This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Yeah, I Got Big Problems....

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello all,
I've been looking around for quite some time now on this site. Great site, and I'd like to thank all of you for helping people. Here's my problems:

Sound won't play/load on anything
I get popups all the time, to the point I have to close the browser and re-open it.
System doctor constantly coming up
CD-RW won't all of a sudden work, nor will the DVD drive.
I-tunes won't even recognize my iPod when I connect it.

I'd like to thank who ever helps me in advance. I've actually had this problem for so long now, I'm getting used to no sound…It's bad, I know.

I also run Adaware and Spybot regularly. I've also read all the sticky's on how to keep your computer clean after it gets clean, and will be doing all this, as well as creating a folder for the HJT notepad logfile's.

Thanks all,
Mike



Logfile of HijackThis v1.99.1
Scan saved at 10:46:04 PM, on 5/15/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Duce6.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\WINDOWS\System32\392855d7.exe
C:\WINDOWS\System32\psc_mon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\PROGRA~1\COMMON~1\MBOLS~1\RGEDIT~1.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\checkers5.exe
C:\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1\msiexec.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {9914E4FB-241E-02EF-4180-72E2EE0020E1} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qhqgy.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bcxjkuy.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ms064175195351] C:\WINDOWS\ms064175195351.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [392855d7.exe] C:\WINDOWS\System32\392855d7.exe
O4 - HKLM\..\Run: [Personal Security Center Monitor] C:\WINDOWS\System32\psc_mon.exe
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\System32\idjyyptl.dll",realset
O4 - HKCU\..\Run: [Vnvjs] C:\PROGRA~1\COMMON~1\MBOLS~1\RGEDIT~1.EXE
O4 - HKCU\..\Run: [SysProtect Free] "C:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [SysProtect] C:\Program Files\SysProtect Free\USYP.exe /scan
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [checkers] C:\WINDOWS\checkers5.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [392855d7.exe] C:\Documents and Settings\Mike.FUCKSTICK\Local Settings\Application Data\392855d7.exe
O4 - HKCU\..\Run: [Haws] "C:\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1\msiexec.exe" -vt ndrv
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra button: Microsoft AntiSpyware helper - {432B4808-E2A1-4076-97AC-E9E500553B5A} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {432B4808-E2A1-4076-97AC-E9E500553B5A} - (no file) (HKCU)
O9 - Extra button: (no name) - {750A64D8-DFAA-485B-A335-F7093333FBB7} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E44CB0D1-8B48-4724-BE13-5249517B5B9C} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E44CB0D1-8B48-4724-BE13-5249517B5B9C} - (no file) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imageservr.com
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/insta…FreeInstall.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - http://awbeta.net-nucleus.com/CABUPDATES/winwcd.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/sy…nnerInstall.cab
O20 - AppInit_DLLs:
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWlrZQ\command.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Hello,

Your system is terribly infected. Problem with these infections nowadays is, it causes a lot of damage. Even if we clean the malware off your system, I can't guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognise and logs won't show.
Also, I can't promise you we can repair all the damage it caused… Even after cleaning the malware, you can still get errors afterwards because of the damage. Solving these is not always possible since it will be searching for a needle in a haystack to find the right cause and solution.
So, we can try to clean this up and do what we can, but keep in mind that we can't solve ALL problems this malware already caused.

In light of this it would be wise for you to back up any files and folders that you don't want to lose before we start. Reason I am telling this is because when a system is so terribly infected and we try to clean this up manually, the damage that is already present may interfere with our removal attempts.
Actually, it doesn't suprise me at all that your system is so terribly infected…. I notice that you do not seem to be running Antivirus software and a Firewall…
This is somewhat suicidal in today's digital world.
That's why I want you to install them first!!

Avira, AVG OR Active Virus Shield (uncheck the Security Toolbar during install) are good FREE antivirus.
Never install more than one antivirusscanner or firewall on your system! Several together can give problems and decrease the reliability of it seriously!
Comodo OR Kerio are FREE firewalls.

Understanding and using firewalls

Then, perform a full scan with your Antivirus and let it remove anything it is finding.
Reboot afterwards.

After reboot, post a new HijackThislog in your next reply, then we can start from there, because it really makes no sense that we try to clean this up manually if an Antivirus should already remove most of it and without any protection present, you'll get reinfected immediately again, also since your Windows is not properly patched either.
Extra note - I cannot guarantee that we will be able to fix all damage the malware already caused though… this also because you are already dealing with this too long. So unfortunately, you have to accept that.
Ok, where to start.

I've installed Avira and Comodo. The computer feels as if it's running somewhat faster. Once the anti-virus came online, I've seriously sat here for the last 45 minutes deleting trojans and other files. WOW.

I've run adaware, spybot, and the firewall and avira are now up and running.

Ok, here's my latest logfile.

Thanks again,
Mike




Logfile of HijackThis v1.99.1
Scan saved at 10:43:32 AM, on 5/16/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\COMMON~1\MBOLS~1\RGEDIT~1.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {9914E4FB-241E-02EF-4180-72E2EE0020E1} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qhqgy.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bcxjkuy.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [yoetyn] C:\WINDOWS\System32\awacyo.exe reg_run
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ms064175195351] C:\WINDOWS\ms064175195351.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [392855d7.exe] C:\WINDOWS\System32\392855d7.exe
O4 - HKLM\..\Run: [Personal Security Center Monitor] C:\WINDOWS\System32\psc_mon.exe
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\System32\idjyyptl.dll",realset
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [vllua] C:\WINDOWS\System32\awacyo.exe reg_run
O4 - HKCU\..\Run: [Vnvjs] C:\PROGRA~1\COMMON~1\MBOLS~1\RGEDIT~1.EXE
O4 - HKCU\..\Run: [SysProtect Free] "C:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [SysProtect] C:\Program Files\SysProtect Free\USYP.exe /scan
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [checkers] C:\WINDOWS\checkers5.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [392855d7.exe] C:\Documents and Settings\Mike.FUCKSTICK\Local Settings\Application Data\392855d7.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra button: Microsoft AntiSpyware helper - {432B4808-E2A1-4076-97AC-E9E500553B5A} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {432B4808-E2A1-4076-97AC-E9E500553B5A} - (no file) (HKCU)
O9 - Extra button: (no name) - {750A64D8-DFAA-485B-A335-F7093333FBB7} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E44CB0D1-8B48-4724-BE13-5249517B5B9C} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E44CB0D1-8B48-4724-BE13-5249517B5B9C} - (no file) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/insta…FreeInstall.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - http://awbeta.net-nucleus.com/CABUPDATES/winwcd.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/sy…nnerInstall.cab
O20 - AppInit_DLLs:
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Hi,

I've installed Avira and Comodo. The computer feels as if it's running somewhat faster. Once the anti-virus came online, I've seriously sat here for the last 45 minutes deleting trojans and other files. WOW.

Do you understand now why it is so important to have an Antivirus running in the background?
Anyway, we're not finished yet since we still have a lot to delete and restore.

It is important you follow my next instructions in the right order without missing a step…

I see you are running Teatimer.
I suggest you to disable it because it can interfere with the changes you'll make on your system.
When everything is done and your log is clean again, you can enable it again. Do NOT enable it before.
If teatimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.
How to disable TeaTimer during HijackThis Cleanup
Then, Download ResetTeaTimer.bat.
Double click ResetTeaTimer.bat to remove all entries set by TeaTimer.

Then,

* Go to start > controlpanel > software > add/remove programs and uninstall next programs if present:

SysProtect Free
Oin
Yazzle by Oin
YazzleActiveX By OIN
Purityscan by Oin
MediaTickets by OIN
Snowballwars by Oin
Cowabanga by OIN
or anything similar with Oin in it.


Reboot when done! Really important!

After reboot,


* Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present (some entries won't be present anymore):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - {9914E4FB-241E-02EF-4180-72E2EE0020E1} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qhqgy.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bcxjkuy.exe
O4 - HKLM\..\Run: [yoetyn] C:\WINDOWS\System32\awacyo.exe reg_run
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [ms064175195351] C:\WINDOWS\ms064175195351.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [392855d7.exe] C:\WINDOWS\System32\392855d7.exe
O4 - HKLM\..\Run: [Personal Security Center Monitor] C:\WINDOWS\System32\psc_mon.exe
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\System32\idjyyptl.dll",realset
O4 - HKCU\..\Run: [vllua] C:\WINDOWS\System32\awacyo.exe reg_run
O4 - HKCU\..\Run: [Vnvjs] C:\PROGRA~1\COMMON~1\MBOLS~1\RGEDIT~1.EXE
O4 - HKCU\..\Run: [SysProtect Free] "C:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [SysProtect] C:\Program Files\SysProtect Free\USYP.exe /scan
O4 - HKCU\..\Run: [checkers] C:\WINDOWS\checkers5.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [392855d7.exe] C:\Documents and Settings\Mike.FUCKSTICK\Local Settings\Application Data\392855d7.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: Microsoft AntiSpyware helper - {432B4808-E2A1-4076-97AC-E9E500553B5A} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {432B4808-E2A1-4076-97AC-E9E500553B5A} - (no file) (HKCU)
O9 - Extra button: (no name) - {750A64D8-DFAA-485B-A335-F7093333FBB7} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {E44CB0D1-8B48-4724-BE13-5249517B5B9C} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E44CB0D1-8B48-4724-BE13-5249517B5B9C} - (no file) (HKCU)
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/insta…FreeInstall.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - http://awbeta.net-nucleus.com/CABUPDATES/winwcd.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/sy…nnerInstall.cab
O20 - AppInit_DLLs:


* Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!
Don't worry if some entries won't go away, we'll deal with that later…

———————

Please download, install, and update AVG Anti-Spyware
  • Load AVG Anti-Spyware and then click the Update tab at the top. Under Manual Update click Start update.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Then click on the Scanner tab at the top. Click the "Settings" tab and then change the recommended action to Quarantine and click Automatically generate report after every scan. Click back to the "Scan" tab and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.
  • AVG Anti-Spyware will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. AVG Anti-Spyware will display "All actions have been applied" on the right hand side.
  • Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).
  • Close AVG Anti-Spyware and reboot!!
    I need the log later.
————————-

* Download Combofix to your desktop.
Doubleclick combofix.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt.
I need that log afterwards.

————————–

* Please download the following file to your desktop:
http://noahdfear.geekstogo.com/FindAWF.exe
Run the file. It will open a log.

Post next logs in your following reply:
  • Log from FindAWF.exe
  • Log from combofix (C:\combofix.txt)
  • Log from AVG Antispyware
  • New HijackThislog
You may need several replies to post the logs in case they won't fit in one reply.

Just wanted to let you know I'm about half way through the list. Still working.

yes I know it may take a while. This is normal with the huge amount of malware present.
If you want things to be clean again, all steps are needed :)

Just wanted to let you know I'm about half way through the list. Still working.

yes I know it may take a while. This is normal with the huge amount of malware present.
If you want things to be clean again, all steps are needed :)



Thanks again for your help. I'm about 75% through with the AVG scan. I will complete all steps and talk to you soon.

I'm about 75% through with the AVG scan. I will complete all steps and talk to you soon

Just make sure you mark them to delete/quarantine and then save the log.
Because many users forget to set AVG to quarantine what it found > so they have to start all over afterwards. :)
I don't want to start over, so I'll definitely remember to do that. The AntiVirus Scan just completed. If I post the logfile from that will it help you. Edit: I just tried to post the logfile. Is there a specific part that you need, it told me it's too long. Or should I just break it up into several posts?
I already thought that this log would be huge.. so Go to this page.
Enter the url of this thread in the first field.
Where it says, browse to the file that you want to submit, click the browse button next to it and browse to the AVG Antispyware log.

Select it and click ok:
Then click the Send File button below.

The other logs should fit in here fine. Just use seperate replies.
Ok, I followed the link and uploaded the AVG Antispyware log.

Find AWF log


Find AWF report by noahdfear ©2006


bak folders found
~~~~~~~~~~~


Directory of C:\WINDOWS\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\ITUNES\BAK

09/12/2006 01:58 AM 229,952 iTunesHelper.exe
1 File(s) 229,952 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

09/01/2006 03:57 PM 282,624 qttask.exe
1 File(s) 282,624 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

0 File(s) 0 bytes

Directory of C:\QOOBOX\PURITY\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1\BAK

0 File(s) 0 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

229952 Sep 12 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
108096 Sep 12 2006 "C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 7.0.0.70\iTunesSetupAdmin.exe"
282624 Sep 1 2006 "C:\Program Files\QuickTime\bak\qttask.exe"


end of report
Combo Fix report

"Mike" - 2007-05-16 15:14:24 Service Pack 1
ComboFix 07-05.17.V - Running from: "C:\Program Files\Mozilla Firefox\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\aedtqtii.dll
C:\WINDOWS\system32\akxhodtk.dll
C:\WINDOWS\system32\aurmhjtr.dll
C:\WINDOWS\system32\bbvjoohf.dll
C:\WINDOWS\system32\bdynivjg.dll
C:\WINDOWS\system32\bnwgrghy.dll
C:\WINDOWS\system32\bqlwjmrx.dll
C:\WINDOWS\system32\bywusrvd.dll
C:\WINDOWS\system32\cepeskma.dll
C:\WINDOWS\system32\cmoslaqn.dll
C:\WINDOWS\system32\diljgbkb.dll
C:\WINDOWS\system32\dofggqwe.dll
C:\WINDOWS\system32\dtqjitog.dll
C:\WINDOWS\system32\ebvuotfk.dll
C:\WINDOWS\system32\edervngo.dll
C:\WINDOWS\system32\eiyepvbl.dll
C:\WINDOWS\system32\exnplssb.dll
C:\WINDOWS\system32\fshbvmpf.dll
C:\WINDOWS\system32\fvldppjr.dll
C:\WINDOWS\system32\htpdeeaj.dll
C:\WINDOWS\system32\ipbhvnft.dll
C:\WINDOWS\system32\jhetwmgg.dll
C:\WINDOWS\system32\jquymjkn.dll
C:\WINDOWS\system32\kwgcfieg.dll
C:\WINDOWS\system32\lifbxtta.dll
C:\WINDOWS\system32\llprghdw.dll
C:\WINDOWS\system32\lthutbhk.dll
C:\WINDOWS\system32\lvckkpkv.dll
C:\WINDOWS\system32\ncdojsoe.dll
C:\WINDOWS\system32\njbuwqoh.dll
C:\WINDOWS\system32\nvrnsbpw.dll
C:\WINDOWS\system32\ohmbpgjv.dll
C:\WINDOWS\system32\ookgbiud.dll
C:\WINDOWS\system32\qtqouwmr.dll
C:\WINDOWS\system32\qygniyod.dll
C:\WINDOWS\system32\qynatidn.dll
C:\WINDOWS\system32\rcjgmcdo.dll
C:\WINDOWS\system32\riothdwj.dll
C:\WINDOWS\system32\rlliorfj.dll
C:\WINDOWS\system32\sdlqimpb.dll
C:\WINDOWS\system32\sukevqbt.dll
C:\WINDOWS\system32\tcamrgea.dll
C:\WINDOWS\system32\tjolsank.dll
C:\WINDOWS\system32\tjwhrblt.dll
C:\WINDOWS\system32\ubrofvtl.dll
C:\WINDOWS\system32\uslsusnp.dll
C:\WINDOWS\system32\uuglfqeg.dll
C:\WINDOWS\system32\vmldlqog.dll
C:\WINDOWS\system32\vxmhoygw.dll
C:\WINDOWS\system32\vybebmsr.dll
C:\WINDOWS\system32\wpipmkni.dll
C:\WINDOWS\system32\wylnbngp.dll
C:\WINDOWS\system32\xjgbshlc.dll
C:\WINDOWS\system32\xmlfyrrf.dll
C:\WINDOWS\system32\xxhrqeie.dll
C:\WINDOWS\system32\xyxmlifx.dll
C:\WINDOWS\system32\ygtmfkvs.dll
C:\WINDOWS\system32\yjrihqua.dll
C:\WINDOWS\system32\ykhhhnbf.dll
C:\WINDOWS\system32\iitqtdea.ini
C:\WINDOWS\system32\ktdohxka.ini
C:\WINDOWS\system32\rtjhmrua.ini
C:\WINDOWS\system32\fhoojvbb.ini
C:\WINDOWS\system32\dvrsuwyb.ini
C:\WINDOWS\system32\nqalsomc.ini
C:\WINDOWS\system32\bkbgjlid.ini
C:\WINDOWS\system32\kftouvbe.ini
C:\WINDOWS\system32\ognvrede.ini
C:\WINDOWS\system32\lbvpeyie.ini
C:\WINDOWS\system32\bsslpnxe.ini
C:\WINDOWS\system32\jaeedpth.ini
C:\WINDOWS\system32\tfnvhbpi.ini
C:\WINDOWS\system32\nkjmyuqj.ini
C:\WINDOWS\system32\geifcgwk.ini
C:\WINDOWS\system32\wdhgrpll.ini
C:\WINDOWS\system32\khbtuhtl.ini
C:\WINDOWS\system32\vkpkkcvl.ini
C:\WINDOWS\system32\eosjodcn.ini
C:\WINDOWS\system32\hoqwubjn.ini
C:\WINDOWS\system32\vjgpbmho.ini
C:\WINDOWS\system32\rmwuoqtq.ini
C:\WINDOWS\system32\doyingyq.ini
C:\WINDOWS\system32\nditanyq.ini
C:\WINDOWS\system32\odcmgjcr.ini
C:\WINDOWS\system32\jwdhtoir.ini
C:\WINDOWS\system32\jfroillr.ini
C:\WINDOWS\system32\bpmiqlds.ini
C:\WINDOWS\system32\tbqvekus.ini
C:\WINDOWS\system32\aegrmact.ini
C:\WINDOWS\system32\knaslojt.ini
C:\WINDOWS\system32\tlbrhwjt.ini
C:\WINDOWS\system32\ltvforbu.ini
C:\WINDOWS\system32\pnsuslsu.ini
C:\WINDOWS\system32\geqflguu.ini
C:\WINDOWS\system32\goqldlmv.ini
C:\WINDOWS\system32\wgyohmxv.ini
C:\WINDOWS\system32\rsmbebyv.ini
C:\WINDOWS\system32\inkmpipw.ini
C:\WINDOWS\system32\clhsbgjx.ini
C:\WINDOWS\system32\eieqrhxx.ini
C:\WINDOWS\system32\xfilmxyx.ini
C:\WINDOWS\system32\svkfmtgy.ini
C:\WINDOWS\system32\auqhirjy.ini
C:\WINDOWS\system32\fbnhhhky.ini


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\keyboard1.dat
C:\DOCUME~1\MIKE~1.FUC\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\PageHistory.txt
C:\DOCUME~1\MIKE~1.FUC\APPLIC~1.\searchtoolbarcorp\Toolbar Vision\WebHistory.txt
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\netmon\log.txt
C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\netmon\log.txt
C:\Program Files\Common Files\y1123ou.exe
C:\WINDOWS\system32ghynf.exe
C:\WINDOWS\system32n9nyb.exe
C:\WINDOWS\winlogin.exe
C:\DOCUME~1\MIKE~1.FUC\APPLIC~1.\searchtoolbarcorp
C:\Program Files\outerinfo
C:\Program Files\vsadd-in
C:\WINDOWS\system32\components
C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\netmon
C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\netmon
C:\Program Files\Common Files\{74704~1
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\PPPATC~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\STEM~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\WNSXS~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0000
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0001
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0002
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0003
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0004
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\ASKS~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\ECURIT~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\MANTEC~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSEMBL~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\STEM32~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1\bak
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1\SSTEM~1
C:\qoobox\purity\C\Program Files\MCROSO~1.NET
C:\qoobox\purity\C\Program Files\TSKS~1
C:\qoobox\purity\C\Program Files\YMBOLS~1
C:\qoobox\purity\C\Program Files\YSTEM~1
C:\qoobox\purity\C\Program Files\Common Files\ASEMBL~1
C:\qoobox\purity\C\Program Files\Common Files\MBOLS~1
C:\qoobox\purity\C\Program Files\Common Files\RACLE~1
C:\qoobox\purity\C\Program Files\Common Files\SCURIT~1
C:\qoobox\purity\C\Program Files\Common Files\YSTEM~1
C:\qoobox\purity\C\WINDOWS\FNTS~1
C:\qoobox\purity\C\WINDOWS\RACLE~1
C:\qoobox\purity\C\WINDOWS\SCURIT~1
C:\qoobox\purity\C\WINDOWS\SYSTEM32\FNTS~1
C:\qoobox\purity\C\WINDOWS\SYSTEM32\ICROSO~1


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CMDSERVICE
——-\LEGACY_COM+_MESSAGES
——-\LEGACY_NETWORK_MONITOR
——-\cmdService


((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-16 ))))))))))))))))))))))))))))))))))


2007-05-16 11:49 3,968 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-05-16 10:07 43,584 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys
2007-05-16 10:07 28,352 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys
2007-05-16 10:07 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\AntiVir PersonalEdition Classic
2007-05-16 09:50 d——– C:\DOCUME~1\MIKE~1.FUC\APPLIC~1\Comodo
2007-05-16 09:50 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Comodo
2007-05-16 09:48 d——– C:\Program Files\Comodo
2007-05-08 18:08 88,340 –a—— C:\WINDOWS\SYSTEM32\vmntsdwo.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-16 15:14:29 ——– d—–w C:\Program Files\iTunes
2007-05-16 15:14:23 ——– d—–w C:\Program Files\QuickTime
2007-05-16 15:03:52 615 —-a-w C:\WINDOWS\xsgiq.dll
2007-05-07 16:11:04 ——– d—–w C:\Program Files\Common Files\qwmk
2007-03-22 13:45:33 ——– d—–w C:\Program Files\Ultimate Cleaner
2007-03-18 15:24:53 ——– d—–w C:\DOCUME~1\MIKE~1.FUC\APPLIC~1\Ultimate Cleaner
2007-02-23 17:50:58 0 —-a-w C:\DOCUME~1\MIKE~1.FUC\APPLIC~1\amlistx.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{11B9AB3F-A91E-4F86-B21C-7ECEF54C5623}=C:\WINDOWS\System32\xufgoujr.dll []
{16D06D3E-2A5B-E9C9-F07C-0B9D099A71D0}=C:\WINDOWS\System32\oeeurfj.dll []
{45B6AD15-60F9-4854-F63D-69E34F97AFBF}=C:\WINDOWS\System32\xrc.dll []
{515B087E-08BF-1665-8CCF-0868A01116CD}=C:\WINDOWS\System32\rbdyam.dll []
{60D0CF58-AFF4-1BD7-9033-059ED7FE9ADC}=C:\WINDOWS\System32\ivyzjkm.dll []
{F446A814-8EF9-4554-A201-8747C82043BB}=C:\WINDOWS\MICROS~1.NET\barolg.dll [2006-11-09 08:58]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe" [2004-12-06 22:31]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
"Logitech Utility"="Logi_MwX.Exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" []
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 13:25]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" []
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-05-16 09:48]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2006-10-07 07:20]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Haws"="\"C:\\DOCUME~1\\MIKE~1.FUC\\APPLIC~1\\ASEMBL~1\\arpa.exe\" -vt ndrv"
@="C:\\PROGRA~1\\COMMON~1\\MBOLS~1\\RGEDIT~1.EXE"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source REG_SZ C:\Program Files\Uninstall Information\memehozet.html

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source REG_SZ C:\Program Files\XEROX\popokyc.html

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{9ae613a2-a13b-4379-8d0e-86a1a78476ec}"="C:\WINDOWS\System32\rmzdzx.dll" []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 09:13]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\barolg]
C:\WINDOWS\MICROS~1.NET\barolg.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\RunOnceEx]
C:\WINDOWS\system32\guard.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxmetwbf]
xxmetwbf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0
Security Packages kerberos msv1_0 schannel wdigest
Notification Packages scecli

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
NetworkService DnsCache
rpcss RpcSs
imgsvc StiSvc
termsvcs TermService

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20070516-114633-925
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/sy…nnerInstall.cab
backup-20070516-114633-123
O16 - DPF: {E4C29FDC-F547-4219-ACFD-571F2A7A564A} (WebCamTest Class) - http://awbeta.net-nucleus.com/CABUPDATES/winwcd.cab
backup-20070516-114632-727
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
backup-20070516-114632-692
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.downloadcontrol.com/files/insta…FreeInstall.cab
backup-20070516-114632-568
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {E44CB0D1-8B48-4724-BE13-5249517B5B9C} - (no file) (HKCU)
backup-20070516-114632-534
O9 - Extra button: Microsoft AntiSpyware helper - {E44CB0D1-8B48-4724-BE13-5249517B5B9C} - (no file) (HKCU)
backup-20070516-114632-359
O9 - Extra button: (no name) - {750A64D8-DFAA-485B-A335-F7093333FBB7} - (no file) (HKCU)
backup-20070516-114632-311
O9 - Extra button: Microsoft AntiSpyware helper - {432B4808-E2A1-4076-97AC-E9E500553B5A} - (no file) (HKCU)
backup-20070516-114631-507
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
backup-20070516-114631-334
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
backup-20070516-114631-329
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
backup-20070516-114631-229
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
backup-20070516-114631-396
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
backup-20070516-114631-346
O4 - HKCU\..\Run: [392855d7.exe] C:\Documents and Settings\Mike.FUCKSTICK\Local Settings\Application Data\392855d7.exe
backup-20070516-114631-624
O4 - HKCU\..\Run: [checkers] C:\WINDOWS\checkers5.exe
backup-20070516-114631-131
O4 - HKCU\..\Run: [Vnvjs] C:\PROGRA~1\COMMON~1\MBOLS~1\RGEDIT~1.EXE
backup-20070516-114631-153
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\System32\idjyyptl.dll",realset
backup-20070516-114631-191
O4 - HKLM\..\Run: [yoetyn] C:\WINDOWS\System32\awacyo.exe reg_run
backup-20070516-114631-198
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,bcxjkuy.exe
backup-20070516-114631-636
O4 - HKLM\..\Run: [392855d7.exe] C:\WINDOWS\System32\392855d7.exe
backup-20070516-114631-683
O4 - HKLM\..\Run: [ms064175195351] C:\WINDOWS\ms064175195351.exe
backup-20070516-114631-796
O4 - HKCU\..\Run: [vllua] C:\WINDOWS\System32\awacyo.exe reg_run
backup-20070516-114631-860
O4 - HKCU\..\Run: [SysProtect Free] "C:\Program Files\SysProtect Free\USYP.exe" /min
backup-20070516-114631-877
O4 - HKLM\..\Run: [Personal Security Center Monitor] C:\WINDOWS\System32\psc_mon.exe
backup-20070516-114631-939
O4 - HKCU\..\Run: [SysProtect] C:\Program Files\SysProtect Free\USYP.exe /scan
backup-20070516-114631-946
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
backup-20070516-114631-206
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
backup-20070516-114631-529
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qhqgy.exe
backup-20070516-114631-392
R3 - URLSearchHook: (no name) - {9914E4FB-241E-02EF-4180-72E2EE0020E1} - (no file)
backup-20070516-114631-314
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
backup-20070516-114631-303
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
backup-20070516-114631-210
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
backup-20070516-114631-125
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
backup-20070516-114631-489
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-16 15:20:29
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-05-16 15:23:15 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-05-16 15:23


— E O F —
Hi, While I am analyzing your logs - you actually sent me the log from Avira. I asked the log from AVG Antispyware to upload. So can you upload the log from AVG Antispyware as well please?
AVG Antispyware log

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 3:07:37 PM 5/16/2007

+ Scan result:



C:\WINDOWS\SYSTEM32\guard.tmp_tobedeleted -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\hrls0537e.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\hrno0553e.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\j6p0lg7m16.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\jt8m07l1e.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ktj6l71s1.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\mvafd.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\sxndmail.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tSpi.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\WinNB58.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\mmc.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\xrc.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\MirarSetup_876075.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\hjwvdnfq.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\rhnvgill.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
C:\WINDOWS\Microsoft.NET\barolg.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ts_www.exe -> Downloader.Bomka.r : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\components\flx153.dll -> Downloader.Zlob.ant : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ofkrlapu.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ptseuwlj.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\swfekaah.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmenlyjt.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tnitlggw.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tvkamxuf.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\vniiipcq.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wdkrlqfe.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\ICD1.tmp\USDR6_0001_D18M2707NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\components\flx107.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\components\flx108.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\components\flx109.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\components\flx122.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\components\flx170.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\components\flx172.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\components\flx88.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024 -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ldDCE6.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wapicc.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wapisvcc32.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\TWlrZQ\nq5Otk.vbs -> Trojan.Small : Cleaned with backup (quarantined).


::Report end
Latest HiJackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 3:44:06 PM, on 5/16/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O20 - AppInit_DLLs:
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI