schlackeye
Topic Starter
Dearest TechMaster,
A nasty virus has taken over my computer and nothing I do seems to get rid of it. The virus takes over from startup and puts multiple pop-ups on the screen such as "your computer is infected and needs . . . . " and names various "anti-virus programs such as ANTIVIRUS PRO 2010 as the solution. I did not install any of this on the computer. I think I closed a pop-up while surfing and that started this mess. It has also gotten into the windows security center and has made it impossible to run some programs or to get online. Windows DEP(?) wouldn't let me get online in normal mode, I had to use safe mode with networking to get online and that's acting pretty hinky- It- the supposed antivirus program opened a tab by itself while I'm here at What the Tech. The virus has also changed my desktop theme and disabled system restore. The computer when started normally also has multiple (dozens) of what looks like an MS DOS prompts that open and close too quickly to see what is going on. It seems to have gotten into quite a few things.
I tried to fix it by running scans (in safe mode) with Windows Defender, Avira AntiVir, and Spybot Search and Destroy. I would run a scan (all 3), it would find a bunch of stuff, say its fixed, tell me to reboot, and then back to square one (virus damaged computer). Repeat until you start to pull hair out. I then went to some of the locations the antivirus programs (the real ones) had mentioned in their reports and manually deleted any file with the time and date of first infection. I also did this in the windows prefetch folder. I used ATF cleaner by atribune and cleaned everything besides the Java cache, prefetch, and the recycle bin. The files that I manually removed I placed in the recycle bin but I did not empty the recycle bin just in case as many of the files were .dll or .exe . . . . .
I also msconfigged startup and disabled anything that was not there the last time I looked. The things I did helped enough to get rid of the pop-ups after startup but that's about it.
Please help! Here are all of the logs you have requested. I ran them in safe mode though. I'm afraid to turn on the computer normally because of how easily the virus seems to replicate. I hope this is OK. I thank you for your time and expertise in advance because this is not the first time you've saved my butt ! ! ! !
Thankfully ! ! ! !
Hopefully ! ! ! ! !
Shubert Schlackeye
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/27 16:17
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF6DB9000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79B9000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF635F000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
——————-
Path: C:\WINDOWS\system32\gasfkygodovtvk.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\gasfkyoeshlhhb.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\gasfkypmukxmyr.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\gasfkyqlruccbg.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\gasfkyvcqguyab.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\gasfkykfenejrrxi.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\gasfkypckehxnmqv.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\drivers\gasfkyviqjyhja.sys
Status: Invisible to the Windows API!
Path: c:\documents and settings\hunter sims\local settings\temp\~dfa051.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Hidden Services
——————-
Service Name: gasfkybxmmodev
Image Path: C:\WINDOWS\system32\drivers\gasfkyviqjyhja.sys
==EOF==
DDS (Ver_09-09-24.01) - NTFSx86 NETWORK
Run by [removed] at 16:12:20.76 on Sun 09/27/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.670 [GMT -4:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Documents and Settings\Hunter Sims\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://insightbb.com/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\drivers\smss.exe
BHO: c:\windows\system32\y2kf4kxb.dll: {a249bc15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\y2kf4kxb.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [mserv] c:\documents and settings\hunter sims\application data\svcst.exe
uRun: [Yjafosi8kdf98winmdkmnkmfnwe] c:\docume~1\hunter~1\locals~1\temp\csrss.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SPAMfighter Agent] "c:\program files\spamfighter\SFAgent.exe" update delay 60
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253491739836
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: __c00F69A - c:\windows\system32\__c00F69A.dat
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL,lekojeta.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\y2kf4kxb.dll: {a249bc15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\y2kf4kxb.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Notification Packages = scecli lekojeta.dll pezetifu.dll
============= SERVICES / DRIVERS ===============
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-20 11608]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-20 108289]
S2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-9-20 185089]
S2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-20 55656]
S2 ColdFusion MX ODBC Agent;ColdFusion MX ODBC Agent;c:\program files\macromedia\db\slserver52\bin\swagent.exe "coldfusion mx odbc agent" –> c:\program files\macromedia\db\slserver52\bin\swagent.exe ColdFusion MX ODBC Agent [?]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\spamfighter\sfus.exe [2009-8-27 189064]
S2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-19 1174152]
=============== Created Last 30 ================
2009-09-27 12:13 –dsh— c:\documents and settings\hunter sims\IECompatCache
2009-09-27 11:24 48,640 a——- c:\windows\system32\drivers\smss.exe_
2009-09-27 09:16 2,713 —sh— c:\windows\system32\neniweja.exe
2009-09-27 05:18 17,167 a——- c:\docume~1\hunter~1\applic~1\iweqycacur.pif
2009-09-27 05:18 13,804 a——- c:\windows\iduge.pif
2009-09-27 05:18 11,507 a——- c:\windows\system32\ezelokaxu._dl
2009-09-27 05:18 11,406 a——- c:\docume~1\hunter~1\applic~1\bufegun.sys
2009-09-27 05:18 11,363 a——- c:\docume~1\alluse~1\applic~1\oruhafyson.com
2009-09-27 05:18 10,673 a——- c:\windows\system32\yvepitacyz.inf
2009-09-27 05:09 13,818 a——- c:\docume~1\hunter~1\applic~1\jewigaj.dll
2009-09-27 05:09 13,334 a——- c:\docume~1\alluse~1\applic~1\genohu.exe
2009-09-27 05:09 12,488 a——- c:\docume~1\alluse~1\applic~1\yfyf.reg
2009-09-27 05:09 12,102 a——- c:\windows\system32\rolyd.bat
2009-09-27 05:05 18,645 a——- c:\windows\system32\imapyjut.dll
2009-09-27 05:05 18,041 a——- c:\docume~1\alluse~1\applic~1\esura.bin
2009-09-27 05:05 12,594 a——- c:\docume~1\hunter~1\applic~1\inanecory.scr
2009-09-27 05:05 19,162 a——- c:\windows\system32\usecupy.com
2009-09-27 05:05 18,251 a——- c:\windows\system32\yhew.exe
2009-09-27 05:05 16,416 a——- c:\windows\system32\kohuwydoji.ban
2009-09-27 05:05 13,156 a——- c:\windows\system32\codep.dll
2009-09-27 05:05 12,090 a——- c:\docume~1\alluse~1\applic~1\xymediwe.bat
2009-09-27 05:05 0 a——- c:\windows\system32\AVR09.exe
2009-09-27 03:50 664 a——- c:\windows\system32\d3d9caps.dat
2009-09-27 03:25 110 a——- C:\xcrashdump.dat
2009-09-27 03:25 19,166 a——- c:\windows\system32\mizedoco.dl
2009-09-27 03:25 19,021 a——- c:\docume~1\hunter~1\applic~1\kiwo.pif
2009-09-27 03:25 18,510 a——- c:\docume~1\hunter~1\applic~1\biny.scr
2009-09-27 03:25 18,319 a——- c:\windows\system32\cenoxi.scr
2009-09-27 03:25 14,226 a——- c:\docume~1\hunter~1\applic~1\timebadesa.bin
2009-09-27 03:25 11,572 a——- c:\windows\system32\hyfihuvu.vbs
2009-09-27 03:25 11,304 a——- c:\docume~1\hunter~1\applic~1\zywypuvate.dat
2009-09-27 03:25 11,080 a——- c:\windows\system32\obibyzepo.reg
2009-09-27 03:25 10,318 a——- c:\windows\system32\mabixaq.exe
2009-09-27 03:10 0 a——- c:\windows\system32\41.exe
2009-09-27 03:10 167,424 a——- c:\windows\system32\_scui.cpl
2009-09-27 03:10 230,000 a——- c:\docume~1\hunter~1\applic~1\lizkavd.exe
2009-09-27 03:07 48,640 a——- c:\windows\system32\drivers\smss.exe
2009-09-27 03:07 264,192 a——- c:\docume~1\hunter~1\applic~1\seres.exe
2009-09-24 16:05 –d—– c:\program files\Agent
2009-09-22 06:53 –d—– C:\Folder
2009-09-21 14:35 –d—– C:\Incomplete
2009-09-21 14:34 –d—– C:\Limewire
2009-09-21 12:42 –d—– c:\program files\SDHelper (Spybot - Search & Destroy)
2009-09-21 12:42 –d—– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-09-21 12:42 –d—– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-09-21 07:06 –d—– c:\documents and settings\hunter sims\.housecall6.6
2009-09-21 02:44 36 a——- c:\windows\system32\sysnet.dat
2009-09-20 22:56 –d—– C:\SHUBERT
2009-09-20 22:18 –d—– c:\program files\common files\Application
2009-09-20 22:18 –d—– c:\program files\SPAMfighter
2009-09-20 22:17 –d—– c:\docume~1\hunter~1\applic~1\SPAMfighter
2009-09-20 22:12 55,656 a——- c:\windows\system32\drivers\avgntflt.sys
2009-09-20 22:12 –d—– c:\program files\Avira
2009-09-20 22:12 –d—– c:\docume~1\alluse~1\applic~1\Avira
2009-09-20 21:56 –d—– c:\program files\VistaCodecPack
2009-09-20 21:55 –d—– c:\docume~1\alluse~1\applic~1\VistaCodecs
2009-09-20 21:44 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-20 21:44 73,728 a——- c:\windows\system32\javacpl.cpl
2009-09-20 21:33 –dsh— c:\documents and settings\hunter sims\PrivacIE
2009-09-20 21:31 –dsh— c:\documents and settings\hunter sims\IETldCache
2009-09-20 21:27 100,352 ——– c:\windows\system32\dllcache\iecompat.dll
2009-09-20 21:27 –d—– c:\windows\ie8updates
2009-09-20 21:27 11,067,392 ——– c:\windows\system32\dllcache\ieframe.dll
2009-09-20 21:27 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll
2009-09-20 21:27 594,432 ——– c:\windows\system32\dllcache\msfeeds.dll
2009-09-20 21:27 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2009-09-20 21:27 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-20 21:27 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2009-09-20 21:26 -cd-h— c:\windows\ie8
2009-09-20 20:57 272,128 ——– c:\windows\system32\dllcache\bthport.sys
2009-09-20 20:55 203,136 ——– c:\windows\system32\dllcache\rmcast.sys
2009-09-20 20:55 691,712 ——– c:\windows\system32\dllcache\inetcomm.dll
2009-09-20 20:55 331,776 ——– c:\windows\system32\dllcache\msadce.dll
2009-09-20 20:55 333,952 ——– c:\windows\system32\dllcache\srv.sys
2009-09-20 20:55 455,296 ——– c:\windows\system32\dllcache\mrxsmb.sys
2009-09-20 20:55 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-09-20 20:54 337,408 ——– c:\windows\system32\dllcache\netapi32.dll
2009-09-20 20:54 1,106,944 ——– c:\windows\system32\dllcache\msxml3.dll
2009-09-20 20:54 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-09-20 20:54 1,203,922 ——– c:\windows\system32\dllcache\sysmain.sdb
2009-09-20 20:54 215,552 ——– c:\windows\system32\dllcache\wordpad.exe
2009-09-20 20:45 –d—– c:\windows\system32\scripting
2009-09-20 20:45 –d—– c:\windows\system32\en
2009-09-20 20:45 –d—– c:\windows\l2schemas
2009-09-20 20:45 –d—– c:\windows\system32\bits
2009-09-20 20:43 –d—– c:\windows\ServicePackFiles
2009-09-20 20:41 –d—– c:\windows\network diagnostic
2009-09-20 20:19 104,960 ——– c:\windows\system32\drivers\atinrvxx.sys
2009-09-20 20:09 31,768 a——- c:\windows\system32\wucltui.dll.mui
2009-09-20 20:09 23,576 a——- c:\windows\system32\wuaucpl.cpl.mui
2009-09-20 20:09 18,456 a——- c:\windows\system32\wuaueng.dll.mui
2009-09-20 20:09 23,576 a——- c:\windows\system32\wuapi.dll.mui
==================== Find3M ====================
2009-09-27 14:49 21 a——- C:\qpmd8376.bin
2009-09-20 20:48 88,263 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-05 05:01 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 15:11 160,564 a——- c:\windows\Sqirlz Water Reflections Uninstaller.exe
2009-08-03 18:24 16,530 a——- c:\docume~1\hunter~1\applic~1\wklnhst.dat
2009-08-03 17:29 2,516 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-07-29 00:37 119,808 a——- c:\windows\system32\t2embed.dll
2009-07-29 00:37 81,920 a——- c:\windows\system32\fontsub.dll
2009-07-29 00:37 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-07-29 00:37 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-07-19 09:18 5,937,152 ——– c:\windows\system32\dllcache\mshtml.dll
2009-07-18 12:05 1,509,888 ——– c:\windows\system32\dllcache\shdocvw.dll
2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll
2009-07-03 13:09 915,456 ——– c:\windows\system32\dllcache\wininet.dll
2009-07-03 13:09 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll
2009-07-03 13:09 206,848 ——– c:\windows\system32\dllcache\occache.dll
2009-07-03 13:09 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 13:09 184,320 ——– c:\windows\system32\dllcache\iepeers.dll
2009-07-03 13:09 386,048 ——– c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 07:01 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-27 03:07 0 a–sh— c:\windows\system32\wepetobe.dll
============= FINISH: 16:13:45.04 ===============
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:57:01 PM, on 9/27/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drivers\smss.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Hunter Sims\My Documents\Software\HIJACKTHIS\HIJACKTHIS V2.0.2.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://insightbb.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\smss.exe
O2 - BHO: C:\WINDOWS\system32\y2kf4kxb.dll - {A249BC15-23F2-42AD-F4E4-00AAC39C0004} - C:\WINDOWS\system32\y2kf4kxb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [mserv] C:\Documents and Settings\Hunter Sims\Application Data\svcst.exe
O4 - HKCU\..\Run: [Yjafosi8kdf98winmdkmnkmfnwe] C:\DOCUME~1\HUNTER~1\LOCALS~1\Temp\csrss.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1253491739836
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,lekojeta.dll
O20 - Winlogon Notify: __c00F69A - C:\WINDOWS\system32\__c00F69A.dat (file missing)
O22 - SharedTaskScheduler: iukjsf8w3jirojs9f8u3jruhsf78s3jijdif - {A249BC15-23F2-42AD-F4E4-00AAC39C0004} - C:\WINDOWS\system32\y2kf4kxb.dll (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ColdFusion MX Application Server - Macromedia Inc. - C:\Program Files\Macromedia\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - C:\Program Files\Macromedia\db\slserver52\bin\swagent.exe
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - C:\Program Files\Macromedia\db\slserver52\bin\swstrtr.exe
O23 - Service: Flash Communication Server (FlashCom) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe
O23 - Service: Flash Communication Admin Service (FlashComAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
–
End of file - 7095 bytes
A nasty virus has taken over my computer and nothing I do seems to get rid of it. The virus takes over from startup and puts multiple pop-ups on the screen such as "your computer is infected and needs . . . . " and names various "anti-virus programs such as ANTIVIRUS PRO 2010 as the solution. I did not install any of this on the computer. I think I closed a pop-up while surfing and that started this mess. It has also gotten into the windows security center and has made it impossible to run some programs or to get online. Windows DEP(?) wouldn't let me get online in normal mode, I had to use safe mode with networking to get online and that's acting pretty hinky- It- the supposed antivirus program opened a tab by itself while I'm here at What the Tech. The virus has also changed my desktop theme and disabled system restore. The computer when started normally also has multiple (dozens) of what looks like an MS DOS prompts that open and close too quickly to see what is going on. It seems to have gotten into quite a few things.
I tried to fix it by running scans (in safe mode) with Windows Defender, Avira AntiVir, and Spybot Search and Destroy. I would run a scan (all 3), it would find a bunch of stuff, say its fixed, tell me to reboot, and then back to square one (virus damaged computer). Repeat until you start to pull hair out. I then went to some of the locations the antivirus programs (the real ones) had mentioned in their reports and manually deleted any file with the time and date of first infection. I also did this in the windows prefetch folder. I used ATF cleaner by atribune and cleaned everything besides the Java cache, prefetch, and the recycle bin. The files that I manually removed I placed in the recycle bin but I did not empty the recycle bin just in case as many of the files were .dll or .exe . . . . .
I also msconfigged startup and disabled anything that was not there the last time I looked. The things I did helped enough to get rid of the pop-ups after startup but that's about it.
Please help! Here are all of the logs you have requested. I ran them in safe mode though. I'm afraid to turn on the computer normally because of how easily the virus seems to replicate. I hope this is OK. I thank you for your time and expertise in advance because this is not the first time you've saved my butt ! ! ! !
Thankfully ! ! ! !
Hopefully ! ! ! ! !
Shubert Schlackeye
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/27 16:17
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF6DB9000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79B9000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF635F000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
——————-
Path: C:\WINDOWS\system32\gasfkygodovtvk.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\gasfkyoeshlhhb.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\gasfkypmukxmyr.dat
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\gasfkyqlruccbg.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\gasfkyvcqguyab.dll
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\gasfkykfenejrrxi.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\Temp\gasfkypckehxnmqv.tmp
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\drivers\gasfkyviqjyhja.sys
Status: Invisible to the Windows API!
Path: c:\documents and settings\hunter sims\local settings\temp\~dfa051.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Hidden Services
——————-
Service Name: gasfkybxmmodev
Image Path: C:\WINDOWS\system32\drivers\gasfkyviqjyhja.sys
==EOF==
DDS (Ver_09-09-24.01) - NTFSx86 NETWORK
Run by [removed] at 16:12:20.76 on Sun 09/27/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.670 [GMT -4:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Documents and Settings\Hunter Sims\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://insightbb.com/
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\drivers\smss.exe
BHO: c:\windows\system32\y2kf4kxb.dll: {a249bc15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\y2kf4kxb.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [mserv] c:\documents and settings\hunter sims\application data\svcst.exe
uRun: [Yjafosi8kdf98winmdkmnkmfnwe] c:\docume~1\hunter~1\locals~1\temp\csrss.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SPAMfighter Agent] "c:\program files\spamfighter\SFAgent.exe" update delay 60
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
mPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\program files\partygaming\partypoker\RunApp.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1253491739836
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: __c00F69A - c:\windows\system32\__c00F69A.dat
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL,lekojeta.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\y2kf4kxb.dll: {a249bc15-23f2-42ad-f4e4-00aac39c0004} - c:\windows\system32\y2kf4kxb.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Notification Packages = scecli lekojeta.dll pezetifu.dll
============= SERVICES / DRIVERS ===============
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-20 11608]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-20 108289]
S2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-9-20 185089]
S2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-20 55656]
S2 ColdFusion MX ODBC Agent;ColdFusion MX ODBC Agent;c:\program files\macromedia\db\slserver52\bin\swagent.exe "coldfusion mx odbc agent" –> c:\program files\macromedia\db\slserver52\bin\swagent.exe ColdFusion MX ODBC Agent [?]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 SPAMfighter Update Service;SPAMfighter Update Service;c:\program files\spamfighter\sfus.exe [2009-8-27 189064]
S2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-19 1174152]
=============== Created Last 30 ================
2009-09-27 12:13 –dsh— c:\documents and settings\hunter sims\IECompatCache
2009-09-27 11:24 48,640 a——- c:\windows\system32\drivers\smss.exe_
2009-09-27 09:16 2,713 —sh— c:\windows\system32\neniweja.exe
2009-09-27 05:18 17,167 a——- c:\docume~1\hunter~1\applic~1\iweqycacur.pif
2009-09-27 05:18 13,804 a——- c:\windows\iduge.pif
2009-09-27 05:18 11,507 a——- c:\windows\system32\ezelokaxu._dl
2009-09-27 05:18 11,406 a——- c:\docume~1\hunter~1\applic~1\bufegun.sys
2009-09-27 05:18 11,363 a——- c:\docume~1\alluse~1\applic~1\oruhafyson.com
2009-09-27 05:18 10,673 a——- c:\windows\system32\yvepitacyz.inf
2009-09-27 05:09 13,818 a——- c:\docume~1\hunter~1\applic~1\jewigaj.dll
2009-09-27 05:09 13,334 a——- c:\docume~1\alluse~1\applic~1\genohu.exe
2009-09-27 05:09 12,488 a——- c:\docume~1\alluse~1\applic~1\yfyf.reg
2009-09-27 05:09 12,102 a——- c:\windows\system32\rolyd.bat
2009-09-27 05:05 18,645 a——- c:\windows\system32\imapyjut.dll
2009-09-27 05:05 18,041 a——- c:\docume~1\alluse~1\applic~1\esura.bin
2009-09-27 05:05 12,594 a——- c:\docume~1\hunter~1\applic~1\inanecory.scr
2009-09-27 05:05 19,162 a——- c:\windows\system32\usecupy.com
2009-09-27 05:05 18,251 a——- c:\windows\system32\yhew.exe
2009-09-27 05:05 16,416 a——- c:\windows\system32\kohuwydoji.ban
2009-09-27 05:05 13,156 a——- c:\windows\system32\codep.dll
2009-09-27 05:05 12,090 a——- c:\docume~1\alluse~1\applic~1\xymediwe.bat
2009-09-27 05:05 0 a——- c:\windows\system32\AVR09.exe
2009-09-27 03:50 664 a——- c:\windows\system32\d3d9caps.dat
2009-09-27 03:25 110 a——- C:\xcrashdump.dat
2009-09-27 03:25 19,166 a——- c:\windows\system32\mizedoco.dl
2009-09-27 03:25 19,021 a——- c:\docume~1\hunter~1\applic~1\kiwo.pif
2009-09-27 03:25 18,510 a——- c:\docume~1\hunter~1\applic~1\biny.scr
2009-09-27 03:25 18,319 a——- c:\windows\system32\cenoxi.scr
2009-09-27 03:25 14,226 a——- c:\docume~1\hunter~1\applic~1\timebadesa.bin
2009-09-27 03:25 11,572 a——- c:\windows\system32\hyfihuvu.vbs
2009-09-27 03:25 11,304 a——- c:\docume~1\hunter~1\applic~1\zywypuvate.dat
2009-09-27 03:25 11,080 a——- c:\windows\system32\obibyzepo.reg
2009-09-27 03:25 10,318 a——- c:\windows\system32\mabixaq.exe
2009-09-27 03:10 0 a——- c:\windows\system32\41.exe
2009-09-27 03:10 167,424 a——- c:\windows\system32\_scui.cpl
2009-09-27 03:10 230,000 a——- c:\docume~1\hunter~1\applic~1\lizkavd.exe
2009-09-27 03:07 48,640 a——- c:\windows\system32\drivers\smss.exe
2009-09-27 03:07 264,192 a——- c:\docume~1\hunter~1\applic~1\seres.exe
2009-09-24 16:05 –d—– c:\program files\Agent
2009-09-22 06:53 –d—– C:\Folder
2009-09-21 14:35 –d—– C:\Incomplete
2009-09-21 14:34 –d—– C:\Limewire
2009-09-21 12:42 –d—– c:\program files\SDHelper (Spybot - Search & Destroy)
2009-09-21 12:42 –d—– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-09-21 12:42 –d—– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-09-21 07:06 –d—– c:\documents and settings\hunter sims\.housecall6.6
2009-09-21 02:44 36 a——- c:\windows\system32\sysnet.dat
2009-09-20 22:56 –d—– C:\SHUBERT
2009-09-20 22:18 –d—– c:\program files\common files\Application
2009-09-20 22:18 –d—– c:\program files\SPAMfighter
2009-09-20 22:17 –d—– c:\docume~1\hunter~1\applic~1\SPAMfighter
2009-09-20 22:12 55,656 a——- c:\windows\system32\drivers\avgntflt.sys
2009-09-20 22:12 –d—– c:\program files\Avira
2009-09-20 22:12 –d—– c:\docume~1\alluse~1\applic~1\Avira
2009-09-20 21:56 –d—– c:\program files\VistaCodecPack
2009-09-20 21:55 –d—– c:\docume~1\alluse~1\applic~1\VistaCodecs
2009-09-20 21:44 411,368 a——- c:\windows\system32\deploytk.dll
2009-09-20 21:44 73,728 a——- c:\windows\system32\javacpl.cpl
2009-09-20 21:33 –dsh— c:\documents and settings\hunter sims\PrivacIE
2009-09-20 21:31 –dsh— c:\documents and settings\hunter sims\IETldCache
2009-09-20 21:27 100,352 ——– c:\windows\system32\dllcache\iecompat.dll
2009-09-20 21:27 –d—– c:\windows\ie8updates
2009-09-20 21:27 11,067,392 ——– c:\windows\system32\dllcache\ieframe.dll
2009-09-20 21:27 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll
2009-09-20 21:27 594,432 ——– c:\windows\system32\dllcache\msfeeds.dll
2009-09-20 21:27 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2009-09-20 21:27 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-20 21:27 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2009-09-20 21:26 -cd-h— c:\windows\ie8
2009-09-20 20:57 272,128 ——– c:\windows\system32\dllcache\bthport.sys
2009-09-20 20:55 203,136 ——– c:\windows\system32\dllcache\rmcast.sys
2009-09-20 20:55 691,712 ——– c:\windows\system32\dllcache\inetcomm.dll
2009-09-20 20:55 331,776 ——– c:\windows\system32\dllcache\msadce.dll
2009-09-20 20:55 333,952 ——– c:\windows\system32\dllcache\srv.sys
2009-09-20 20:55 455,296 ——– c:\windows\system32\dllcache\mrxsmb.sys
2009-09-20 20:55 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2009-09-20 20:54 337,408 ——– c:\windows\system32\dllcache\netapi32.dll
2009-09-20 20:54 1,106,944 ——– c:\windows\system32\dllcache\msxml3.dll
2009-09-20 20:54 2,560 ——– c:\windows\system32\xpsp4res.dll
2009-09-20 20:54 1,203,922 ——– c:\windows\system32\dllcache\sysmain.sdb
2009-09-20 20:54 215,552 ——– c:\windows\system32\dllcache\wordpad.exe
2009-09-20 20:45 –d—– c:\windows\system32\scripting
2009-09-20 20:45 –d—– c:\windows\system32\en
2009-09-20 20:45 –d—– c:\windows\l2schemas
2009-09-20 20:45 –d—– c:\windows\system32\bits
2009-09-20 20:43 –d—– c:\windows\ServicePackFiles
2009-09-20 20:41 –d—– c:\windows\network diagnostic
2009-09-20 20:19 104,960 ——– c:\windows\system32\drivers\atinrvxx.sys
2009-09-20 20:09 31,768 a——- c:\windows\system32\wucltui.dll.mui
2009-09-20 20:09 23,576 a——- c:\windows\system32\wuaucpl.cpl.mui
2009-09-20 20:09 18,456 a——- c:\windows\system32\wuaueng.dll.mui
2009-09-20 20:09 23,576 a——- c:\windows\system32\wuapi.dll.mui
==================== Find3M ====================
2009-09-27 14:49 21 a——- C:\qpmd8376.bin
2009-09-20 20:48 88,263 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-08-05 05:01 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-08-05 05:01 204,800 ——– c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 15:11 160,564 a——- c:\windows\Sqirlz Water Reflections Uninstaller.exe
2009-08-03 18:24 16,530 a——- c:\docume~1\hunter~1\applic~1\wklnhst.dat
2009-08-03 17:29 2,516 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-07-29 00:37 119,808 a——- c:\windows\system32\t2embed.dll
2009-07-29 00:37 81,920 a——- c:\windows\system32\fontsub.dll
2009-07-29 00:37 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-07-29 00:37 81,920 ——– c:\windows\system32\dllcache\fontsub.dll
2009-07-19 09:18 5,937,152 ——– c:\windows\system32\dllcache\mshtml.dll
2009-07-18 12:05 1,509,888 ——– c:\windows\system32\dllcache\shdocvw.dll
2009-07-17 15:01 58,880 a——- c:\windows\system32\atl.dll
2009-07-17 15:01 58,880 ——– c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 a——- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a——- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 ——– c:\windows\system32\dllcache\wmpdxm.dll
2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll
2009-07-03 13:09 915,456 ——– c:\windows\system32\dllcache\wininet.dll
2009-07-03 13:09 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll
2009-07-03 13:09 206,848 ——– c:\windows\system32\dllcache\occache.dll
2009-07-03 13:09 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 13:09 184,320 ——– c:\windows\system32\dllcache\iepeers.dll
2009-07-03 13:09 386,048 ——– c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 07:01 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-06-27 03:07 0 a–sh— c:\windows\system32\wepetobe.dll
============= FINISH: 16:13:45.04 ===============
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:57:01 PM, on 9/27/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\drivers\smss.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Hunter Sims\My Documents\Software\HIJACKTHIS\HIJACKTHIS V2.0.2.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://insightbb.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070119
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\drivers\smss.exe
O2 - BHO: C:\WINDOWS\system32\y2kf4kxb.dll - {A249BC15-23F2-42AD-F4E4-00AAC39C0004} - C:\WINDOWS\system32\y2kf4kxb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [mserv] C:\Documents and Settings\Hunter Sims\Application Data\svcst.exe
O4 - HKCU\..\Run: [Yjafosi8kdf98winmdkmnkmfnwe] C:\DOCUME~1\HUNTER~1\LOCALS~1\Temp\csrss.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1253491739836
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,lekojeta.dll
O20 - Winlogon Notify: __c00F69A - C:\WINDOWS\system32\__c00F69A.dat (file missing)
O22 - SharedTaskScheduler: iukjsf8w3jirojs9f8u3jruhsf78s3jijdif - {A249BC15-23F2-42AD-F4E4-00AAC39C0004} - C:\WINDOWS\system32\y2kf4kxb.dll (file missing)
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ColdFusion MX Application Server - Macromedia Inc. - C:\Program Files\Macromedia\runtime\bin\jrunsvc.exe
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - C:\Program Files\Macromedia\db\slserver52\bin\swagent.exe
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - C:\Program Files\Macromedia\db\slserver52\bin\swstrtr.exe
O23 - Service: Flash Communication Server (FlashCom) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe
O23 - Service: Flash Communication Admin Service (FlashComAdmin) - Macromedia, Inc. - C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
–
End of file - 7095 bytes