This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Various Problems

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is my HJT file. Not sure exactly what the problem is. I have run AdAware and Spybot with different responses coming as to what is the actual problem. I closed all programs, but I couldn't keep the popups from happening for log enough to run HJT. Thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 10:24:56 PM, on 4/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\WINDOWS\system32\svchost.exe
C:\DOCUME~1\Daren\LOCALS~1\Temp\hhin.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Daren\LOCALS~1\Temp\Rar$EX01.094\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Getca] C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [VaCtrls] v7
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\tusqno.dll",setvm
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\wvwwwx.dll",realset
O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O4 - HKLM\..\RunOnce: [clcl] command.com /c del C:\WINDOWS\system32\clcl.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [Ben] C:\WINDOWS\?icrosoft\?canregw.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [qwqm] C:\PROGRA~1\COMMON~1\qwqm\qwqmm.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168893765694
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Belkin 54Mbps Wireless USB Network Service (Belkin 54Mbps Wireless USB) - Unknown owner - C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi,rnjholleyand welcome to Tom Coyote forums

I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Thanks for your patience!
dan
Hi rnjholley

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed.

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.

Also do whatever else that seems appropriate.

If you decide to reformat you should check that you have all the necessary information and software.

If you decide to continue with a cleanup you should not use this computer for financial or other sensitive transaction.

Let me know what you want to do.

Thanks dan
Once the cleanup is done can I continue to use the computer as I did before (i.e. sensitive information?). If so then I choose to just clean it up.
I'm happy to carry out the clean up for you as long as you have taken on board the warning. I cant guarantee that it will be safe to carry out sensitive Information on. You have to make that decision as to the sensitive Information you carry out on your pc. Please let me know if you want to go ahead dan
Hi rnjholley

Are you having any problem with net connection?

This is a badly Infected machine.I'm not suprised It's infested you have no protection! we will deal with that soon, I need to get on top of the Infections.
___________

Ok, first thing I want you to do :

Highjackthis.exe is running out of a temp folder.
HijackThis.exe in a Temp folder: > C:\DOCUME~1\Daren\LOCALS~1\Temp\Rar$EX01.094\HijackThis.exe < It Can be accidentally deleted when the temp files are cleaned out, so to the backups.
Highjackthis.exe needs a permanant folder of it's own in order to create backups
Create a folder on the desktop, right click on the desktop, select new folder,and name it HJT . Now locate HijackThis.exe copy and paste it into the new folder ( HJT ) you created on the desktop.
Do this before you continue.

____________

Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath,browse and find the file click open which will place it in the field.do this one file at a time.

C:\DOCUME~1\Daren\LOCALS~1\Temp\hhin.exe
C:\WINDOWS\wvwwwx.dll
C:\PROGRA~1\COMMON~1\qwqm\qwqmm.exe

Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html


Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.


Please post vundofix.txt, jotti's report and a new HJT log
I was given this computer by my brother after he bought a new laptop so really I don't know much about what I am getting into here. The antivirus keeps popping up saying the PC isn't protected so it is in the works. I have been using a Mac (not by choice) for the last year or so, therefore I really don't know what is the best option for virus protection. anyway…

I think I have all the info you asked for. If I missed anything, or copied the wrong info, I will get it right away.

———
Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1

File: hhin.exe
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 61c8339fc77ec99480f5f0b84c6a8e38
Packers detected: -

Scanner results
Scan taken on 14 Apr 2007 03:57:47 (GMT)
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found BehavesLike:Win32.Malware (probable variant)
ClamAV Found nothing
Dr.Web Found BackDoor.Insyst
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found W32/Backdoor.AW
Panda Antivirus Found nothing
Rising Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found Trojan.Agent.82 (paranoid heuristics) (probable variant)

———
File: wvwwwx.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 59cde4eeb40b012559fb0860692dbc0d
Packers detected: UPACK

Scanner results
Scan taken on 14 Apr 2007 04:01:12 (GMT)
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found W32/Tibs.BT!tr
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found W32/Suspicious_U.gen
Panda Antivirus Found nothing
Rising Antivirus Found nothing
VirusBuster Found Packed/Upack
VBA32 Found nothing

———
File: qwqmm.exe_
Status: INFECTED/MALWARE
MD5 50bc808c87d8f0c428780bb6d09041e1
Packers detected: PE_PATCH.UPX, UPX

Scanner results
Scan taken on 14 Apr 2007 04:04:23 (GMT)
AntiVir Found TR/Click.Agent.JH.3
ArcaVir Found Trojan.Clicker.Agent.Jh
Avast Found Win32:Obfuscated-DH
AVG Antivirus Found Downloader.Generic3.ZJQ
BitDefender Found Trojan.AVKiller.Agent.E
ClamAV Found Trojan.Clicker-139
Dr.Web Found Trojan.DownLoader.19701
F-Prot Antivirus Found W32/Trojan.ABVY
F-Secure Anti-Virus Found Trojan-Clicker.Win32.Agent.jh
Fortinet Found nothing
Kaspersky Anti-Virus Found Trojan-Clicker.Win32.Agent.jh
NOD32 Found Win32/TrojanDownloader.Agent.AWF
Norman Virus Control Found W32/Agent.BIYJ
Panda Antivirus Found Trj/KillAV.FG
Rising Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found Trojan.Win32.TrojanDownloader.Agent.AWF


—–


VundoFix V6.3.19

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 11:06:11 PM 4/13/2007

Listing files found while scanning….

C:\WINDOWS\SYSTEM32\bcoywvol.dll
C:\WINDOWS\SYSTEM32\byxvwuu.dll
C:\WINDOWS\SYSTEM32\eugkyvko.dll
C:\WINDOWS\SYSTEM32\isabdyhs.dll
C:\WINDOWS\SYSTEM32\khffgfd.dll
C:\WINDOWS\SYSTEM32\nhayafes.dll
C:\WINDOWS\SYSTEM32\nwfmfnnk.dll
C:\WINDOWS\system32\qpqss.bak1
C:\WINDOWS\system32\qpqss.ini
C:\WINDOWS\SYSTEM32\sdvfbkuk.dll
C:\WINDOWS\system32\ssqpq.dll

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\bcoywvol.dll
C:\WINDOWS\SYSTEM32\bcoywvol.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\byxvwuu.dll
C:\WINDOWS\SYSTEM32\byxvwuu.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\eugkyvko.dll
C:\WINDOWS\SYSTEM32\eugkyvko.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\isabdyhs.dll
C:\WINDOWS\SYSTEM32\isabdyhs.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\khffgfd.dll
C:\WINDOWS\SYSTEM32\khffgfd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nhayafes.dll
C:\WINDOWS\SYSTEM32\nhayafes.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nwfmfnnk.dll
C:\WINDOWS\SYSTEM32\nwfmfnnk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qpqss.bak1
C:\WINDOWS\system32\qpqss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\qpqss.ini
C:\WINDOWS\system32\qpqss.ini Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sdvfbkuk.dll
C:\WINDOWS\SYSTEM32\sdvfbkuk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqpq.dll
C:\WINDOWS\system32\ssqpq.dll Has been deleted!

Performing Repairs to the registry.
Done!

——-

Logfile of HijackThis v1.99.1
Scan saved at 11:17:23 PM, on 4/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\v7.exe
C:\WINDOWS\system32\svehost.exe
C:\WINDOWS\system32\clcl3.exe
C:\Program Files\Common Files\{54DAEEE3-0958-1033-1202-030512200001}\Update.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Daren\Desktop\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {04564BE0-A9C1-55D2-38CE-083ACCD5584C} - C:\WINDOWS\system32\bewjocj.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0a720914-a097-48c6-8fd4-0f233464d15e} - C:\WINDOWS\system32\inetonf.dll
O2 - BHO: 0 - {160DD5FB-D94E-44BC-3D92-8AE3190ED903} - C:\Program Files\Movie Maker\qufaqydit.dll
O2 - BHO: (no name) - {195FF362-78F4-42DD-95FB-3858E8D1EBC0} - C:\WINDOWS\system32\jfsvdcqn.dll
O2 - BHO: (no name) - {1EED04C6-3AC2-40D1-8DB0-084DE72FE44A} - C:\WINDOWS\system32\psyistc.dll
O2 - BHO: (no name) - {3728B359-CB24-4A81-8F8C-EFA4ADC639B1} - C:\WINDOWS\system32\ssqpq.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\tmp189.tmp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7842CAD9-10B6-4F6D-A2AF-C6C89C33ED0b} - C:\WINDOWS\system32\jfsvdcqn.dll
O2 - BHO: (no name) - {B360F286-C903-4236-953F-234151C2E5B8} - C:\Program Files\MSN\mesowic.dll
O2 - BHO: (no name) - {B9697716-61E6-4FBC-89FD-EAC504D9EFE3} - C:\WINDOWS\system32\byxvwuu.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Getca] C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [VaCtrls] v7
O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\xxyvvt.dll",realset
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [Ben] C:\WINDOWS\?icrosoft\?canregw.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [qwqm] C:\PROGRA~1\COMMON~1\qwqm\qwqmm.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168893765694
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: inetonf - C:\WINDOWS\SYSTEM32\inetonf.dll
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Belkin 54Mbps Wireless USB Network Service (Belkin 54Mbps Wireless USB) - Unknown owner - C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

—-

whew!!! :blink:
Hi rnjholley

Your doing fine every thing I asked for.

Please submit these files to upload malware here
leave a link back to this topic then browse find each file then submit

or to here

Start yourself a new topic
Put in topic title "Request by dan12"
Put in body of messege the link to our thread here.
then press the browse button and then navigate to & select the files
press Post to upload the file

It is normal you will not see the file you just posted because only approved members can see them to download them.

C:\WINDOWS\system32\bewjocj.dll
C:\WINDOWS\system32\inetonf.dll
C:\WINDOWS\system32\jfsvdcqn.dll
C:\WINDOWS\system32\byxvwuu.dll
C:\WINDOWS\SYSTEM32\instcat.dll
C:\WINDOWS\system32\tmp189.tmp.dll
C:\WINDOWS\system32\jfsvdcqn.dll
C:\WINDOWS\system32\psyistc.dll
C:\WINDOWS\system32\ssqpq.dll

___________________

We need to reveal system folders
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options
  • After the new window appears select the View tab.
  • Place a checkmark in the checkbox labeled Display the contents of system folders
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types
  • Remove the checkmark from the checkbox labeled Hide protected operating system files
  • Press the Apply and then the ok button and shut down my computer
  • Now your computer is configured to show all hidden files.
  • For you and the tools to be able to see appropriate files we need to Show Hidden Files

Double-click VundoFix.exe to run it again.
Right Click inside the listbox (white box) and click add more files
Copy&Paste the entries below into the open boxes

C:\WINDOWS\system32\bewjocj.dll
C:\WINDOWS\system32\inetonf.dll
C:\WINDOWS\system32\jfsvdcqn.dll
C:\WINDOWS\system32\byxvwuu.dll
C:\WINDOWS\SYSTEM32\instcat.dll
C:\WINDOWS\system32\tmp189.tmp.dll
C:\WINDOWS\system32\jfsvdcqn.dll
C:\WINDOWS\system32\psyistc.dll
C:\WINDOWS\system32\ssqpq.dll



Click Add Files and Click Close Window
Click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.

In this case, VundoFix will run on reboot,allow the computer to reboot and VundoFix to load.

Just add the very same files as before and Click Remove Vundo.
____________

Make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

[external image: Posted Image]

5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.


Please include new HJT log, vundofix.txt
in your next post
Thanks dan
I couldn't load all the files onto Malware site. I was able to load all but three of them because they were no longer located on the hard drive.

—–
Logfile of HijackThis v1.99.1
Scan saved at 10:09:47 PM, on 4/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\v7.exe
C:\WINDOWS\system32\svehost.exe
C:\WINDOWS\system32\clcl3.exe
C:\Program Files\Common Files\{54DAEEE3-0958-1033-1202-030512200001}\Update.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Documents and Settings\Daren\Desktop\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {04564BE0-A9C1-55D2-38CE-083ACCD5584C} - C:\WINDOWS\system32\bewjocj.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0a720914-a097-48c6-8fd4-0f233464d15e} - C:\WINDOWS\system32\iaslug.dll
O2 - BHO: 0 - {160DD5FB-D94E-44BC-3D92-8AE3190ED903} - C:\Program Files\Movie Maker\qufaqydit.dll
O2 - BHO: (no name) - {195FF362-78F4-42DD-95FB-3858E8D1EBC0} - C:\WINDOWS\system32\jfsvdcqn.dll (file missing)
O2 - BHO: (no name) - {1EED04C6-3AC2-40D1-8DB0-084DE72FE44A} - C:\WINDOWS\system32\psyistc.dll (file missing)
O2 - BHO: (no name) - {3728B359-CB24-4A81-8F8C-EFA4ADC639B1} - C:\WINDOWS\system32\ssqpq.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\tmp275.tmp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7842CAD9-10B6-4F6D-A2AF-C6C89C33ED0b} - C:\WINDOWS\system32\jfsvdcqn.dll (file missing)
O2 - BHO: (no name) - {B360F286-C903-4236-953F-234151C2E5B8} - C:\Program Files\MSN\mesowic.dll
O2 - BHO: (no name) - {B9697716-61E6-4FBC-89FD-EAC504D9EFE3} - C:\WINDOWS\system32\byxvwuu.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Getca] C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [VaCtrls] v7
O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\qonmjk.dll",realset
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [Ben] C:\WINDOWS\?icrosoft\?canregw.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [qwqm] C:\PROGRA~1\COMMON~1\qwqm\qwqmm.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168893765694
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: iaslug - C:\WINDOWS\SYSTEM32\iaslug.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Belkin 54Mbps Wireless USB Network Service (Belkin 54Mbps Wireless USB) - Unknown owner - C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

——-
Ad-Aware SE Personal
Adobe Acrobat - Reader 6.0.2 Update
Adobe Acrobat 5.0
Adobe Reader 6.0.1
Adobe Shockwave Player
Apple Software Update
AutoCAD 2000
Azureus
Banctec Service Agreement
Belkin 54Mbps Wireless USB Network Adapter
Broadcom Management Programs
CardRd81
CCScore
Conexant D850 56K V.9x DFVc Modem
CR2
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Media Experience
Dell Media Experience Update
Dell Picture Studio v3.0
Dell Support 5.0.0 (766)
DeluxeCommunications
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
ESPN RunTime
ESSBrwr
ESSCDBK
ESScore
ESSCT
ESSgui
ESShelp
ESSini
ESSPCD
ESSPDock
ESSSONIC
ESSTOOLS
ESSTUTOR
ESSvpaht
ESSvpot
HijackThis 1.99.1
HLPIndex
HLPPDOCK
HLPRFO
Hotfix for Windows XP (KB926239)
Intel® Extreme Graphics Driver
Internet Explorer Default Page
iTunes
J2SE Runtime Environment 5.0 Update 11
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Kodak EasyShare software
KSU
LiveUpdate 1.90 (Symantec Corporation)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office XP Professional with FrontPage
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Modem Helper
MSN
NetWaiting
Norton WMI Update
Notifier
OTtBP
OTtBPSDK
Outerinfo
Quicken 2004
QuickTime
RealPlayer Basic
Security Toolbar
Security Update for Step By Step Interactive Training (KB898458)
SFR
SHASTA
SKIN0001
SKINXSDK
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Spybot - Search & Destroy 1.4
Viewpoint Media Player
VPRINTOL
Web Buying
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
WinRAR archiver
WIRELESS
WordPerfect Office 12
Yahoo! Toolbar

———–

VundoFix V6.3.19

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 11:06:11 PM 4/13/2007

Listing files found while scanning….

C:\WINDOWS\SYSTEM32\bcoywvol.dll
C:\WINDOWS\SYSTEM32\byxvwuu.dll
C:\WINDOWS\SYSTEM32\eugkyvko.dll
C:\WINDOWS\SYSTEM32\isabdyhs.dll
C:\WINDOWS\SYSTEM32\khffgfd.dll
C:\WINDOWS\SYSTEM32\nhayafes.dll
C:\WINDOWS\SYSTEM32\nwfmfnnk.dll
C:\WINDOWS\system32\qpqss.bak1
C:\WINDOWS\system32\qpqss.ini
C:\WINDOWS\SYSTEM32\sdvfbkuk.dll
C:\WINDOWS\system32\ssqpq.dll

Beginning removal…

Attempting to delete C:\WINDOWS\SYSTEM32\bcoywvol.dll
C:\WINDOWS\SYSTEM32\bcoywvol.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\byxvwuu.dll
C:\WINDOWS\SYSTEM32\byxvwuu.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\eugkyvko.dll
C:\WINDOWS\SYSTEM32\eugkyvko.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\isabdyhs.dll
C:\WINDOWS\SYSTEM32\isabdyhs.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\khffgfd.dll
C:\WINDOWS\SYSTEM32\khffgfd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nhayafes.dll
C:\WINDOWS\SYSTEM32\nhayafes.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\nwfmfnnk.dll
C:\WINDOWS\SYSTEM32\nwfmfnnk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qpqss.bak1
C:\WINDOWS\system32\qpqss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\qpqss.ini
C:\WINDOWS\system32\qpqss.ini Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\sdvfbkuk.dll
C:\WINDOWS\SYSTEM32\sdvfbkuk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqpq.dll
C:\WINDOWS\system32\ssqpq.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.19

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 11:39:56 PM 4/13/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Attempting to delete C:\WINDOWS\system32\bewjocj.dll
C:\WINDOWS\system32\bewjocj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\inetonf.dll
C:\WINDOWS\system32\inetonf.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\instcat.dll
C:\WINDOWS\SYSTEM32\instcat.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jfsvdcqn.dll
C:\WINDOWS\system32\jfsvdcqn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\psyistc.dll
C:\WINDOWS\system32\psyistc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tmp189.tmp.dll
C:\WINDOWS\system32\tmp189.tmp.dll Has been deleted!

Performing Repairs to the registry.
Done!
Hi rnjholley

You are seriously lacking in xp updates please do this now > start > all programs > windows updates

Double-click VundoFix.exe to run it again.
Right Click inside the listbox (white box) and click add more files
Copy&Paste the entries below into the open boxes

C:\WINDOWS\system32\iaslug.dll

Click Add Files and Click Close Window
Click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.

In this case, VundoFix will run on reboot,allow the computer to reboot and VundoFix to load.

Just add the very same files as before and Click Remove Vundo.



Download "FindAWF"

Save to desktop and run. Output is to awf.txt

If a DOS window does not stay open throughout the search (approx a minute) you need to change how the program runs. Heres how:

1. Locate the file
2. Right-click and select Properties
3. Select Compatibility and select Run this program in compatibility mode for: Windows 98/Windows ME and click OK.
4. The tool should now work.

please include a further uninstall list
vundofix txt and awf txt in your next post.

Thanks dan
I can't thank you enough for all the help you are giving… ——- Ad-Aware SE Personal Adobe Acrobat - Reader 6.0.2 Update Adobe Acrobat 5.0 Adobe Reader 6.0.1 Adobe Shockwave Player Apple Software Update AutoCAD 2000 Azureus Banctec Service Agreement Belkin 54Mbps Wireless USB Network Adapter Broadcom Management Programs CardRd81 CCScore Conexant D850 56K V.9x DFVc Modem CR2 Dell Digital Jukebox Driver Dell Driver Reset Tool Dell Media Experience Dell Media Experience Update Dell Picture Studio v3.0 Dell Support 5.0.0 (766) DeluxeCommunications DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Web Player ESPN RunTime ESSBrwr ESSCDBK ESScore ESSCT ESSgui ESShelp ESSini ESSPCD ESSPDock ESSSONIC ESSTOOLS ESSTUTOR ESSvpaht ESSvpot HijackThis 1.99.1 HLPIndex HLPPDOCK HLPRFO Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Intel® Extreme Graphics Driver Internet Explorer Default Page iTunes J2SE Runtime Environment 5.0 Update 11 Jasc Paint Shop Photo Album 5 Jasc Paint Shop Pro Studio, Dell Editon Java 2 Runtime Environment, SE v1.4.2_03 Kodak EasyShare software KSU LiveUpdate 1.90 (Symantec Corporation) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office XP Professional with FrontPage Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft User-Mode Driver Framework Feature Pack 1.0 Modem Helper MSN MSXML 4.0 SP2 (KB927978) NetWaiting Norton WMI Update Notifier OTtBP OTtBPSDK Outerinfo Outerinfo Quicken 2004 QuickTime RealPlayer Basic Security Toolbar Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) SFR SHASTA SKIN0001 SKINXSDK Sonic DLA Sonic RecordNow! Sonic Update Manager Spybot - Search & Destroy 1.4 Update for Windows XP (KB894391) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB931836) Viewpoint Media Player VPRINTOL Web Buying Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver WIRELESS WordPerfect Office 12 Yahoo! Toolbar ——– VundoFix V6.3.19 Checking Java version… Java version is 1.4.2.3 Old versions of java are exploitable and should be removed. Java version is 1.5.0.11 Scan started at 11:06:11 PM 4/13/2007 Listing files found while scanning…. C:\WINDOWS\SYSTEM32\bcoywvol.dll C:\WINDOWS\SYSTEM32\byxvwuu.dll C:\WINDOWS\SYSTEM32\eugkyvko.dll C:\WINDOWS\SYSTEM32\isabdyhs.dll C:\WINDOWS\SYSTEM32\khffgfd.dll C:\WINDOWS\SYSTEM32\nhayafes.dll C:\WINDOWS\SYSTEM32\nwfmfnnk.dll C:\WINDOWS\system32\qpqss.bak1 C:\WINDOWS\system32\qpqss.ini C:\WINDOWS\SYSTEM32\sdvfbkuk.dll C:\WINDOWS\system32\ssqpq.dll Beginning removal… Attempting to delete C:\WINDOWS\SYSTEM32\bcoywvol.dll C:\WINDOWS\SYSTEM32\bcoywvol.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\byxvwuu.dll C:\WINDOWS\SYSTEM32\byxvwuu.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\eugkyvko.dll C:\WINDOWS\SYSTEM32\eugkyvko.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\isabdyhs.dll C:\WINDOWS\SYSTEM32\isabdyhs.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\khffgfd.dll C:\WINDOWS\SYSTEM32\khffgfd.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\nhayafes.dll C:\WINDOWS\SYSTEM32\nhayafes.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\nwfmfnnk.dll C:\WINDOWS\SYSTEM32\nwfmfnnk.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\qpqss.bak1 C:\WINDOWS\system32\qpqss.bak1 Has been deleted! Attempting to delete C:\WINDOWS\system32\qpqss.ini C:\WINDOWS\system32\qpqss.ini Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\sdvfbkuk.dll C:\WINDOWS\SYSTEM32\sdvfbkuk.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\ssqpq.dll C:\WINDOWS\system32\ssqpq.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.3.19 Checking Java version… Java version is 1.4.2.3 Old versions of java are exploitable and should be removed. Java version is 1.5.0.11 Scan started at 11:39:56 PM 4/13/2007 Listing files found while scanning…. No infected files were found. Beginning removal… Attempting to delete C:\WINDOWS\system32\bewjocj.dll C:\WINDOWS\system32\bewjocj.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\inetonf.dll C:\WINDOWS\system32\inetonf.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\instcat.dll C:\WINDOWS\SYSTEM32\instcat.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\jfsvdcqn.dll C:\WINDOWS\system32\jfsvdcqn.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\psyistc.dll C:\WINDOWS\system32\psyistc.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\tmp189.tmp.dll C:\WINDOWS\system32\tmp189.tmp.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.3.19 Checking Java version… Java version is 1.4.2.3 Old versions of java are exploitable and should be removed. Java version is 1.5.0.11 Scan started at 10:18:09 PM 4/14/2007 Listing files found while scanning…. No infected files were found. Beginning removal… Attempting to delete C:\WINDOWS\system32\iaslug.dll C:\WINDOWS\system32\iaslug.dll Has been deleted! Performing Repairs to the registry. Done! ——— Find AWF report by noahdfear ©2006 bak folders found ~~~~~~~~~~~ Directory of C:\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\BELKIN~1\BAK 03/10/2004 08:57 PM 45,056 InfoMyCa.exe 1 File(s) 45,056 bytes Directory of C:\PROGRA~1\DELLSU~1\BAK 07/19/2004 08:51 AM 306,688 DSAgnt.exe 1 File(s) 306,688 bytes Directory of C:\PROGRA~1\DELUXE~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\DIGSTR~1\BAK 05/18/2005 02:49 PM 282,624 digstream.exe 1 File(s) 282,624 bytes Directory of C:\PROGRA~1\ESPNRU~1\BAK 05/19/2005 01:55 PM 101,888 DIGServices.exe 1 File(s) 101,888 bytes Directory of C:\PROGRA~1\ITUNES\BAK 03/02/2007 04:24 PM 257,088 iTunesHelper.exe 1 File(s) 257,088 bytes Directory of C:\PROGRA~1\MESSEN~1\BAK 10/13/2004 11:24 AM 1,694,208 msmsgs.exe 1 File(s) 1,694,208 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 02/16/2007 11:54 AM 282,624 qttask.exe 1 File(s) 282,624 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 08/20/2004 04:51 PM 118,784 hkcmd.exe 08/20/2004 04:55 PM 155,648 igfxtray.exe 03/25/2007 06:22 PM 37,058 lsasss.exe 3 File(s) 311,490 bytes Directory of C:\PROGRA~1\ANALOG~1\CORE\BAK 10/14/2004 04:42 PM 1,404,928 smax4pnp.exe 1 File(s) 1,404,928 bytes Directory of C:\PROGRA~1\COMMON~1\QWQM\BAK 07/19/2006 03:56 PM 9,216 qwqmm.exe 1 File(s) 9,216 bytes Directory of C:\PROGRA~1\MCAFEE\SPAMKI~1\BAK 08/03/2004 06:18 PM 1,083,392 MSKDetct.exe 1 File(s) 1,083,392 bytes Directory of C:\PROGRA~1\REAL\REALPL~1\BAK 02/08/2005 11:59 PM 26,112 RealPlay.exe 1 File(s) 26,112 bytes Directory of C:\WINDOWS\SYSTEM32\DLA\BAK 08/13/2004 02:05 AM 122,939 tfswctrl.exe 1 File(s) 122,939 bytes Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK 01/07/2004 02:01 AM 110,592 sgtray.exe 1 File(s) 110,592 bytes Directory of C:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK 12/15/2006 04:23 AM 75,520 jusched.exe 1 File(s) 75,520 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 37581 Apr 4 2007 "C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe" 45056 Mar 10 2004 "C:\Program Files\BELKIN USB Wireless Monitor\bak\InfoMyCa.exe" 37581 Apr 4 2007 "C:\Program Files\Dell Support\DSAgnt.exe" 306688 Jul 19 2004 "C:\Program Files\Dell Support\bak\DSAgnt.exe" 37581 Apr 4 2007 "C:\Program Files\DIGStream\digstream.exe" 282624 May 18 2005 "C:\Program Files\DIGStream\bak\digstream.exe" 37581 Apr 4 2007 "C:\Program Files\ESPNRunTime\DIGServices.exe" 101888 May 19 2005 "C:\Program Files\ESPNRunTime\bak\DIGServices.exe" 37581 Apr 4 2007 "C:\Program Files\iTunes\iTunesHelper.exe" 257088 Mar 2 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe" 102400 Mar 14 2007 "C:\WINDOWS\Installer\{01B51908-02EF-453B-87A9-815182E8C2F2}\iTunesIco.exe" 116288 Mar 14 2007 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.1.0.59\iTunesSetupAdmin.exe" 37581 Apr 4 2007 "C:\Program Files\Messenger\msmsgs.exe" 1694208 Oct 13 2004 "C:\Program Files\Messenger\bak\msmsgs.exe" 1694208 Oct 13 2004 "C:\WINDOWS\$hf_mig$\KB887472\SP2QFE\msmsgs.exe" 37581 Apr 4 2007 "C:\Program Files\QuickTime\qttask.exe" 282624 Feb 16 2007 "C:\Program Files\QuickTime\bak\qttask.exe" 118784 Aug 20 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE" 37581 Apr 4 2007 "C:\WINDOWS\SYSTEM32\hkcmd.exe" 118784 Aug 20 2004 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 155648 Aug 20 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE" 37581 Apr 4 2007 "C:\WINDOWS\SYSTEM32\igfxtray.exe" 155648 Aug 20 2004 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" 37581 Apr 4 2007 "C:\WINDOWS\SYSTEM32\lsasss.exe" 37058 Mar 25 2007 "C:\WINDOWS\SYSTEM32\bak\lsasss.exe" 1404928 Oct 14 2004 "C:\DRIVERS\AUDIO\SMAX4PNP.EXE" 37581 Apr 4 2007 "C:\Program Files\Analog Devices\Core\smax4pnp.exe" 1404928 Oct 14 2004 "C:\Program Files\Analog Devices\Core\bak\smax4pnp.exe" 37581 Apr 4 2007 "C:\Program Files\Common Files\qwqm\qwqmm.exe" 9216 Jul 19 2006 "C:\Program Files\Common Files\qwqm\bak\qwqmm.exe" 37581 Apr 4 2007 "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" 1083392 Aug 3 2004 "C:\Program Files\McAfee\SpamKiller\bak\MSKDetct.exe" 37581 Apr 4 2007 "C:\Program Files\Real\RealPlayer\RealPlay.exe" 26112 Feb 8 2005 "C:\Program Files\Real\RealPlayer\bak\RealPlay.exe" 37581 Apr 4 2007 "C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe" 122939 Aug 13 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe" 122939 Aug 13 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe" 37581 Apr 4 2007 "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" 110592 Jan 7 2004 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" 32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" 37581 Apr 4 2007 "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" 75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\bak\jusched.exe" end of report thanks!!!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI