Logfile of HijackThis v1.99.1
Scan saved at 3:22:52 PM, on 14/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Mike\Desktop\HJT\removal.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {00ED0F42-375E-4B56-B156-65D26DDE500A} - (no file)
O2 - BHO: (no name) - {42FA70E1-4537-4C80-AF6D-B6B373E4F259} - (no file)
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7A180363-495D-48A7-9F14-65AB0E9F0130} - (no file)
O2 - BHO: (no name) - {E44527F6-1296-4A84-B67D-A6CEA6ED4B69} - (no file)
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /S
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?LinkID=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1175623727953
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
VundoFix V6.3.19
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Scan started at 1:06:02 PM 14/04/2007
Listing files found while scanning....
C:\WINDOWS\system32\aihnjrpf.dll
C:\WINDOWS\system32\avisnkth.dll
C:\WINDOWS\system32\awtqo.dll
C:\WINDOWS\system32\awtuust.dll
C:\WINDOWS\system32\axafrdhw.exe
C:\WINDOWS\system32\bkfxnuti.dll
C:\WINDOWS\system32\cttnanot.ini
C:\WINDOWS\system32\cxibdlhb.dll
C:\WINDOWS\system32\dajtskbl.dll
C:\WINDOWS\system32\dwtnowoh.dll
C:\WINDOWS\system32\eoorognw.exe
C:\WINDOWS\system32\fqoujmrs.dll
C:\WINDOWS\system32\fupidxoc.dll
C:\WINDOWS\system32\fuvgkqeh.dll
C:\WINDOWS\system32\geilofps.dll
C:\WINDOWS\system32\gprkdkgo.exe
C:\WINDOWS\system32\hgghhfc.dll
C:\WINDOWS\system32\howontwd.ini
C:\WINDOWS\system32\hqedwiav.dll
C:\WINDOWS\system32\iewwuypo.exe
C:\WINDOWS\system32\jmphqjff.dll
C:\WINDOWS\system32\jwmamlee.dll
C:\WINDOWS\system32\kaeqfeky.dll
C:\WINDOWS\system32\kubmspsi.dll
C:\WINDOWS\system32\lftfrwqo.exe
C:\WINDOWS\system32\llwjktrl.dll
C:\WINDOWS\system32\mljihhh.dll
C:\WINDOWS\system32\mlnmp.bak1
C:\WINDOWS\system32\mlnmp.bak2
C:\WINDOWS\system32\mlnmp.ini
C:\WINDOWS\system32\mlnmp.ini2
C:\WINDOWS\system32\mlnmp.tmp
C:\WINDOWS\system32\nntpmriq.dll
C:\WINDOWS\system32\odltmqcc.dll
C:\WINDOWS\system32\oqpfaswd.dll
C:\WINDOWS\system32\oqtwa.ini
C:\WINDOWS\system32\phdqfion.dll
C:\WINDOWS\system32\pmnlm.dll
C:\WINDOWS\system32\ppshuqpt.exe
C:\WINDOWS\system32\qcqutxdg.dll
C:\WINDOWS\system32\rfbtirdc.dll
C:\WINDOWS\system32\rqrpppo.dll
C:\WINDOWS\system32\tonanttc.dll
C:\WINDOWS\system32\ujrlwxhp.dll
C:\WINDOWS\system32\vobrxijr.exe
C:\WINDOWS\system32\wvywnjcp.exe
C:\WINDOWS\system32\xpcbrthr.exe
C:\WINDOWS\system32\xteablxl.dll
C:\WINDOWS\system32\xtrdfihy.exe
C:\WINDOWS\system32\xvdaybfe.exe
C:\WINDOWS\system32\yaeyshwg.exe
Beginning removal...
Attempting to delete C:\WINDOWS\system32\aihnjrpf.dll
C:\WINDOWS\system32\aihnjrpf.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\avisnkth.dll
C:\WINDOWS\system32\avisnkth.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\awtqo.dll
C:\WINDOWS\system32\awtqo.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\awtuust.dll
C:\WINDOWS\system32\awtuust.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\axafrdhw.exe
C:\WINDOWS\system32\axafrdhw.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\bkfxnuti.dll
C:\WINDOWS\system32\bkfxnuti.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\cttnanot.ini
C:\WINDOWS\system32\cttnanot.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\cxibdlhb.dll
C:\WINDOWS\system32\cxibdlhb.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\dajtskbl.dll
C:\WINDOWS\system32\dajtskbl.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\dwtnowoh.dll
C:\WINDOWS\system32\dwtnowoh.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\eoorognw.exe
C:\WINDOWS\system32\eoorognw.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\fqoujmrs.dll
C:\WINDOWS\system32\fqoujmrs.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\fupidxoc.dll
C:\WINDOWS\system32\fupidxoc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\fuvgkqeh.dll
C:\WINDOWS\system32\fuvgkqeh.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\geilofps.dll
C:\WINDOWS\system32\geilofps.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\gprkdkgo.exe
C:\WINDOWS\system32\gprkdkgo.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\hgghhfc.dll
C:\WINDOWS\system32\hgghhfc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\howontwd.ini
C:\WINDOWS\system32\howontwd.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\hqedwiav.dll
C:\WINDOWS\system32\hqedwiav.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\iewwuypo.exe
C:\WINDOWS\system32\iewwuypo.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\jmphqjff.dll
C:\WINDOWS\system32\jmphqjff.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\jwmamlee.dll
C:\WINDOWS\system32\jwmamlee.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\kaeqfeky.dll
C:\WINDOWS\system32\kaeqfeky.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\kubmspsi.dll
C:\WINDOWS\system32\kubmspsi.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\lftfrwqo.exe
C:\WINDOWS\system32\lftfrwqo.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\llwjktrl.dll
C:\WINDOWS\system32\llwjktrl.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mljihhh.dll
C:\WINDOWS\system32\mljihhh.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mlnmp.bak1
C:\WINDOWS\system32\mlnmp.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\mlnmp.bak2
C:\WINDOWS\system32\mlnmp.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\mlnmp.ini
C:\WINDOWS\system32\mlnmp.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\mlnmp.ini2
C:\WINDOWS\system32\mlnmp.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\mlnmp.tmp
C:\WINDOWS\system32\mlnmp.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\nntpmriq.dll
C:\WINDOWS\system32\nntpmriq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\odltmqcc.dll
C:\WINDOWS\system32\odltmqcc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqpfaswd.dll
C:\WINDOWS\system32\oqpfaswd.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqtwa.ini
C:\WINDOWS\system32\oqtwa.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\phdqfion.dll
C:\WINDOWS\system32\phdqfion.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmnlm.dll
C:\WINDOWS\system32\pmnlm.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ppshuqpt.exe
C:\WINDOWS\system32\ppshuqpt.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\qcqutxdg.dll
C:\WINDOWS\system32\qcqutxdg.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\rfbtirdc.dll
C:\WINDOWS\system32\rfbtirdc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\rqrpppo.dll
C:\WINDOWS\system32\rqrpppo.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tonanttc.dll
C:\WINDOWS\system32\tonanttc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ujrlwxhp.dll
C:\WINDOWS\system32\ujrlwxhp.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\vobrxijr.exe
C:\WINDOWS\system32\vobrxijr.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\wvywnjcp.exe
C:\WINDOWS\system32\wvywnjcp.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\xpcbrthr.exe
C:\WINDOWS\system32\xpcbrthr.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\xteablxl.dll
C:\WINDOWS\system32\xteablxl.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\xtrdfihy.exe
C:\WINDOWS\system32\xtrdfihy.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\xvdaybfe.exe
C:\WINDOWS\system32\xvdaybfe.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\yaeyshwg.exe
C:\WINDOWS\system32\yaeyshwg.exe Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\awtuust.dll
C:\WINDOWS\system32\awtuust.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.3.19
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Scan started at 1:18:31 PM 14/04/2007
Listing files found while scanning....
No infected files were found.
Beginning removal...
Beginning removal...
Attempting to delete C:\WINDOWS\system32\etgfskqs.dll
C:\WINDOWS\system32\etgfskqs.dll Has been deleted!
Performing Repairs to the registry.
Done!