This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rundll, Spyware Guard And Trojan Horse Issues. Please Help!

46 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

Looks like a partial success if there's no C:\WINDOWS\system32\mcryilyr.dll :)

Disable Spywareguard and Winpatrol as instructed above.

Open HijackThis, click do a system scan only and checkmark these:

O2 - BHO: (no name) - {075DCF1A-760A-42F8-A38A-CA3B7E317F51} - C:\WINDOWS\system32\xxyyx.dll (file missing)
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\mcryilyr.dll",setvm
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O20 - Winlogon Notify: jkkjjjj - jkkjjjj.dll (file missing)


Close all windows including browser and press fix checked.

Use process explorer to this like before -> C:\WINDOWS\SYSTEM32\wvuvutt.dll (kill it from winlogon.exe and explorer.exe and also possible files with reverse filename)

Double-click Killbox.exe to run it.

Select "Standard file kill".
Place the following line (complete path) in bold in the "Full Path of File to Delete" box in Killbox:
C:\WINDOWS\SYSTEM32\wvuvutt.dll
Click the red-and-white "Delete File" button. Click "No" at the Pending Operations prompt.

Re-run vundofix

Post:

- a fresh HijackThis log
- vundofix report
Well, everything seems fine after those scans, fingers crossed I've finally gotten rid of all that stuff :P Spoke to soon, I got these 2 files coming up now…a trojan horse error for mhjqwsmg.dll and a watchdog patrol one for nnlii.dll, wxxfycwd.dll and wfvhtmoo.dll

Vundofix Report

VundoFix V6.3.18

Checking Java version…

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 11:08:38 PM 4/6/2007

Listing files found while scanning….

C:\WINDOWS\system32\byvvu.dll
C:\WINDOWS\system32\cbxyyvu.dll
C:\WINDOWS\system32\eqvmtnku.dll
C:\WINDOWS\system32\ukntmvqe.ini
C:\WINDOWS\system32\uvvyb.bak1
C:\WINDOWS\system32\uvvyb.ini
C:\WINDOWS\system32\xeasufyp.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\byvvu.dll
C:\WINDOWS\system32\byvvu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbxyyvu.dll
C:\WINDOWS\system32\cbxyyvu.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\eqvmtnku.dll
C:\WINDOWS\system32\eqvmtnku.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ukntmvqe.ini
C:\WINDOWS\system32\ukntmvqe.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvvyb.bak1
C:\WINDOWS\system32\uvvyb.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\uvvyb.ini
C:\WINDOWS\system32\uvvyb.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xeasufyp.dll
C:\WINDOWS\system32\xeasufyp.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\cbxyyvu.dll
C:\WINDOWS\system32\cbxyyvu.dll Has been deleted!

Performing Repairs to the registry.
Done!

HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 12:02:22 AM, on 4/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
D:\programs\Quicktime\qttask.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
D:\Programs\Avast!\ashserv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
D:\Programs\SpywareGuard\sgbhp.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
D:\Programs\HiJackThis\foamy.exe
C:\WINDOWS\system32\notepad.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: mljgeeb - C:\WINDOWS\SYSTEM32\mljgeeb.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hi

One baddie left :)

Disconnect from internet during that fix (unplug network cable or shutdown modem). Do you have a possible second computer that is connected to internet and you could use it for sending logs?

Use process explorer to this like before -> C:\WINDOWS\SYSTEM32\mljgeeb.dll (kill it from winlogon.exe and explorer.exe and also possible files with reverse filename)

Double-click Killbox.exe to run it.

Select "Standard file kill".
Place the following line (complete path) in bold in the "Full Path of File to Delete" box in Killbox:
C:\WINDOWS\SYSTEM32\mljgeeb.dll. Checkmark "Unregister .dll Before Deleting".
Click the red-and-white "Delete File" button. Click "No" at the Pending Operations prompt.

EDIT: Add also those two bad files two both fixes above if found (use All files then in KillBox)

Re-run vundofix

Post:

- a fresh HijackThis log
- vundofix report
The scans ran fine, however MSN Messenger is still giving me grief, I'm not convinced that the IM worms been completely wiped from it. Whenever it tries to sign in, the mouse suddenly freezes and other programs don't respond so I end up having to shut it down. It also advised me to change my password, so I've done that as well. The troubleshoot box keeps coming up as well. Also, I found getting rid of nnlii.dll very difficult and I'm not sure if thats completely gone either.

Vundofix Report

VundoFix V6.3.18

Checking Java version…

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 9:48:54 AM 4/7/2007

Listing files found while scanning….

C:\WINDOWS\system32\bwcyfxxw.ini
C:\WINDOWS\system32\iilnn.bak1
C:\WINDOWS\system32\iilnn.ini
C:\WINDOWS\system32\mljhebc.dll
C:\WINDOWS\system32\nnlii.dll
C:\WINDOWS\system32\opnoolk.dll
C:\WINDOWS\system32\wfvhtmoo.dll
C:\WINDOWS\system32\wxxfycwb.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\bwcyfxxw.ini
C:\WINDOWS\system32\bwcyfxxw.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\iilnn.bak1
C:\WINDOWS\system32\iilnn.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\iilnn.ini
C:\WINDOWS\system32\iilnn.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljhebc.dll
C:\WINDOWS\system32\mljhebc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opnoolk.dll
C:\WINDOWS\system32\opnoolk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wfvhtmoo.dll
C:\WINDOWS\system32\wfvhtmoo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wxxfycwb.dll
C:\WINDOWS\system32\wxxfycwb.dll Has been deleted!

Performing Repairs to the registry.
Done!


HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 10:10:08 AM, on 4/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
D:\programs\Quicktime\qttask.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Programs\Avast!\ashserv.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
D:\Programs\SpywareGuard\sgbhp.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Programs\HiJackThis\foamy.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {B1FEA525-90A0-4C63-AC1A-FAAAB996C958} - C:\WINDOWS\system32\nnlii.dll (file missing)
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: mljgeeb - mljgeeb.dll (file missing)
O20 - Winlogon Notify: nnlii - C:\WINDOWS\system32\nnlii.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Now these errors are coming up for wnhimwcm.dll, pmkig.dll, qmjccfuh.dll and xtqynlxt.dll. It doesn't look like this worms gonna stop anytime soon, its very persistant, maybe we need another strategy coz Killbox and Vundofix aren't stopping it.
Hi

Sure we need.

Two choices:

1) All fixes must be done on safe mode

2) Modem must be off during the fix

Or third choice is that if you have a second computer that you can keep infected computer all the time offline.

Please download the OTMoveIt by OldTimer.

Save it to your desktop

Boot in safe mode

Fix these:

O2 - BHO: (no name) - {B1FEA525-90A0-4C63-AC1A-FAAAB996C958} - C:\WINDOWS\system32\nnlii.dll (file missing)
O20 - Winlogon Notify: mljgeeb - mljgeeb.dll (file missing)
O20 - Winlogon Notify: nnlii - C:\WINDOWS\system32\nnlii.dll (file missing)


Take a look at HijackThis log and look for other Winlogon Notify entries (not this -> O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll). Use Process Explorer to them like before.

After killing those with Process Explorer, fix corresponding lines with HjT.

Now go to c:\windows\system32 and look for suspicious looking dlls that have been created today or yesterday (like wnhimwcm.dll, pmkig.dll, qmjccfuh.dll and xtqynlxt.dll). Write down those filenames with full path to Notepad and copy text to Clipboard.
  • Please double-click OTMoveIt.exe to run it
  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Re-run vundofix

Re-run dss

Post:

- dss log
- vundofix report
Well, I think I've gotten rid of almost all the .dll in the system, only 2 entries showed up on the Vundofix scan so thats a really promising sign. Heres the logs:

Vundofix Report

VundoFix V6.3.18

Checking Java version…

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 9:31:59 AM 4/8/2007

Listing files found while scanning….

C:\WINDOWS\system32\yaywxvu.dll
C:\WINDOWS\system32\yayxxvu.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\yaywxvu.dll
C:\WINDOWS\system32\yaywxvu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayxxvu.dll
C:\WINDOWS\system32\yayxxvu.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\yayxxvu.dll
C:\WINDOWS\system32\yayxxvu.dll Has been deleted!

Performing Repairs to the registry.
Done!

DSS Report

Deckard's System Scanner v20070328.36
Run by [removed] on 2007-04-08 at 10:15:51
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as michael.exe) ———————————————

Logfile of HijackThis v1.99.1
Scan saved at 10:16:03 AM, on 4/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Avast!\ashserv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
D:\programs\Quicktime\qttask.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
D:\Programs\SpywareGuard\sgbhp.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\michael\Desktop\dss.exe
D:\Programs\HIJACK~1\michael.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


– Files created between 2007-03-08 and 2007-04-08 —————————–

2007-04-07 12:30:56 518926 —hs—- C:\WINDOWS\system32\gikmp.bak1
2007-04-07 12:30:17 280676 —hs—- C:\WINDOWS\system32\pmkig.dll
2007-04-06 21:58:36 0 d——– C:\!KillBox
2007-04-06 21:09:46 517935 —hs—- C:\WINDOWS\system32\xyyxx.bak1
2007-04-06 20:05:01 0 d——– C:\avenger
2007-04-06 15:28:03 0 d——– C:\WAR2
2007-04-06 10:06:07 192000 –a—— C:\Documents and Settings\michael\pp.exe
2007-04-06 09:57:59 462330 –a—— C:\dss.exe
2007-04-03 18:24:34 0 d——– C:\Getservice
2007-04-03 16:29:24 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-04-02 10:26:31 0 d——– C:\VundoFix Backups
2007-03-29 21:59:20 0 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-03-23 15:49:19 0 d——– C:\Documents and Settings\michael\Application Data\Google
2007-03-11 23:23:37 0 d——– C:\Documents and Settings\michael\Application Data\Yahoo! Messenger


– Find3M Report —————————————————————

2007-04-08 10:15:00 0 d——– C:\Program Files\SP2 Connection Patcher
2007-04-06 19:50:56 2576 –a—— C:\Program Files\vwjotcbc.txt
2007-04-02 21:32:59 0 d——– C:\Program Files\Java
2007-04-01 21:01:30 4212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-03-29 21:59:32 0 d——– C:\Program Files\MSN Messenger
2007-03-23 15:48:12 0 d–h—– C:\Program Files\InstallShield Installation Information
2007-03-23 15:48:12 0 d——– C:\Program Files\Google
2007-03-09 01:36:28 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-09 01:36:28 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-09 01:36:28 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-09 00:02:00 75512 –a—— C:\WINDOWS\zllsputility.exe
2007-03-09 00:01:42 1087216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-03-08 23:47:48 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-03 21:00:24 532480 –a—— C:\WINDOWS\system32\Sci Fi Screensaver.scr
2007-03-03 09:55:02 0 d——– C:\Program Files\Common Files\Ahead
2007-01-27 15:53:42 139264 –a—— C:\WINDOWS\mirar_distro_876260.exe
2007-01-27 15:53:34 374 –a—— C:\Documents and Settings\michael\Application Data\internaldb6334.dat
2007-01-27 15:53:33 538 –a—— C:\Documents and Settings\michael\Application Data\internaldb8467.dat
2007-01-27 15:53:33 18432 –a—— C:\Documents and Settings\michael\Application Data\internaldb41.dat
2007-01-19 11:53:04 51056 –a—— C:\WINDOWS\system32\sirenacm.dll
2007-01-16 03:32:07 689280 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-01-16 03:23:20 90112 –a—— C:\WINDOWS\system32\AVASTSS.scr


– Registry Dump —————————————————————


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"SP2 Connection Patcher"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
"Creative Detector"="D:\\Programs\\Creative MediaSource\\Detector\\CTDetect.exe /R"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Yahoo! Pager"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"avast!"="D:\\Programs\\Avast!\\ashDisp.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"WinPatrol"="D:\\Programs\\WinPatrol 9.8\\winpatrol.exe"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"D:\\programs\\Quicktime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"D:\\Programs\\iTunes\\iTunesHelper.exe\""
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"="SpywareGuard"
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
"{D15EFFBE-61EE-480B-9507-25264732DE0F}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://i.myspace.com/img/groups/crs/goblet…r/group_800.jpg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



– End of Deckard's System Scanner: finished at 2007-04-08 at 10:16:41 ———
I've deleted those files in the C:\WINDOWS\System32\ folder, but now these ones are coming up…byxyx.dll, hggfdbx.dll and vpbfdsee.dll, setvm. And also this which I think is related to the MSN Messenger worm…C:\Documents and Settings\michael\in.exe.

Logfile of HijackThis v1.99.1
Scan saved at 2:35:18 PM, on 4/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Avast!\ashserv.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
D:\programs\Quicktime\qttask.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
D:\Programs\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
D:\Programs\SpywareGuard\sgbhp.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\MSN Messenger\usnsvc.exe
D:\Programs\HiJackThis\foamy.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {5F5DE252-63CE-46A7-86D2-63212A33DBE7} - C:\WINDOWS\system32\byxyx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {D15EFFBE-61EE-480B-9507-25264732DE0F} - C:\WINDOWS\system32\hggfdbx.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\System32\nzdd.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: byxyx - C:\WINDOWS\system32\byxyx.dll
O20 - Winlogon Notify: hggfdbx - C:\WINDOWS\SYSTEM32\hggfdbx.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hi I must say that this really isn't looking good at the moment :( Use process explorer in safe mode for those files in winlogon notify and also otmoveit those( including C:\Documents and Settings\michael\in.exe) And also use otmoveit to any recent dlls in system32-folder. Re-run dss Re-run vundofix Post: - vundofix report - dss log
I think I may have worked out my dilemma with getting rid of all these .dll files that keep coming back. I remember last time dealing with spyware, it created a folder in C:\WINDOWS\Prefetch and its happened again now. I can't remember exactly how you dispose of it without it coming back though, but I've deleted the folder anyway. I'm finding it hard to get rid of C:\Documents and Settings\michael\in.exe. Also I've noticed many hidden files that have been created recently in the C Drive. Hmm I really think we gotta tackle this from a different angle coz no matter how many files I delete through Project Explorer, OTMoveIt and Vundofix, it comes back even stronger with more .dll files.
Anyway, here are your reports:

Vundofix Report

VundoFix V6.3.18

Checking Java version…

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 9:55:11 PM 4/9/2007

Listing files found while scanning….

C:\WINDOWS\system32\cbxwxvt.dll
C:\WINDOWS\system32\dasptfyh.dll
C:\WINDOWS\system32\eeslgsug.ini
C:\WINDOWS\system32\fypvrlbv.dll
C:\WINDOWS\system32\gusglsee.dll
C:\WINDOWS\system32\jkkhfec.dll
C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\tuvttqn.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\cbxwxvt.dll
C:\WINDOWS\system32\cbxwxvt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dasptfyh.dll
C:\WINDOWS\system32\dasptfyh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eeslgsug.ini
C:\WINDOWS\system32\eeslgsug.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\fypvrlbv.dll
C:\WINDOWS\system32\fypvrlbv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gusglsee.dll
C:\WINDOWS\system32\gusglsee.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkkhfec.dll
C:\WINDOWS\system32\jkkhfec.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\mljgg.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvttqn.dll
C:\WINDOWS\system32\tuvttqn.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\mljgg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvttqn.dll
C:\WINDOWS\system32\tuvttqn.dll Has been deleted!

Performing Repairs to the registry.
Done!


DSS Report

Deckard's System Scanner v20070328.36
Run by [removed] on 2007-04-09 at 22:28:18
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as michael.exe) ———————————————

Logfile of HijackThis v1.99.1
Scan saved at 10:28:31 PM, on 4/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Avast!\ashserv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
D:\programs\Quicktime\qttask.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
D:\Programs\SpywareGuard\sgbhp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\michael\Desktop\dss.exe
D:\Programs\HIJACK~1\michael.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\htcsmtbd.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {F94AC239-F181-46E9-B1D8-9DFB13F89F1F} - C:\WINDOWS\system32\mljgg.dll (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\kdytlmjj.dll",setvm
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O20 - Winlogon Notify: wvuvspn - C:\WINDOWS\SYSTEM32\wvuvspn.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


– Files created between 2007-03-09 and 2007-04-09 —————————–

2007-04-09 22:24:19 26694 –a—— C:\WINDOWS\system32\wvuvspn.dll
2007-04-09 22:20:36 0 d——– C:\WINDOWS\Prefetch
2007-04-09 21:53:28 518966 —hs—- C:\WINDOWS\system32\ggjlm.bak1
2007-04-09 21:47:15 192000 –a—— C:\Documents and Settings\michael\pp.exe
2007-04-09 14:26:58 521402 —hs—- C:\WINDOWS\system32\xyxyb.bak2
2007-04-08 10:26:45 518926 —hs—- C:\WINDOWS\system32\xyxyb.bak1
2007-04-06 21:58:36 0 d——– C:\!KillBox
2007-04-06 20:05:01 0 d——– C:\avenger
2007-04-06 15:28:03 0 d——– C:\WAR2
2007-04-06 09:57:59 462330 –a—— C:\dss.exe
2007-04-03 18:24:34 0 d——– C:\Getservice
2007-04-03 16:29:24 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-04-02 10:26:31 0 d——– C:\VundoFix Backups
2007-03-29 21:59:20 0 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-03-23 15:49:19 0 d——– C:\Documents and Settings\michael\Application Data\Google
2007-03-11 23:23:37 0 d——– C:\Documents and Settings\michael\Application Data\Yahoo! Messenger


– Find3M Report —————————————————————

2007-04-09 22:23:48 0 d——– C:\Program Files\SP2 Connection Patcher
2007-04-06 19:50:56 2576 –a—— C:\Program Files\vwjotcbc.txt
2007-04-02 21:32:59 0 d——– C:\Program Files\Java
2007-04-01 21:01:30 4212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-03-29 21:59:32 0 d——– C:\Program Files\MSN Messenger
2007-03-23 15:48:12 0 d–h—– C:\Program Files\InstallShield Installation Information
2007-03-23 15:48:12 0 d——– C:\Program Files\Google
2007-03-09 01:36:28 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-09 01:36:28 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-09 01:36:28 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-09 00:02:00 75512 –a—— C:\WINDOWS\zllsputility.exe
2007-03-09 00:01:42 1087216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-03-08 23:47:48 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-03 21:00:24 532480 –a—— C:\WINDOWS\system32\Sci Fi Screensaver.scr
2007-03-03 09:55:02 0 d——– C:\Program Files\Common Files\Ahead
2007-01-27 15:53:42 139264 –a—— C:\WINDOWS\mirar_distro_876260.exe
2007-01-27 15:53:34 374 –a—— C:\Documents and Settings\michael\Application Data\internaldb6334.dat
2007-01-27 15:53:33 538 –a—— C:\Documents and Settings\michael\Application Data\internaldb8467.dat
2007-01-27 15:53:33 18432 –a—— C:\Documents and Settings\michael\Application Data\internaldb41.dat
2007-01-19 11:53:04 51056 –a—— C:\WINDOWS\system32\sirenacm.dll
2007-01-16 03:32:07 689280 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-01-16 03:23:20 90112 –a—— C:\WINDOWS\system32\AVASTSS.scr


– Registry Dump —————————————————————


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"SP2 Connection Patcher"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
"Creative Detector"="D:\\Programs\\Creative MediaSource\\Detector\\CTDetect.exe /R"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Yahoo! Pager"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"avast!"="D:\\Programs\\Avast!\\ashDisp.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"WinPatrol"="D:\\Programs\\WinPatrol 9.8\\winpatrol.exe"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"D:\\programs\\Quicktime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"D:\\Programs\\iTunes\\iTunesHelper.exe\""
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"SoundService"="rundll32.exe \"C:\\WINDOWS\\system32\\kdytlmjj.dll\",setvm"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"="SpywareGuard"
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
"{D15EFFBE-61EE-480B-9507-25264732DE0F}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://i.myspace.com/img/groups/crs/goblet…r/group_800.jpg

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvspn

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



– End of Deckard's System Scanner: finished at 2007-04-09 at 22:29:15 ———
Hi

I think that the main problem is that you should stay completely offline all the time (it downloads new baddies as soon as you connect to internet). You really don't have another computer that you could use for posting logs?

If instructions doesn't work, I'll ask experts for help.

Boot in safe mode

Use process explorer + otmoveit to file in Winlogon Notify

Use otmoveit to these:

C:\WINDOWS\system32\ggjlm.bak1
C:\Documents and Settings\michael\pp.exe
C:\WINDOWS\system32\xyxyb.bak2
C:\WINDOWS\system32\xyxyb.bak1

Fix these with HijackThis:

O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\htcsmtbd.dll (file missing)
O2 - BHO: (no name) - {F94AC239-F181-46E9-B1D8-9DFB13F89F1F} - C:\WINDOWS\system32\mljgg.dll (file missing)
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\kdytlmjj.dll",setvm
O20 - Winlogon Notify: wvuvspn - C:\WINDOWS\SYSTEM32\wvuvspn.dll

Reboot

Re-run dss

Re-run vundofix

Post:

- vundofix report
- dss log
Yeah, I just realised that myself, I'm on the net most of the time and don't even think to turn the modem off when I'm running scans. Technically no, my old computers packed away in a box in the garage :P I'll be back at TAFE next week though, so I can use the net on the library computers during my lunchbreak. But yeah, I'll get onto those instructions soon, I think safe modes the way to go.
Hey, for the first time, the Vundofix scan has found no infected files, yay. Now would you know how exactly I go about preventing more files being downloaded as soon as I turn the modem on? I've stopped MSN Messenger being in the tray on startup, which is a major cause of it I think. It's all looking good, hopefully touch wood not having MSN come up has prevented the worm from being effective. I really think it's time to home in on the main source of all this, MSN Messenger is still being controlled by the worm last time I checked this arvo. Heres the reports:

Vundofix Report

VundoFix V6.3.18

Checking Java version…

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 11:32:50 PM 4/9/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

DSS Log

Deckard's System Scanner v20070328.36
Run by [removed] on 2007-04-09 at 23:49:20
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as michael.exe) ———————————————

Logfile of HijackThis v1.99.1
Scan saved at 11:49:32 PM, on 4/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Programs\Avast!\aswUpdSv.exe
D:\Programs\Avast!\ashserv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
D:\Programs\Avast!\ashMaiSv.exe
D:\Programs\Avast!\ashWebSv.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programs\Avast!\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Programs\WinPatrol 9.8\winpatrol.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
D:\programs\Quicktime\qttask.exe
D:\Programs\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Programs\iTunes\iPod\bin\iPodService.exe
D:\Programs\Creative MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
D:\Programs\SpywareGuard\sgmain.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
D:\Programs\SpywareGuard\sgbhp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\michael\Desktop\dss.exe
D:\Programs\HIJACK~1\michael.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\programs\Acrobat Reader\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Programs\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\system32\htcsmtbd.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programs\Avast!\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] D:\Programs\WinPatrol 9.8\winpatrol.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\Quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [Creative Detector] D:\Programs\Creative MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = D:\Programs\SpywareGuard\sgmain.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: LG SyncManager.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C0DAA4E-35A3-4970-822E-F5F405E54798}: Domain = vic.bigpond.net.au
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Programs\Avast!\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Programs\Avast!\ashserv.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Programs\Avast!\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Programs\Avast!\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Programs\iTunes\iPod\bin\iPodService.exe
O23 - Service: STOPzilla Local Service - Unknown owner - D:\Programs\STOPzilla\szntsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


– Files created between 2007-03-09 and 2007-04-09 —————————–

2007-04-09 22:20:36 0 d——– C:\WINDOWS\Prefetch
2007-04-06 21:58:36 0 d——– C:\!KillBox
2007-04-06 20:05:01 0 d——– C:\avenger
2007-04-06 15:28:03 0 d——– C:\WAR2
2007-04-06 09:57:59 462330 –a—— C:\dss.exe
2007-04-03 18:24:34 0 d——– C:\Getservice
2007-04-03 16:29:24 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-04-02 10:26:31 0 d——– C:\VundoFix Backups
2007-03-29 21:59:20 0 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-03-23 15:49:19 0 d——– C:\Documents and Settings\michael\Application Data\Google
2007-03-11 23:23:37 0 d——– C:\Documents and Settings\michael\Application Data\Yahoo! Messenger


– Find3M Report —————————————————————

2007-04-09 23:32:03 0 d——– C:\Program Files\SP2 Connection Patcher
2007-04-06 19:50:56 2576 –a—— C:\Program Files\vwjotcbc.txt
2007-04-02 21:32:59 0 d——– C:\Program Files\Java
2007-04-01 21:01:30 4212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-03-29 21:59:32 0 d——– C:\Program Files\MSN Messenger
2007-03-23 15:48:12 0 d–h—– C:\Program Files\InstallShield Installation Information
2007-03-23 15:48:12 0 d——– C:\Program Files\Google
2007-03-09 01:36:28 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-09 01:36:28 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-09 01:36:28 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-09 00:02:00 75512 –a—— C:\WINDOWS\zllsputility.exe
2007-03-09 00:01:42 1087216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-03-08 23:47:48 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-03 21:00:24 532480 –a—— C:\WINDOWS\system32\Sci Fi Screensaver.scr
2007-03-03 09:55:02 0 d——– C:\Program Files\Common Files\Ahead
2007-01-27 15:53:42 139264 –a—— C:\WINDOWS\mirar_distro_876260.exe
2007-01-27 15:53:34 374 –a—— C:\Documents and Settings\michael\Application Data\internaldb6334.dat
2007-01-27 15:53:33 538 –a—— C:\Documents and Settings\michael\Application Data\internaldb8467.dat
2007-01-27 15:53:33 18432 –a—— C:\Documents and Settings\michael\Application Data\internaldb41.dat
2007-01-19 11:53:04 51056 –a—— C:\WINDOWS\system32\sirenacm.dll
2007-01-16 03:32:07 689280 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-01-16 03:23:20 90112 –a—— C:\WINDOWS\system32\AVASTSS.scr


– Registry Dump —————————————————————


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"SP2 Connection Patcher"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
"Creative Detector"="D:\\Programs\\Creative MediaSource\\Detector\\CTDetect.exe /R"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Yahoo! Pager"="C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe -quiet"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SiSUSBRG"="C:\\WINDOWS\\SiSUSBrg.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"avast!"="D:\\Programs\\Avast!\\ashDisp.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"WinPatrol"="D:\\Programs\\WinPatrol 9.8\\winpatrol.exe"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"QuickTime Task"="\"D:\\programs\\Quicktime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"D:\\Programs\\iTunes\\iTunesHelper.exe\""
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{81559C35-8464-49F7-BB0E-07A383BEF910}"="SpywareGuard"
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
"{D15EFFBE-61EE-480B-9507-25264732DE0F}"=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ http://i.myspace.com/img/groups/crs/goblet…r/group_800.jpg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



– End of Deckard's System Scanner: finished at 2007-04-09 at 23:50:05 ———
Hi

I suggest that you uninstall & re-install MSN Messenger.

Well if there's no bad files left I think that they won't download more :)

Let's do one offline scan now:

Please print these instructions out, or write them down, as you can't read them during the fix.

Please download MWav:
  • Unzip it to its predetermined directory (C:\Kaspersky)
  • Locate kavupd.exe in the new folder and double-click to Update.
  • If your firewall gives any messages about this program accessing to internet, allow it.
  • If it says the signatures are more than 30 days old, keep trying, until you get the actual definition updates.
  • When you see Updates Downloaded Successfully, hit Enter to continue.
  • Restart onto Safe Mode and locate the Kaspersky folder.
  • Locate mwavscan.com and double-click on it to launch the MWAV Scanner.
Now lets do the settings:
  • Leave the Default Settings checked.
  • Add a check to Drives
  • This will light up All Drives
  • Add a check to Scan all Files
  • Click Scan Clean to begin.
This scan might take around 3+ hours to finish when set to scan everything.
  • Please be sure it has finished before proceeding.
  • Once the Scan has finished, all entries identified as Infected, will be displayed in the lower panel.
  • Highlight everything that is inside the lower panel and hit Ctrl+C at the same time to copy.
  • Open an empty notepad file and paste the results (Ctrl+V) to it. Save the notepad to your desktop, name it as you want (e.g; MWav Results).
Reboot into normal Windows and post the results here along with a fresh HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI