This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] [Re-opened] Help - Crazy Virus

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi
I have been following the self help logs but I think I need an experts help.
I thought I got rid of the problems but they are back and are pissed off

I have done a few scans and have some logs


HiJackThis Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:33:34 AM, on 5/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Asif Sheikh\Desktop\Emergency Virus\Norman_Malware_Cleaner.exe
C:\Documents and Settings\Asif Sheikh\Desktop\Emergency Virus\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1c9bd12181be60) (gupdate1c9bd12181be60) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 5017 bytes

Following some self help logs I also installed ComboFix and This is the Log:

ComboFix 09-05-20.A0 - Asif Sheikh 05/21/2009 2:12.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.282 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Emergency Virus\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\apusinaw.ini
c:\windows\system32\imetagug.ini
c:\windows\system32\imuzudaj.ini
c:\windows\system32\iwurobag.ini
c:\windows\system32\mebetewu.dll.tmp
c:\windows\system32\mepavuhi.dll
c:\windows\system32\mizezapo.dll.tmp
c:\windows\system32\rurisugo.dll.tmp
c:\windows\system32\soyopuvo.dll
c:\windows\system32\telemize.dll
c:\windows\system32\ulojavuh.ini
c:\windows\system32\urimizam.ini
c:\windows\system32\wesagibu.dll

.
((((((((((((((((((((((((( Files Created from 2009-04-21 to 2009-05-21 )))))))))))))))))))))))))))))))
.

2009-05-14 06:11 . 2003-06-05 21:15 57436 —-a-w c:\windows\DASShp.dll
2009-05-14 06:11 . 2009-05-14 06:11 ——– d—–w c:\program files\Microsoft Reader
2009-05-12 08:29 . 2006-11-29 17:06 3426072 —-a-w c:\windows\system32\d3dx9_32.dll
2009-05-12 08:28 . 2009-05-12 08:28 ——– d—–w c:\program files\Microsoft SQL Server Compact Edition
2009-05-11 23:58 . 2008-10-16 18:06 208744 —-a-w c:\windows\system32\muweb.dll
2009-05-09 05:36 . 2009-05-09 05:36 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-05-09 05:36 . 2009-05-09 05:36 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-05-09 05:36 . 2009-05-09 05:36 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-09 05:36 . 2009-05-19 12:44 ——– d—–w c:\windows\system32\drivers\Avg
2009-05-09 05:36 . 2009-05-17 05:33 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\AVGTOOLBAR
2009-05-09 02:42 . 2009-05-09 02:42 410984 —-a-w c:\windows\system32\deploytk.dll
2009-05-09 01:07 . 2009-05-09 01:07 ——– d—–w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-05-05 22:59 . 2009-05-06 01:00 85504 —-a-w c:\windows\system32\click_setup.exe
2009-05-04 02:01 . 2009-05-08 21:53 ——– d—–w c:\documents and settings\Asif Sheikh\Tracing
2009-05-04 01:49 . 2009-05-04 01:49 ——– d—–w c:\program files\Microsoft Office Outlook Connector
2009-05-04 01:47 . 2009-05-04 01:47 ——– d—–w c:\program files\Microsoft
2009-05-04 01:47 . 2009-05-04 01:47 ——– d—–w c:\program files\Windows Live SkyDrive
2009-05-04 01:42 . 2009-05-04 01:42 ——– d—–w c:\program files\Common Files\Windows Live
2009-04-30 04:08 . 2009-04-30 04:08 ——– d—–w c:\program files\Microsoft ActiveSync
2009-04-30 04:08 . 2009-04-30 04:08 ——– d—–w c:\program files\Microsoft Works
2009-04-30 04:05 . 2009-04-30 04:05 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\Malwarebytes
2009-04-30 04:01 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-30 04:01 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-30 04:01 . 2009-04-30 04:01 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-30 04:01 . 2009-04-30 04:04 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-30 03:51 . 2009-04-30 03:51 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\jviyimrb
2009-04-30 03:51 . 2009-04-30 03:51 ——– d—–w c:\documents and settings\Asif Sheikh\Local Settings\Application Data\jviyimrb
2009-04-30 03:29 . 2009-04-30 03:29 ——– d—–w c:\program files\microsoft frontpage
2009-04-29 19:39 . 2009-05-01 04:14 0 —-a-w c:\windows\system32\drivers\e56a3f44.sys
2009-04-22 05:59 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-22 05:59 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-22 05:59 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-22 05:59 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-22 05:59 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-22 05:59 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-22 05:59 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-22 05:59 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-22 05:59 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-22 05:58 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-22 05:58 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-22 05:47 . 2009-04-30 02:14 ——– d-sh–w C:\found.000

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-14 06:11 . 2008-01-09 06:51 ——– d–h–w c:\program files\InstallShield Installation Information
2009-05-12 08:36 . 2008-03-08 00:33 ——– d—–w c:\program files\Windows Live
2009-05-09 05:23 . 2008-01-09 07:06 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-09 02:41 . 2008-02-15 16:07 ——– d—–w c:\program files\Java
2009-05-04 02:00 . 2009-01-01 11:28 76072 —-a-w c:\documents and settings\Asif Sheikh\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-30 03:34 . 2001-08-23 14:00 ——– d—–w c:\program files\Common Files\Mozilla Shared
2009-04-30 02:15 . 2008-01-10 04:33 ——– d—–w c:\program files\Windows Media Connect 2
2009-04-20 04:27 . 2009-04-20 04:27 ——– d—–w c:\program files\uTorrent
2009-04-14 15:02 . 2008-01-14 03:56 ——– d—–w c:\program files\Google
2009-04-08 22:37 . 2008-01-09 10:15 ——– d—–w c:\program files\DivX
2009-04-08 22:35 . 2009-04-08 22:35 ——– d—–w c:\program files\Common Files\DivX Shared
2009-04-07 22:38 . 2009-01-07 10:35 ——– d—–w c:\program files\QuickTime
2009-04-05 14:38 . 2008-11-18 18:38 ——– d—–w c:\program files\MagicISO
2009-03-25 05:37 . 2009-03-25 05:37 ——– d—–w c:\program files\VirtuaWin
2009-03-25 05:29 . 2009-03-25 05:29 ——– d—–w c:\program files\Zhypermu
2009-03-06 14:22 . 2004-08-04 00:56 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-04 00:56 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-24 19:34 . 2009-02-24 19:34 90112 —-a-w c:\windows\system32\dpl100.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 —-a-w c:\windows\system32\divx_xx0c.dll
2009-02-24 19:34 . 2009-02-24 19:34 823296 —-a-w c:\windows\system32\divx_xx07.dll
2009-02-24 19:34 . 2009-02-24 19:34 815104 —-a-w c:\windows\system32\divx_xx0a.dll
2009-02-24 19:34 . 2009-02-24 19:34 802816 —-a-w c:\windows\system32\divx_xx11.dll
2009-02-24 19:34 . 2009-02-24 19:34 684032 —-a-w c:\windows\system32\DivX.dll
2009-02-20 18:09 . 2004-08-04 00:56 78336 —-a-w c:\windows\system32\ieencode.dll
2008-11-12 22:53 . 2008-11-12 22:53 270128 —-a-w c:\program files\uTorrent.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-12_00.09.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-21 06:18 . 2009-05-21 06:18 16384 c:\windows\Temp\Perflib_Perfdata_754.dat
+ 2009-05-14 00:42 . 2009-05-14 00:42 16384 c:\windows\Temp\Perflib_Perfdata_6fc.dat
+ 2009-05-21 06:18 . 2009-05-21 06:18 16384 c:\windows\Temp\Perflib_Perfdata_658.dat
+ 2009-05-16 04:37 . 2009-05-16 04:37 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-09 06:42 . 2009-05-11 06:23 65536 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-01-09 06:42 . 2009-05-16 04:37 65536 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-01-09 06:42 . 2009-05-11 06:23 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-01-09 06:42 . 2009-05-16 04:37 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-05-13 04:56 . 2009-05-13 04:56 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2009-04-22 17:00 . 2009-04-22 17:00 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2007-03-22 23:05 . 2007-03-22 23:05 97632 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PP7X32.DLL
+ 2006-10-27 02:07 . 2006-10-27 02:07 17680 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6021\PXBPROXY.DLL
+ 2009-05-13 14:20 . 2009-05-13 14:20 49152 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveWriter\9275f70617e63542bf5cb197c63a1858\WindowsLiveWriter.ni.exe
+ 2009-04-14 15:05 . 2009-05-15 10:13 5632 c:\windows\system32\pndx5032.dll
- 2009-04-14 15:05 . 2009-04-14 15:05 5632 c:\windows\system32\pndx5032.dll
- 2009-04-14 15:05 . 2009-04-14 15:05 6656 c:\windows\system32\pndx5016.dll
+ 2009-04-14 15:05 . 2009-05-15 10:13 6656 c:\windows\system32\pndx5016.dll
+ 2008-02-13 18:31 . 2009-05-13 04:57 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-02-06 23:03 . 2009-02-06 23:03 307576 c:\windows\WLXPGSS.SCR
+ 2008-11-08 02:05 . 2008-07-11 08:55 347648 c:\windows\system32\windowscodecsext.dll
+ 2008-11-08 02:05 . 2008-07-11 08:55 712704 c:\windows\system32\windowscodecs.dll
- 2008-11-08 02:05 . 2008-04-14 00:12 712704 c:\windows\system32\windowscodecs.dll
+ 2009-04-14 15:05 . 2009-05-15 10:13 185920 c:\windows\system32\rmoc3260.dll
- 2009-04-14 15:05 . 2009-04-14 15:05 185920 c:\windows\system32\rmoc3260.dll
- 2009-04-14 15:05 . 2009-04-14 15:05 278528 c:\windows\system32\pncrt.dll
+ 2009-04-14 15:05 . 2009-05-15 10:12 278528 c:\windows\system32\pncrt.dll
+ 2008-06-21 01:04 . 2009-05-21 06:18 224790 c:\windows\system32\inetsrv\MetaBase.bin
+ 2008-01-09 01:24 . 2009-05-15 11:46 288496 c:\windows\system32\FNTCACHE.DAT
- 2008-02-13 18:31 . 2009-04-30 04:08 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-02-13 18:31 . 2009-04-30 04:08 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-02-13 18:31 . 2009-05-13 04:57 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-05-12 08:35 . 2009-05-12 08:35 132096 c:\windows\Installer\{3C52E7DA-C431-4239-B66B-1BF703D5B194}\WLXPhotoGalleryIcon.exe
+ 2009-01-07 10:44 . 2009-05-15 11:37 102400 c:\windows\Installer\{318AB667-3230-41B5-A617-CB3BF748D371}\iTunesIco.exe
- 2009-01-07 10:44 . 2009-01-07 10:44 102400 c:\windows\Installer\{318AB667-3230-41B5-A617-CB3BF748D371}\iTunesIco.exe
+ 2009-05-13 14:20 . 2009-05-13 14:20 638976 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLiveLocal.Wr#\c49bab7d515a9742b89b8efc0544652b\WindowsLiveLocal.WriterPlugin.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 335872 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\e9ac44906f5ed84897cac0e36f9b379c\WindowsLive.Writer.Interop.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 176128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d7a0a40240921849b1d4530846b61b5f\WindowsLive.Writer.HtmlParser.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 643072 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\d1018b8b7e9ee243ad2b3042d3731d30\WindowsLive.Writer.HtmlEditor.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 876544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c5bd79acb5b1be48b43a19d58341821a\WindowsLive.Writer.Controls.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 475136 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c4a56db08deec047a6997e51c1c162fe\WindowsLive.Writer.Localization.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 139264 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\c2217656ac15ca4d8e06820a7f263aac\WindowsLive.Writer.FileDestinations.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 352256 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b772ab05d79ee140af00e027a283c851\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 135168 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\b3125949705210419cd9d98873a07f37\WindowsLive.Writer.Passport.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 143360 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\931fc5cb102716449c9ca93a13c7db22\WindowsLive.Writer.Extensibility.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\8d4029235c7ac8478f741c58e30aa302\WindowsLive.Writer.Instrumentation.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 204800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7b241ae45b9e814fa1391a48a2ee34e9\WindowsLive.Writer.BrowserControl.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 286720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\384bf20b5853974fb1962f232faff5d9\WindowsLive.Writer.Mshtml.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 929792 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\35369bde79a95e45bea9c911989fafce\WindowsLive.Writer.BlogClient.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 114688 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\21ea9a0358e9054fa50a2e5f72a31729\WindowsLive.Writer.Api.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 376832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1e9b76b3b02f5347a3bc3e784a3e47ba\WindowsLive.Writer.SpellChecker.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 335872 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\04ae27e408f20b43a932602ff399f910\WindowsLive.Writer.Interop.Mshtml.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\d9cb6897e828b049ac1218de678b7279\WindowsLive.Client.ni.dll
+ 2009-05-13 14:19 . 2009-05-13 14:19 651264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlServ#\8497e2d80d5d8c4d889fb99dc8725200\System.Data.SqlServerCe.ni.dll
+ 2009-05-13 14:19 . 2009-05-13 14:19 745472 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.SqlServer#\5a333c0dc7b0604ca37f1dc14c22b2fc\Microsoft.SqlServerCe.Client.ni.dll
+ 2009-05-12 08:28 . 2009-05-12 08:28 236392 c:\windows\assembly\GAC_MSIL\System.Data.SqlServerCe\9.0.242.0__89845dcd8080cc91\System.Data.SqlServerCe.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 6516736 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\f3ec69021b982048954c7242e4507f73\WindowsLive.Writer.PostEditor.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 2093056 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\1a59f64ba1feb842a2304029a84405cf\WindowsLive.Writer.CoreServices.ni.dll
+ 2009-05-13 14:20 . 2009-05-13 14:20 1163264 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\145169b252616f4bb1dfdf39ef3b11c1\WindowsLive.Writer.ApplicationFramework.ni.dll
- 2009-04-22 06:00 . 2007-07-01 03:31 2455488 c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\ieapfltr.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-04-20 272688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-09 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-09 1932568]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-15 198160]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-09 05:36 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"29468:TCP"= 29468:TCP:utorr

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/9/2009 1:36 AM 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/9/2009 1:36 AM 108552]
S0 cmdjuwzw;cmdjuwzw;c:\windows\system32\drivers\vobkvv.sys –> c:\windows\system32\drivers\vobkvv.sys [?]
S0 kjsmrxij;kjsmrxij;c:\windows\system32\drivers\bzovyy.sys –> c:\windows\system32\drivers\bzovyy.sys [?]
S1 e56a3f44;e56a3f44;c:\windows\system32\drivers\e56a3f44.sys [4/29/2009 3:39 PM 0]

— Other Services/Drivers In Memory —

*Deregistered* - ALG
*Deregistered* - AudioSrv
*Deregistered* - avg8wd
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - gupdate1c9bd12181be60
*Deregistered* - HTTPFilter
*Deregistered* - IISADMIN
*Deregistered* - ImapiService
*Deregistered* - iPod Service
*Deregistered* - JavaQuickStarterService
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LmHosts
*Deregistered* - MDM
*Deregistered* - MsDtsServer
*Deregistered* - msftesql
*Deregistered* - MSSQLSERVER
*Deregistered* - MSSQLServerOLAPService
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NtLmSsp
*Deregistered* - PolicyAgent
*Deregistered* - ProtectedStorage
*Deregistered* - RasMan
*Deregistered* - reijcawyx
*Deregistered* - RemoteRegistry
*Deregistered* - ReportServer
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - SMTPSVC
*Deregistered* - Spooler
*Deregistered* - SQLBrowser
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - W3SVC
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wltrysvc
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
nfrlbnxx
reijcawyx
.
Contents of the 'Scheduled Tasks' folder

2009-05-21 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 15:01]

2009-05-13 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2008-08-06 19:15]

2008-08-06 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2008-08-06 19:15]

2009-04-30 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2008-05-23 13:50]
.
- - - - ORPHANS REMOVED - - - -

BHO-{6ee6795f-a9ff-4887-9658-20f5666aef67} - c:\windows\system32\wubefivu.dll
HKLM-Run-zerahadoju - c:\windows\system32\pabuzili.dll
HKLM-Run-CPM474eeec1 - c:\windows\system32\lepopoka.dll
HKLM-Run-447ddd5d - c:\windows\system32\wanisupa.dll


.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\Asif Sheikh\Application Data\Mozilla\Firefox\Profiles\yfxkz44x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

—- FIREFOX POLICIES —-
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
FF - user.js: network.proxy.http_port - 0
FF - user.js: network.proxy.ssl -
FF - user.js: network.proxy.ssl_port - 0
FF - user.js: network.proxy.ftp -
FF - user.js: network.proxy.ftp_port - 0
FF - user.js: network.proxy.gopher -
FF - user.js: network.proxy.gopher_port - 0
FF - user.js: network.proxy.socks_version - 5
FF - user.js: network.proxy.socks -
FF - user.js: network.proxy.socks_port - 0
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-21 02:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\controlset002\Services\msftesql]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(4084)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
c:\program files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-05-21 2:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-21 06:30
ComboFix2.txt 2009-05-12 00:13

Pre-Run: 3,890,798,592 bytes free
Post-Run: 4,233,605,120 bytes free

Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
377 — E O F — 2009-05-21 06:23
Hi,

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

FileLook::
c:\windows\system32\click_setup.exe

File::
c:\windows\system32\drivers\vobkvv.sys
c:\windows\system32\drivers\bzovyy.sys
c:\windows\system32\drivers\e56a3f44.sys

Folder::
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb
c:\documents and settings\Asif Sheikh\Local Settings\Application Data\jviyimrb

Driver::
cmdjuwzw
kjsmrxij
e56a3f44
nfrlbnxx
reijcawyx

NetSvcs::
nfrlbnxx
reijcawyx

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.

Let me know how things are running after all this.
hi
Thank you for your reply
I cannot find the GooredFix.exe on my desktop but I did run the Combofix with the notepad.

This is the Hijackthis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:32:39 PM, on 5/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Asif Sheikh\Desktop\Emergency Virus\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1c9bd12181be60) (gupdate1c9bd12181be60) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 4532 bytes
The Computer is working ALOT better but I'm still getting the v1.Adwarefeed.com redirect

This is the Combo fix Log:

ComboFix 09-05-25.A2 - Asif Sheikh 05/26/2009 12:02.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.224 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Emergency Virus\ComboFix.exe
Command switches used :: c:\documents and settings\Asif Sheikh\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\windows\system32\drivers\bzovyy.sys"
"c:\windows\system32\drivers\e56a3f44.sys"
"c:\windows\system32\drivers\vobkvv.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Asif Sheikh\Application Data\jviyimrb
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\profiles.ini
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\cert8.db
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\compatibility.ini
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\compreg.dat
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\cookies.sqlite
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\formhistory.sqlite
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\key3.db
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\localstore.rdf
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\permissions.sqlite
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\places.sqlite-journal
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\places.sqlite
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\pluginreg.dat
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\prefs.js
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\secmod.db
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\webappsstore.sqlite
c:\documents and settings\Asif Sheikh\Application Data\jviyimrb\Profiles\2f9g2r11.default\xpti.dat
c:\documents and settings\Asif Sheikh\Local Settings\Application Data\jviyimrb
c:\documents and settings\Asif Sheikh\Local Settings\Application Data\jviyimrb\Profiles\2f9g2r11.default\urlclassifier3.sqlite
c:\documents and settings\Asif Sheikh\Local Settings\Application Data\jviyimrb\Profiles\2f9g2r11.default\XPC.mfl
c:\windows\system32\drivers\e56a3f44.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_nfrlbnxx
——-\Service_cmdjuwzw
——-\Service_e56a3f44
——-\Service_kjsmrxij


((((((((((((((((((((((((( Files Created from 2009-04-26 to 2009-05-26 )))))))))))))))))))))))))))))))
.

2009-05-14 06:11 . 2003-06-05 21:15 57436 —-a-w c:\windows\DASShp.dll
2009-05-14 06:11 . 2009-05-14 06:11 ——– d—–w c:\program files\Microsoft Reader
2009-05-12 08:29 . 2006-11-29 17:06 3426072 —-a-w c:\windows\system32\d3dx9_32.dll
2009-05-12 08:28 . 2009-05-12 08:28 ——– d—–w c:\program files\Microsoft SQL Server Compact Edition
2009-05-11 23:58 . 2008-10-16 18:06 208744 —-a-w c:\windows\system32\muweb.dll
2009-05-09 05:36 . 2009-05-09 05:36 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-05-09 05:36 . 2009-05-09 05:36 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-05-09 05:36 . 2009-05-09 05:36 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-05-09 05:36 . 2009-05-09 05:36 27656 —-a-w c:\windows\system32\drivers\avgmfx86.sys
2009-05-09 05:36 . 2009-05-24 13:46 ——– d—–w c:\windows\system32\drivers\Avg
2009-05-09 05:36 . 2009-05-17 05:33 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\AVGTOOLBAR
2009-05-09 02:43 . 2009-05-09 02:43 57344 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-460170d7-n\Decora-SSE.dll
2009-05-09 02:43 . 2009-05-09 02:43 24064 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-5a7efe26-n\Decora-D3D.dll
2009-05-09 02:43 . 2009-05-09 02:43 315392 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-2aee18b0-n\jogl.dll
2009-05-09 02:43 . 2009-05-09 02:43 20480 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-2aee18b0-n\jogl_awt.dll
2009-05-09 02:43 . 2009-05-09 02:43 114688 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-2aee18b0-n\jogl_cg.dll
2009-05-09 02:43 . 2009-05-09 02:43 499712 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-11ce17b9-n\msvcp71.dll
2009-05-09 02:43 . 2009-05-09 02:43 348160 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-11ce17b9-n\msvcr71.dll
2009-05-09 02:43 . 2009-05-09 02:43 20480 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-7459bd57-n\gluegen-rt.dll
2009-05-09 02:42 . 2009-05-09 02:43 499712 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-11ce17b9-n\jmc.dll
2009-05-09 02:42 . 2009-05-09 02:42 410984 —-a-w c:\windows\system32\deploytk.dll
2009-05-09 02:41 . 2009-05-09 02:41 152576 —-a-w c:\documents and settings\Asif Sheikh\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-09 01:07 . 2009-05-09 01:07 ——– d—–w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-05-05 22:59 . 2009-05-06 01:00 85504 —-a-w c:\windows\system32\click_setup.exe
2009-05-04 02:01 . 2009-05-26 15:49 ——– d—–w c:\documents and settings\Asif Sheikh\Tracing
2009-05-04 01:49 . 2009-05-04 01:49 ——– d—–w c:\program files\Microsoft Office Outlook Connector
2009-05-04 01:47 . 2009-05-04 01:47 ——– d—–w c:\program files\Microsoft
2009-05-04 01:47 . 2009-05-04 01:47 ——– d—–w c:\program files\Windows Live SkyDrive
2009-05-04 01:42 . 2009-05-04 01:42 ——– d—–w c:\program files\Common Files\Windows Live
2009-04-30 04:08 . 2009-04-30 04:08 ——– d—–w c:\program files\Microsoft ActiveSync
2009-04-30 04:08 . 2009-04-30 04:08 ——– d—–w c:\program files\Microsoft Works
2009-04-30 04:05 . 2009-04-30 04:05 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\Malwarebytes
2009-04-30 04:01 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-30 04:01 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-30 04:01 . 2009-04-30 04:04 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-30 04:01 . 2009-04-30 04:01 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-30 03:29 . 2009-04-30 03:29 ——– d—–w c:\program files\microsoft frontpage

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 16:05 . 2009-01-02 08:09 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\uTorrent
2009-05-17 05:26 . 2008-08-01 07:23 ——– d—–w c:\documents and settings\All Users\Application Data\avg8
2009-05-14 06:11 . 2008-01-09 06:51 ——– d–h–w c:\program files\InstallShield Installation Information
2009-05-12 08:36 . 2008-03-08 00:33 ——– d—–w c:\program files\Windows Live
2009-05-09 05:23 . 2008-01-09 07:06 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-09 02:41 . 2008-02-15 16:07 ——– d—–w c:\program files\Java
2009-05-04 02:00 . 2009-01-01 11:28 76072 —-a-w c:\documents and settings\Asif Sheikh\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-02 07:40 . 2009-04-07 22:37 ——– d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-30 06:25 . 2008-12-27 05:28 ——– d—–w c:\documents and settings\Family\Application Data\Desktopicon
2009-04-30 03:34 . 2001-08-23 14:00 ——– d—–w c:\program files\Common Files\Mozilla Shared
2009-04-30 02:15 . 2008-01-10 04:33 ——– d—–w c:\program files\Windows Media Connect 2
2009-04-30 01:51 . 2009-01-05 09:54 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\Uniblue
2009-04-20 04:27 . 2009-04-20 04:27 ——– d—–w c:\program files\uTorrent
2009-04-14 15:02 . 2008-01-14 03:56 ——– d—–w c:\program files\Google
2009-04-13 03:49 . 2009-04-13 03:48 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\Media Player Classic
2009-04-11 15:03 . 2009-01-05 10:58 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\DivX
2009-04-08 22:37 . 2008-01-09 10:15 ——– d—–w c:\program files\DivX
2009-04-08 22:35 . 2009-04-08 22:35 ——– d—–w c:\program files\Common Files\DivX Shared
2009-04-08 21:35 . 2009-01-07 10:14 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\Apple Computer
2009-04-07 22:38 . 2009-01-07 10:35 ——– d—–w c:\program files\QuickTime
2009-04-07 22:36 . 2009-04-07 22:36 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\vlc
2009-04-07 14:01 . 2009-04-07 13:33 ——– d—–w c:\documents and settings\Asif Sheikh\Application Data\Hide IP NG
2009-04-05 14:38 . 2008-11-18 18:38 ——– d—–w c:\program files\MagicISO
2009-04-04 21:12 . 2008-05-18 04:32 ——– d—–w c:\documents and settings\Family\Application Data\uTorrent
2009-03-28 12:44 . 2009-03-28 12:44 ——– d—–w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-03-06 14:22 . 2004-08-04 00:56 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-04 00:56 826368 —-a-w c:\windows\system32\wininet.dll
2008-11-12 22:53 . 2008-11-12 22:53 270128 —-a-w c:\program files\uTorrent.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

— c:\windows\system32\click_setup.exe —
Company: !VERINFO: NOT PE FILE!
File Description: !VERINFO: NOT PE FILE!
File Version: !VERINFO: NOT PE FILE!
Product Name: !VERINFO: NOT PE FILE!
Copyright: !VERINFO: NOT PE FILE!
Original Filename: !VERINFO: NOT PE FILE!
File size: 85504
Created time: 2009-05-05 22:59
Modified time: 2009-05-06 01:00
MD5: 8F4EA8AD17AF997F23C92937939FE32D
SHA1: E9C3D338CD33E51F9A7E3A2DA4D8CD5CC1011626


((((((((((((((((((((((((((((( SnapShot_2009-05-21_06.20.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-26 16:07 . 2009-05-26 16:07 16384 c:\windows\Temp\Perflib_Perfdata_748.dat
+ 2009-05-26 16:07 . 2009-05-26 16:07 16384 c:\windows\Temp\Perflib_Perfdata_628.dat
+ 2008-06-21 01:04 . 2009-05-26 16:09 224795 c:\windows\system32\inetsrv\MetaBase.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-04-20 272688]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-09 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-09 1932568]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-05-15 198160]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-09 05:36 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"29468:TCP"= 29468:TCP:utorr

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/9/2009 1:36 AM 325640]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/9/2009 1:36 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/9/2009 1:36 AM 298264]
R2 MsDtsServer;SQL Server Integration Services;c:\program files\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe [3/3/2007 11:12 PM 202096]
R2 ReportServer;SQL Server Reporting Services (MSSQLSERVER);c:\program files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe [3/3/2007 11:09 PM 17264]
S2 gupdate1c9bd12181be60;Google Update Service (gupdate1c9bd12181be60);c:\program files\Google\Update\GoogleUpdate.exe [4/14/2009 11:02 AM 133104]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 7:01 AM 2799808]
.
Contents of the 'Scheduled Tasks' folder

2009-05-26 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 15:01]

2009-05-23 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2008-08-06 19:15]

2008-08-06 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe [2008-08-06 19:15]

2009-04-30 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2008-05-23 13:50]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
FF - ProfilePath - c:\documents and settings\Asif Sheikh\Application Data\Mozilla\Firefox\Profiles\yfxkz44x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

—- FIREFOX POLICIES —-
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
FF - user.js: network.proxy.http_port - 0
FF - user.js: network.proxy.ssl -
FF - user.js: network.proxy.ssl_port - 0
FF - user.js: network.proxy.ftp -
FF - user.js: network.proxy.ftp_port - 0
FF - user.js: network.proxy.gopher -
FF - user.js: network.proxy.gopher_port - 0
FF - user.js: network.proxy.socks_version - 5
FF - user.js: network.proxy.socks -
FF - user.js: network.proxy.socks_port - 0
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-26 19:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\controlset002\Services\msftesql]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2828)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2009-05-26 19:29 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-26 23:28
ComboFix2.txt 2009-05-21 06:30
ComboFix3.txt 2009-05-12 00:13

Pre-Run: 5,159,927,808 bytes free
Post-Run: 5,294,534,656 bytes free

Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
263 — E O F — 2009-05-22 07:06
Sorry about that, not sure what I was thinking there.

Please download GooredFix and save it to your Desktop.
  • Double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.
Hi
I just Ran GooredFix Here is the Log:

GooredFix v1.92 by jpshortstuff
Log created at 10:39 on 27/05/2009 running Option #2 (Asif Sheikh)
Firefox version 3.0.10 (en-US)

=====Goored Deletions=====
C:\Program Files\Mozilla Firefox\extensions\{CD64A061-280A-42B8-9190-80203310AFE0}
->Backing up folder… Done.
->Emptying folder… Done.
->Deleting folder… Done.
C:\Program Files\Mozilla Firefox\extensions\{11D66083-EBBE-43F9-8905-E9C09FDC993E}
->Backing up folder… Done.
->Emptying folder… Done.
->Deleting folder… Done.

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"="C:\Program Files\Real\RealPlayer\browserrecord"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{1d5287d1-8a92-0001-1f31-1cec198018d8}"="C:\Program Files\AVG\AVG8\ToolbarFF"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox"
Has that fixed the redirect problem?

You can delete this file, unless you put it there:
c:\windows\system32\click_setup.exe


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please run MalwareBytes' Anti-Malware, update it and then run a full system scan. If it finds anything please post the log it gives, after fixing what it finds.

Let me know how things are running now.
Hi,
No I did not put it there, I have deleted the click_setup.exe
My computer is working very well, no redirects at all, the virus seems to have subsided.
Though I think my system restore is holding some parts of the virus, So I have turned it off for a little while. I while reactive it after I restart.
Thank you for all your help, Tell me what steps I should take next?


Anyways these are the log from Malwarebytes' Anti-Malware :

Malwarebytes' Anti-Malware 1.37
Database version: 2186
Windows 5.1.2600 Service Pack 3

5/28/2009 3:16:27 AM
mbam-log-2009-05-28 (03-16-27).txt

Scan type: Full Scan (C:\|G:\|)
Objects scanned: 183371
Time elapsed: 2 hour(s), 44 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Qoobox\quarantine\C\documents and settings\asif sheikh\protect.dll.vir (Worm.Autorun) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\documents and settings\asif sheikh\start menu\Programs\Startup\ChkDisk.dll.vir (Worm.Autorun) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\documents and settings\localservice\protect.dll.vir (Worm.Autorun) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\autochk.dll.vir (Worm.Autorun) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\mebetewu.dll.tmp.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\mepavuhi.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\mizezapo.dll.tmp.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\ovfsthaawqkhoqblvnoybjevjbkjxxemhwcxwi.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\ovfsthdatsminhvtumrfpfueampqvrpxkbsxhd.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\rurisugo.dll.tmp.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\soyopuvo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\config\systemprofile\protect.dll.vir (Worm.Autorun) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\WINDOWS\system32\drivers\ovfsthpownvpixnsdpnolrxwnomqfvamhctrtn.sys.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
Hi,

Log looks good :thumbup:

There's was no need to disable System Restore as this next step would have cleaned the old points for you. Just make sure it is switched on after we're done.


Click Start >> Run, and then type ComboFix /u and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Now that your system appears to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Hey Thanks for all your help Everything seems to be working just fine I'm going to download the Spybot and WinPotrol Hope I stay clean, Thanks
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
Hi
Thank you for reopening this topic
I don't believe this is a new virus .. I would have known if something weird happened.
Firefox has been redirecting me to the an error page for some reason, i think it happens at random.
when i click the page again it works fine.

the redirect is to some "Net error page"
with the address starting with http://avg.urlseek.vmn.net … etc.

(I can post a shot if it is needed)

Also related to firefox, when i try to play some flash movies i get a Microsoft visual Runtime Library error (3times) and then sometimes firefox shuts down or restarts.

I have noticed that realplayer download works sometimes and others times it has stopped

HiJackThis Log :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:00 PM, on 6/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\Reporting Services\ReportServer\bin\ReportingServicesService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
C:\Program Files\Real\RealPlayer\RecordingManager.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\Asif Sheikh\Desktop\Emergency Virus\HiJackThis.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1243606689921
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate1c9bd12181be60) (gupdate1c9bd12181be60) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 6228 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI