This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Zlob need help

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 4:28:42 AM, on 12/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\{24094B37-0C80-1033-0916-050913200001}\Update.exe
C:\WINDOWS\system32\RACLE~1\ntvdm.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BitTornado\btdownloadgui.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\IZArc\IZArc.exe
C:\DOCUME~1\CABOOSE\LOCALS~1\Temp\ARC1CE1\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A2CFE8BA-0F06-7F8F-7240-2FD73E0C64C6} - C:\WINDOWS\system32\fjxkdpy.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: OIN Search - {B9F6E8EB-A4E3-478E-88A4-D3995B5C45C8} - C:\Program Files\OIN Search\OINSearch.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [dgvski.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\dgvski.dll,bfzhcz
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvjah.dll,startup
O4 - HKLM\..\Run: [1pop06apelt3] C:\WINDOWS\octeltpop.exe
O4 - HKLM\..\Run: [howc0187] RUNDLL32.EXE w05848e4.dll,n 006c01810000000205848e4
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [vvdkkpe.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\vvdkkpe.dll,agkxvbc
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
O4 - HKCU\..\Run: [Wrco] "C:\WINDOWS\system32\RACLE~1\ntvdm.exe" -vt yazb
O4 - HKCU\..\Run: [Tszmdesw] C:\Documents and Settings\CABOOSE\My Documents\?ymantec\?vchost.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by112fd.bay112.hotmail.msn.com/resources/MsnPUpld.cab
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
Hi Dream Pendulumand welcome to Tom Coyote forums

I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Thanks for your patience!
Hi Dream Pendulum

Firstly before we start any fix you are running with no protection on your system!

There are a few very important security program that you are In need of. These programs are essential to prevent you from getting reinfected:
Note! You can only run one antivirus program and one firewall.


* Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. Please download and install one antivirus program from the following list, download the latest signatures, and do a full system scan.

o Anti-Virus
o Avast Home Edition
* Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check This webpage out. Two free ones available for personal use:

o Kerio Personal Firewall
o ZoneAlarm

Without these programs, you will be quickly reinfected, and we would just be wasting our time trying to clean your computer.

______________________


Please note that HJT is running from a temp folder
You currently are running HijackThis from here: C:\DOCUME~1\CABOOSE\LOCALS~1\Temp\ARC1CE1\HijackThis.exe

Please Create a new folder either here:
C:\ or create a folder on your desktop and call it this folder HJT and place "HijackThis.exe" in that folder.

DO NOT follow the steps below until you have moved HijackThis


post a new HJT log in your next post
Thanks dan
Logfile of HijackThis v1.99.1
Scan saved at 1:42:44 AM, on 12/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\octeltpop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\{24094B37-0C80-1033-0916-050913200001}\Update.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\CABOOSE\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A2CFE8BA-0F06-7F8F-7240-2FD73E0C64C6} - C:\WINDOWS\system32\fjxkdpy.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: OIN Search - {B9F6E8EB-A4E3-478E-88A4-D3995B5C45C8} - C:\Program Files\OIN Search\OINSearch.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [dgvski.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\dgvski.dll,bfzhcz
O4 - HKLM\..\Run: [1pop06apelt3] C:\WINDOWS\octeltpop.exe
O4 - HKLM\..\Run: [howc0187] RUNDLL32.EXE w05848e4.dll,n 006c01810000000205848e4
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Wrco] "C:\WINDOWS\system32\RACLE~1\ntvdm.exe" -vt yazb
O4 - HKCU\..\Run: [Tszmdesw] C:\Documents and Settings\CABOOSE\My Documents\?ymantec\?vchost.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by112fd.bay112.hotmail.msn.com/resources/MsnPUpld.cab
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
Hi Dream Pendulum

We have, I believe some files hiding from us and I want to flush them out
Please go to the C:\Documents and Settings\CABOOSE\Desktop\HJT\HijackThis.exe. Right click on the HijackThis.exe file and select "Rename". Rename it removal.exe,

Then run HijackThis again and post a new log please in your returned post
__________________


1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a logfile located at C:\ComboFix.txt.
4. Post the contents of that log in your next reply with a new hijackthis log.


Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
__________________________

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm


Please include new HJT log, combofix report and smitfraud txt
in your next post
Thanks dan
Logfile of HijackThis v1.99.1
Scan saved at 3:13:48 PM, on 12/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\octeltpop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\CPSHelpRunner.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\CABOOSE\Desktop\HJT\Removal.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A2CFE8BA-0F06-7F8F-7240-2FD73E0C64C6} - C:\WINDOWS\system32\fjxkdpy.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {099D0986-C204-F967-3343-00A64FA96FB9} - C:\Documents and Settings\CABOOSE\Local Settings\Application Data\vorenbj.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\xcnovrcg.dll
O2 - BHO: (no name) - {3FDF44CE-41DB-601E-1725-06490A83D940} - C:\WINDOWS\system32\ydsxqjk.dll
O2 - BHO: (no name) - {5B4926DE-D92B-A707-79B5-06DED9A49269} - C:\WINDOWS\system32\nkdwfqm.dll
O2 - BHO: (no name) - {5FCFB96D-6439-F01A-1D1A-01C78C6963AE} - C:\WINDOWS\system32\jzarjsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {A2CFE8BA-0F06-7F8F-7240-2FD73E0C64C6} - C:\WINDOWS\system32\fjxkdpy.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: (no name) - {C2E61DF7-6639-4B2D-A57B-DA6256F48B1F} - C:\WINDOWS\system32\ssqpq.dll
O2 - BHO: (no name) - {F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2} - C:\WINDOWS\system32\jkkijgf.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: OIN Search - {B9F6E8EB-A4E3-478E-88A4-D3995B5C45C8} - C:\Program Files\OIN Search\OINSearch.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [dgvski.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\dgvski.dll,bfzhcz
O4 - HKLM\..\Run: [1pop06apelt3] C:\WINDOWS\octeltpop.exe
O4 - HKLM\..\Run: [howc0187] RUNDLL32.EXE w05848e4.dll,n 006c01810000000205848e4
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Wrco] "C:\WINDOWS\system32\RACLE~1\ntvdm.exe" -vt yazb
O4 - HKCU\..\Run: [Tszmdesw] C:\Documents and Settings\CABOOSE\My Documents\?ymantec\?vchost.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by112fd.bay112.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: jkkijgf - C:\WINDOWS\SYSTEM32\jkkijgf.dll
O20 - Winlogon Notify: ssqpq - C:\WINDOWS\system32\ssqpq.dll
O20 - Winlogon Notify: winzdn32 - winzdn32.dll (file missing)
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
CABOOSE - 06-12-04 14:55:19.93 Service Pack 2 ComboFix 06.11.27W - Running from: "C:\Program Files\Mozilla Firefox" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe C:\WINDOWS\system32\components C:\Program Files\Common Files\{34094B37-0C80-1033-0916-050913200001} C:\Program Files\Common Files\{24094B37-0C80-1033-0916-050913200001} ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: C:\QooBox\Purity\Documents and Settings\CABOOSE\Application Data\ASKS~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\Application Data\DOBE~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\Application Data\ICROSO~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\Application Data\MANTEC~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\Application Data\SSTEM3~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\Application Data\WNSXS~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\Application Data\YSTEM3~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\My Documents\FNTS~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\My Documents\SKS~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\My Documents\SSTEM3~1 C:\QooBox\Purity\Documents and Settings\CABOOSE\My Documents\STEM~1 C:\QooBox\Purity\Program Files\YSTEM~1 C:\QooBox\Purity\Program Files\Common Files\ASEMBL~1 C:\QooBox\Purity\Program Files\Common Files\CROSOF~1 C:\QooBox\Purity\Program Files\Common Files\WNSXS~1 C:\QooBox\Purity\WINDOWS\APPATC~1 C:\QooBox\Purity\WINDOWS\MCROSO~1.NET C:\QooBox\Purity\WINDOWS\SEMBLY~1 C:\QooBox\Purity\WINDOWS\SMBOLS~1 C:\QooBox\Purity\WINDOWS\system32\RACLE~1 C:\QooBox\Purity\WINDOWS\system32\RACLE~2 C:\QooBox\Purity\WINDOWS\system32\STEM32~1 C:\QooBox\Purity\WINDOWS\system32\RACLE~1\?racle ((((((((((((((((((((((((((((((( Files Created from 2006-11-04 to 2006-12-04 )))))))))))))))))))))))))))))))))) 2006-12-03 23:45 90,112 –a—— C:\WINDOWS\system32\AVASTSS.scr 2006-12-03 23:45 87,424 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys 2006-12-03 23:45 85,952 –a—— C:\WINDOWS\system32\drivers\aswmon.sys 2006-12-03 23:45 666,240 –a—— C:\WINDOWS\system32\aswBoot.exe 2006-12-03 23:45 36,176 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys 2006-12-03 23:45 24,560 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys 2006-12-03 23:45 16,352 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys 2006-12-03 23:45 d——– C:\Program Files\Alwil Software 2006-12-03 17:02 88,340 –a—— C:\WINDOWS\system32\hsfvgrdg.exe 2006-12-03 17:02 d——– C:\Program Files\VSAdd-in 2006-12-02 17:02 88,340 –a—— C:\WINDOWS\system32\vondijld.exe 2006-12-01 17:02 88,340 –a—— C:\WINDOWS\system32\vmcavbdq.exe 2006-12-01 12:40 d——– C:\Documents and Settings\CABOOSE\Application Data\AdobeUM 2006-11-30 17:01 88,340 –a—— C:\WINDOWS\system32\nsvatklh.exe 2006-11-29 17:01 88,340 –a—— C:\WINDOWS\system32\cibywtpq.exe 2006-11-29 17:01 126,996 –a—— C:\WINDOWS\system32\kxtmqpkr.dll 2006-11-29 01:47 d——– C:\Documents and Settings\All Users\Application Data\nView_Profiles 2006-11-29 01:22 126,996 –a—— C:\WINDOWS\system32\mbwyceya.dll 2006-11-29 00:37 d——– C:\Documents and Settings\CABOOSE\Application Data\Roxio 2006-11-29 00:33 d——– C:\Documents and Settings\All Users\Application Data\InstallShield 2006-11-29 00:30 d——– C:\Program Files\Common Files\Sonic Shared 2006-11-29 00:28 d——– C:\Documents and Settings\All Users\Application Data\Sonic 2006-11-29 00:16 d——– C:\Documents and Settings\All Users\Application Data\Roxio 2006-11-29 00:15 d——– C:\Program Files\Roxio 2006-11-29 00:15 d——– C:\Program Files\Common Files\Roxio Shared 2006-11-28 11:58 88,340 –a—— C:\WINDOWS\system32\fberqllm.exe 2006-11-27 22:09 71,168 –a—— C:\WINDOWS\system32\drvjah.dll 2006-11-27 22:09 40,973 —hs—- C:\WINDOWS\system32\jkkiigg.dll 2006-11-27 22:09 d——– C:\Documents and Settings\CABOOSE\Application Data\Talkback 2006-11-27 13:00 d——– C:\Documents and Settings\All Users\Application Data\Adobe 2006-11-27 12:53 d——– C:\WINDOWS\RegisteredPackages 2006-11-27 12:51 d——– C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage 2006-11-27 11:58 88,340 –a—— C:\WINDOWS\system32\vccgeglm.exe 2006-11-27 11:58 42,516 –a—— C:\WINDOWS\system32\xcnovrcg.dll 2006-11-27 11:37 126,996 –a—— C:\WINDOWS\system32\ibvfeejp.dll 2006-11-26 11:57 110,612 –a—— C:\WINDOWS\system32\nfyvcejq.exe 2006-11-25 11:57 110,612 –a—— C:\WINDOWS\system32\orialmjn.exe 2006-11-23 11:09 38,420 –a—— C:\WINDOWS\system32\omwqpppv.dll 2006-11-23 11:09 110,612 –a—— C:\WINDOWS\system32\smlggeqk.exe 2006-11-22 10:30 110,612 –a—— C:\WINDOWS\system32\wkgnaibb.exe 2006-11-21 19:26 d——– C:\Program Files\Common Files\InstallShield 2006-11-21 09:31 126,996 –a—— C:\WINDOWS\system32\wgsroetm.dll 2006-11-21 09:31 110,612 –a—— C:\WINDOWS\system32\lccjxyoo.exe 2006-11-20 20:11 d——– C:\WINDOWS\system32\àppPatch 2006-11-20 20:11 d——– C:\Program Files\Common Files\xing shared 2006-11-20 20:10 d——– C:\Documents and Settings\CABOOSE\Application Data\Adobe 2006-11-20 20:09 d——– C:\Config.Msi 2006-11-20 20:04 93,696 –a—— C:\WINDOWS\system32\vvdkkpe.dll 2006-11-20 20:04 71,680 –a—— C:\WINDOWS\system32\vorenbj.dll 2006-11-20 20:04 40,973 –ahs—- C:\WINDOWS\system32\rqrsqno.dll 2006-11-20 09:31 110,612 –a—— C:\WINDOWS\system32\tarmecsu.exe 2006-11-19 11:21 d——– C:\Program Files\Common Files\Real 2006-11-19 09:30 110,612 –a—— C:\WINDOWS\system32\ainyoyit.exe 2006-11-18 04:00 110,612 –a—— C:\WINDOWS\system32\ikjedbqt.exe 2006-11-17 04:00 110,612 –a—— C:\WINDOWS\system32\ntbkimmn.exe 2006-11-17 02:00 126,996 –a—— C:\WINDOWS\system32\kfpvqfuk.dll 2006-11-17 02:00 110,612 –a—— C:\WINDOWS\system32\cjctsxwf.exe 2006-11-16 02:42 d——– C:\Program Files\Adobe 2006-11-16 02:38 d——– C:\Program Files\Common Files\Adobe 2006-11-16 00:59 d–hs—- C:\Documents and Settings\All Users\DRM 2006-11-15 23:59 40,973 —hs—- C:\WINDOWS\system32\urqroll.dll 2006-11-15 23:59 110,612 –a—— C:\WINDOWS\system32\xstalvlb.exe 2006-11-14 03:14 d——– C:\Program Files\Common Files\Java 2006-11-14 03:02 110,612 –a—— C:\WINDOWS\system32\owsnwluo.exe 2006-11-09 20:48 110,612 –a—— C:\WINDOWS\system32\xqfkeqtq.exe 2006-11-08 20:22 110,612 –a—— C:\WINDOWS\system32\fnbvtsmf.exe 2006-11-07 20:21 110,612 –a—— C:\WINDOWS\system32\wecdtpem.exe 2006-11-06 18:07 110,612 –a—— C:\WINDOWS\system32\kkgtjwnu.exe 2006-11-06 00:54 40,973 —hs—- C:\WINDOWS\system32\urqroon.dll 2006-11-06 00:16 d–hs—- C:\WINDOWS\UVVF 2006-11-06 00:15 979 –a—— C:\WINDOWS\system32\winpfg32.sys 2006-11-06 00:15 45,056 –a—— C:\WINDOWS\octeltpop.exe 2006-11-06 00:15 36,864 –a—— C:\WINDOWS\unstall.exe 2006-11-06 00:10 94,208 –a—— C:\WINDOWS\system32\xanhbok.dll 2006-11-06 00:10 72,704 –a—— C:\WINDOWS\system32\ydsxqjk.dll 2006-11-06 00:09 40,973 —hs—- C:\WINDOWS\system32\jkkijgf.dll 2006-11-05 17:36 110,612 –a—— C:\WINDOWS\system32\wucpioxi.exe 2006-11-05 00:05 d—s—- C:\Documents and Settings\CABOOSE\UserData 2006-11-04 04:15 110,612 –a—— C:\WINDOWS\system32\shfwiyml.exe (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-12-04 14:59 ——– d——– C:\Program Files\Common Files 2006-12-04 14:54 ——– d——– C:\Program Files\Mozilla Firefox 2006-12-03 23:34 ——– d——– C:\Program Files\Trillian 2006-12-03 17:02 870088 —hs—- C:\WINDOWS\system32\qpqss.bak2 2006-12-02 17:32 2 –a—— C:\WINDOWS\system32\wapiit.exe 2006-12-02 17:02 868851 —hs—- C:\WINDOWS\system32\qpqss.bak1 2006-11-29 01:31 ——– d——– C:\Program Files\Internet Explorer 2006-11-27 12:58 0 –a—— C:\Documents and Settings\CABOOSE\Application Data\dm.ini 2006-11-27 12:58 ——– d——– C:\Program Files\Windows Media Player 2006-11-21 19:26 ——– d–h—– C:\Program Files\InstallShield Installation Information 2006-11-21 19:26 ——– d——– C:\Documents and Settings\CABOOSE\Application Data\Google 2006-11-20 20:11 ——– d——– C:\Documents and Settings\CABOOSE\Application Data\Real 2006-11-20 20:10 ——– d——– C:\Documents and Settings\CABOOSE\Application Data\Xfire 2006-11-20 20:09 ——– d—s—- C:\Program Files\Xfire 2006-11-20 19:57 ——– d——– C:\Program Files\SpywareBlaster 2006-11-14 03:16 ——– d——– C:\Program Files\Java 2006-11-04 23:12 ——– d——– C:\Program Files\Spybot - Search & Destroy 2006-11-03 04:15 110612 –a—— C:\WINDOWS\system32\unsdwlmu.exe 2006-11-02 05:04 163644 –a—— C:\WINDOWS\system32\drivers\secdrv.sys 2006-11-02 05:04 ——– d——– C:\Documents and Settings\CABOOSE\Application Data\Activision 2006-11-02 04:15 110612 –a—— C:\WINDOWS\system32\spmxqtdp.exe 2006-11-01 04:14 110612 –a—— C:\WINDOWS\system32\fqureutd.exe 2006-11-01 04:09 660936 —hs—- C:\WINDOWS\system32\qpqss.ini2 2006-11-01 03:58 ——– d——– C:\Program Files\Super DVD Creator 9.25.0 2006-10-31 23:29 110612 –a—— C:\WINDOWS\system32\xoqrxsgh.exe 2006-10-30 23:29 110612 –a—— C:\WINDOWS\system32\ijlvrlbl.exe 2006-10-30 13:44 110612 –a—— C:\WINDOWS\system32\lovjjxjb.exe 2006-10-30 13:36 110612 –a—— C:\WINDOWS\system32\uprrpphi.exe 2006-10-30 03:20 110612 –a—— C:\WINDOWS\system32\aymrwfuj.exe 2006-10-28 16:08 ——– d——– C:\Documents and Settings\CABOOSE\Application Data\Macromedia 2006-10-25 18:13 94720 –a—— C:\WINDOWS\system32\dgvski.dll 2006-10-25 18:13 72192 –a—— C:\WINDOWS\system32\nkdwfqm.dll 2006-10-25 16:50 94080 –a—— C:\Documents and Settings\CABOOSE\Application Data\ezplay.sys 2006-10-25 16:50 81920 –a—— C:\Documents and Settings\CABOOSE\Application Data\ezpinst.exe 2006-10-25 16:50 7176 –a—— C:\Documents and Settings\CABOOSE\Application Data\pcouffin.cat 2006-10-25 16:50 7172 –a—— C:\Documents and Settings\CABOOSE\Application Data\ezplay.cat 2006-10-25 16:50 47360 –a—— C:\Documents and Settings\CABOOSE\Application Data\pcouffin.sys 2006-10-25 16:50 33 –a—— C:\Documents and Settings\CABOOSE\Application Data\YFECRSUN.log 2006-10-25 16:50 33 –a—— C:\Documents and Settings\CABOOSE\Application Data\pcouffin.log 2006-10-25 16:50 1144 –a—— C:\Documents and Settings\CABOOSE\Application Data\pcouffin.inf 2006-10-25 16:50 1104 –a—— C:\Documents and Settings\CABOOSE\Application Data\YFECRSUN.inf 2006-10-25 16:50 ——– d——– C:\Documents and Settings\CABOOSE\Application Data\Vso 2006-10-25 16:34 ——– d——– C:\Program Files\THQ 2006-10-25 16:33 ——– d——– C:\Documents and Settings\CABOOSE\Application Data\InstallShield 2006-10-24 01:02 94080 –a—— C:\WINDOWS\system32\drivers\ezplay.sys 2006-10-24 01:02 47360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys 2006-10-24 01:02 125 –a—— C:\Documents and Settings\CABOOSE\Application Data\YFECRSUN.ini 2006-10-21 19:03 688180 —hs—- C:\WINDOWS\system32\ssqpq.dll 2006-10-21 18:58 93696 –a—— C:\WINDOWS\system32\wbdmvzi.dll 2006-10-21 18:58 72704 –a—— C:\WINDOWS\system32\jzarjsg.dll 2006-10-20 00:41 98304 –a—— C:\WINDOWS\system32\CmdLineExt.dll 2006-10-20 00:08 ——– d——– C:\Program Files\Sierra 2006-10-17 11:10 ——– d——– C:\Program Files\Fraps 2006-10-13 04:35 65536 –a—— C:\WINDOWS\system32\nwwks.dll 2006-10-13 04:35 64000 –a—— C:\WINDOWS\system32\nwapi32.dll 2006-10-13 04:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll 2006-10-13 02:23 163584 –a—— C:\WINDOWS\system32\drivers\nwrdr.sys 2006-10-08 02:45 ——– d——– C:\Program Files\LimeWire 2006-10-08 02:45 ——– d——– C:\Program Files\Intel Audio Studio 2006-09-12 21:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Wrco"="\"C:\\WINDOWS\\system32\\RACLE~1\\ntvdm.exe\" -vt yazb" "Tszmdesw"="C:\\Documents and Settings\\CABOOSE\\My Documents\\?ymantec\\?vchost.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "nwiz"="nwiz.exe /install" "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\"" "SigmatelSysTrayApp"="sttray.exe" "dgvski.dll"="C:\\WINDOWS\\system32\\rundll32.exe C:\\WINDOWS\\system32\\dgvski.dll,bfzhcz" "1pop06apelt3"="C:\\WINDOWS\\octeltpop.exe" "howc0187"="RUNDLL32.EXE w05848e4.dll,n 006c01810000000205848e4" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "RoxioDragToDisc"="\"C:\\Program Files\\Roxio\\Easy Media Creator 8\\Drag to Disc\\DrgToDsc.exe\"" @="" "RoxWatchTray"="\"C:\\Program Files\\Common Files\\Roxio Shared\\SharedCOM8\\RoxWatchTray.exe\"" "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e4,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoCDBurning"=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" "incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "IntelAudioStudio"="\"C:\\Program Files\\Intel Audio Studio\\IntelAudioStudio.exe\" BOOT" "NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKLM" "command"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033" "inimapping"="0" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkijgf HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqpq HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzdn32 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\Ace Optimizer Maintenance.job Completion time: 06-12-04 15:01:09.54 C:\ComboFix.txt … 06-12-04 15:01
SmitFraudFix v2.128 Scan done at 15:10:45.07, Mon 12/04/2006 Run from C:\Documents and Settings\CABOOSE\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ot.ico FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\CABOOSE »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\CABOOSE\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CABOOSE\FAVORI~1 C:\DOCUME~1\CABOOSE\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Hi Dream Pendulum

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

_________________________


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Download ATF Cleaner by Atribune and save it to your Desktop.
Do not use yet!

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Run ATF cleaner
  • Double click ATF-Cleaner.exe to run the program.
  • Check the following boxes:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Recycle Bin
    • Java Cache
  • The rest are optional - if you want to remove the lot, check Select All.
  • Now click Empty Selected.
  • When you get the Done Cleaning message, click OK.
  • If you use Firefox browser.
    • Click Firefox at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
  • If you use Opera browser.
    • Click Opera at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter.
Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________

Please post:
  • c:\rapport.txt
  • AVG Anti-Spyware report
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.

Thanks dan
SmitFraudFix v2.128 Scan done at 18:07:06.21, Tue 12/05/2006 Run from C:\Documents and Settings\CABOOSE\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\ot.ico Deleted C:\DOCUME~1\CABOOSE\FAVORI~1\Antivirus Test Online.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 7:26:04 PM 12/5/2006 + Scan result: C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP183\A0035290.exe -> Adware.180Solutions : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP153\A0029534.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP153\A0029553.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP153\A0030553.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP154\A0030567.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP156\A0032242.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP157\A0032249.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP158\A0032414.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP159\A0032533.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP161\A0032680.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP161\A0032877.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP163\A0033077.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP164\A0033114.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP165\A0033862.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP169\A0034011.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP171\A0034020.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP172\A0034049.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP173\A0034100.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP174\A0034119.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP175\A0034128.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP177\A0034203.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP177\A0034719.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP177\A0035042.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP182\A0035273.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP183\A0035285.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP183\A0035293.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP186\A0035437.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP187\A0035475.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\WINDOWS\unstall.exe -> Adware.EliteMedia : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP192\A0036129.exe -> Adware.Maxifiles : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP177\A0034169.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP177\A0034170.dll -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP177\A0034171.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP186\A0035429.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP190\A0035787.dll -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP190\A0035788.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP198\A0036696.dll -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP198\A0036697.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP177\A0034721.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\WINDOWS\system32\jkkiigg.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\WINDOWS\system32\jkkijgf.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\WINDOWS\system32\rqrsqno.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\WINDOWS\system32\urqroll.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\WINDOWS\system32\urqroon.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP143\A0025321.exe -> Downloader.PurityScan.dc : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP143\A0025315.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP191\A0035801.exe -> Downloader.Zlob.bbe : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP144\A0025467.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP145\A0026472.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP151\A0028473.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP153\A0029467.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP153\A0029542.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP154\A0030561.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP156\A0032244.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP158\A0032413.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP159\A0032532.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP160\A0032670.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP161\A0032842.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP163\A0033076.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP166\A0033950.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP174\A0034118.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP175\A0034130.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP176\A0034155.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP177\A0034160.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP182\A0035272.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP186\A0035436.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP187\A0035473.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP190\A0035789.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP193\A0036456.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP194\A0036508.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP195\A0036539.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BAD46C6B-264B-4F1B-B911-56E72F7AE63E}\RP196\A0036552.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\UVVF\oppI.vbs -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\wapiit.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\octeltpop.exe -> Trojan.Winpop : Cleaned with backup (quarantined). ::Report end
Logfile of HijackThis v1.99.1
Scan saved at 7:45:06 PM, on 12/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\CPSHelpRunner.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\CABOOSE\Desktop\HJT\Removal.exe

R3 - URLSearchHook: (no name) - {A2CFE8BA-0F06-7F8F-7240-2FD73E0C64C6} - C:\WINDOWS\system32\fjxkdpy.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\xcnovrcg.dll
O2 - BHO: (no name) - {3FDF44CE-41DB-601E-1725-06490A83D940} - C:\WINDOWS\system32\ydsxqjk.dll (file missing)
O2 - BHO: (no name) - {473C3A08-FB15-4326-A161-6ED10FF8570C} - C:\WINDOWS\system32\sstqn.dll
O2 - BHO: (no name) - {5B4926DE-D92B-A707-79B5-06DED9A49269} - C:\WINDOWS\system32\nkdwfqm.dll (file missing)
O2 - BHO: (no name) - {5FCFB96D-6439-F01A-1D1A-01C78C6963AE} - C:\WINDOWS\system32\jzarjsg.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {A2CFE8BA-0F06-7F8F-7240-2FD73E0C64C6} - C:\WINDOWS\system32\fjxkdpy.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: (no name) - {C2E61DF7-6639-4B2D-A57B-DA6256F48B1F} - C:\WINDOWS\system32\ssqpq.dll (file missing)
O3 - Toolbar: OIN Search - {B9F6E8EB-A4E3-478E-88A4-D3995B5C45C8} - C:\Program Files\OIN Search\OINSearch.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [dgvski.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\dgvski.dll,bfzhcz
O4 - HKLM\..\Run: [howc0187] RUNDLL32.EXE w05848e4.dll,n 006c01810000000205848e4
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Wrco] "C:\WINDOWS\system32\RACLE~1\ntvdm.exe" -vt yazb
O4 - HKCU\..\Run: [Tszmdesw] C:\Documents and Settings\CABOOSE\My Documents\?ymantec\?vchost.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by112fd.bay112.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: sstqn - C:\WINDOWS\system32\sstqn.dll
O20 - Winlogon Notify: winzdn32 - winzdn32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
Hi Dream Pendulum Have you run the vundo fix ? Please post the contents of C:\vundofix.txt. If you have not run vundo, I will need a new HJT log after you have run it. I will be off line later until tomorrow and hope to be back with you soon Thanks dan
VundoFix V6.2.13 Checking Java version… Java version is 1.5.0.3 Java version is 1.5.0.6 Java version is 1.5.0.9 Scan started at 4:56:43 PM 12/5/2006 Listing files found while scanning…. C:\WINDOWS\system32\jzarjsg.dll C:\WINDOWS\system32\nkdwfqm.dll C:\WINDOWS\system32\xanhbok.dll C:\WINDOWS\system32\ydsxqjk.dll C:\WINDOWS\system32\ssqpq.dll C:\WINDOWS\system32\qpqss.ini C:\WINDOWS\system32\qpqss.bak1 C:\WINDOWS\system32\qpqss.bak2 C:\WINDOWS\system32\qpqss.ini2 Beginning removal… Attempting to delete C:\WINDOWS\system32\jzarjsg.dll C:\WINDOWS\system32\jzarjsg.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\nkdwfqm.dll C:\WINDOWS\system32\nkdwfqm.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\xanhbok.dll C:\WINDOWS\system32\xanhbok.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\ydsxqjk.dll C:\WINDOWS\system32\ydsxqjk.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\ssqpq.dll C:\WINDOWS\system32\ssqpq.dll Could not be deleted. Attempting to delete C:\WINDOWS\system32\qpqss.ini C:\WINDOWS\system32\qpqss.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\qpqss.bak1 C:\WINDOWS\system32\qpqss.bak1 Has been deleted! Attempting to delete C:\WINDOWS\system32\qpqss.bak2 C:\WINDOWS\system32\qpqss.bak2 Has been deleted! Attempting to delete C:\WINDOWS\system32\qpqss.ini2 C:\WINDOWS\system32\qpqss.ini2 Has been deleted! Performing Repairs to the registry. Done! Beginning removal… Attempting to delete C:\WINDOWS\system32\ssqpq.dll C:\WINDOWS\system32\ssqpq.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.2.13 Checking Java version… Java version is 1.5.0.3 Java version is 1.5.0.6 Java version is 1.5.0.9 Scan started at 5:27:50 PM 12/5/2006 Listing files found while scanning…. C:\WINDOWS\system32\sstqn.dll C:\WINDOWS\system32\nqtss.ini C:\WINDOWS\system32\nqtss.bak1 Beginning removal… Attempting to delete C:\WINDOWS\system32\sstqn.dll C:\WINDOWS\system32\sstqn.dll Could not be deleted. Attempting to delete C:\WINDOWS\system32\nqtss.ini C:\WINDOWS\system32\nqtss.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\nqtss.bak1 C:\WINDOWS\system32\nqtss.bak1 Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.2.13 Checking Java version… Java version is 1.5.0.3 Java version is 1.5.0.6 Java version is 1.5.0.9 Scan started at 5:35:06 PM 12/5/2006 Listing files found while scanning…. No infected files were found.
Hi Dream Pendulum



Ok we have a regfix I want you to carry out, which you will be fine with!


Copy/paste the following text into a new Notepad document. (You must use Notepad, NOT Wordpad). Make sure that you have NO blank lines at the beginning of the document before REGEDIT4, and ONE blank line at the end of the document as shown in the quoted text:

REGEDIT4

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Wrco"=-
"Tszmdesw"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"dgvski.dll"=-
"1pop06apelt3"=-
"howc0187"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2}"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"incestuously"=-

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkijgf]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqpq]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzdn32]



Save it to your desktop as Fixme.reg. Save it as follows…
File Type: "All Files" (not as a text document or it wont work).
Name: Fixme.reg

Locate Fixme.reg on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the merged successfully prompt.

Post a new HJT log in your next post

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI