This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Cleaned Malware but...

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello -

My daughter's PC was filled with malware. It's since been scanned with Malwarebyte's Anti-Malware, Ad-Aware, and AVG Anti-Virus Free. There were 48 trojans and all types of adware, etc. removed. The performance of the machine is much better. However, before the clean-up it randomly shut down (during web browsing, sitting idly, running a scan, etc.). After the clean-up it seemed to be okay for a couple hours and then the random shut-downs started again - sometimes 2-3 hours apart and sometimes immediately after rebooting, and most of the time somewhere in-between.

I opened the box and it was actually not very dusty. However, I still cleaned and vacuumed any dust there was on the CPU fan and power supply fans. Yet the shut-downs continue. This is leading me to think it is software/virus related. Further, the AVG resident program has reported the Trojan Vundo.FV several times.

I really appreciate any help that can be provided, as I've already put well over 12 hours into trying to get this machine back to normal.

Following is the HiJackThis log. Thanks again!

————————————————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:11:33 PM, on 3/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKLM\..\Run: [PSDiagnosticM] "C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [juhalubafi] Rundll32.exe "C:\WINDOWS\system32\linanotu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [juhalubafi] Rundll32.exe "C:\WINDOWS\system32\linanotu.dll",s (User 'NETWORK SERVICE')
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1173712368031
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: dawemd.dll c:\windows\system32\pofolehe.dll,C:\WINDOWS\system32\gipofosi.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 6506 bytes
Hello jgraham4263 and :welcome:

Yep, lots of stuff still infecting that box I'm afraid :(

Please do the following:


Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.



NEXT
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

  • Notes:
  • Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
  • CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi CatByte - Thanks so much for helping! I followed all your instructions including disabling all anti-virus and anti-spyware applications. ComboFix was running fine. It did have to install the MS Windows Recovery Console. It got to a point where it reboot the machine and then opened a window that indicated it was creating the log file. While doing so, the computer shut down! :pullhair: Per your instructions, I did not re-run ComboFix. It did create a log file but I don't think it's complete due to the shut-down. In fact, some of the computer settings (e.g. system clock) were not reset. Regardless, I am posting the ComboFix.txt file for your review. Unfortunately, I can't speak to how the computer is running since it is still exhibiting the same behavior. I look forward to your further instructions. Jim —————————————————– ComboFix 09-03-23.01 - Jim 2009-03-25 17:21:28.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.153 [GMT -4:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\igadelut.ini C:\WINDOWS\system32\jorxae.dll C:\WINDOWS\system32\rhmpuj.dll C:\WINDOWS\system32\suwunahe.dll C:\WINDOWS\system32\tebusuka.dll C:\WINDOWS\system32\wiinpp.dll C:\WINDOWS\system32\yunukino.dll . ((((((((((((((((((((((((( Files Created from 2009-02-25 to 2009-03-25 ))))))))))))))))))))))))))))))) . 2009-03-24 17:36 . 2009-03-24 17:36 d——– C:\Documents and Settings\Tara\Application Data\AVGTOOLBAR 2009-03-24 17:33 . 2009-03-24 17:33 d——– C:\Program Files\Trend Micro 2009-03-24 12:52 . 2009-03-25 08:42 d–h—– C:\$AVG8.VAULT$ 2009-03-24 10:51 . 2009-03-24 10:51 d——– C:\WINDOWS\system32\scripting 2009-03-24 10:51 . 2009-03-24 10:51 d——– C:\WINDOWS\l2schemas 2009-03-24 10:50 . 2009-03-24 10:50 d——– C:\WINDOWS\system32\en 2009-03-24 10:50 . 2009-03-24 10:50 d——– C:\WINDOWS\system32\bits 2009-03-24 10:46 . 2009-03-24 10:51 d——– C:\WINDOWS\ServicePackFiles 2009-03-24 10:17 . 2009-03-09 15:06 15,688 –a—— C:\WINDOWS\system32\lsdelete.exe 2009-03-24 10:02 . 2009-03-25 17:03 d——– C:\WINDOWS\system32\drivers\Avg 2009-03-24 10:02 . 2009-03-24 10:15 d——– C:\Documents and Settings\Jim\Application Data\AVGTOOLBAR 2009-03-24 10:02 . 2009-03-24 10:02 325,640 –a—— C:\WINDOWS\system32\drivers\avgldx86.sys 2009-03-24 10:02 . 2009-03-24 10:02 107,912 –a—— C:\WINDOWS\system32\drivers\avgtdix.sys 2009-03-24 10:02 . 2009-03-24 10:02 10,520 –a—— C:\WINDOWS\system32\avgrsstx.dll 2009-03-24 10:01 . 2009-03-24 10:01 d——– C:\Program Files\AVG 2009-03-24 10:01 . 2009-03-24 10:01 d——– C:\Documents and Settings\All Users\Application Data\avg8 2009-03-23 22:50 . 2009-03-23 22:50 d—-c— C:\WINDOWS\system32\DRVSTORE 2009-03-23 22:50 . 2009-03-09 15:06 64,160 –a—— C:\WINDOWS\system32\drivers\Lbd.sys 2009-03-23 22:49 . 2009-03-23 22:49 d–h-c— C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} 2009-03-23 20:57 . 2009-03-23 20:57 d——– C:\Documents and Settings\Jim\Application Data\Malwarebytes 2009-03-21 18:20 . 2009-03-21 19:27 d——– C:\Program Files\Malwarebytes' Anti-Malware 2009-03-21 18:20 . 2009-03-21 18:20 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes 2009-03-21 18:20 . 2009-03-21 18:20 d——– C:\Documents and Settings\Administrator\Application Data\Malwarebytes 2009-03-21 18:20 . 2009-02-11 10:19 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2009-03-21 18:20 . 2009-02-11 10:19 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys 2009-03-21 18:12 . 2008-04-13 14:39 14,592 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-24 18:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2009-03-24 13:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trend Micro 2009-03-24 02:48 ——— d—–w C:\Program Files\Lavasoft 2009-03-24 00:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint 2009-03-24 00:25 ——— d—–w C:\Program Files\Common Files\Real 2007-04-29 20:10 32 —-a-r C:\Documents and Settings\All Users\hash.dat 2007-03-18 22:45 774,144 —-a-w C:\Program Files\RngInterstitial.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 20:12 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LiveMonitor"="C:\Program Files\MSI\Live Update 3\LMonitor.exe" [2006-09-05 17:45 497152] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23 75520] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088] "Camera Detector"="C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE" [2002-12-09 14:35 208896] "PSDiagnosticM"="C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-02-27 16:29 315392] "Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 15:06 515416] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2009-03-24 10:01 1932568] "VTTimer"="VTTimer.exe" [2005-03-07 15:33 53248 C:\WINDOWS\system32\VTTimer.exe] "VTTrayp"="VTtrayp.exe" [2006-04-11 04:06 176128 C:\WINDOWS\system32\VTTrayp.exe] "SoundMan"="SOUNDMAN.EXE" [2006-08-02 17:12 577536 C:\WINDOWS\soundman.exe] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-03 19:58:20 40960] officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-12-03 19:23:30 147456] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-03-24 10:02 10520 C:\WINDOWS\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "C:\\Program Files\\Linksys Wireless-G Print Server\\PSDiagnosticM.exe"= R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [2009-03-23 22:50:51 64160] R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\drivers\xfilt.sys [2007-03-12 09:18:12 11264] R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\drivers\avgldx86.sys [2009-03-24 10:02:11 325640] R1 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\drivers\avgtdix.sys [2009-03-24 10:02:19 107912] R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-03-24 10:01:42 298264] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 15:06:55 951632] R3 lknuhst;Linksys Network USB Host Controller;C:\WINDOWS\system32\drivers\lknuhst.sys [2007-08-12 17:24:37 11136] R3 LKNUHUB;Linksys Network USB Root Hub;C:\WINDOWS\system32\drivers\lknuhub.sys [2007-08-12 17:24:40 37248] S3 LKNUCMP;Linksys Network USB Composite Device;C:\WINDOWS\system32\drivers\lknucmp.sys [2007-08-12 17:26:11 11648] S3 SetupNTGLM7X;SetupNTGLM7X;C:\Program Files\MSI\Live Update 3\NTGLM7X.SYS [2007-03-12 09:28:46 28160] . Contents of the 'Scheduled Tasks' folder 2009-03-24 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job - C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 15:06] 2009-03-24 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42] 2009-03-24 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1186953004.job - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-03 19:40] . - - - - ORPHANS REMOVED - - - - HKLM-Run-Blubster - C:\Program Files\Blubster\Blubster.exe . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ IE: E&xport; to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 .
Hi,

Well, I think that was most of the log that I needed….
How's the computer running now?


I see you have MalwareBytes on your computer,
could you please open the program, check for updates and run a quick scan ,
then post the log back here,


then do this:


Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

Once that is complete (be patient it can take many hours)

please open HJT - do a scan and save a log file and post the fresh HJT log here as well as the Kaspersky log and MBAM log.

Thanks
Hi CatByte -

Well, things aren't going too well. The computer is still running fairly slow and keeps shutting down. I tried running the Kaspersky scan about 5 times and each time the computer shut down somewhere between 2-10 minutes into the scan. The last three times I monitored CPU usage with Task Manager during the scan and it appears to shut down during CPU intensive operations (CPU pegged at or near 100%). Yet I've monitored CPU usage during other more routine "non-scan" operations and even though CPU usage hits 100% it doesn't shut down. Then there are times when the computer is just sitting idly and it shuts down. So I'm still going back and forth between, "Is this a hardware problem or software problem, or both?"

As mentioned in my original post, the inside of the computer is clean, so I don't believe dust is causing any overheating issues.

Also, as you'll see in the MBAM log, I keep removing Vundo via MBAM but it keeps reappearing.

Anyway, I'm attaching the requested MBAM and HJT logs. Obviously, I can't provide a Kaspersky log.

I look forward to your next thoughts.

Thanks again!

———————————————————————-

Malwarebytes' Anti-Malware 1.34
Database version: 1900
Windows 5.1.2600 Service Pack 3

2009-03-26 09:10:16
mbam-log-2009-03-26 (09-10-02).txt

Scan type: Quick Scan
Objects scanned: 72233
Time elapsed: 3 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\tituzeki.dll (Trojan.Vundo) -> No action taken.

————————————

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:24, on 2009-03-26
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKLM\..\Run: [PSDiagnosticM] "C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1173712368031
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

–
End of file - 5846 bytes
Hi, have MBAM fix that entry as it's showing no action taken… It's hard to tell if the original combofix scanned properly as I didn't get all the log. Please delete the version of combo fix that you have on your computer now. Download Combo fix again from one of the links I provided before and give it another run… Make sure you disable all your security programs before you run it and close any other open programs…lets see if we can get a complete scan and a full log so I can identify what is respawning this infection. Thanks CB
Hi CatByte -

It took many tries but I finally got a complete ComboFix log. The computer kept shutting down when ComboFix was preparing the log report. But here is a good one. I hope it shows you something! :wacko:

————————————-

ComboFix 09-03-26.03 - Jim 2009-03-27 17:29:12.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.161 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\windows\system32\igadelut.ini
c:\windows\system32\jorxae.dll
c:\windows\system32\rhmpuj.dll
c:\windows\system32\suwunahe.dll
c:\windows\system32\tebusuka.dll
c:\windows\system32\wiinpp.dll
c:\windows\system32\yunukino.dll

.
((((((((((((((((((((((((( Files Created from 2009-02-27 to 2009-03-27 )))))))))))))))))))))))))))))))
.

2009-03-27 08:17 . 2009-03-27 08:17 d——– c:\documents and settings\Jim\WINDOWS
2009-03-24 17:36 . 2009-03-24 17:36 d——– c:\documents and settings\Tara\Application Data\AVGTOOLBAR
2009-03-24 17:33 . 2009-03-24 17:33 d——– c:\program files\Trend Micro
2009-03-24 12:52 . 2009-03-25 08:42 d–h—– C:\$AVG8.VAULT$
2009-03-24 10:51 . 2009-03-24 10:51 d——– c:\windows\system32\scripting
2009-03-24 10:51 . 2009-03-24 10:51 d——– c:\windows\l2schemas
2009-03-24 10:50 . 2009-03-24 10:50 d——– c:\windows\system32\en
2009-03-24 10:50 . 2009-03-24 10:50 d——– c:\windows\system32\bits
2009-03-24 10:46 . 2009-03-24 10:51 d——– c:\windows\ServicePackFiles
2009-03-24 10:17 . 2009-03-09 15:06 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-03-24 10:02 . 2009-03-27 08:13 d——– c:\windows\system32\drivers\Avg
2009-03-24 10:02 . 2009-03-24 10:15 d——– c:\documents and settings\Jim\Application Data\AVGTOOLBAR
2009-03-24 10:02 . 2009-03-24 10:02 325,640 –a—— c:\windows\system32\drivers\avgldx86.sys
2009-03-24 10:02 . 2009-03-24 10:02 107,912 –a—— c:\windows\system32\drivers\avgtdix.sys
2009-03-24 10:02 . 2009-03-24 10:02 10,520 –a—— c:\windows\system32\avgrsstx.dll
2009-03-24 10:01 . 2009-03-24 10:01 d——– c:\program files\AVG
2009-03-24 10:01 . 2009-03-24 10:01 d——– c:\documents and settings\All Users\Application Data\avg8
2009-03-23 22:50 . 2009-03-23 22:50 d—-c— c:\windows\system32\DRVSTORE
2009-03-23 22:50 . 2009-03-09 15:06 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-03-23 22:49 . 2009-03-23 22:49 d–h-c— c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-23 20:57 . 2009-03-23 20:57 d——– c:\documents and settings\Jim\Application Data\Malwarebytes
2009-03-21 18:20 . 2009-03-27 08:23 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-21 18:20 . 2009-03-21 18:20 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-21 18:20 . 2009-03-21 18:20 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-03-21 18:20 . 2009-03-26 16:49 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-21 18:20 . 2009-03-26 16:49 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-21 18:12 . 2008-04-13 14:39 14,592 –a—— c:\windows\system32\drivers\kbdhid.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-24 18:06 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-24 13:35 ——— d—–w c:\documents and settings\All Users\Application Data\Trend Micro
2009-03-24 02:48 ——— d—–w c:\program files\Lavasoft
2009-03-24 00:26 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-03-24 00:25 ——— d—–w c:\program files\Common Files\Real
2009-03-17 00:18 7,972 –sha-w c:\windows\system32\vimuvayo.dll
2009-03-17 00:18 7,972 –sha-w c:\windows\system32\somituso.dll
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2007-04-29 20:10 32 —-a-r c:\documents and settings\All Users\hash.dat
2007-03-18 22:45 774,144 —-a-w c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LiveMonitor"="c:\program files\MSI\Live Update 3\LMonitor.exe" [2006-09-05 497152]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 75520]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-14 257088]
"Camera Detector"="c:\progra~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE" [2002-12-09 208896]
"Blubster"="c:\program files\Blubster\Blubster.exe" [BU]
"PSDiagnosticM"="c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-02-27 315392]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-24 1932568]
"VTTimer"="VTTimer.exe" [2005-03-07 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2006-04-11 c:\windows\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-08-02 c:\windows\soundman.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-03 40960]
officejet 6100.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-12-03 147456]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-24 10:02 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Linksys Wireless-G Print Server\\PSDiagnosticM.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-23 64160]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [2007-03-12 11264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-24 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-03-24 107912]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-24 298264]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2007-08-12 11136]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2007-08-12 37248]
S3 LKNUCMP;Linksys Network USB Composite Device;c:\windows\system32\drivers\lknucmp.sys [2007-08-12 11648]
S3 SetupNTGLM7X;SetupNTGLM7X;c:\program files\MSI\Live Update 3\NTGLM7X.SYS [2007-03-12 28160]
.
Contents of the 'Scheduled Tasks' folder

2009-03-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 15:06]

2009-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

2009-03-24 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1186953004.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-03 19:40]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jim\Application Data\Mozilla\Firefox\Profiles\7crm7phn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmnqmp07030901.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-27 17:31:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-27 17:32:41
ComboFix-quarantined-files.txt 2009-03-27 21:32:38

Pre-Run: 68,102,328,320 bytes free
Post-Run: 68,089,413,632 bytes free

150 — E O F — 2009-03-27 11:56:09
Hi,

This is being very stubborn,

Please do the following:


Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please click OTMoveIt3 and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Services

:Reg

:Files
c:\windows\system32\vimuvayo.dll
c:\windows\system32\somituso.dll

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



NEXT


Lets try a stand alone tool by Kaspersky in stead of the online scan

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder. Click Next.
  • Hit OK at the prompt for scanning in Safe Mode.
  • It will then open a box. There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the top right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then choose the delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file, name it Kas.
  • Save it to your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.




NEXT


Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here



NEXT


Lets see if there are anymore remnants left:

Please open your MalwareBytes AntiMalware program
click on the updates tab and search for updates
run a quick scan and remove anything it finds

Post the MBAM log in your next reply

NEXT

run HJT and save a log file



In your next reply please post


  • OTMoveIt3 log
  • AVP log
  • Rooter log
  • MBAM log
  • Fresh HJT Log

also please advise how your computer is running now
Hi CatByte - I had to give up. The computer kept shutting down while I tried running the standalone Kaspersky tool. I tried it many times with no luck. So I called a local computer repair guy to try to get the machine back up and running for me. I really appreciate your help and will continue to use WTT should I need to in the future. Thanks again. Jim
Hi, I'm very sorry it came down to that, hopefully you have been able to restore your PC back to 100% working… If you have any questions or want any recommendations for how to protect yourself for the future, please ask.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI