MatureCompguy
Topic Starter
Just yesterday I was searching the web and listening to some music on a site and I think somehow I got infected with something. I've tried to clean whatever it is with my spy sweeper and spy bot and also tried to do it with Superanti Spyware. They all seem to have found something and quaratine it or deleted it. But when I start the computer I get gijabawu.dll missing or something and I don't think my computer is completely back to normal. Here is my Hijack Log first and after it is the log that SUPERAntiSpyware created after i ran it :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:36 PM, on 4/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://oishelp.webex.com/client/T25L/support/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D79094E-5A85-456D-A3F0-754E78D15438}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{51CCF873-6D22-4B82-A9DA-13A0D0891A16}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - AppInit_DLLs: c:\windows\system32\rinokulo.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
–
End of file - 5811 bytes
-Superantispyware Scan Log :
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/28/2009 at 08:13 PM
Application Version : 4.26.1000
Core Rules Database Version : 3870
Trace Rules Database Version: 1818
Scan type : Complete Scan
Total Scan Time : 00:39:25
Memory items scanned : 393
Memory threats detected : 4
Registry items scanned : 5535
Registry threats detected : 34
File items scanned : 23174
File threats detected : 127
Trojan.Dropper/Sys-NV
C:\WINDOWS\SYSTEM32\NVRSK.DLL
C:\WINDOWS\SYSTEM32\NVRSK.DLL
C:\WINDOWS\SYSTEM32\READER_S.EXE
Adware.Vundo/Variant-SR
C:\WINDOWS\SYSTEM32\RINOKULO.DLL
C:\WINDOWS\SYSTEM32\RINOKULO.DLL
Trojan.Smitfraud Variant-Gen/Bensorty
C:\WINDOWS\SYSTEM32\SJG9S8GUIGJS.DLL
C:\WINDOWS\SYSTEM32\SJG9S8GUIGJS.DLL
C:\DOCUMENTS AND SETTINGS\S3\MY DOCUMENTS\APPS\HIJACKTHIS V2\BACKUPS\BACKUP-20090428-181541-909.DLL
Adware.Vundo/Variant-EC
C:\WINDOWS\SYSTEM32\TEYUNUFA.DLL
C:\WINDOWS\SYSTEM32\TEYUNUFA.DLL
Trojan.Sino-PWS/Gen
HKLM\Software\Classes\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}#ThreadingModel
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}\InProcServer32
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}\InProcServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKU\S-1-5-21-1360147005-1681554014-312552118-1013\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}
HKCR\CLSID\{EC43E3FD-5C60-46A6-97D7-E0B85DBDD6C4}
HKCR\CLSID\{EC43E3FD-5C60-46A6-97D7-E0B85DBDD6C4}\InprocServer32
HKCR\CLSID\{EC43E3FD-5C60-46A6-97D7-E0B85DBDD6C4}\InprocServer32#ThreadingModel
Adware.Tracking Cookie
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@atdmt[2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@roiservice[2].txt
C:\Documents and Settings\S3\Cookies\s3@insightexpressai[3].txt
C:\Documents and Settings\S3\Cookies\s3@imrworldwide[2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][3].txt
C:\Documents and Settings\S3\Cookies\s3@specificmedia[2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@specificclick[2].txt
C:\Documents and Settings\S3\Cookies\s3@serving-sys[1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@adinterax[2].txt
C:\Documents and Settings\S3\Cookies\s3@advertising[2].txt
C:\Documents and Settings\S3\Cookies\s3@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\s3@adbrite[4].txt
C:\Documents and Settings\S3\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\S3\Cookies\[removed][3].txt
C:\Documents and Settings\S3\Cookies\[removed][3].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@doubleclick[1].txt
C:\Documents and Settings\S3\Cookies\s3@redirectclicks[1].txt
C:\Documents and Settings\S3\Cookies\[removed][7].txt
C:\Documents and Settings\S3\Cookies\s3@oasn04.247realmedia[1].txt
C:\Documents and Settings\S3\Cookies\s3@zedo[1].txt
C:\Documents and Settings\S3\Cookies\s3@collective-media[3].txt
C:\Documents and Settings\S3\Cookies\s3@tacoda[2].txt
C:\Documents and Settings\S3\Cookies\s3@chitika[1].txt
C:\Documents and Settings\S3\Cookies\s3@revsci[3].txt
C:\Documents and Settings\S3\Cookies\s3@indextools[1].txt
C:\Documents and Settings\S3\Cookies\s3@kontera[3].txt
C:\Documents and Settings\S3\Cookies\s3@myroitracking[1].txt
C:\Documents and Settings\S3\Cookies\s3@interclick[3].txt
C:\Documents and Settings\S3\Cookies\s3@questionmarket[1].txt
C:\Documents and Settings\S3\Cookies\s3@hearstmagazines.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\s3@msnportal.112.2o7[2].txt
C:\Documents and Settings\S3\Cookies\s3@warnerbros.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@buzznet.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@youporn[1].txt
C:\Documents and Settings\S3\Cookies\s3@247realmedia[1].txt
C:\Documents and Settings\S3\Cookies\[removed][5].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@msnbc.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@earthlink.122.2o7[1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@media6degrees[3].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@trafficmp[2].txt
C:\Documents and Settings\S3\Cookies\s3@ads.x17online[3].txt
C:\Documents and Settings\S3\Cookies\s3@dmtracker[1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@ads.x17online[2].txt
C:\Documents and Settings\S3\Cookies\s3@webstatsmaster[1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@adbrite[2].txt
C:\Documents and Settings\S3\Cookies\s3@ad.myp2p[1].txt
C:\Documents and Settings\S3\Cookies\s3@adbrite[1].txt
C:\Documents and Settings\S3\Cookies\s3@adbrite[3].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@collective-media[1].txt
C:\Documents and Settings\S3\Cookies\s3@collective-media[2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@insightexpressai[1].txt
C:\Documents and Settings\S3\Cookies\s3@insightexpressai[2].txt
C:\Documents and Settings\S3\Cookies\s3@interclick[1].txt
C:\Documents and Settings\S3\Cookies\s3@kontera[2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@media6degrees[2].txt
C:\Documents and Settings\S3\Cookies\s3@msnbc.112.2o7[2].txt
C:\Documents and Settings\S3\Cookies\s3@msnportal.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\s3@precisionclick[2].txt
C:\Documents and Settings\S3\Cookies\s3@revsci[2].txt
C:\Documents and Settings\S3\Cookies\s3@roiservice[1].txt
C:\Documents and Settings\S3\Cookies\[removed][4].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][3].txt
C:\Documents and Settings\S3\Cookies\s3@youporn[2].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@atdmt[2].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@mediatraffic[1].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@msnportal.112.2o7[1].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@nextag[2].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@partner2profit[2].txt
Trojan.DNSChanger-Codec
HKLM\Software\1
HKLM\Software\1#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\1#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\1#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\6
HKLM\Software\6#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\6#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\6#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\7
HKLM\Software\7#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\7#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\7#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\8
HKLM\Software\8#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\8#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\8#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\9
HKLM\Software\9#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\9#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\9#31C2E1E4D78E6A11B88DFA803456A1FFA5
Rogue.Component/Trace
HKU\S-1-5-21-1360147005-1681554014-312552118-1013\Software\Microsoft\FIAS4057
Trojan.Agent/Gen-Reader_S
C:\DOCUMENTS AND SETTINGS\S3\READER_S.EXE
Trojan.Agent/Gen-FakeAlert
C:\EFTKGUWN.EXE
C:\RECYCLER\S-1-5-21-1360147005-1681554014-312552118-1013\DC17.EXE
Trojan.Agent/Gen-FDUPX
C:\LSASS.EXE
C:\RECYCLER\S-1-5-21-1360147005-1681554014-312552118-1013\DC16.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000001.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000006.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000007.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000024.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000025.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000034.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000035.EXE
C:\WINDOWS\TEMP\TEMPORARY INTERNET FILES\CONTENT.IE5\85M3S1AN\PIFCCPDNAB[1].HTM
C:\WINDOWS\Prefetch\LSASS.EXE-2A807D13.pf
Adware.WhenU
C:\PROGRAM FILES\DAEMON TOOLS\SETUPDTSB.EXE
Adware.Vundo/Variant-EmpiaA
C:\WINDOWS\SYSTEM32\RUWIRAJE.DLL
Trojan.Agent/Gen-SpamTool
C:\WINDOWS\TEMP\KJSFH3JFOKDF3.EXE
C:\WINDOWS\TEMP\QCXDVLH.EXE
C:\WINDOWS\Prefetch\QCXDVLH.EXE-2DE181E2.pf
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:36 PM, on 4/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - https://oishelp.webex.com/client/T25L/support/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2D79094E-5A85-456D-A3F0-754E78D15438}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{51CCF873-6D22-4B82-A9DA-13A0D0891A16}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O20 - AppInit_DLLs: c:\windows\system32\rinokulo.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
–
End of file - 5811 bytes
-Superantispyware Scan Log :
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/28/2009 at 08:13 PM
Application Version : 4.26.1000
Core Rules Database Version : 3870
Trace Rules Database Version: 1818
Scan type : Complete Scan
Total Scan Time : 00:39:25
Memory items scanned : 393
Memory threats detected : 4
Registry items scanned : 5535
Registry threats detected : 34
File items scanned : 23174
File threats detected : 127
Trojan.Dropper/Sys-NV
C:\WINDOWS\SYSTEM32\NVRSK.DLL
C:\WINDOWS\SYSTEM32\NVRSK.DLL
C:\WINDOWS\SYSTEM32\READER_S.EXE
Adware.Vundo/Variant-SR
C:\WINDOWS\SYSTEM32\RINOKULO.DLL
C:\WINDOWS\SYSTEM32\RINOKULO.DLL
Trojan.Smitfraud Variant-Gen/Bensorty
C:\WINDOWS\SYSTEM32\SJG9S8GUIGJS.DLL
C:\WINDOWS\SYSTEM32\SJG9S8GUIGJS.DLL
C:\DOCUMENTS AND SETTINGS\S3\MY DOCUMENTS\APPS\HIJACKTHIS V2\BACKUPS\BACKUP-20090428-181541-909.DLL
Adware.Vundo/Variant-EC
C:\WINDOWS\SYSTEM32\TEYUNUFA.DLL
C:\WINDOWS\SYSTEM32\TEYUNUFA.DLL
Trojan.Sino-PWS/Gen
HKLM\Software\Classes\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}#ThreadingModel
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}\InProcServer32
HKCR\CLSID\{B2BA40A2-74F0-42BD-F434-12345A2C8953}\InProcServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{B2BA40A2-74F0-42BD-F434-12345A2C8953}
HKU\S-1-5-21-1360147005-1681554014-312552118-1013\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BA40A2-74F0-42BD-F434-12345A2C8953}
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}
HKCR\CLSID\{EC43E3FD-5C60-46A6-97D7-E0B85DBDD6C4}
HKCR\CLSID\{EC43E3FD-5C60-46A6-97D7-E0B85DBDD6C4}\InprocServer32
HKCR\CLSID\{EC43E3FD-5C60-46A6-97D7-E0B85DBDD6C4}\InprocServer32#ThreadingModel
Adware.Tracking Cookie
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@atdmt[2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@roiservice[2].txt
C:\Documents and Settings\S3\Cookies\s3@insightexpressai[3].txt
C:\Documents and Settings\S3\Cookies\s3@imrworldwide[2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][3].txt
C:\Documents and Settings\S3\Cookies\s3@specificmedia[2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@specificclick[2].txt
C:\Documents and Settings\S3\Cookies\s3@serving-sys[1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@adinterax[2].txt
C:\Documents and Settings\S3\Cookies\s3@advertising[2].txt
C:\Documents and Settings\S3\Cookies\s3@microsoftwindows.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\s3@adbrite[4].txt
C:\Documents and Settings\S3\Cookies\[removed]-sys[1].txt
C:\Documents and Settings\S3\Cookies\[removed][3].txt
C:\Documents and Settings\S3\Cookies\[removed][3].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@doubleclick[1].txt
C:\Documents and Settings\S3\Cookies\s3@redirectclicks[1].txt
C:\Documents and Settings\S3\Cookies\[removed][7].txt
C:\Documents and Settings\S3\Cookies\s3@oasn04.247realmedia[1].txt
C:\Documents and Settings\S3\Cookies\s3@zedo[1].txt
C:\Documents and Settings\S3\Cookies\s3@collective-media[3].txt
C:\Documents and Settings\S3\Cookies\s3@tacoda[2].txt
C:\Documents and Settings\S3\Cookies\s3@chitika[1].txt
C:\Documents and Settings\S3\Cookies\s3@revsci[3].txt
C:\Documents and Settings\S3\Cookies\s3@indextools[1].txt
C:\Documents and Settings\S3\Cookies\s3@kontera[3].txt
C:\Documents and Settings\S3\Cookies\s3@myroitracking[1].txt
C:\Documents and Settings\S3\Cookies\s3@interclick[3].txt
C:\Documents and Settings\S3\Cookies\s3@questionmarket[1].txt
C:\Documents and Settings\S3\Cookies\s3@hearstmagazines.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\s3@msnportal.112.2o7[2].txt
C:\Documents and Settings\S3\Cookies\s3@warnerbros.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@buzznet.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@youporn[1].txt
C:\Documents and Settings\S3\Cookies\s3@247realmedia[1].txt
C:\Documents and Settings\S3\Cookies\[removed][5].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@msnbc.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@earthlink.122.2o7[1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@media6degrees[3].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@trafficmp[2].txt
C:\Documents and Settings\S3\Cookies\s3@ads.x17online[3].txt
C:\Documents and Settings\S3\Cookies\s3@dmtracker[1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@ads.x17online[2].txt
C:\Documents and Settings\S3\Cookies\s3@webstatsmaster[1].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@adbrite[2].txt
C:\Documents and Settings\S3\Cookies\s3@ad.myp2p[1].txt
C:\Documents and Settings\S3\Cookies\s3@adbrite[1].txt
C:\Documents and Settings\S3\Cookies\s3@adbrite[3].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@collective-media[1].txt
C:\Documents and Settings\S3\Cookies\s3@collective-media[2].txt
C:\Documents and Settings\S3\Cookies\[removed][2].txt
C:\Documents and Settings\S3\Cookies\s3@insightexpressai[1].txt
C:\Documents and Settings\S3\Cookies\s3@insightexpressai[2].txt
C:\Documents and Settings\S3\Cookies\s3@interclick[1].txt
C:\Documents and Settings\S3\Cookies\s3@kontera[2].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\s3@media6degrees[2].txt
C:\Documents and Settings\S3\Cookies\s3@msnbc.112.2o7[2].txt
C:\Documents and Settings\S3\Cookies\s3@msnportal.112.2o7[1].txt
C:\Documents and Settings\S3\Cookies\s3@precisionclick[2].txt
C:\Documents and Settings\S3\Cookies\s3@revsci[2].txt
C:\Documents and Settings\S3\Cookies\s3@roiservice[1].txt
C:\Documents and Settings\S3\Cookies\[removed][4].txt
C:\Documents and Settings\S3\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Cookies\[removed][3].txt
C:\Documents and Settings\S3\Cookies\s3@youporn[2].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@atdmt[2].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@mediatraffic[1].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@msnportal.112.2o7[1].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@nextag[2].txt
C:\Documents and Settings\S3\Local Settings\Temp\Cookies\s3@partner2profit[2].txt
Trojan.DNSChanger-Codec
HKLM\Software\1
HKLM\Software\1#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\1#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\1#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\6
HKLM\Software\6#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\6#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\6#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\7
HKLM\Software\7#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\7#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\7#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\8
HKLM\Software\8#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\8#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\8#31C2E1E4D78E6A11B88DFA803456A1FFA5
HKLM\Software\9
HKLM\Software\9#31AC70412E939D72A9234CDEBB1AF5867B
HKLM\Software\9#31897356954C2CD3D41B221E3F24F99BBA
HKLM\Software\9#31C2E1E4D78E6A11B88DFA803456A1FFA5
Rogue.Component/Trace
HKU\S-1-5-21-1360147005-1681554014-312552118-1013\Software\Microsoft\FIAS4057
Trojan.Agent/Gen-Reader_S
C:\DOCUMENTS AND SETTINGS\S3\READER_S.EXE
Trojan.Agent/Gen-FakeAlert
C:\EFTKGUWN.EXE
C:\RECYCLER\S-1-5-21-1360147005-1681554014-312552118-1013\DC17.EXE
Trojan.Agent/Gen-FDUPX
C:\LSASS.EXE
C:\RECYCLER\S-1-5-21-1360147005-1681554014-312552118-1013\DC16.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000001.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000006.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000007.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000024.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000025.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000034.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8E0B152F-6199-4D58-A375-09AB20D410A5}\RP1\A0000035.EXE
C:\WINDOWS\TEMP\TEMPORARY INTERNET FILES\CONTENT.IE5\85M3S1AN\PIFCCPDNAB[1].HTM
C:\WINDOWS\Prefetch\LSASS.EXE-2A807D13.pf
Adware.WhenU
C:\PROGRAM FILES\DAEMON TOOLS\SETUPDTSB.EXE
Adware.Vundo/Variant-EmpiaA
C:\WINDOWS\SYSTEM32\RUWIRAJE.DLL
Trojan.Agent/Gen-SpamTool
C:\WINDOWS\TEMP\KJSFH3JFOKDF3.EXE
C:\WINDOWS\TEMP\QCXDVLH.EXE
C:\WINDOWS\Prefetch\QCXDVLH.EXE-2DE181E2.pf