This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Random Pop-ups and Slow internet

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I was wondering if you guys can help me out. Just recently I have been getting these random pop-up when I surf the web. It isn't one particular site and it's not the browser either since it has happen to me with Chrome, FF, and IE. The pop-ups tells me to download some kind of Windows Registry Defender. I have tried using several programs like CleanUp! to remove whatever was causing it but it has not worked. Can you look at my HJ log and see what's wrong? Also my internet has been running really really slow as well. Here is a screenshot of what the pop-ups look like:

http://img11.imageshack.us/img11/345/78739301.png

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:04:26 AM, on 3/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\God\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\World of Warcraft\BackgroundDownloader.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {78622ab5-afcd-447b-b26a-8f1d2052f0a6} - C:\WINDOWS\system32\dirupahu.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [suwemosule] Rundll32.exe "C:\WINDOWS\system32\dewukobe.dll",s
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [54f6d7b1] rundll32.exe "C:\WINDOWS\system32\nijetiyi.dll",b
O4 - HKLM\..\Run: [CPM57c5e42d] Rundll32.exe "c:\windows\system32\yatevipi.dll",a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\God\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [suwemosule] Rundll32.exe "C:\WINDOWS\system32\dewukobe.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [suwemosule] Rundll32.exe "C:\WINDOWS\system32\dewukobe.dll",s (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: NCProTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O20 - AppInit_DLLs: wbsys.dll C:\WINDOWS\system32\lawireyo.dll c:\windows\system32\yatevipi.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yatevipi.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yatevipi.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe

–
End of file - 10108 bytes


I saw on another topic that I should scan with Rooter as well so here's the log for that:

Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3

A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - NTFS - (Total:232322 Mo/Free:3400 Mo)
D:\ [CD-Rom] (Total:7908 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [Removable] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [Removable] (Total:0 Mo/Free:0 Mo)
I:\ [Removable] (Total:0 Mo/Free:0 Mo)
J:\ [Fixed] - NTFS - (Total:6149 Mo/Free:2020 Mo)

Sat 03/28/2009| 1:41

———————-\\ Processes..

–Locked– [System Process]
———- System
———- \SystemRoot\System32\smss.exe
———- \??\C:\WINDOWS\system32\csrss.exe
———- \??\C:\WINDOWS\system32\winlogon.exe
———- C:\WINDOWS\system32\services.exe
———- C:\WINDOWS\system32\lsass.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\system32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\WINDOWS\system32\spoolsv.exe
———- C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
———- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
———- C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
———- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
———- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
———- C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
———- C:\WINDOWS\System32\alg.exe
———- C:\WINDOWS\AGRSMMSG.exe
———- C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
———- C:\WINDOWS\System32\ezSP_Px.exe
———- C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe
———- C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
———- C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
———- C:\WINDOWS\system32\rundll32.exe
———- C:\Documents and Settings\God\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
———- C:\Program Files\Logitech\SetPoint\SetPoint.exe
———- C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
———- C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
———- C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
———- C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
———- C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
———- C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
———- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
———- C:\WINDOWS\explorer.exe
———- C:\Program Files\World of Warcraft\BackgroundDownloader.exe
———- C:\Program Files\World of Warcraft\WoW.exe
———- C:\WINDOWS\System32\svchost.exe
———- C:\Program Files\Mozilla Firefox\firefox.exe
———- C:\WINDOWS\system32\cmd.exe
———- C:\Rooter$\RK.exe

———————-\\ Search..

———————-\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - Sat 03/28/2009| 1:41

———————-\\ Scan completed at 1:41
Hi Zachariah, welcome to the forum.


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.



Open hijackthis, do a system scan only and checkmark these lines, if present

O2 - BHO: (no name) - {78622ab5-afcd-447b-b26a-8f1d2052f0a6} - C:\WINDOWS\system32\dirupahu.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [suwemosule] Rundll32.exe "C:\WINDOWS\system32\dewukobe.dll",s
O4 - HKLM\..\Run: [54f6d7b1] rundll32.exe "C:\WINDOWS\system32\nijetiyi.dll",b
O4 - HKLM\..\Run: [CPM57c5e42d] Rundll32.exe "c:\windows\system32\yatevipi.dll",a
O4 - HKUS\S-1-5-19\..\Run: [suwemosule] Rundll32.exe "C:\WINDOWS\system32\dewukobe.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [suwemosule] Rundll32.exe "C:\WINDOWS\system32\dewukobe.dll",s (User 'NETWORK SERVICE')
O20 - AppInit_DLLs: wbsys.dll C:\WINDOWS\system32\lawireyo.dll c:\windows\system32\yatevipi.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yatevipi.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\yatevipi.dll



Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



It is important to allow the next tool to reboot your computer when prompted.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\dirupahu.dll
    C:\WINDOWS\system32\dewukobe.dll
    C:\WINDOWS\system32\nijetiyi.dll
    c:\windows\system32\yatevipi.dll
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Next
Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Ok I did everything you asked and here are the logs:

Malwarebytes' Anti-Malware 1.35
Database version: 1911
Windows 5.1.2600 Service Pack 3

3/28/2009 12:58:03 PM
mbam-log-2009-03-28 (12-58-03).txt

Scan type: Quick Scan
Objects scanned: 64113
Time elapsed: 3 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Registry Keys Infected: 6
Registry Values Infected: 5
Registry Data Items Infected: 6
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\robejaku.dll (Trojan.Vundo.H) -> Delete on reboot.
c:\WINDOWS\system32\juposeno.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\lawireyo.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{78622ab5-afcd-447b-b26a-8f1d2052f0a6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{78622ab5-afcd-447b-b26a-8f1d2052f0a6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\54f6d7b1 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\suwemosule (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm57c5e42d (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\juposeno.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\juposeno.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: c:\windows\system32\lawireyo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\lawireyo.dll  -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo) -> Data: system32\lawireyo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\robejaku.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\ukajebor.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\juposeno.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\hamohive.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mubohome.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lawireyo.dll (Trojan.Vundo) -> Delete on reboot.


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
DllUnregisterServer procedure not found in C:\WINDOWS\system32\dirupahu.dll
C:\WINDOWS\system32\dirupahu.dll NOT unregistered.
C:\WINDOWS\system32\dirupahu.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\dewukobe.dll
C:\WINDOWS\system32\dewukobe.dll NOT unregistered.
C:\WINDOWS\system32\dewukobe.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\nijetiyi.dll
C:\WINDOWS\system32\nijetiyi.dll NOT unregistered.
C:\WINDOWS\system32\nijetiyi.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\yatevipi.dll
c:\windows\system32\yatevipi.dll NOT unregistered.
c:\windows\system32\yatevipi.dll moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\God\LOCALS~1\Temp\etilqs_Sb8u1Rb6MN0EcJTeEmnx scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\JET928B.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\JET93E3.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Documents and Settings\God\Local Settings\Application Data\Mozilla\Firefox\Profiles\jmb1mm40.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\God\Local Settings\Application Data\Mozilla\Firefox\Profiles\jmb1mm40.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\God\Local Settings\Application Data\Mozilla\Firefox\Profiles\jmb1mm40.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\God\Local Settings\Application Data\Mozilla\Firefox\Profiles\jmb1mm40.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\God\Local Settings\Application Data\Mozilla\Firefox\Profiles\jmb1mm40.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\God\Local Settings\Application Data\Mozilla\Firefox\Profiles\jmb1mm40.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
 
OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03282009_124907


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:01:26 PM, on 3/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Documents and Settings\God\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDPop3.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SoftwareDistribution\Download\0f4651f0d7e6cb55f0a983df3c4744d0\update\update.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\God\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [suwemosule] Rundll32.exe "C:\WINDOWS\system32\dewukobe.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [suwemosule] Rundll32.exe "C:\WINDOWS\system32\dewukobe.dll",s (User 'NETWORK SERVICE')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: NCProTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O20 - AppInit_DLLs:   c:\windows\system32\yatevipi.dll 
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe

–
End of file - 9452 bytes


I haven't seen any pop-ups since I did it and loading speed is up. Do you see anything in the logs?
Hi Zachariah,

Some of it may have been replaced. Bigger stick.


Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please post back with
  • combofix log
  • new HJT log


Thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:10:40 PM, on 3/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Documents and Settings\God\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\SEC\Natural Color Pro\NCProTray.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
C:\Program Files\Logitech\GamePanel Software\Applets\LCDRSS.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Launch LgDevAgt] "C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe"
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\God\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: NCProTray.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O20 - AppInit_DLLs:   c:\windows\system32\yatevipi.dll 
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\PACSPT~1.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\vaio media integrated server\Platform\UPnPFramework.exe

–
End of file - 9350 bytes


ComboFix 09-03-27.02 - God 2009-03-28 15:04:00.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.2047.1635 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\setup.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\iyitejin.ini
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_PCIDump


(((((((((((((((((((((((((   Files Created from 2009-02-28 to 2009-03-28  )))))))))))))))))))))))))))))))
.

2009-03-28 14:29 . 2009-03-28 14:29		d——–	c:\documents and settings\God\Application Data\Ventrilo
2009-03-28 13:58 . 2009-03-28 13:58		d——–	c:\program files\Ventrilo
2009-03-28 13:58 . 2009-03-28 13:58		d——–	c:\program files\Common Files\Wise Installation Wizard
2009-03-28 13:58 . 2009-03-28 13:58	262	–a——	c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2009-03-28 13:36 . 2009-03-28 13:36	3,688	–a——	c:\windows\system32\d3d9caps.dat
2009-03-28 12:54 . 2009-03-28 12:54		d——–	c:\program files\Malwarebytes' Anti-Malware
2009-03-28 12:54 . 2009-03-28 12:54		d——–	c:\documents and settings\God\Application Data\Malwarebytes
2009-03-28 12:54 . 2009-03-28 12:54		d——–	c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-28 12:54 . 2009-03-26 16:49	38,496	–a——	c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-28 12:54 . 2009-03-26 16:49	15,504	–a——	c:\windows\system32\drivers\mbam.sys
2009-03-28 12:49 . 2009-03-28 12:49		d——–	C:\_OTMoveIt
2009-03-28 01:41 . 2009-03-28 01:41		d——–	C:\Rooter$
2009-03-28 01:36 . 2009-03-28 01:36		d——–	C:\OutputFolder
2009-03-28 01:36 . 2009-03-28 13:13	135	–a——	c:\windows\system32\test.aok
2009-03-28 01:35 . 2009-03-28 01:35		d——–	c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter
2009-03-28 01:00 . 2009-03-28 01:08		d——–	c:\program files\ConvertHelper
2009-03-28 00:50 . 2009-03-28 00:50		d——–	c:\documents and settings\God\dwhelper
2009-03-28 00:07 . 2009-03-28 00:07		d——–	c:\program files\Trend Micro
2009-03-28 00:02 . 2009-03-28 00:02		d——–	c:\program files\CleanUp!
2009-03-27 23:51 . 2009-03-27 23:51		d——–	c:\program files\Panda Security
2009-03-27 23:51 . 2008-06-19 16:24	28,544	–a——	c:\windows\system32\drivers\pavboot.sys
2009-03-27 21:49 . 2009-03-27 21:49		d——–	c:\program files\Windows Media Connect 2
2009-03-27 21:45 . 2009-03-27 21:45		d——–	c:\windows\system32\LogFiles
2009-03-27 21:45 . 2009-03-27 21:46		d——–	c:\windows\system32\drivers\UMDF
2009-03-27 21:01 . 2009-03-27 21:01		d——–	c:\documents and settings\All Users\Application Data\Blizzard
2009-03-27 20:14 . 2009-03-27 20:14		d——–	c:\program files\Common Files\Adobe
2009-03-27 20:14 . 2009-03-27 20:14		d——–	c:\documents and settings\God\Application Data\AdobeUM
2009-03-27 19:45 . 2009-03-27 19:45		d——–	c:\program files\Stardock
2009-03-27 19:40 . 2009-03-28 13:37		d——–	c:\program files\World of Warcraft
2009-03-27 19:40 . 2009-03-27 20:06		d——–	c:\program files\Common Files\Blizzard Entertainment
2009-03-27 17:08 . 2009-03-27 17:08		d——–	c:\windows\system32\scripting
2009-03-27 17:08 . 2009-03-27 17:08		d——–	c:\windows\system32\en
2009-03-27 17:08 . 2009-03-27 17:08		d——–	c:\windows\l2schemas
2009-03-26 23:42 . 2008-12-20 18:15	6,066,688	—–c—	c:\windows\system32\dllcache\ieframe.dll
2009-03-26 23:42 . 2007-04-17 04:32	2,455,488	—–c—	c:\windows\system32\dllcache\ieapfltr.dat
2009-03-26 23:42 . 2007-03-08 00:10	991,232	—–c—	c:\windows\system32\dllcache\ieframe.dll.mui
2009-03-26 23:42 . 2008-12-20 18:15	459,264	—–c—	c:\windows\system32\dllcache\msfeeds.dll
2009-03-26 23:42 . 2008-12-20 18:15	383,488	—–c—	c:\windows\system32\dllcache\ieapfltr.dll
2009-03-26 23:42 . 2008-12-20 18:15	267,776	—–c—	c:\windows\system32\dllcache\iertutil.dll
2009-03-26 23:42 . 2008-12-20 18:15	63,488	—–c—	c:\windows\system32\dllcache\icardie.dll
2009-03-26 23:42 . 2008-12-20 18:15	52,224	—–c—	c:\windows\system32\dllcache\msfeedsbs.dll
2009-03-26 23:42 . 2008-12-19 04:10	13,824	—–c—	c:\windows\system32\dllcache\ieudinit.exe
2009-03-26 23:38 . 2007-08-13 18:54	33,792	–a–c—	c:\windows\system32\dllcache\custsat.dll
2009-03-26 23:31 . 2008-11-11 18:34	10,838,016	—–c—	c:\windows\system32\dllcache\wmp.dll
2009-03-26 23:30 . 2008-06-13 06:05	272,128	—–c—	c:\windows\system32\dllcache\bthport.sys
2009-03-26 23:28 . 2009-01-16 21:35	3,594,752	—–c—	c:\windows\system32\dllcache\mshtml.dll
2009-03-26 23:26 . 2008-04-11 14:04	691,712	—–c—	c:\windows\system32\dllcache\inetcomm.dll
2009-03-26 23:26 . 2008-10-24 06:21	455,296	—–c—	c:\windows\system32\dllcache\mrxsmb.sys
2009-03-26 23:26 . 2008-10-15 11:34	337,408	—–c—	c:\windows\system32\dllcache\netapi32.dll
2009-03-26 23:26 . 2008-12-11 05:57	333,952	—–c—	c:\windows\system32\dllcache\srv.sys
2009-03-26 23:26 . 2008-05-01 09:33	331,776	—–c—	c:\windows\system32\dllcache\msadce.dll
2009-03-26 23:26 . 2008-10-03 05:02	247,326	—–c—	c:\windows\system32\dllcache\strmdll.dll
2009-03-26 23:26 . 2008-05-08 09:02	203,136	—–c—	c:\windows\system32\dllcache\rmcast.sys
2009-03-26 22:15 . 2009-03-26 22:15		d——–	c:\windows\provisioning
2009-03-26 22:15 . 2009-03-27 17:08		d——–	c:\windows\peernet
2009-03-26 22:14 . 2009-03-26 22:14		d——–	c:\windows\ServicePackFiles
2009-03-26 22:10 . 2009-03-27 17:01		d——–	c:\windows\EHome
2009-03-26 19:55 . 2009-03-26 19:55	0	———	c:\windows\WB.ini
2009-03-26 19:51 . 2002-04-15 22:11	67,866	———	c:\windows\system32\drivers\netwlan5.img
2009-03-26 19:51 . 2008-04-14 06:42	11,264	———	c:\windows\system32\spnpinst.exe
2009-03-26 19:51 . 2004-08-02 15:20	7,208	———	c:\windows\system32\secupd.sig
2009-03-26 19:51 . 2004-08-02 15:20	4,569	———	c:\windows\system32\secupd.dat
2009-03-26 19:36 . 2008-04-13 19:11	1,082,368	–a——	c:\windows\system32\esent.dll
2009-03-26 19:32 . 2009-03-26 19:32		d–hs—-	c:\documents and settings\God\UserData
2009-03-26 19:16 . 2008-04-26 17:14	42,672	———	c:\windows\system32\wbsys.dll
2009-03-26 19:04 . 2008-04-13 13:47	25,856	–a——	c:\windows\system32\drivers\usbprint.sys
2009-03-26 19:04 . 2008-04-13 19:11	21,504	–a——	c:\windows\system32\hidserv.dll
2009-03-26 19:04 . 2008-04-13 13:39	14,592	–a——	c:\windows\system32\drivers\kbdhid.sys
2009-03-26 19:04 . 2008-04-13 13:45	10,368	–a——	c:\windows\system32\drivers\hidusb.sys
2009-03-26 19:03 . 2009-03-27 23:15	90,112	–a——	c:\windows\DUMP3519.tmp
2009-03-26 19:03 . 2009-03-27 23:16	90,112	–a——	c:\windows\DUMP31ce.tmp
2009-03-26 19:03 . 2009-03-27 23:17	90,112	–a——	c:\windows\DUMP30c4.tmp
2009-03-26 18:52 . 2009-03-27 17:08		d——–	c:\windows\system32\bits
2009-03-26 18:51 . 2009-03-27 19:39		d–h—–	c:\windows\$hf_mig$
2009-03-26 17:45 . 2009-03-26 17:45		d——–	c:\documents and settings\God\Application Data\Logitech
2009-03-26 17:45 . 2009-03-26 17:45		d——–	c:\documents and settings\All Users\Application Data\LogiShrd
2009-03-26 17:44 . 2008-04-13 14:18	52,480	–a——	c:\windows\system32\drivers\i8042prt.sys
2009-03-26 17:44 . 2007-07-27 09:41	26,488	–a——	c:\windows\system32\spupdsvc.exe
2009-03-26 17:44 . 2008-04-13 13:39	23,040	–a——	c:\windows\system32\drivers\mouclass.sys
2009-03-26 17:44 . 2001-08-17 14:48	12,160	–a——	c:\windows\system32\drivers\mouhid.sys
2009-03-26 17:44 . 2001-08-17 14:48	12,160	–a–c—	c:\windows\system32\dllcache\mouhid.sys
2009-03-26 17:44 . 2009-03-26 17:44	0	–ah—–	c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-03-26 17:44 . 2009-03-26 17:44	0	–ah—–	c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-03-26 17:44 . 2009-03-26 17:44	0	–ah—–	c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2009-03-26 17:43 . 2009-02-19 01:26	301,656	–a——	c:\windows\system32\BtCoreIf.dll
2009-03-26 17:43 . 2009-02-19 01:27	170,512	–a——	c:\windows\system32\kemutb.dll
2009-03-26 17:43 . 2009-02-19 01:27	145,936	–a——	c:\windows\system32\KemUtil.dll
2009-03-26 17:43 . 2009-02-19 01:27	117,264	–a——	c:\windows\system32\KemWnd.dll
2009-03-26 17:43 . 2009-02-19 01:27	84,496	–a——	c:\windows\system32\KemXML.dll
2009-03-26 17:29 . 2008-04-13 19:12	354,304	–a——	c:\windows\system32\winhttp.dll
2009-03-26 17:29 . 2008-04-13 19:12	18,944	–a——	c:\windows\system32\qmgrprxy.dll
2009-03-26 17:29 . 2008-04-13 19:11	8,192	———	c:\windows\system32\bitsprx2.dll
2009-03-26 17:29 . 2008-04-13 19:11	7,168	———	c:\windows\system32\bitsprx3.dll
2009-03-26 17:25 . 2008-10-16 15:12	561,688	–a——	c:\windows\system32\wuapi.dll
2009-03-26 17:25 . 2008-10-16 15:12	323,608	–a——	c:\windows\system32\wucltui.dll
2009-03-26 17:25 . 2008-10-16 15:12	213,528	–a——	c:\windows\system32\wuaucpl.cpl
2009-03-26 17:25 . 2008-10-16 15:13	202,776	–a——	c:\windows\system32\wuweb.dll
2009-03-26 17:25 . 2008-04-13 19:12	183,296	–a——	c:\windows\system32\wuaueng1.dll
2009-03-26 17:25 . 2008-04-13 19:12	165,888	–a——	c:\windows\system32\wuauclt1.exe
2009-03-26 17:25 . 2008-10-16 15:08	34,328	–a——	c:\windows\system32\wups.dll
2009-03-26 17:23 . 2009-03-26 17:23		d——–	c:\windows\SHELLNEW
2009-03-26 17:23 . 2009-03-26 17:23		d——–	c:\program files\Microsoft ActiveSync
2009-03-26 17:23 . 2003-06-18 18:31	17,920	–a——	c:\windows\system32\mdimon.dll
2009-03-26 17:23 . 2009-03-26 17:23	376	–a——	c:\windows\ODBC.INI
2009-03-26 17:22 . 2009-03-26 17:22		d—-c—	c:\windows\system32\DRVSTORE
2009-03-26 17:22 . 2009-03-26 17:22		dr-h—–	C:\MSOCache
2009-03-26 17:21 . 2009-03-26 17:21		d——–	c:\program files\SEC
2009-03-26 17:21 . 2009-03-26 17:44		d——–	c:\program files\Common Files\Logishrd
2009-03-26 17:21 . 2009-03-26 17:43		d——–	c:\documents and settings\All Users\Application Data\Logitech
2009-03-26 17:21 . 2006-08-28 18:12	13,312	–a——	c:\windows\system32\drivers\MTictwl.sys
2009-03-26 17:20 . 2009-03-26 17:22		d——–	c:\program files\Logitech
2009-03-26 17:18 . 2009-03-27 21:21		d——–	c:\program files\Microsoft Works
2009-03-26 17:18 . 2009-03-26 17:18	0	–a——	c:\windows\nsreg.dat
2009-03-26 17:14 . 2009-03-26 17:14		d——–	c:\documents and settings\All Users\Application Data\VAIO Media Platform
2009-03-26 17:13 . 2009-03-26 17:13		d——–	c:\program files\drag'n drop cd+dvd
2009-03-26 17:13 . 2003-09-08 22:15	2	———	c:\windows\system32\Px.ini
2009-03-26 17:12 . 2003-12-05 14:33	118,784	–a——	c:\windows\system32\tvtuner.cpl
2009-03-26 17:11 . 2009-03-26 17:11		d——–	C:\WUTemp
2009-03-26 17:11 . 2009-03-26 17:11		d——–	c:\program files\InterVideo
2009-03-26 17:11 . 2008-04-13 19:12	221,184	–a——	c:\windows\system32\wmpns.dll
2009-03-26 17:11 . 2002-11-21 11:57	204,800	–a——	c:\windows\system32\IVIresizeW7.dll
2009-03-26 17:11 . 2002-11-21 11:57	200,704	–a——	c:\windows\system32\IVIresizeA6.dll
2009-03-26 17:11 . 2002-11-21 11:57	192,512	–a——	c:\windows\system32\IVIresizeP6.dll
2009-03-26 17:11 . 2002-11-21 11:57	192,512	–a——	c:\windows\system32\IVIresizeM6.dll
2009-03-26 17:11 . 2002-11-21 11:57	188,416	–a——	c:\windows\system32\IVIresizePX.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-28 05:28	———	d—–w	c:\program files\Google
2009-03-28 02:29	———	d—–w	c:\program files\Sony
2009-03-26 22:43	———	d–h–w	c:\program files\InstallShield Installation Information
2009-03-26 22:16	———	d—–w	c:\documents and settings\All Users\Application Data\Sony Corporation
2009-03-26 22:14	———	d—–w	c:\program files\Common Files\Sony Shared
2009-03-26 22:14	———	d—–w	c:\program files\Common Files\InstallShield
2009-03-26 22:11	———	d—–w	c:\program files\Common Files\Symantec Shared
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\MSMSGS.EXE" [2008-04-13 1695232]
"Google Update"="c:\documents and settings\God\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-03-27 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-07 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-07 114688]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-16 335872]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"Launch LgDevAgt"="c:\program files\Logitech\GamePanel Software\LgDevAgt.exe" [2008-11-06 358920]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2008-11-06 1548296]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2008-11-06 2816520]
"AGRSMMSG"="AGRSMMSG.exe" [2003-05-23 c:\windows\AGRSMMSG.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 c:\windows\KHALMNPR.Exe]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\system32\Ati2mdxx.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-03-26 809488]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2009-03-26 49220]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 01:30 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2009-03-27 19:47 210168 c:\program files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=  c:\windows\system32\yatevipi.dll 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=c:\windows\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Remocon Driver.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Remocon Driver.lnk
backup=c:\windows\pss\Remocon Driver.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ARStartup]
–a—— 2003-12-15 18:15 192512 c:\windows\SONYSYS\VAIO Recovery\arinit.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2003-09-06 02:20 70816 c:\program files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreateCD_Reminder]
–a—— 2004-03-05 19:32 53248 c:\windows\SONYSYS\VAIO Recovery\Reminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
–a—— 2003-08-20 15:55 124096 c:\program files\Common Files\Symantec Shared\CfgWiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\URLLSTCK.exe]
–a—— 2003-09-06 18:36 70840 c:\program files\Norton Internet Security\UrlLstCk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Update 2]
–a—— 2004-01-17 06:36 135168 c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOSurvey]
–a—— 2003-11-03 14:55 1052672 c:\program files\Sony\VAIO Survey\SurveySA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZZZ]
–a—— 2003-04-10 17:22 111144 c:\windows\SONYSYS\Eflyer\SubFlyer.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-03-27 28544]
R2 VAIO Entertainment File Import Service;VAIO Entertainment File Import Service;c:\program files\Common Files\Sony Shared\VAIO Entertainment\VzCdb\VzFw.exe [2009-03-26 86098]
S3 VAIO Entertainment UPnP Client Adapter;VAIO Entertainment UPnP Client Adapter;c:\program files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe -RunBySCM –> c:\program files\Common Files\Sony Shared\VAIO Entertainment\VCSW\VCSW.exe -RunBySCM [?]
.
.
——- Supplementary Scan ——-
.
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward &Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Si&milar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\God\Application Data\Mozilla\Firefox\Profiles\jmb1mm40.default\
FF - plugin: c:\documents and settings\God\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJPI142_01.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-28 15:07:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …  

scanning hidden autostart entries … 

scanning hidden files …  

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(696)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
c:\program files\Stardock\Object Desktop\WindowBlinds\WBSrv.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDCountdown.exe
c:\program files\Logitech\GamePanel Software\Applets\LCDRSS.exe
c:\program files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
.
**************************************************************************
.
Completion time: 2009-03-28 15:09:51 - machine was rebooted [God]
ComboFix-quarantined-files.txt  2009-03-28 20:09:48

Pre-Run: 204,855,803,904 bytes free
Post-Run: 204,782,448,640 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

295	— E O F —	2009-03-28 18:14:38
Hi Zachariah,

How's the computer running?

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    
    :Files
    c:\windows\DUMP3519.tmp
    c:\windows\DUMP31ce.tmp
    c:\windows\DUMP30c4.tmp
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Go here to run an online scannner from ESET:
http://www.eset.eu/online-scanner

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. We will need this later.
Please post back with the ESET log and a new HJT log.

Please post back with
  • combofix log
  • ESET log
  • new HJT log

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI