Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93104 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

I Am Infected And Need Help.


  • Please log in to reply
30 replies to this topic

#1 vu_loki

vu_loki

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 03 April 2007 - 12:50 PM

Hello all,
I became infected with something on the 23rd of March. I have used adaware, symantic corporate edition 9.0, and spybot s&d to try and end my problems. They all find stuff and I remove or fix the problem but it keeps coming back. I think something is being installed or run at startup. of course I don't really know what is happening. Symantic senses an infostealer threat and blocks it but does not find the source when I scan. I decided my best hope is to seek help here. I have run a hijack this scan and the log is as follows:


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 12:41:01 PM, on 4/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AltDesk\AltDesk.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\hh.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Documents and Settings\will\My Documents\My Received Files\software\antispy\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: cdromdrv32.shell_plugin - {0D708714-CF29-488B-98BE-24D1B96230AA} - C:\WINDOWS\system32\cdromdrv32.dll (file missing)
O2 - BHO: (no name) - {182B90A3-F372-438A-800C-6814B4DE417B} - C:\WINDOWS\system32\tuvuutr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {81AE71EE-A184-45CE-8207-53428677F5FB} - C:\WINDOWS\system32\mljgf.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {CED5B102-CDB2-4A2D-8D53-3F54F35C79Ed} - C:\WINDOWS\system32\cdrgmcme.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\essshmpo.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [Handy Backup 4.1] C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon
O4 - HKCU\..\Run: [AltDesk] C:\Program Files\AltDesk\AltDesk.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Policies\Explorer\Run: [{705C6EE4-0DBF-1033-0223-040530030001}] "C:\Program Files\Common Files\{705C6EE4-0DBF-1033-0223-040530030001}\Update.exe" mc-110-12-0000501
O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1137446630656
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\Software\..\Telephony: DomainName = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{94AD5894-E43C-46C8-9A51-8B9982915D10}: NameServer = 10.10.7.6,10.10.11.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O20 - Winlogon Notify: mljgf - C:\WINDOWS\system32\mljgf.dll
O20 - Winlogon Notify: tuvuutr - C:\WINDOWS\SYSTEM32\tuvuutr.dll
O20 - Winlogon Notify: tuvwtts - C:\WINDOWS\SYSTEM32\tuvwtts.dll
O20 - Winlogon Notify: xxyaxxu - C:\WINDOWS\SYSTEM32\xxyaxxu.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: MobiLink Synchronization - coyotEYEPro (ASANYm_coyotEYEPro) - Unknown owner - C:\Program Files\Sybase\SQL Anywhere 9\win32\dbmlsrv9.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 10686 bytes



Please let me know if there is abnything else you need from me to make this an easier fix. Thank you!

    Advertisements

Register to Remove


#2 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 03 April 2007 - 02:13 PM

The version of HJT that you are using is a beta version and, as such, i'd like you to remove it and do the following:

Download a copy of HJTsetup.exe from one of these locations and save it to your Desktop:Location one.
Location two.
Location three.
  • Double click HJTsetup.exe to begin installation.
  • By default it will install to C:\Program Files\HijackThis.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the prompts from there.
  • At the final dialogue box uncheck the box to the left of "Launch Hijackthis" and then click Finish
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download VundoFix.exe by Atribune from here and save it to your desktop.
  • Close all open programs and windows as this may require a reboot.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Post the contents of C:\vundofix.txt and a new HijackThis log.
Note: It is possible that VundoFix encountered a file it could not remove - in this case, VundoFix will run on reboot - simply repeat the above instructions.
Death to the salad eaters!

#3 vu_loki

vu_loki

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 03 April 2007 - 02:40 PM

Here is the new hjt log:

Logfile of HijackThis v1.99.1
Scan saved at 2:37:29 PM, on 4/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\AltDesk\AltDesk.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\essshmpo.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [Handy Backup 4.1] C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon
O4 - HKCU\..\Run: [AltDesk] C:\Program Files\AltDesk\AltDesk.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1137446630656
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\Software\..\Telephony: DomainName = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{94AD5894-E43C-46C8-9A51-8B9982915D10}: NameServer = 10.10.7.6,10.10.11.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: MobiLink Synchronization - coyotEYEPro (ASANYm_coyotEYEPro) - Unknown owner - C:\Program Files\Sybase\SQL Anywhere 9\win32\dbmlsrv9.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - ".exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


And here is the Vundo log:



VundoFix V6.3.19

Checking Java version...

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 2:18:01 PM 4/3/2007

Listing files found while scanning....

C:\WINDOWS\system32\bpqngvhj.dll
C:\WINDOWS\system32\chkgeiqj.dll
C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\fgjlm.bak1
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\hpdfavvj.dll
C:\WINDOWS\system32\isuhwbnv.dll
C:\WINDOWS\system32\jjqcoyeh.dll
C:\WINDOWS\system32\klppfinp.dll
C:\WINDOWS\system32\mdyadqmc.dll
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\oehsphvs.dll
C:\WINDOWS\system32\oyksqecm.dll
C:\WINDOWS\system32\qlhsniyi.dll
C:\WINDOWS\system32\qvajyfgt.dll
C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvwtts.dll
C:\WINDOWS\system32\tuvwvtu.dll
C:\WINDOWS\system32\wddofjpm.dll
C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xxyaxxu.dll
C:\WINDOWS\system32\yhtllcps.dll
C:\WINDOWS\system32\yrgedwtg.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\bpqngvhj.dll
C:\WINDOWS\system32\bpqngvhj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\chkgeiqj.dll
C:\WINDOWS\system32\chkgeiqj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\ddabx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fgjlm.bak1
C:\WINDOWS\system32\fgjlm.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\hpdfavvj.dll
C:\WINDOWS\system32\hpdfavvj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\isuhwbnv.dll
C:\WINDOWS\system32\isuhwbnv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jjqcoyeh.dll
C:\WINDOWS\system32\jjqcoyeh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\klppfinp.dll
C:\WINDOWS\system32\klppfinp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mdyadqmc.dll
C:\WINDOWS\system32\mdyadqmc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\oehsphvs.dll
C:\WINDOWS\system32\oehsphvs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oyksqecm.dll
C:\WINDOWS\system32\oyksqecm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qlhsniyi.dll
C:\WINDOWS\system32\qlhsniyi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qvajyfgt.dll
C:\WINDOWS\system32\qvajyfgt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvuutr.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvwtts.dll
C:\WINDOWS\system32\tuvwtts.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvwvtu.dll
C:\WINDOWS\system32\tuvwvtu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wddofjpm.dll
C:\WINDOWS\system32\wddofjpm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxyaxxu.dll
C:\WINDOWS\system32\xxyaxxu.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\yhtllcps.dll
C:\WINDOWS\system32\yhtllcps.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yrgedwtg.dll
C:\WINDOWS\system32\yrgedwtg.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvuutr.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvwtts.dll
C:\WINDOWS\system32\tuvwtts.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxyaxxu.dll
C:\WINDOWS\system32\xxyaxxu.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Anything else?? I noticed it is giving me heck for having old java installed ...I will remove those. Thanks!

#4 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 03 April 2007 - 04:06 PM

You'll need to update Java to version 6.1 once the Pc has been cleaned up. There are still a few nasties that Vundofix hasn't got rid of, so we'll deal with these first.

Double click Vundofix.exe:
  • Right click an empty area of the central window.
  • Click Add more files?
  • Copy and paste the following into the two boxes, one line in each:
    • C:\WINDOWS\system32\mljgf.dll
      C:\WINDOWS\system32\tuvuutr.dll
  • Click Add File(s).
  • Click Close Window.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Post the contents of C:\vundofix.txt and a new HijackThis log.
Note: It is possible that VundoFix encountered a file it could not remove - in this case, VundoFix will run on reboot - simply repeat the above instructions.
Death to the salad eaters!

#5 vu_loki

vu_loki

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 04 April 2007 - 09:15 AM

Good Morning. Yes vundofix had some problems removing the files but I kept running it until it was successful. here is the new vundofix log:




VundoFix V6.3.19

Checking Java version...

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 2:18:01 PM 4/3/2007

Listing files found while scanning....

C:\WINDOWS\system32\bpqngvhj.dll
C:\WINDOWS\system32\chkgeiqj.dll
C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\fgjlm.bak1
C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\hpdfavvj.dll
C:\WINDOWS\system32\isuhwbnv.dll
C:\WINDOWS\system32\jjqcoyeh.dll
C:\WINDOWS\system32\klppfinp.dll
C:\WINDOWS\system32\mdyadqmc.dll
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\oehsphvs.dll
C:\WINDOWS\system32\oyksqecm.dll
C:\WINDOWS\system32\qlhsniyi.dll
C:\WINDOWS\system32\qvajyfgt.dll
C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvwtts.dll
C:\WINDOWS\system32\tuvwvtu.dll
C:\WINDOWS\system32\wddofjpm.dll
C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xxyaxxu.dll
C:\WINDOWS\system32\yhtllcps.dll
C:\WINDOWS\system32\yrgedwtg.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\bpqngvhj.dll
C:\WINDOWS\system32\bpqngvhj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\chkgeiqj.dll
C:\WINDOWS\system32\chkgeiqj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\ddabx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fgjlm.bak1
C:\WINDOWS\system32\fgjlm.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\hpdfavvj.dll
C:\WINDOWS\system32\hpdfavvj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\isuhwbnv.dll
C:\WINDOWS\system32\isuhwbnv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jjqcoyeh.dll
C:\WINDOWS\system32\jjqcoyeh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\klppfinp.dll
C:\WINDOWS\system32\klppfinp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mdyadqmc.dll
C:\WINDOWS\system32\mdyadqmc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\oehsphvs.dll
C:\WINDOWS\system32\oehsphvs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oyksqecm.dll
C:\WINDOWS\system32\oyksqecm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qlhsniyi.dll
C:\WINDOWS\system32\qlhsniyi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qvajyfgt.dll
C:\WINDOWS\system32\qvajyfgt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvuutr.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvwtts.dll
C:\WINDOWS\system32\tuvwtts.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvwvtu.dll
C:\WINDOWS\system32\tuvwvtu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wddofjpm.dll
C:\WINDOWS\system32\wddofjpm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxyaxxu.dll
C:\WINDOWS\system32\xxyaxxu.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\yhtllcps.dll
C:\WINDOWS\system32\yhtllcps.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yrgedwtg.dll
C:\WINDOWS\system32\yrgedwtg.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvuutr.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvwtts.dll
C:\WINDOWS\system32\tuvwtts.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxyaxxu.dll
C:\WINDOWS\system32\xxyaxxu.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

VundoFix V6.3.19

Checking Java version...

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 2:43:26 PM 4/3/2007

Listing files found while scanning....

C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\tuvuutr.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvuutr.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvuutr.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

VundoFix V6.3.19

Checking Java version...

Java version is 1.4.2.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 3:04:22 PM 4/3/2007

Listing files found while scanning....

C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\tuvuutr.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\fgjlm.ini
C:\WINDOWS\system32\fgjlm.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mljgf.dll
C:\WINDOWS\system32\mljgf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvuutr.dll
C:\WINDOWS\system32\tuvuutr.dll Has been deleted!

Performing Repairs to the registry.
Done!





Here is the latest hjt log:





Logfile of HijackThis v1.99.1
Scan saved at 9:11:43 AM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AltDesk\AltDesk.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\PROGRA~1\MOZILL~2\FIREFOX.EXE
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {0514ACD2-C3F2-4DEA-9EFC-E3A4FF7A297F} - C:\WINDOWS\system32\mljgf.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: cdromdrv32.shell_plugin - {0D708714-CF29-488B-98BE-24D1B96230AA} - C:\WINDOWS\system32\cdromdrv32.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {CED5B102-CDB2-4A2D-8D53-3F54F35C79Ed} - C:\WINDOWS\system32\ofjhbhhn.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\essshmpo.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Handy Backup 4.1] C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon
O4 - HKCU\..\Run: [AltDesk] C:\Program Files\AltDesk\AltDesk.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1137446630656
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\Software\..\Telephony: DomainName = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{94AD5894-E43C-46C8-9A51-8B9982915D10}: NameServer = 10.10.7.6,10.10.11.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: MobiLink Synchronization - coyotEYEPro (ASANYm_coyotEYEPro) - Unknown owner - C:\Program Files\Sybase\SQL Anywhere 9\win32\dbmlsrv9.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Client IP-IPX - Unknown owner - ".exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe





I also did a scan with avg anti-spyware and here is what it found (I have not removed anything using it as of yet, the file found in C:\WINDOWS\potential-virus\ are files I thought were potential bad files based on their date of creation (march 23rd) :




---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:12:57 AM 4/4/2007

+ Scan result:



C:\Program Files\Common Files\{305C6EE4-0DBF-1033-0223-040530030001}\Bar888.dll -> Adware.Bar888 : Ignored.
C:\Program Files\Video ActiveX Object -> Adware.Generic : Ignored.
HKU\S-1-5-21-343818398-764733703-725345543-1003\Software\Microsoft\Active Setup\Installed Components\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} -> Adware.Generic : Ignored.
HKU\S-1-5-21-343818398-764733703-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Ignored.
HKU\S-1-5-21-343818398-764733703-725345543-1003\Software\Internet Security -> Adware.IntCodec : Ignored.
C:\VundoFix Backups\tuvwvtu.dll.bad -> Adware.Virtumonde : Ignored.
C:\WINDOWS\potential-virus\xcun.exe -> Downloader.Small.bve : Ignored.
:mozilla.194:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.247realmedia : Ignored.
:mozilla.47:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.48:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.49:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.51:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.52:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.53:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.54:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.55:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.56:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.57:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.58:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.59:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.60:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.61:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.62:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.63:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.64:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.65:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.66:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.67:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.116:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.117:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.118:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.119:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.190:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.142:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.143:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.144:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.145:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.146:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.147:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.148:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.149:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Ignored.
:mozilla.103:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.104:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.105:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.106:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.107:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.108:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.109:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.110:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.111:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.112:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.45:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.47:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.49:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.50:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.95:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.96:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.97:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.98:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.38:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Atdmt : Ignored.
:mozilla.6:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Bridgetrack : Ignored.
:mozilla.8:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Bridgetrack : Ignored.
:mozilla.43:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Centrport : Ignored.
:mozilla.44:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Centrport : Ignored.
C:\Documents and Settings\will\Cookies\will@clickbank[1].txt -> TrackingCookie.Clickbank : Ignored.
C:\Documents and Settings\will\Cookies\will@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.14:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.20:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.11:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.12:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.13:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.165:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.187:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.212:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.213:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.214:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.215:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.216:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.217:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.90:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.91:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.92:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.37:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.93:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.94:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\will\Cookies\will@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.161:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Paypal : Ignored.
:mozilla.16:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.17:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.18:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.19:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.7:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.171:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.172:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.173:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.174:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.45:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.46:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.34:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.35:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.36:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.37:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.195:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Spinbox : Ignored.
:mozilla.57:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.58:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.59:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.60:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.61:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.166:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.167:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.168:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.169:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.170:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.178:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.188:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Webtrendslive : Ignored.
:mozilla.189:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Webtrendslive : Ignored.
:mozilla.70:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.X10 : Ignored.
:mozilla.71:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.X10 : Ignored.
:mozilla.72:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.X10 : Ignored.
:mozilla.25:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.175:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.176:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.177:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Zedo : Ignored.
C:\Documents and Settings\will\Cookies\will@zedo[2].txt -> TrackingCookie.Zedo : Ignored.


::Report end


Thanks again!!

#6 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 04 April 2007 - 01:26 PM

I guess Vundo likes your system a whole lot!

1) Download SmitfraudFix.exe by S!Ri from here and save it to your Desktop.

2) Double click SmitfraudFix.exe - this will open a Command Window and also create the SmitfraudFix folder on your Desktop. Once you have read the information, "press any key to continue..."
Press "1" and then <ENTER> to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.

A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlog...processutil.htm
Death to the salad eaters!

#7 vu_loki

vu_loki

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 04 April 2007 - 01:56 PM

here is the smitfraudfix.exe log: SmitFraudFix v2.163 Scan done at 13:55:53.51, Wed 04/04/2007 Run from C:\Documents and Settings\will\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\will »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\will\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\will\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\Video ActiveX Object\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32 »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel® PRO/1000 CT Network Connection - Packet Scheduler Miniport DNS Server Search Order: 10.10.7.6 DNS Server Search Order: 10.10.11.2 HKLM\SYSTEM\CCS\Services\Tcpip\..\{94AD5894-E43C-46C8-9A51-8B9982915D10}: NameServer=10.10.7.6,10.10.11.2 HKLM\SYSTEM\CS1\Services\Tcpip\..\{94AD5894-E43C-46C8-9A51-8B9982915D10}: NameServer=10.10.7.6,10.10.11.2 HKLM\SYSTEM\CS2\Services\Tcpip\..\{94AD5894-E43C-46C8-9A51-8B9982915D10}: NameServer=10.10.7.6,10.10.11.2 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End

#8 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 04 April 2007 - 02:23 PM

You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download SDFix by AndyManchesta from here and save it to your Desktop.
Double click SDFix.exe and it will extract the files to a folder on the drive that contains the Windows Directory - typically C:\SDFix.

2) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode:
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
2) Navigate to and open the SDFix folder and double click RunThis.bat to begin the fix.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished - press any key to end the script and load your desktop icons.
  • Once the desktop icons load, the SDFix report will open on screen and a copy will be saved into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
Post a new HJT log, Report.txt AND a description of how your PC is running.
Death to the salad eaters!

#9 vu_loki

vu_loki

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 04 April 2007 - 04:01 PM

here is my report.txt


SDFix: Version 1.76

Run by will - Wed 04/04/2007 - 15:00:36.89

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
Client IP-IPX

"" -e mc-110-12-0000501

Client IP-IPX Deleted


Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

No Trojan Files Found...




ADS Check:

C:\WINDOWS\system32
No streams found.


Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\ASUS\\AsusUpdate\\Update.exe"="C:\\Program Files\\ASUS\\AsusUpdate\\Update.exe:*:Enabled:ASUS Update"
"C:\\WINDOWS\\system32\\ftp.exe"="C:\\WINDOWS\\system32\\ftp.exe:*:Enabled:File Transfer Program"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"C:\\Perl\\bin\\perl.exe"="C:\\Perl\\bin\\perl.exe:*:Disabled:Perl Command Line Interpreter"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"="C:\\Program Files\\QuickTime\\QuickTimePlayer.exe:*:Enabled:QuickTime Player"
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"="C:\\WINDOWS\\system32\\usmt\\migwiz.exe:*:Disabled:Files and Settings Transfer Wizard"
"C:\\Program Files\\Sybase\\Shared\\Sybase Central 4.3\\win32\\scjview.exe"="C:\\Program Files\\Sybase\\Shared\\Sybase Central 4.3\\win32\\scjview.exe:*:Enabled:Sybase Central"
"C:\\Program Files\\Sybase\\SQL Anywhere 9\\win32\\dbisqlg.exe"="C:\\Program Files\\Sybase\\SQL Anywhere 9\\win32\\dbisqlg.exe:*:Enabled:Adaptive Server Anywhere ISQL"
"C:\\Program Files\\Sybase\\SQL Anywhere 9\\win32\\dbeng9.exe"="C:\\Program Files\\Sybase\\SQL Anywhere 9\\win32\\dbeng9.exe:*:Enabled:Adaptive Server Anywhere Database Engine"
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE:*:Disabled:Connection Manager"
"C:\\Program Files\\FileZilla\\FileZilla.exe"="C:\\Program Files\\FileZilla\\FileZilla.exe:*:Disabled:FileZilla"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\Tor\\tor.exe"="C:\\Program Files\\Tor\\tor.exe:*:Enabled:tor"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"


Remaining Files:
---------------


Checking For Files with Hidden Attributes :

C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL0004.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL0479.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL0911.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL1266.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL1758.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL2584.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL2736.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL3527.tmp
C:\Documents and Settings\will\Application Data\Microsoft\Word\~WRL4033.tmp
C:\Documents and Settings\will\My Documents\~WRL2295.tmp
C:\Documents and Settings\will\My Documents\~WRL3670.tmp
C:\Documents and Settings\will\My Documents\~WRL3845.tmp
C:\Documents and Settings\will\My Documents\~WRL4031.tmp

Finished


hjt log:


Logfile of HijackThis v1.99.1
Scan saved at 3:54:13 PM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AltDesk\AltDesk.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {0514ACD2-C3F2-4DEA-9EFC-E3A4FF7A297F} - C:\WINDOWS\system32\mljgf.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: cdromdrv32.shell_plugin - {0D708714-CF29-488B-98BE-24D1B96230AA} - C:\WINDOWS\system32\cdromdrv32.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {CED5B102-CDB2-4A2D-8D53-3F54F35C79Ed} - C:\WINDOWS\system32\ofjhbhhn.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\essshmpo.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Handy Backup 4.1] C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon
O4 - HKCU\..\Run: [AltDesk] C:\Program Files\AltDesk\AltDesk.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1137446630656
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\Software\..\Telephony: DomainName = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{94AD5894-E43C-46C8-9A51-8B9982915D10}: NameServer = 10.10.7.6,10.10.11.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: MobiLink Synchronization - coyotEYEPro (ASANYm_coyotEYEPro) - Unknown owner - C:\Program Files\Sybase\SQL Anywhere 9\win32\dbmlsrv9.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


so far it is running smoothly however sdfix did hang for @ 45 minutes and I had to force a reboot.

#10 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 04 April 2007 - 04:36 PM

You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware 7.5 from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.
  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is..." - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

3) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: (no name) - {0514ACD2-C3F2-4DEA-9EFC-E3A4FF7A297F} - C:\WINDOWS\system32\mljgf.dll (file missing)
O2 - BHO: cdromdrv32.shell_plugin - {0D708714-CF29-488B-98BE-24D1B96230AA} - C:\WINDOWS\system32\cdromdrv32.dll (file missing)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: (no name) - {CED5B102-CDB2-4A2D-8D53-3F54F35C79Ed} - C:\WINDOWS\system32\ofjhbhhn.dll


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
3) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

4) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

5) Go to Start > Control Panel > Internet Options.

For I.E. 6 - under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.

For I.E. 7 - under Browsing History, click delete...
Under Temporary Internet Files, click Delete files...

6) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG Anti-Spyware.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG Anti-Spyware.

7) Remove any/all of the following files/folders that you can find:

Files

C:\WINDOWS\system32\ofjhbhhn.dll

As an example:
To delete C:\WINDOWS\system32\filetogo.bye
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'


8) Boot into Normal Mode.

Post a new HJT log, the AVG log AND a description of how your PC is running.
Death to the salad eaters!

    Advertisements

Register to Remove


#11 vu_loki

vu_loki

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 05 April 2007 - 09:53 AM

New HJT log.


Logfile of HijackThis v1.99.1
Scan saved at 9:51:05 AM, on 4/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AltDesk\AltDesk.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\essshmpo.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Handy Backup 4.1] C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon
O4 - HKCU\..\Run: [AltDesk] C:\Program Files\AltDesk\AltDesk.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1137446630656
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\Software\..\Telephony: DomainName = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{94AD5894-E43C-46C8-9A51-8B9982915D10}: NameServer = 10.10.7.6,10.10.11.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = wru.umt.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = wru.umt.edu
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: MobiLink Synchronization - coyotEYEPro (ASANYm_coyotEYEPro) - Unknown owner - C:\Program Files\Sybase\SQL Anywhere 9\win32\dbmlsrv9.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: CYGWIN sshd (sshd) - Unknown owner - C:\cygwin\bin\cygrunsrv.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe




Results of the AVG anti-spyware scan:




---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:05:14 AM 4/5/2007

+ Scan result:



C:\Program Files\Common Files\{305C6EE4-0DBF-1033-0223-040530030001}\Bar888.dll -> Adware.Bar888 : Cleaned with backup (quarantined).
C:\Program Files\Video ActiveX Object -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-343818398-764733703-725345543-1003\Software\Microsoft\Active Setup\Installed Components\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-343818398-764733703-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-343818398-764733703-725345543-1003\Software\Internet Security -> Adware.IntCodec : Cleaned with backup (quarantined).
C:\VundoFix Backups\tuvwvtu.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\potential-virus\xcun.exe -> Downloader.Small.bve : Cleaned with backup (quarantined).
:mozilla.194:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.47:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.48:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.49:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.51:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.52:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.53:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.54:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.55:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.56:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.57:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.58:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.59:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.60:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.61:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.62:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.63:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.64:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.65:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.66:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.67:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.117:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.118:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.119:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.190:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.142:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.143:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.144:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.145:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.146:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.147:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.148:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.149:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.103:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.104:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.105:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.106:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.107:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.108:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.109:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.110:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.111:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.112:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.53:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.54:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.56:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.57:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.95:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.96:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.97:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.98:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.38:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.8:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.6:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.8:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.122:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.43:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.44:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\will\Cookies\will@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\will\Cookies\will@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.20:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.127:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.128:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.129:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.165:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.187:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.212:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.213:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.214:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.215:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.216:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.217:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.90:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.91:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.92:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.136:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.93:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.94:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\will\Cookies\will@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.161:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.16:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.17:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.18:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.19:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.38:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.39:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.40:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.43:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.7:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.92:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.93:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.171:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.172:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.173:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.174:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.45:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.46:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.34:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.35:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.36:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.37:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.195:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Spinbox : Cleaned.
:mozilla.50:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.51:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.52:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.58:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.59:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.114:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.115:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.116:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.117:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.118:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.119:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.120:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.121:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.166:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.167:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.168:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.169:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.170:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.178:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.9:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.188:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.189:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.70:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.X10 : Cleaned.
:mozilla.71:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.X10 : Cleaned.
:mozilla.72:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.X10 : Cleaned.
:mozilla.78:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.79:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.80:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.81:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.82:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.175:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.176:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.177:C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.71:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.72:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.73:C:\Documents and Settings\will\Application Data\Mozilla\Firefox\Profiles\aeh2nzut.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\will\Cookies\will@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.


::Report end



The machine is running normally now--no popups or other strangeness yet this morning. :) :)

#12 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 05 April 2007 - 01:10 PM

The machine is running normally now--no popups or other strangeness yet this morning.

Always good to read! Given the gunk that was lurking on your hard drive, i'd like you to give it a workout it for another 24 hours and then do the following:

Run the following online scan: Panda ActiveScan.
  • Please note that IE is required to run this scan.
  • You will need to fill in the "Country, region, email address" information before you can download and install the ActiveX components necessary to run the scan.
  • Decide whether you want to click the radio button underneath this part that says -
    "I do not want to receive marketing information from Panda Software and/or its International Representatives where applicable." - it's your choice!
  • When you are asked to "Select a device to scan...", click on "My Computer".
When the scan has finished, click See Report > Save Report which by default will save the scan results as Activescan.txt in My Documents.

Copy and paste the result of the above scan into your next reply along with a fresh HJT log AND a description of how your PC is running.

It will probably be wise to post this in a second reply:

Download gmer.zip from here and save it to your Desktop.
You will need to unzip it before you run it.

To do this: Right click on the zipped folder and from the menu that appears, click on Extract All...
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


Double click gmer.exe to begin:
  • If you get a message about "system modification", click Yes and work through the rest of the instructions.
  • Ensure that the Rootkit Tab at the top is selected.
  • Make sure all the boxes on the right of the screen are checked, EXCEPT for ‘Show All’.
  • Click the Scan button on the right.
  • When the scan has completed, (you'll have time for a snack and a cuppa!), click the Copy button underneath - this will save the report to your Clipboard.
  • Paste it into Notepad (Start > All Programs > Accessories > Notepad) and save it somewhere convenient.
  • Click the >>> Tab at the top and select the Autostart Tab.
  • Click the Scan button on the right - this one should only take seconds to complete.
  • Save the log as before.
Copy and paste both reports into your next reply - you may need to post them separately.
The Preview option may show the whole logs being posted, but they sometimes get cut down when the actual post is made, so check the post once it is completed.

All being well, you'll be clean and that will be that.
Death to the salad eaters!

#13 vu_loki

vu_loki

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 10 April 2007 - 10:14 AM

Incident Status Location Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\will\Application Data\Mozilla\Profiles\default\2jz69z5s.slt\cookies.txt[.atwola.com/] Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\will\Cookies\will@ads.addynamix[2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\will\Cookies\will@advertising[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\will\Cookies\will@atdmt[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\will\Cookies\will@doubleclick[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\will\Cookies\will@fastclick[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\will\Cookies\will@media.fastclick[1].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\will\Cookies\will@overture[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\will\Cookies\will@realmedia[2].txt Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\will\Cookies\will@tradedoubler[1].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\will\Cookies\will@trafficmp[2].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\will\Cookies\will@tribalfusion[2].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\will\Cookies\will@zedo[2].txt Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\will\My Documents\My Received Files\software\antispy\SDFix.exe[SDFix\apps\Process.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\will\My Documents\My Received Files\software\antispy\SmitfraudFix\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\tuvuutr.dll.bad Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\tuvwtts.dll.bad Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\xxyaxxu.dll.bad Adware:adware/tubby Not disinfected C:\WINDOWS\system32\WER8274.DLL

#14 vu_loki

vu_loki

    New Member

  • Authentic Member
  • Pip
  • 18 posts

Posted 10 April 2007 - 10:15 AM

GMER 1.0.12.12086 - http://www.gmer.net
Rootkit scan 2007-04-10 10:09:30
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.12 ----

SSDT E172F110 ZwConnectPort
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

---- Kernel code sections - GMER 1.0.12 ----

? PxHelp20.sys The system cannot find the file specified.
? drvmcdb.sys The system cannot find the file specified.
? system32\drivers\sscdbhk5.sys The system cannot find the file specified.
? system32\drivers\ssrtln.sys The system cannot find the file specified.
? system32\drivers\drvnddm.sys The system cannot find the file specified.
? system32\dla\tfsndres.sys The system cannot find the file specified.
? system32\dla\tfsnifs.sys The system cannot find the file specified.
? system32\dla\tfsnopio.sys The system cannot find the file specified.
? system32\dla\tfsnpool.sys The system cannot find the file specified.
? system32\dla\tfsnboio.sys The system cannot find the file specified.
? system32\dla\tfsncofs.sys The system cannot find the file specified.
? system32\dla\tfsndrct.sys The system cannot find the file specified.
? system32\dla\tfsnudf.sys The system cannot find the file specified.
? system32\dla\tfsnudfa.sys The system cannot find the file specified.

---- User code sections - GMER 1.0.12 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[2324] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 00ACF205 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2324] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 00C5FEBF C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2324] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 00C5FE40 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2324] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 00C5FE84 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2324] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 00C5FDCC C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2324] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 00C5FE06 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2324] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 00C5FEFA C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[2324] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 00AF15DA C:\WINDOWS\system32\IEFRAME.dll

---- Devices - GMER 1.0.12 ----

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [A80AF175] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [A80AF175] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [A80AF175] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [A80AF175] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [A80AF175] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [A80AF2ED] tfsnifs.sys

---- EOF - GMER 1.0.12 ----



Autostart Scan:



GMER 1.0.12.12086 - http://www.gmer.net
Autostart scan 2007-04-10 10:10:14
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
NavLogon@DLLName = C:\WINDOWS\system32\NavLogon.dll
WgaLogon@DLLName = WgaLogon.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
ASANYm_coyotEYEPro /*MobiLink Synchronization - coyotEYEPro*/@ = C:\Program Files\Sybase\SQL Anywhere 9\win32\dbmlsrv9.exe -hvASANYm_coyotEYEPro /*file not found*/
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
ccEvtMgr /*Symantec Event Manager*/@ = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ccSetMgr /*Symantec Settings Manager*/@ = "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
DefWatch /*Symantec AntiVirus Definition Watcher*/@ = "C:\Program Files\Symantec AntiVirus\DefWatch.exe"
NVSvc /*NVIDIA Display Driver Service*/@ = %SystemRoot%\system32\nvsvc32.exe
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
SoundMAX Agent Service (default) /*SoundMAX Agent Service*/@ = C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe
sshd /*CYGWIN sshd*/@ = C:\cygwin\bin\cygrunsrv.exe /*file not found*/
Symantec AntiVirus /*Symantec AntiVirus*/@ = "C:\Program Files\Symantec AntiVirus\Rtvscan.exe"
WinDefend /*Windows Defender*/@ = "C:\Program Files\Windows Defender\MsMpEng.exe"
WMPNetworkSvc /*Windows Media Player Network Sharing Service*/@ = "C:\Program Files\Windows Media Player\WMPNetwk.exe"

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@Ptipbmfrundll32.exe ptipbmf.dll,SetWriteCacheMode = rundll32.exe ptipbmf.dll,SetWriteCacheMode
@SoundMAXPnPC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
@SoundMAX"C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray = "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
@ASUS ProbeC:\Program Files\ASUS\Probe\AsusProb.exe /*file not found*/ = C:\Program Files\ASUS\Probe\AsusProb.exe /*file not found*/
@ccApp"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
@vptrayC:\PROGRA~1\SYMANT~1\VPTray.exe = C:\PROGRA~1\SYMANT~1\VPTray.exe
@ISUSPM StartupC:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup /*file not found*/ = C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup /*file not found*/
@ISUSScheduler"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start /*file not found*/ = "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start /*file not found*/
@QuickTime Task"C:\Program Files\QuickTime\qttask.exe" -atboottime = "C:\Program Files\QuickTime\qttask.exe" -atboottime
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
@nwiznwiz.exe /install = nwiz.exe /install
@NvMediaCenterRunDLL32.exe NvMCTray.dll,NvTaskbarInit = RunDLL32.exe NvMCTray.dll,NvTaskbarInit
@WatchDogC:\Program Files\mobile PhoneTools\WatchDog.exe /*file not found*/ = C:\Program Files\mobile PhoneTools\WatchDog.exe /*file not found*/
@SunJavaUpdateSched"C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" = "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
@Windows Defender"C:\Program Files\Windows Defender\MSASCui.exe" -hide = "C:\Program Files\Windows Defender\MSASCui.exe" -hide
@!AVG Anti-Spyware"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@Handy Backup 4.1C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon /*file not found*/ = C:\Program Files\Novosoft\Handy Backup\hbagent.exe -logon /*file not found*/
@AltDeskC:\Program Files\AltDesk\AltDesk.exe = C:\Program Files\AltDesk\AltDesk.exe
@WMPNSCFGC:\Program Files\Windows Media Player\WMPNSCFG.exe = C:\Program Files\Windows Media Player\WMPNSCFG.exe
@BitTorrent"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized /*file not found*/ = "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized /*file not found*/
@Yahoo! Pager"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet = "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WPDShServiceObj = C:\WINDOWS\system32\WPDShServiceObj.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
@{182B90A3-F372-438A-800C-6814B4DE417B}(null) =
@{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}C:\PROGRA~1\WIFD1F~1\MpShHook.dll = C:\PROGRA~1\WIFD1F~1\MpShHook.dll
@{57B86673-276A-48B2-BAE7-C6DBB3020EB8}C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} /*Adobe.Acrobat.ContextMenu*/C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Program Files\Real\RealPlayer\rpshell.dll = C:\Program Files\Real\RealPlayer\rpshell.dll
@{68DD2975-D9B9-4530-846E-EFA41B7470ED} /*Handy Backup*/(null) =
@{2AA59FC0-31E8-42DA-9D3C-E9A52953853B} /*CopyToCD shell extension*/(null) =
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{BDA77241-42F6-11d0-85E2-00AA001FE28C} /*LDVP Shell Extensions*/C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} /*OpenOffice.org Column Handler*/"C:\Program Files\OpenOffice.org 2.1\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.1\program\shlxthdl.dll"
@{087B3AE3-E237-4467-B8DB-5A38AB959AC9} /*OpenOffice.org Infotip Handler*/"C:\Program Files\OpenOffice.org 2.1\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.1\program\shlxthdl.dll"
@{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice.org Property Sheet Handler*/"C:\Program Files\OpenOffice.org 2.1\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.1\program\shlxthdl.dll"
@{3B092F0C-7696-40E3-A80F-68D74DA84210} /*OpenOffice.org Thumbnail Viewer*/"C:\Program Files\OpenOffice.org 2.1\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.1\program\shlxthdl.dll"
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft.XPS.Shell.Metadata.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft.XPS.Shell.Thumbnail.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved@{BDEADF00-C265-11d0-BCED-00A0C90AB50F} /*Web Folders*/ = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
Adobe.Acrobat.ContextMenu@{D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} = C:\Program Files\Adobe\Acrobat 6.0\Acrobat Elements\ContextMenu.dll
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
LDVPMenu@{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
VIDEOTRANS@{548773BA-874E-4C02-9DC7-B7A096772C7D} = C:\Program Files\MP3 Player Utilities 3.57\AMVTools\SrcCount.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu@{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\PROGRA~1\SPYBOT~1\SDHelper.dll = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll = C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
@{AE7CD045-E861-484f-8273-0445EE161910}C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll = C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\System32\scrnsave.scr

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft....k/?LinkId=69157
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft....k/?LinkId=69157
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.yahoo.com/ = http://www.yahoo.com/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
lid@CLSID = C:\WINDOWS\System32\msvidctl.dll
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters@Domain = wru.umt.edu

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{94AD5894-E43C-46C8-9A51-8B9982915D10} /*Local Area Connection*/ >>>
@IPAddress10.8.19.34 = 10.8.19.34
@NameServer10.10.7.6,10.10.11.2 = 10.10.7.6,10.10.11.2
@DefaultGateway10.8.19.254 = 10.8.19.254
@Domain =

C:\Documents and Settings\All Users\Start Menu\Programs\Startup >>>
Acrobat Assistant.lnk = Acrobat Assistant.lnk
Adobe Reader Speed Launch.lnk = Adobe Reader Speed Launch.lnk
Adobe Reader Synchronizer.lnk = Adobe Reader Synchronizer.lnk
Acrobat Assistant.lnk = Acrobat Assistant.lnk
Adobe Reader Speed Launch.lnk = Adobe Reader Speed Launch.lnk
Adobe Reader Synchronizer.lnk = Adobe Reader Synchronizer.lnk

---- EOF - GMER 1.0.12 ----



So far the machine seems to be running fine. No glitches as of yet.

vu_loki

#15 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 10 April 2007 - 12:18 PM

Glad to hear it.

You can delete the following file: C:\WINDOWS\system32\WER8274.DLL
and this folder: C:\VundoFix Backups

You are running an old version of Sun Java which needs updating:
  • Go here and click on the Download button to the right of Java Runtime Environment (JRE) 6u1.
  • Accept the license agreement by clicking the appropriate radio button and then continue.
  • Under Windows Platform - Java™ SE Runtime Environment 6 Update 1, click the Windows Offline Installation, Multi-language link.
  • Go to Add/Remove Programs and remove any entries that refer to Java 2 Runtime Environment and then reboot your PC.
  • Navigate to and delete the following folder, if it exists: C:\Program Files\Java.
  • Finally double click the installation file that you downloaded earlier.
As long as the above goes OK, I want you to run your PC as normal for a few days. When you are happy that everything is fine, do the following:

Update your anti-virus program,
Disable System Restore,
Boot into Safe Mode,
Scan your computer for viruses.
When you get the all clear, reboot into Normal Mode.
Re-enable System Restore,
Create a Restore Point.
This will give a clean Restore Point should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.
Death to the salad eaters!

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users