINDOWS\system32\djycqgys.ini
2008-01-01 12:46 . 2008-01-01 13:29 1,031,199 ---hs---- C:\WINDOWS\system32\ldaatncd.ini
2007-12-31 10:17 . 2007-12-31 10:17 1,031,259 ---hs---- C:\WINDOWS\system32\lboxrvxu.ini
2007-12-30 18:58 . 2007-12-31 08:08 1,031,199 ---hs---- C:\WINDOWS\system32\kuassuod.ini
2007-12-29 18:22 . 2007-12-30 12:33 1,031,199 ---hs---- C:\WINDOWS\system32\usemhhbf.ini
2007-12-29 14:33 . 2007-12-29 14:33 1,031,439 ---hs---- C:\WINDOWS\system32\lqmriyor.ini
2007-12-28 16:17 . 2007-12-29 14:33 1,031,379 ---hs---- C:\WINDOWS\system32\liokyoxm.ini
2007-12-28 13:13 . 2007-12-28 15:09 1,031,199 ---hs---- C:\WINDOWS\system32\lusnvwop.ini
2007-12-26 18:01 . 2007-12-26 18:01 30,208 --a------ C:\Round 1.doc
2007-12-26 17:38 . 2007-12-27 16:44 1,027,493 ---hs---- C:\WINDOWS\system32\tqdwqbqy.ini
2007-12-19 19:14 . 2007-12-19 19:56 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-17 18:40 . 2007-12-29 15:27 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\ZoomBrowser EX
2007-12-17 18:30 . 2007-12-29 15:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2007-12-17 18:29 . 2007-12-17 18:32 <DIR> d-------- C:\Program Files\Canon
2007-12-17 18:26 . 2007-12-17 18:26 <DIR> d-------- C:\Program Files\Common Files\Canon
2007-12-13 14:52 . 2007-12-13 14:52 0 --a------ C:\Install

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 23:23 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\Azureus
2008-01-02 13:12 --------- d-----w C:\Program Files\Azureus
2007-12-13 14:52 --------- d-----w C:\Program Files\MalwareAlarm
2007-11-30 23:15 --------- d-----w C:\Program Files\Rrztfqhf
2007-11-30 23:15 --------- d-----w C:\Program Files\qtidarsv
2007-11-30 23:15 --------- d-----w C:\Program Files\fwlubmna
2007-11-18 18:02 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\AVG7
2007-11-15 20:10 --------- d-----w C:\Program Files\SubmachineFLF_at
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-08 21:47 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\SKIP ONCE MANAGER
2006-08-21 07:27 0 ----a-w C:\Documents and Settings\Compaq_Owner\loaded.exe
2004-08-04 12:00 94,784 --sh--w C:\WINDOWS\twain.dll
2004-08-04 12:00 50,688 --sh--w C:\WINDOWS\twain_32.dll
2005-05-02 10:14 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
2004-08-04 12:00 54,784 --sh--w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 12:00 413,696 --sh--w C:\WINDOWS\system32\msvcp60.dll
2007-05-17 11:28 549,376 --sh--w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 12:00 83,456 --sh--w C:\WINDOWS\system32\olepro32.dll
2004-08-04 12:00 11,776 --sh--w C:\WINDOWS\system32\regsvr32.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8e90c012-0a97-44c3-8aab-791c3e3ac718}]
2008-01-06 10:12 75840 --a------ C:\WINDOWS\system32\ghpgqhwb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E4AF4207-C99D-49C6-B740-693E5BBA4725}]
C:\WINDOWS\system32\awvvt.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F2BADA0D-FD61-45EF-A994-64A073FD6613}"= C:\Program Files\Video Add-on\ictmdl.dll [ ]

[HKEY_CLASSES_ROOT\clsid\{f2bada0d-fd61-45ef-a994-64a073fd6613}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25 6731312]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 12:00 158208]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HPAiODevice(hp psc 700 series) - 1.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp psc 700 series) - 1.lnk
backup=C:\WINDOWS\pss\HPAiODevice(hp psc 700 series) - 1.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^OpenMG Jukebox Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OpenMG Jukebox Startup.lnk
backup=C:\WINDOWS\pss\OpenMG Jukebox Startup.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3wPlayer Service]
2007-10-09 10:48 139264 --a------ C:\Program Files\3wPlayer\wakeservice.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4842d3dc]
rundll32.exe C:\WINDOWS\system32\mawsndub.dll,b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 10:09 63712 --a------ C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-10 19:51 39792 --a------ C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-03-14 18:05 257088 --a------ C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAZAA]
C:\Program Files\Kazaa\kazaa.exe /SYSTRAY

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe /icon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"btwdins"=2 (0x2)
"PREVXAgent"=2 (0x2)
"iPod Service"=3 (0x3)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"SNDSrvc"=3 (0x3)
"BthServ"=2 (0x2)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"usnjsvc"=3 (0x3)
"PnkBstrA"=2 (0x2)
"IDriverT"=3 (0x3)
"NVSvc"=2 (0x2)
"DomainService"=2 (0x2)

R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [2004-11-22 14:15]
S3 aaudstum;aaudstum;C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\aaudstum.sys []
S3 DLPortIO;DriverLINX Port I/O Driver;C:\WINDOWS\system32\DRIVERS\DLPortIO.SYS [2000-06-29 16:24]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-06 12:00:00 C:\WINDOWS\Tasks\ABAE28E29185DF92.job"
- c:\docume~1\compaq~1\applic~1\skipon~1\Way Idle Bin.exe
"2007-12-24 07:58:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-06 12:22:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 12:28:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-06 12:30:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-06 12:30:04
.
2007-12-21 16:21:47 --- E O F ---
Robbington
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 11:31 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Sun Jan 06, 2008 2:57 pm

User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Robbington » Sun Jan 06, 2008 9:53 pm

Hi sorry about the late reply. Had to go out for a while. Anyways here is the reports not sure if you wanted two smitfraud reports (before and after I ran combo fix) but better safe than sorry huh.

SmitFraudFix v2.274

Scan done at 20:31:30.67, 06/01/2008
Run from C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Netscape\Navigator 9\navigator.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Compaq_Owner


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Compaq_Owner\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\COMPAQ~1\FAVORI~1

C:\DOCUME~1\COMPAQ~1\FAVORI~1\Online Security Test.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: WAN (PPP/SLIP) Interface
DNS Server Search Order: 62.24.128.5
DNS Server Search Order: 62.24.128.69

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer=62.24.128.5 62.24.128.69
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer=62.24.128.5 62.24.128.69


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

ComboFix 08-01-04.1 - Compaq_Owner 2008-01-06 20:36:12.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.236 [GMT 0:00]
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Compaq_Owner\Desktop\CFscript.txt
* Created a new restore point

FILE
C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\aaudstum.sys
C:\WINDOWS\system32\bcceioyt.ini
C:\WINDOWS\system32\bsoyuqos.ini
C:\WINDOWS\system32\budnswam.ini
C:\WINDOWS\system32\daxfntnt.ini
C:\WINDOWS\system32\djycqgys.ini
C:\WINDOWS\system32\flvbtukx.ini
C:\WINDOWS\system32\ghpgqhwb.dll
C:\WINDOWS\system32\hviiylwd.ini
C:\WINDOWS\system32\kuassuod.ini
C:\WINDOWS\system32\lboxrvxu.ini
C:\WINDOWS\system32\ldaatncd.ini
C:\WINDOWS\system32\liokyoxm.ini
C:\WINDOWS\system32\lqmriyor.ini
C:\WINDOWS\system32\lusnvwop.ini
C:\WINDOWS\system32\osapbbsp.ini
C:\WINDOWS\system32\qavvpqyb.ini
C:\WINDOWS\system32\tmxnvpop.ini
C:\WINDOWS\system32\tqdwqbqy.ini
C:\WINDOWS\system32\udwuvefa.ini
C:\WINDOWS\system32\usemhhbf.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\bcceioyt.ini
C:\WINDOWS\system32\bsoyuqos.ini
C:\WINDOWS\system32\budnswam.ini
C:\WINDOWS\system32\daxfntnt.ini
C:\WINDOWS\system32\djycqgys.ini
C:\WINDOWS\system32\flvbtukx.ini
C:\WINDOWS\system32\hviiylwd.ini
C:\WINDOWS\system32\kuassuod.ini
C:\WINDOWS\system32\lboxrvxu.ini
C:\WINDOWS\system32\ldaatncd.ini
C:\WINDOWS\system32\liokyoxm.ini
C:\WINDOWS\system32\lqmriyor.ini
C:\WINDOWS\system32\lusnvwop.ini
C:\WINDOWS\system32\osapbbsp.ini
C:\WINDOWS\system32\qavvpqyb.ini
C:\WINDOWS\system32\tmxnvpop.ini
C:\WINDOWS\system32\tqdwqbqy.ini
C:\WINDOWS\system32\udwuvefa.ini
C:\WINDOWS\system32\usemhhbf.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.

2008-01-06 20:31 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-01-06 20:31 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-01-06 20:31 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-01-06 20:31 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-01-06 20:31 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-01-06 20:31 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-06 20:31 . 2008-01-06 20:31 1,486 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-06 12:20 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-06 11:43 . 2008-01-06 11:43 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-01-06 11:18 . 2008-01-06 11:18 <DIR> d-------- C:\VundoFix Backups
2008-01-05 17:18 . 2008-01-05 17:44 <DIR> d-------- C:\Poker
2007-12-26 18:01 . 2007-12-26 18:01 30,208 --a------ C:\Round 1.doc
2007-12-19 19:14 . 2007-12-19 19:56 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-17 18:40 . 2007-12-29 15:27 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\ZoomBrowser EX
2007-12-17 18:30 . 2007-12-29 15:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2007-12-17 18:29 . 2007-12-17 18:32 <DIR> d-------- C:\Program Files\Canon
2007-12-17 18:26 . 2007-12-17 18:26 <DIR> d-------- C:\Program Files\Common Files\Canon
2007-12-13 14:52 . 2007-12-13 14:52 0 --a------ C:\Install

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-06 19:13 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\Azureus
2008-01-02 13:12 --------- d-----w C:\Program Files\Azureus
2007-12-16 18:04 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-12-13 14:52 --------- d-----w C:\Program Files\MalwareAlarm
2007-11-30 23:15 --------- d-----w C:\Program Files\Rrztfqhf
2007-11-30 23:15 --------- d-----w C:\Program Files\qtidarsv
2007-11-30 23:15 --------- d-----w C:\Program Files\fwlubmna
2007-11-20 15:14 104,448 ----a-w C:\WINDOWS\system32\drvbun.dll
2007-11-18 18:02 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\AVG7
2007-11-15 20:10 --------- d-----w C:\Program Files\SubmachineFLF_at
2007-11-14 10:09 104,960 ----a-w C:\WINDOWS\system32\drvxop.dll
2007-11-14 07:26 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-08 21:47 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\SKIP ONCE MANAGER
2007-10-30 10:16 3,058,688 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 08:39 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:36 8,454,656 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 06:13 96,256 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
2007-10-11 06:13 659,456 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-11 06:13 615,424 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-11 06:13 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-11 06:13 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-11 06:13 474,112 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-10-11 06:13 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-11 06:13 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-10-11 06:13 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-10-11 06:13 251,392 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-10-11 06:13 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-11 06:13 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-11 06:13 151,040 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-10-11 06:13 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-11 06:13 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-10-11 06:13 1,054,208 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
2007-10-11 06:13 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
2007-10-10 11:16 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2006-08-21 07:27 0 ----a-w C:\Documents and Settings\Compaq_Owner\loaded.exe
2004-08-04 12:00 94,784 --sh--w C:\WINDOWS\twain.dll
2004-08-04 12:00 50,688 --sh--w C:\WINDOWS\twain_32.dll
2005-05-02 10:14 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
2004-08-04 12:00 54,784 --sh--w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 12:00 413,696 --sh--w C:\WINDOWS\system32\msvcp60.dll
2007-05-17 11:28 549,376 --sh--w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 12:00 83,456 --sh--w C:\WINDOWS\system32\olepro32.dll
2004-08-04 12:00 11,776 --sh--w C:\WINDOWS\system32\regsvr32.exe
.

((((((((((((((((((((((((((((( snapshot@2008-01-06_12.29.50.87 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-06 11:55:56 63,472 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-06 20:27:20 63,472 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-06 11:55:56 403,180 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-06 20:27:20 403,180 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F2BADA0D-FD61-45EF-A994-64A073FD6613}"= C:\Program Files\Video Add-on\ictmdl.dll [ ]

[HKEY_CLASSES_ROOT\clsid\{f2bada0d-fd61-45ef-a994-64a073fd6613}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25 6731312]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 12:00 158208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HPAiODevice(hp psc 700 series) - 1.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp psc 700 series) - 1.lnk
backup=C:\WINDOWS\pss\HPAiODevice(hp psc 700 series) - 1.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^OpenMG Jukebox Startup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\OpenMG Jukebox Startup.lnk
backup=C:\WINDOWS\pss\OpenMG Jukebox Startup.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\WINDOWS\pss\MagicDisc.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\3wPlayer Service]
2007-10-09 10:48 139264 --a------ C:\Program Files\3wPlayer\wakeservice.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2007-03-09 10:09 63712 --a------ C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-10 19:51 39792 --a------ C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-03-14 18:05 257088 --a------ C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAZAA]
C:\Program Files\Kazaa\kazaa.exe /SYSTRAY

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe /icon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"btwdins"=2 (0x2)
"PREVXAgent"=2 (0x2)
"iPod Service"=3 (0x3)
"Avg7UpdSvc"=2 (0x2)
"Avg7Alrt"=2 (0x2)
"SNDSrvc"=3 (0x3)
"BthServ"=2 (0x2)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"usnjsvc"=3 (0x3)
"PnkBstrA"=2 (0x2)
"IDriverT"=3 (0x3)
"NVSvc"=2 (0x2)
"DomainService"=2 (0x2)

R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [2004-11-22 14:15]
S3 aaudstum;aaudstum;C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\aaudstum.sys []
S3 DLPortIO;DriverLINX Port I/O Driver;C:\WINDOWS\system32\DRIVERS\DLPortIO.SYS [2000-06-29 16:24]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-06 19:00:00 C:\WINDOWS\Tasks\ABAE28E29185DF92.job"
- c:\docume~1\compaq~1\applic~1\skipon~1\Way Idle Bin.exe
"2007-12-24 07:58:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-06 20:37:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 20:40:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-06 20:40:28
ComboFix-quarantined-files.txt 2008-01-06 20:40:27
ComboFix2.txt 2008-01-06 12:30:07
.
2007-12-21 16:21:47 --- E O F ---


SmitFraudFix v2.274

Scan done at 20:52:27.75, 06/01/2008
Run from C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Netscape\Navigator 9\navigator.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Compaq_Owner


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Compaq_Owner\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\COMPAQ~1\FAVORI~1

C:\DOCUME~1\COMPAQ~1\FAVORI~1\Online Security Test.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: WAN (PPP/SLIP) Interface
DNS Server Search Order: 62.24.128.5
DNS Server Search Order: 62.24.128.69

HKLM\SYSTEM\CCS\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer=62.24.128.5 62.24.128.69
HKLM\SYSTEM\CS1\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer=62.24.128.5 62.24.128.69


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
Robbington
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 11:31 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Mon Jan 07, 2008 12:14 am

Robbington,

It's starting to look better let's get rid of some more.

Reboot in to Safe mode:
Restart Windows after you see the BIOS screen and before Windows starts to load.
Start tapping the F8 key. The Windows Advanced Options Menu appears.
Use the Arrow key to ensure that the Safe Mode option is selected.
Press Enter. The computer then begins to start in Safe mode.

Double-click SmitfraudFix.exe
Select 2 and hit Enter to delete infect files.
You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter.
The tool will now check if wininet.dll is infected.
You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.

A reboot will be needed to finish the cleaning process.
The report can be found at the root of the system drive, usually at C:\rapport.txt

Please copy/paste the contents of that report into your next reply a long with a new hijackthis log.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

Postby Robbington » Mon Jan 07, 2008 7:45 pm

SmitFraudFix v2.274

Scan done at 18:36:03.68, 07/01/2008
Run from C:\Documents and Settings\Compaq_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 18:45:00, on 07/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Netscape\Navigator 9\navigator.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Compaq_Owner\Desktop\Hijack-this\HiJackThis_v2(2).exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O14 - IERESET.INF: START_PAGE_URL=http://www.virgin.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-U ... E_UNO1.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Fac ... loader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/mpp_2 ... lashAX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer = 62.24.128.5 62.24.128.69
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F05F2CC-1DD1-4E3A-8E1F-4433DCD8477C}: NameServer = 62.24.128.5 62.24.128.69
O21 - SSODL: E404Helper - {069e4792-ee19-48a9-ae3b-170f0b86b14e} - (no file)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

--
End of file - 3495 bytes


You sir are a king among men.
Robbington
Newbie
Newbie
 
Posts: 5
Joined: Sun Jan 06, 2008 11:31 am

Thanks given:0
Thanks received:0
Top

Postby Gecko » Mon Jan 07, 2008 8:29 pm

Robbington,

Start HijackThis and click "Do a system scan only" put a check next to each of the following entries:
O21 - SSODL: E404Helper - {069e4792-ee19-48a9-ae3b-170f0b86b14e} - (no file)
Now click the "Fixed checked" button and then close HijackThis

Otherwise your log is clean.
So how is it running now?
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron