This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Remove Ddayv.dll

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have run Spybot, CWShredder, AVG and HijackThis to no avail. HijackThis shows a message that it can not create a backup and then tries to remove the entry. The same ddayv.dll entries still show up when i scan again.

At this point I can not boot the computer in safe mode.

Here is the Hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 12:42:36 PM, on 4/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
C:\WINDOWS\system32\xl.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\retadpu2000340.exe
C:\WINDOWS\9129837.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\UPS\WSTD\Messages\WSTDMessaging.exe
C:\UPS\WSTD\WorldShipTD.exe
C:\UPS\WSTD\upslnkmg.exe
c:\ups\wstd\tdrptsrv.exe
C:\PROGRA~1\MI05E6~1\OFFICE11\OUTLOOK.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\inrlctak.dll (file missing)
O2 - BHO: Helper Class - {33161E98-0A6C-4d3c-BD62-3A7D56137F52} - c:\windows\system32\mac.dll (file missing)
O2 - BHO: (no name) - {36DBC179-A19F-48F2-B16A-6A3E19B42A87} - C:\WINDOWS\system32\ipv6monl.Dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {731FF5F9-7A85-4CB5-83DE-EA9923EB024a} - C:\WINDOWS\system32\ekrvsgxq.dll
O2 - BHO: (no name) - {9D7EF71F-92F4-4E1E-93DE-E21436E4C815} - C:\WINDOWS\system32\vtutrrp.dll
O2 - BHO: (no name) - {A70E4D86-2924-4C49-9DC6-977348075ADb} - C:\WINDOWS\system32\ekrvsgxq.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {EFC425D6-DF77-4561-AAB9-36B75541DDE2} - C:\WINDOWS\system32\ddayv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [QuickBooks Remote Data Sharing Server] C:\Program Files\Common Files\Intuit\QuickBooks\RDS\qbRDSServer.exe /Autostart
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\jdigtjrc.dll",setvm
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu2000340.exe 61A847B5BBF72810329B385576F901F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [uvnx] c:\windows\system32\uvnx.exe
O4 - HKCU\..\Run: [ttool] C:\WINDOWS\9129837.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: NkvMon.exe.lnk.disabled
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\Messages\WSTDMessaging.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI05E6~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {61F8894B-CA7F-4964-AB94-F5BC48EE79DD} (QSAPI Active WebMenu 2.0) - http://rrd.mercurygate.net/MercuryGate/new…veWebMenu20.cab
O20 - Winlogon Notify: ddayv - C:\WINDOWS\system32\ddayv.dll
O20 - Winlogon Notify: vtutrrp - C:\WINDOWS\SYSTEM32\vtutrrp.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Unknown owner - C:\Program Files\Verizon\Verizon Internet Security Suite\fws.exe (file missing)
O23 - Service: XtreamLok License Manager - Unknown owner - C:\WINDOWS\system32\xl.exe
sbg2 :D

Welcome to the forum, you are infected with Vundo, lets run the removal tool.

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

If there is a file VundoFix doesn't find we need it submitted. Please submit
the files to upload malware http://www.uploadmalware.com


Post the Vundo log and a New HJT log please.
Glad you took care of it but just removing those bad entries or files will not remove the Vundo infection. If you feel this is resolved I will close this thread in a couple of days or you can post a new HJT log to make sure its gone. Ken :D
You're right. Better safe than sorry. looking at the new log I'm guessing the Hijacked Internet Access By WebHancer is not a good thing.

Logfile of HijackThis v1.99.1
Scan saved at 9:55:37 AM, on 5/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
C:\WINDOWS\system32\xl.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\webHancer\Programs\whagent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\UPS\WSTD\Messages\WSTDMessaging.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Outlook\OFFICE11\OUTLOOK.EXE
C:\UPS\WSTD\WorldShipTD.exe
C:\UPS\WSTD\upslnkmg.exe
C:\Program Files\FileMaker\FileMaker Pro 7\FileMaker Pro.exe
C:\WINDOWS\system32\WISPTIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {731FF5F9-7A85-4CB5-83DE-EA9923EB024a} - C:\WINDOWS\system32\ekrvsgxq.dll
O2 - BHO: (no name) - {A70E4D86-2924-4C49-9DC6-977348075ADb} - C:\WINDOWS\system32\ekrvsgxq.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [uvnx] c:\windows\system32\uvnx.exe
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\veagujpo.dll",realset
O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\Messages\WSTDMessaging.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI05E6~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Unknown owner - C:\Program Files\Verizon\Verizon Internet Security Suite\fws.exe (file missing)
O23 - Service: ScriptBlocking Service (SBService) - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (file missing)
O23 - Service: XtreamLok License Manager - Unknown owner - C:\WINDOWS\system32\xl.exe
sbg2,

Don't know what you have done to correct the problem but you still have a mess going on here. You still have some trojans and malware on your log.

First go to your Add Remove Programs in the Control Panel and uninstall WebEnhancer if it will let you, let me know if if did or did not.


Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall


I need to see the log from Combofix and a new HJT log
Webenhancer is playing around with your internet connection, do this first.


Winsockxpfix
Your malware infection is playing around with your internet connection, I want you to download this program to your desktop and in the event ofremoving Webehancer you lose your connection, run this tool to repair it.
"mario" - 07-05-04 10:52:47 Service Pack 2
ComboFix 07-04-25.4V - Running from: "E:\Mario\SpyWare Stuff\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\bgreicdv.dll
C:\WINDOWS\system32\feqmscou.dll
C:\WINDOWS\system32\ekrvsgxq.dll
C:\WINDOWS\system32\fcoieshr.dll
C:\WINDOWS\system32\qvocvqjr.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\WINDOWS\system32\ipv6monl.Dll
C:\Program Files\ipwindows\ipwins.exe
C:\Program Files\ipwindows\UnInstall.exe
C:\Program Files\webhancer\Programs\whagent.exe
C:\Program Files\webhancer\Programs\whiehlpr.dll
C:\Program Files\webhancer\Programs\webhdll.dll
C:\Program Files\webhancer\Programs\whinstaller.exe
C:\WINDOWS\system32\uvnx.exe
C:\WINDOWS\hosts
C:\WINDOWS\start.exe
C:\Program Files\inetget2
C:\Program Files\ipwindows
C:\WINDOWS\system32\pcs
C:\Program Files\webhancer


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\new_drv


((((((((((((((((((((((((((((((( Files Created from 2007-04-04 to 2007-05-04 ))))))))))))))))))))))))))))))))))


2007-04-30 13:45 d——– C:\DOCUME~1\Mario\APPLIC~1\Aladdin Systems
2007-04-30 13:45 d——– C:\DOCUME~1\FRONTD~1\APPLIC~1\Aladdin Systems
2007-04-26 20:02 262,144 –a—— C:\DOCUME~1\FRONTD~1\NTUSER.DAT
2007-04-25 18:47 d——– C:\VundoFix Backups
2007-04-25 17:33 132,660 –a—— C:\WINDOWS\SYSTEM32\veagujpo.dll
2007-04-25 08:30 1 –a—— C:\WINDOWS\SYSTEM32\ps.dat
2007-04-25 08:29 26,624 –a—— C:\WINDOWS\clt.exe
2007-04-25 08:28 78 –a—— C:\WINDOWS\file.bat
2007-04-24 11:22 d——– C:\WINDOWS\SYSTEM32\E177E04D548C4006A465EEB92D3DE021
2007-04-23 15:35 6,656 –a—— C:\WINDOWS\SYSTEM32\haspvdd.dll
2007-04-23 15:35 47,616 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\Haspnt.sys
2007-04-23 15:35 383 –a—— C:\WINDOWS\SYSTEM32\haspdos.sys
2007-04-23 15:03 C:\WINDOWS\SYSTEM32\?3
2007-04-23 12:49 304,640 –a—— C:\WINDOWS\SYSTEM32\hlvdd.dll
2007-04-23 12:48 52,224 –a—— C:\WINDOWS\SYSTEM32\Crypserv.exe
2007-04-23 12:48 27,648 -ra—— C:\WINDOWS\Setup_ck.exe
2007-04-23 12:48 24,608 –a—— C:\WINDOWS\SYSTEM32\Ckldrv.sys
2007-04-23 12:48 197,696 ——— C:\WINDOWS\SYSTEM32\Unidrv.dll
2007-04-23 12:48 18,432 –a—— C:\WINDOWS\Setup_ck.dll
2007-04-23 12:48 165,888 –a—— C:\WINDOWS\Ckconfig.exe
2007-04-23 12:48 11,776 –a—— C:\WINDOWS\Ckrfresh.exe
2007-04-23 12:47 81,920 ——— C:\WINDOWS\SYSTEM32\RcLocaleu.dll
2007-04-23 12:22 d—s—- C:\DOCUME~1\Mario\UserData
2007-04-23 10:13 d——– C:\DOCUME~1\Mario\APPLIC~1\AdobeUM
2007-04-20 14:31 d——– C:\DOCUME~1\Mario\APPLIC~1\Corel
2007-04-20 13:23 d——– C:\Program Files\SATO
2007-04-20 13:23 d——– C:\Program Files\Common Files\EuroPlus Shared
2007-04-20 13:23 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SATO
2007-04-20 11:58 364,544 –a—— C:\WINDOWS\SYSTEM32\softokn3.dll
2007-04-20 11:58 339,968 –a—— C:\WINDOWS\SYSTEM32\nss3.dll
2007-04-20 11:58 28,672 –a—— C:\WINDOWS\SYSTEM32\plc4.dll
2007-04-20 11:58 24,576 –a—— C:\WINDOWS\SYSTEM32\plds4.dll
2007-04-20 11:58 180,224 –a—— C:\WINDOWS\SYSTEM32\nssckbi.dll
2007-04-20 11:58 155,648 –a—— C:\WINDOWS\SYSTEM32\nspr4.dll
2007-04-20 11:58 110,592 –a—— C:\WINDOWS\SYSTEM32\ssl3.dll
2007-04-20 11:58 106,496 –a—— C:\WINDOWS\SYSTEM32\smime3.dll
2007-04-20 11:42 33,340 –a—— C:\WINDOWS\SYSTEM32\dbmsqlgc.dll
2007-04-20 11:42 24,576 –a—— C:\WINDOWS\SYSTEM32\dbmsgnet.dll
2007-04-20 11:41 d——– C:\Program Files\Microsoft SQL Server
2007-04-20 11:38 d——– C:\UPS
2007-04-20 11:36 24,576 -ra—— C:\WINDOWS\InstallManager.exe
2007-04-20 11:21 d——– C:\WINDOWS\SYSTEM32\FxsTmp
2007-04-20 11:20 24,816 –a—— C:\WINDOWS\SYSTEM32\mdimon.dll
2007-04-20 11:10 d——– C:\Program Files\Microsoft.NET
2007-04-20 11:10 d——– C:\Program Files\Microsoft Outlook
2007-04-20 10:59 1,986,560 –a—— C:\DOCUME~1\__SBS_~1\NTUSER.DAT
2007-04-20 10:59 d–hs—- C:\WINDOWS\CSC
2007-04-20 10:57 d——– C:\WINDOWS\SchCache
2007-04-20 10:56 d——– C:\Program Files\Microsoft Windows Small Business Server
2007-04-19 18:52 d——– C:\WINDOWS\SYSTEM32\appmgmt
2007-04-19 18:33 3,407,872 –ah—– C:\DOCUME~1\Mario\NTUSER.DAT
2007-04-19 17:37 d——– C:\WINDOWS\Prefetch
2007-04-19 17:22 11,264 –a—— C:\WINDOWS\SYSTEM32\atrace.dll
2007-04-19 17:14 20,992 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.sys
2007-04-19 17:10 24,661 –a—— C:\WINDOWS\SYSTEM32\spxcoins.dll
2007-04-19 17:10 13,312 –a—— C:\WINDOWS\SYSTEM32\irclass.dll
2007-04-19 16:55 d——– C:\WINDOWS\ehome
2007-04-12 13:56 d——– C:\WINDOWS\network diagnostic
2007-04-11 14:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-19 19:18 278 –a—— C:\WINDOWS\freedom.backup.dat
2007-04-19 17:21 23348 –a—— C:\WINDOWS\SYSTEM32\emptyregdb.dat
2007-04-19 17:10 62 –ahs—- C:\DOCUME~1\Mario\APPLIC~1\desktop.ini
2007-03-15 10:08 101438 –a—— C:\WINDOWS\b122.exe
2007-02-19 07:01 252356 –a—— C:\WINDOWS\b128.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
{731FF5F9-7A85-4CB5-83DE-EA9923EB024a} C:\WINDOWS\system32\ekrvsgxq.dll [x]
{A70E4D86-2924-4C49-9DC6-977348075ADb} C:\WINDOWS\system32\ekrvsgxq.dll [x]
{AE7CD045-E861-484f-8273-0445EE161910} C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Synchronization Manager"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,\
"NA1Messenger"="C:\\UPS\\WSTD\\PolicyMgr\\NA1Msgr.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"InfoData"="rundll32.exe \"C:\\WINDOWS\\system32\\veagujpo.dll\",realset"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"Printing Migration"="rundll32.exe C:\\WINDOWS\\system32\\spool\\migrate.dll,ProcessWin9xNetworkPrinters"
"tscuninstall"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,6d,\
33,32,5c,74,73,63,75,70,67,72,64,2e,65,78,65,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisablePersonalDirChange"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\s-1-5-21-3827822998-3278726706-263255761-1150\scripts\logon\
script REG_SZ map s drive.bat


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Numc"="C:\\Documents and Settings\\FrontDesk\\Application Data\\atoc.exe"
"WINT"="C:\\WINDOWS\\SYSTEM32\\wcpsvit.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TaskMonitor"="c:\\windows\\taskmon.exe"
"QBCD Autorun"="D:\\autorun.exe restart TIMER_SEQUENCE first"
"HP SchedIndexer"="C:\\Program Files\\Hewlett-Packard\\LaserJet 33xx\\hppschedindexer.exe"
"HP AutoIndexer"="C:\\Program Files\\Hewlett-Packard\\LaserJet 33xx\\hppautoindexer.exe"
"CreateCD50"="\"c:\\Program Files\\Common Files\\Adaptec Shared\\CreateCD\\CreateCD50.exe\" -r"
"AdaptecDirectCD"="c:\\Program Files\\Adaptec\\Easy CD Creator 5\\DirectCD\\DirectCD.exe"
"mswspl"=""
"bhorbpfd"="C:\\WINDOWS\\SYSTEM32\\xxmeqpus.exe"
"Bakra"="C:\\WINDOWS\\SYSTEM32\\IEHost.EXE"
"Dsi"="C:\\WINDOWS\\SYSTEM32\\dp-him.exe"
"qqmS35V"="C:\\WINDOWS\\SYSTEM32\\msmlean.exe"
"Pcsv"="C:\\WINDOWS\\system32\\pcs\\pcsvc.exe"
"Dpi"="C:\\PROGRAM FILES\\COMMON FILES\\DPI\\DPI.EXE"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"ccRegVfy"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"mdac_runonce"="C:\\WINDOWS\\SYSTEM32\\RUNONCE.EXE"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Tune-up Application Start.job
C:\WINDOWS\tasks\Maintenance-Disk cleanup.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-04 10:54:53
Windows 5.1.2600 Service Pack 2 FAT

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 07-05-04 10:54:57
C:\ComboFix-quarantined-files.txt … 07-05-04 10:54


————————————————————————–

Logfile of HijackThis v1.99.1
Scan saved at 11:00, on 07-05-04
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\UPS\WSTD\MSSQL$UPSWSDBSERVER\Binn\sqlservr.exe
C:\WINDOWS\system32\xl.exe
C:\WINDOWS\Explorer.EXE
C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\UPS\WSTD\Messages\WSTDMessaging.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [NA1Messenger] C:\UPS\WSTD\PolicyMgr\NA1Msgr.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\veagujpo.dll",realset
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\WSTD\wstdPldReminder.exe
O4 - Global Startup: UPS WorldShip Messaging Utility.lnk = C:\UPS\WSTD\Messages\WSTDMessaging.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI05E6~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Verizon Internet Security Suite Firewall (RP_FWS) - Unknown owner - C:\Program Files\Verizon\Verizon Internet Security Suite\fws.exe (file missing)
O23 - Service: XtreamLok License Manager - Unknown owner - C:\WINDOWS\system32\xl.exe
Ok Moving right along. :D

It looks like Webenhancer is gone. :thumbup: After your completely clean I will provide links to free programs that will hamper a lot of this garbage from installing.

Combofix removed webenhancer but it also found bad files related to other trojans, before we remove them I need you to run the trial of AVG Anti Spyware, it most likely will find them and remove them so lets see what it does.

You need to enable windows to show all files and folders, instructions Here

Make sure you follow these instructions correctly to Remove or Quarantine what it finds and also to save the report, without me seeing the report my hands are tied.
Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop. It's very important that I see the report so make sure you follow the instructions and save the log.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5
Still in safemode, look for and delete these files. AVG may have removed them so not to worry if there not there.

C:\WINDOWS\b122.exe
C:\WINDOWS\b128.exe
C:\WINDOWS\SYSTEM32\IEHost.EXE
C:\WINDOWS\\SYSTEM32\dp-him.exe


Reboot and run this system cleaner.


Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up


Post the AVG Report and a New HJT log .
The AVG part will be easy as I installed it on all our machines a week and a half ago. I may not be able to get to the safe mode run today as it is a work machine and I'm being pulled in about 50 different directions. I will post the results as soon as I can. P.S. I am also running Spybot on all machines now.
OK, computer will not start in safe Mode. When trying to load I get a monitor level message "Frequency out of range". I let the computer run for a while after receiving the error but the screen never comes back on. I manually shut off and turned the monitor back on only to receive the same message. I also tried a different brand monitor which gave the same error mesage. After hard drive activity had been stopped for approximately 15 minutes I gave up and rebooted the computer. At this point I have AVG running a scan in normal mode. Not sure if this will be helpful or not. Should I try and delete the 4 .exe files and run ATF Cleaner once AVG finishes its scan?
AVG in normal windows is better than nothing. Lets see what it removes before you remove those files, it may have done it for you. ATF cleaner will just remove temp files and such, sometimes malware files hide there
I don't have AVG on the computer I am on right now but I think you open AVG and look under reports , pull the last one up and copy and paste it into this thread. If you said no infected files found don't don't worry about it if you can't find the report.

Where you able to delete those files???

Go to VirusTotal and submit these files for analysis, just use the browse feature and then submit them , you will get a report back, post the report into this thread for me to see.


C:\WINDOWS\SYSTEM32\veagujpo.dll
C:\WINDOWS\system32\ekrvsgxq.dll
C:\\WINDOWS\\SYSTEM32\xxmeqpus.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI