This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Hijackthis log please help

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My brother thinks he downloaded a virus. Great! Someone please help. Thanks for your help in advance.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:47:52 AM, on 2/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Update\GoogleUpdate.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\TWFyY28gQm9ycmVsbGk\command.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\McAfee\MBK\MBackMonitor.exe
D:\WINDOWS\Explorer.EXE
D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
d:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
D:\Program Files\McAfee\VirusScan\McShield.exe
D:\Program Files\Network Monitor\netmon.exe
e:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
D:\WINDOWS\system32\pctspk.exe
D:\WINDOWS\System32\svchost.exe
d:\PROGRA~1\mcafee.com\agent\mcagent.exe
D:\Program Files\Windows Media Player\WMPNetwk.exe
D:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
E:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\QuickTime\QTTask.exe
D:\WINDOWS\system32\prunnet.exe
D:\Program Files\MSI\Live Update 3\LMonitor.exe
D:\Program Files\ESPNRunTime\DIGServices.exe
D:\WINDOWS\system32\CTHELPER.EXE
D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Windows Media Player\WMPNSCFG.exe
D:\Program Files\Common Files\wrmr\wrmrm.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\Common Files\wrmr\wrmra.exe
D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
D:\Program Files\GetModule\GetModule37.exe
E:\Program Files\DAEMON Tools\daemon.exe
D:\Program Files\Microsoft Office\Office\OSA.EXE
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
D:\WINDOWS\System32\alg.exe
D:\Program Files\McAfee\MPF\MPFSrv.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Mozilla\firefox.exe
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\Java\jre6\bin\jucheck.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
D:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: {b69ccb43-7fa5-3988-cbb4-921d9c448693} - {396844c9-d129-4bbc-8893-5af734bcc96b} - D:\WINDOWS\system32\fsjoko.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - D:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - D:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - D:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: HelloWorldBHO - {D88E1558-7C2D-407A-953A-C044F5607CEA} - D:\Program Files\Mjcore\Mjcore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {e89fbc18-c447-4c98-bd9e-dcf3876aded3} - D:\WINDOWS\system32\tegiwezo.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - D:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - D:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [McAfee Backup] D:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [mcagent_exe] D:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [fenehujesa] Rundll32.exe "D:\WINDOWS\system32\muyanuji.dll",s
O4 - HKLM\..\Run: [487f99e3] rundll32.exe "D:\WINDOWS\system32\jevukevi.dll",b
O4 - HKLM\..\Run: [CPM2f07bf0b] Rundll32.exe "d:\windows\system32\vofiposa.dll",a
O4 - HKLM\..\Run: [MBkLogOnHook] D:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [prunnet] "D:\WINDOWS\system32\prunnet.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LiveMonitor] D:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DIGServices] D:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "e:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [cogad] "D:\Documents and Settings\Marc\Application Data\cogad\cogad.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKCU\..\Run: [WMPNSCFG] D:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [wrmr] D:\Program Files\Common Files\wrmr\wrmrm.exe
O4 - HKCU\..\Run: [V7F[vWqT4exnsRF] D:\Documents and Settings\Marc\Application Data\Microsoft\Windows\vxhgcu.exe
O4 - HKCU\..\Run: [updateMgr] "E:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] E:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ResChanger2004] NONE
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [igndlm.exe] E:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [GetModule37] D:\Program Files\GetModule\GetModule37.exe
O4 - HKCU\..\Run: [DAEMON Tools] "e:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [prunnet] "D:\WINDOWS\system32\prunnet.exe"
O4 - HKUS\S-1-5-19\..\Run: [fenehujesa] Rundll32.exe "D:\WINDOWS\system32\muyanuji.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fenehujesa] Rundll32.exe "D:\WINDOWS\system32\muyanuji.dll",s (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Find Fast.lnk = D:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = D:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://D:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: D:\WINDOWS\system32\lagipale.dll d:\windows\system32\vofiposa.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - d:\windows\system32\vofiposa.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - d:\windows\system32\vofiposa.dll
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Command Service (cmdService) - Unknown owner - D:\WINDOWS\TWFyY28gQm9ycmVsbGk\command.exe
O23 - Service: Google Update Service (gupdate1c985d7be262faa) (gupdate1c985d7be262faa) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBackMonitor - McAfee - D:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - D:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Network Monitor - Unknown owner - D:\Program Files\Network Monitor\netmon.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - e:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - D:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe

–
End of file - 14421 bytes
hello

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Aright so now i have a bigger problem. My computer will not load windows xp at all now except on safe mode with no network support so i cant run the program you suggested. I did however manage to download the file you suggested into a folder on the hard drive. And the recovery console shows up when my computer asks me which operating system i want to use. Any help from here would be greatly appreciated.
Thats cause of Service Pack 3 Boot into safe mode, click Start > Add Remove Programs > Remove Windows Service Pack 3 Post a new HJT log when you do that
Ok so I got Windows to load up last night before I recieved your new message. I ran Combofix and let it go. Unfortuantely the virus or w/e infected my computer has also messed up my internet connection. I get numerous metwork errors when windows boots up. Here is the Combofix log:

ComboFix 09-02-21.01 - Marc 2009-02-23 22:38:47.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3071.2679 [GMT -6:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Resident AV is active

.
The following files were disabled during the run:
d:\windows\TWFyY28gQm9ycmVsbGk\asappsrv.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\docume~1\Marc\LOCALS~1\Temp\mousehook.dll
d:\docume~1\Marc\LOCALS~1\Temp\ntdll64.dll
d:\documents and settings\LocalService\Application Data\NetMon
d:\documents and settings\LocalService\Application Data\NetMon\domains.txt
d:\documents and settings\LocalService\Application Data\NetMon\log.txt
d:\documents and settings\Marc\Application Data\GetModule
d:\documents and settings\Marc\Application Data\GetModule\dicik.gz
d:\documents and settings\Marc\Application Data\GetModule\kwdik.gz
d:\documents and settings\Marc\Application Data\GetModule\ofadik.gz
d:\documents and settings\Marc\Local Settings\Temporary Internet Files\bestwiner.stt
d:\documents and settings\Marc\Local Settings\Temporary Internet Files\fbk.sts
d:\program files\Common Files\wrmr
d:\program files\Common Files\wrmr\wrmra.exe
d:\program files\Common Files\wrmr\wrmra.lck
d:\program files\Common Files\wrmr\wrmrd\class-barrel
d:\program files\Common Files\wrmr\wrmrd\vocabulary
d:\program files\Common Files\wrmr\wrmrd\wrmrc.dll
d:\program files\Common Files\wrmr\wrmrh
d:\program files\Common Files\wrmr\wrmrl.exe
d:\program files\Common Files\wrmr\wrmrl.lck
d:\program files\Common Files\wrmr\wrmrm.exe
d:\program files\Common Files\wrmr\wrmrm.lck
d:\program files\Common Files\wrmr\wrmrp.exe
d:\program files\GetModule
d:\program files\GetModule\GetModule37.exe
d:\program files\iCheck
d:\program files\iCheck\Uninstall.exe
d:\program files\inetget2
d:\program files\INSTALL.LOG
d:\program files\Mjcore
d:\program files\Mjcore\Mjcore.dll
d:\program files\network monitor
d:\program files\network monitor\netmon.exe
d:\program files\TinyProxy
d:\program files\VnrPack
d:\program files\VnrPack\dicts.gz
d:\program files\VnrPack\trgts.gz
d:\program files\VnrPack\VnrPack25.exe
d:\windows\IE4 Error Log.txt
d:\windows\system32\998.exe
d:\windows\system32\ahtn.htm
d:\windows\system32\atmtd.dll
d:\windows\system32\atmtd.dll._
d:\windows\system32\bb1.dat
d:\windows\system32\cmds.txt
d:\windows\system32\cs.dat
d:\windows\system32\drivers\seneka.sys
d:\windows\system32\drivers\senekaoejboyly.sys
d:\windows\system32\frmwrk32.exe
d:\windows\system32\init32.exe
d:\windows\system32\lagipale.dll
d:\windows\system32\Memman.vxd
d:\windows\system32\player.dll
d:\windows\system32\prunnet.exe
d:\windows\system32\ps1.dat
d:\windows\system32\rc.dat
d:\windows\system32\rs
d:\windows\system32\senekaewjwxktu.dll
d:\windows\system32\senekagylnxdop.dat
d:\windows\system32\senekarfcndejw.dll
d:\windows\system32\senekatkbaqcme.dat
d:\windows\system32\senekatqdmruow.dll
d:\windows\system32\skinboxer43.dll
d:\windows\system32\test.ttt
d:\windows\system32\tsuninst.exe
d:\windows\system32\uniq.tll
d:\windows\system32\warning.gif
d:\windows\system32\win32hlp.cnf
d:\windows\system32\xlk.dll
d:\windows\TWFyY28gQm9ycmVsbGk\
d:\windows\TWFyY28gQm9ycmVsbGk\\asappsrv.dll.vir
d:\windows\TWFyY28gQm9ycmVsbGk\\command.exe
d:\windows\TWFyY28gQm9ycmVsbGk\\nqIVsZf0kA6VwApPv34.vbs
d:\windows\TWFyY28gQm9ycmVsbGk\command.exe
d:\windows\uninstall_nmon.vbs
d:\windows\winhelp.ini
d:\windows\wrmr
d:\windows\wrmr\wrmr.dat
d:\windows\wrmr\wu

Infected copy of d:\windows\system32\userinit.exe was found and disinfected
Restored copy from - d:\windows\$NtServicePackUninstall$\userinit.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SENEKA
——-\Legacy_CMDSERVICE
——-\Legacy_NETWORK_MONITOR
——-\Service_cmdService
——-\Service_Network Monitor


((((((((((((((((((((((((( Files Created from 2009-01-24 to 2009-02-24 )))))))))))))))))))))))))))))))
.

2009-02-23 22:09 . 2009-02-23 22:09 d——– D:\New Folder
2009-02-23 21:54 . 2009-02-23 21:54 d——– d:\documents and settings\Marcos
2009-02-23 14:42 . 2009-02-23 15:11 d——– d:\program files\New Folder
2009-02-23 13:21 . 2009-02-23 13:21 129,024 –ahs—- d:\windows\system32\gqinnw.dll
2009-02-23 01:53 . 2009-02-23 01:53 d——– d:\program files\ERUNT
2009-02-23 01:49 . 2009-02-23 01:49 d——– d:\program files\Trend Micro
2009-02-23 01:30 . 2009-02-23 01:30 d——– d:\program files\Spybot - Search & Destroy
2009-02-23 00:50 . 2009-02-23 00:50 129,024 –ahs—- d:\windows\system32\qsylmp.dll
2009-02-22 12:50 . 2009-02-22 12:50 129,024 –ahs—- d:\windows\system32\fsjoko.dll
2009-02-22 02:34 . 2009-02-22 02:48 d——– d:\documents and settings\Marc\Application Data\Twain
2009-02-22 00:49 . 2009-02-22 00:49 129,024 –ahs—- d:\windows\system32\trgllw.dll
2009-02-22 00:45 . 2009-02-22 03:58 d——– d:\documents and settings\Marc\Application Data\cogad
2009-02-20 17:51 . 2009-02-21 23:48 d——– d:\program files\jg
2009-02-14 16:58 . 2009-02-14 17:02 d——– d:\documents and settings\Marc\Application Data\ImgBurn
2009-02-14 16:54 . 2009-02-14 16:54 d——– d:\program files\ImgBurn

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 04:30 ——— d—–w d:\documents and settings\Marc\Application Data\Skype
2009-02-23 07:28 ——— d—–w d:\documents and settings\Marc\Application Data\skypePM
2009-02-12 03:16 ——— d—–w d:\program files\Google
2008-12-31 11:39 ——— d—–w d:\program files\iPod
2008-12-31 11:39 ——— d—–w d:\program files\Common Files\Apple
2008-12-31 11:39 ——— d—–w d:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-31 11:38 ——— d—–w d:\program files\Bonjour
2008-12-31 11:37 ——— d—–w d:\program files\QuickTime
2008-12-31 11:36 ——— d—–w d:\documents and settings\All Users\Application Data\Apple Computer
2008-12-31 11:34 ——— d—–w d:\program files\Apple Software Update
2008-12-31 11:32 ——— d—–w d:\documents and settings\All Users\Application Data\Apple
2008-12-06 01:02 106,496 —-a-w d:\windows\DUMP3fe7.tmp
2006-05-03 17:51 2,130 —-a-w d:\program files\install.sss
2006-05-03 17:51 145 —-a-w d:\program files\EINST.INF
2006-05-03 17:50 583,171 —-a-w d:\program files\Uninstall.exe
2006-03-31 20:39 64,524 ——w d:\program files\Release notes.pdf
2006-02-24 22:58 774,144 —-a-w d:\program files\RngInterstitial.dll
2006-01-26 19:24 2,498,560 ——w d:\program files\MPEGPlayer.exe
2005-11-26 00:34 64,156 ——w d:\program files\Elecard EULA.rtf
2005-11-18 00:02 512,825 ——w d:\program files\Elecard MPEG Player UG.chm
2003-07-05 21:38 147,456 ——r d:\program files\ExtReg.dll
2008-04-07 06:59 67,696 —-a-w d:\program files\mozilla firefox\components\jar50.dll
2008-04-07 06:59 54,376 —-a-w d:\program files\mozilla firefox\components\jsd3250.dll
2008-04-07 06:59 34,952 —-a-w d:\program files\mozilla firefox\components\myspell.dll
2008-04-07 06:59 46,720 —-a-w d:\program files\mozilla firefox\components\spellchk.dll
2008-04-07 06:59 172,144 —-a-w d:\program files\mozilla firefox\components\xpinstal.dll
1601-01-01 00:12 47,616 –sha-w d:\windows\system32\muyanuji.dll
1601-01-01 00:12 47,616 –sha-w d:\windows\system32\tegiwezo.dll
2008-08-30 13:29 32,768 –sha-w d:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008083020080831\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{396844c9-d129-4bbc-8893-5af734bcc96b}]
2009-02-22 12:50 129024 –ahs—- d:\windows\system32\fsjoko.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e89fbc18-c447-4c98-bd9e-dcf3876aded3}]
47616 –ahs—- d:\windows\system32\tegiwezo.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ResChanger2004"="NONE" [X]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"NVIDIA nTune"="e:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 81920]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-14 68856]
"WMPNSCFG"="d:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"updateMgr"="e:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"MsnMsgr"="d:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"igndlm.exe"="e:\program files\IGN\Download Manager\DLM.exe" [2007-03-05 1103480]
"DAEMON Tools"="e:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McAfee Backup"="d:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 4838952]
"mcagent_exe"="d:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-01 61440]
"iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"fenehujesa"="d:\windows\system32\muyanuji.dll" [ 47616]
"MBkLogOnHook"="d:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2008-11-26 136600]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"LiveMonitor"="d:\program files\MSI\Live Update 3\LMonitor.exe" [2006-09-05 497152]
"HPDJ Taskbar Utility"="d:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-07 176128]
"DIGServices"="d:\program files\ESPNRunTime\DIGServices.exe" [2005-05-19 101888]
"Adobe Photo Downloader"="d:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"CPM2f07bf0b"="d:\windows\system32\misiruvu.dll" [2009-02-23 84992]
"CTHelper"="CTHELPER.EXE" [2007-04-09 d:\windows\system32\CtHelper.exe]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - e:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Microsoft Find Fast.lnk - d:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-07-10 111376]
Office Startup.lnk - d:\program files\Microsoft Office\Office\OSA.EXE [1997-07-10 51984]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "d:\windows\system32\misiruvu.dll" [2009-02-23 84992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - d:\windows\system32\misiruvu.dll [2009-02-23 84992]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli d:\windows\system32\lagipale.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Vent Server\\ventrilo_srv.exe"=
"d:\\WINDOWS\\system32\\mmc.exe"=
"d:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"e:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"e:\\Program Files\\mIRC\\mirc.exe"=
"d:\\StubInstaller.exe"=
"e:\\Program Files\\Morpheus\\Morpheus.exe"=
"e:\\Program Files\\World of Warcraft\\WoW.exe"=
"e:\\Program Files\\World of Warcraft\\Repair.exe"=
"d:\\Program Files\\Common Files\\Blizzard Entertainment\\World of Warcraft\\Uninstall.exe"=
"e:\\Program Files\\World of Warcraft\\Launcher.exe"=
"e:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"e:\\Program Files\\World of Warcraft\\WoW-1.9.4.5086-to-1.10.0.5195-enUS-patch.exe"=
"d:\\WINDOWS\\system32\\dpvsetup.exe"=
"e:\\Program Files\\VentSrv\\ventrilo_srv.exe"=
"e:\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
"d:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"=
"e:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"=
"d:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"e:\\Program Files\\Curse\\CurseClient.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Program Files\\World of Warcraft\\WoW-3.0.8.9464-to-3.0.8.9506-enUS-downloader.exe"=
"e:\\Program Files\\World of Warcraft\\WoW-3.0.8.9506-to-3.0.9.9551-enUS-downloader.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8500:TCP"= 8500:TCP:198.65.111.254/255.255.255.255:Enabled:Speedtest
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

S2 gupdate1c985d7be262faa;Google Update Service (gupdate1c985d7be262faa);d:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 133104]
S3 HCWBT8XX;Hauppauge WinTV 848/9 WDM Video Driver;d:\windows\system32\drivers\HCWBT8xx.sys [2005-05-11 458820]
S3 s3legacy;s3legacy;d:\windows\system32\drivers\s3legacy.sys [2008-12-05 65664]
S3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);d:\windows\system32\drivers\SMCWGU.sys [2008-05-15 408064]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\Launch.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-20 d:\windows\Tasks\At1.job
- c:\program files\norton pc checkup\pc_checkup.exe []

2009-02-22 d:\windows\Tasks\At2.job
- c:\program files\norton pc checkup\pc_checkup.exe []

2009-02-23 d:\windows\Tasks\GoogleUpdateTaskMachine.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-02-03 02:16]

2009-02-15 d:\windows\Tasks\McDefragTask.job
- d:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]

2009-02-01 d:\windows\Tasks\McQcTask.job
- d:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32]
.
- - - - ORPHANS REMOVED - - - -

BHO-{89F2C12A-027A-4de3-88F6-9F31A1C0F17C} - xlk.dll
BHO-{D88E1558-7C2D-407A-953A-C044F5607CEA} - d:\program files\Mjcore\Mjcore.dll
HKCU-Run-cogad - d:\documents and settings\Marc\Application Data\cogad\cogad.exe
HKCU-Run-V7F[vWqT4exnsRF - d:\documents and settings\Marc\Application Data\Microsoft\Windows\vxhgcu.exe
HKCU-Run-Uniblue RegistryBooster 2 - e:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe
HKCU-Run-GetModule37 - d:\program files\GetModule\GetModule37.exe
HKCU-Run-prunnet - d:\windows\system32\prunnet.exe
HKLM-Run-prunnet - d:\windows\system32\prunnet.exe
HKLM-Run-NvMediaCenter - d:\windows\system32\NvMcTray.dll
HKLM-Run-NvCplDaemon - d:\windows\system32\NvCpl.dll
HKLM-Run-487f99e3 - d:\windows\system32\jevukevi.dll
HKLM-Run-nwiz - nwiz.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/
mStart Page = hxxp://www.comcast.net/
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local;
IE: &Windows Live Search - d:\program files\Windows Live Toolbar\msntb.dll/search.htm
FF - ProfilePath - d:\documents and settings\Marc\Application Data\Mozilla\Firefox\Profiles\dk0n4r6p.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net/
FF - component: e:\program files\Mozilla\components\srff.dll
FF - plugin: d:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: d:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: e:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF - plugin: e:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: e:\program files\iTunes\Mozilla Plugins\npitunes.dll

—- FIREFOX POLICIES —-
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
FF - user.js: network.proxy.http_port - 0
FF - user.js: network.proxy.ssl -
FF - user.js: network.proxy.ssl_port - 0
FF - user.js: network.proxy.ftp -
FF - user.js: network.proxy.ftp_port - 0
FF - user.js: network.proxy.gopher -
FF - user.js: network.proxy.gopher_port - 0
FF - user.js: network.proxy.socks_version - 5
FF - user.js: network.proxy.socks -
FF - user.js: network.proxy.socks_port - 0
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-23 22:53:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = d:\program files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(764)
d:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
d:\windows\system32\ati2evxx.exe
d:\windows\system32\ati2evxx.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\McAfee\MBK\MBackMonitor.exe
d:\progra~1\McAfee\MSC\mcmscsvc.exe
d:\program files\McAfee\VirusScan\Mcshield.exe
d:\progra~1\McAfee.com\Agent\mcagent.exe
d:\windows\system32\pctspk.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
d:\program files\iPod\bin\iPodService.exe
d:\progra~1\McAfee\MSC\mcuimgr.exe
d:\program files\Skype\Plugin Manager\skypePM.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-02-23 23:01:56 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-24 05:01:52

Pre-Run: 750,743,552 bytes free
Post-Run: 1,170,194,432 bytes free

Current=17 Default=17 Failed=16 LastKnownGood=18 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18
343 — E O F — 2009-02-11 09:06:36

Also uninstalled service pack 3 and have this hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:14:25 AM, on 2/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Google\Update\GoogleUpdate.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\McAfee\MBK\MBackMonitor.exe
D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
D:\Program Files\McAfee\VirusScan\McShield.exe
d:\PROGRA~1\mcafee.com\agent\mcagent.exe
D:\WINDOWS\system32\pctspk.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
E:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\QuickTime\QTTask.exe
D:\Program Files\MSI\Live Update 3\LMonitor.exe
D:\Program Files\ESPNRunTime\DIGServices.exe
D:\WINDOWS\system32\CTHELPER.EXE
D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Windows Media Player\WMPNSCFG.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
E:\Program Files\DAEMON Tools\daemon.exe
D:\Program Files\Microsoft Office\Office\OSA.EXE
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\WINDOWS\system32\msiexec.exe
d:\PROGRA~1\mcafee\msc\mcuimgr.exe
D:\Program Files\Skype\Plugin Manager\skypePM.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: {b69ccb43-7fa5-3988-cbb4-921d9c448693} - {396844c9-d129-4bbc-8893-5af734bcc96b} - D:\WINDOWS\system32\fsjoko.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - D:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - D:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - D:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: (no name) - {e89fbc18-c447-4c98-bd9e-dcf3876aded3} - D:\WINDOWS\system32\tegiwezo.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - D:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - D:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [McAfee Backup] D:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [mcagent_exe] D:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [fenehujesa] Rundll32.exe "D:\WINDOWS\system32\muyanuji.dll",s
O4 - HKLM\..\Run: [MBkLogOnHook] D:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [LiveMonitor] D:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DIGServices] D:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [CPM2f07bf0b] Rundll32.exe "d:\windows\system32\misiruvu.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "e:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] D:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [updateMgr] "E:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ResChanger2004] NONE
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [igndlm.exe] E:\Program Files\IGN\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [DAEMON Tools] "e:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Find Fast.lnk = D:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = D:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://D:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: D:\WINDOWS\system32\lagipale.dll d:\windows\system32\misiruvu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - d:\windows\system32\misiruvu.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - d:\windows\system32\misiruvu.dll
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c985d7be262faa) (gupdate1c985d7be262faa) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBackMonitor - McAfee - D:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan\McShield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - D:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - e:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - D:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\WINDOWS\system32\HPZipm12.exe

–
End of file - 11746 bytes


Still cannot access internet and windows is taking like 10 mins to load up. Error messages during startup with network and anti vrus and .NET framework errors.
Don't fix anything with this, just save me the log please

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI