This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ad Problem

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 3:46:58 AM, on 6/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\Common Files\?icrosoft.NET\n?tdde.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\rundll32.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\win32F.tmp.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\TEMP\2410593.exe
C:\Documents and Settings\Mike\Desktop\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\3.bin\MBSRCAS.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Repair Registry Pro] C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe -s
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\arpl.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKLM\..\Run: [xiladgte.exe] C:\Documents and Settings\All Users\Application Data\xiladgte.exe
O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win32F.tmp.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvcuk.dll,startup
O4 - HKLM\..\Run: [dyfmvipo.exe] C:\Documents and Settings\All Users\Application Data\dyfmvipo.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu1000272.exe 61A847B5BBF72813329B385475FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\vbaapdpo.dll",forkonce
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EA Downloader\Core.exe -silent
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Ncao] "C:\DOCUME~1\Mike\MYDOCU~1\SEMBLY~1\dexplore.exe" -vt yazb
O4 - HKCU\..\Run: [Fepolcd] "C:\Program Files\Common Files\?icrosoft.NET\n?tdde.exe"
O4 - HKCU\..\Run: [ttool] C:\WINDOWS\9129837.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\kfowpleu.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

Any help would be much appreciatted.
Hi sparhawk814 ,

Welcome to Tom Coyote Forums

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Since there may be other issues with your system besides your original symptoms, please continue to follow this thread until I have given you an "All Clean.".
If you can do these things, everything should go smoothly.

Ready? Let's go.

*=========================*

Please download Suspicious File Packer from Safer-Networking.Org
http://www.safer-networking.org/files/sfp.zip and unzip it to your desktop.

IMPORTANT. There are some files on your computer we'd like to have a look at. If you can upload a copy of them to us, we would appreciate it.

Run SFP.exe.
Please copy the following lines into the Step 1: Paste Text window:
C:\WINDOWS\system32\arpl.exe
Click Continue.
This will create a .cab file on your desktop named requested-files[Date/Time].cab


Now please submit those files to Spykiller by clicking here
  • You will be taken to a new post page (at a different forum).
  • In the topic title put Request by Rogue
  • Put in body of messege the link to our thread here. ( http://forums.tomcoyote.org/Ad_Problem_t80788.html )
  • Press the browse button and then navigate to & select the file on desktop. (requested-files[Date/Time].cab)
  • Press Post to upload the file
It is normal you will not see the file you just posted because only approved members can see them to download them.

Let me know here when you have posted. .

*=========================*

Download Combofix by sUBs! from
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
or
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Save it to your Desktop
Double click combofix.exe and follow the prompts.
When finished, it shall produce a log C:\ComboFix.txt
Post that log in your next reply

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall
*=========================*

Create Uninstall List with Hijackthis
This is how you do that:
Open HiJackThis
Click on the tab "Open the Misc Tools Session"
Click on the Box that says "Uninstall Manager"
Click on the button "Save list"
Copy and past the List from notepad into your post
*=========================*

Please post the following;

C:\ComboFix.txt
New hijackthis log
Uninstall list

Thanks,
Rogue
Below is the ComboFix report:

ComboFix 07-06-18.2 - C:\Documents and Settings\Mike\Desktop\ComboFix.exe
"Mike" - 2007-07-02 16:00:50 - Service Pack 2 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\winhab32.dll
C:\WINDOWS\system32\bbadd.bak1
C:\WINDOWS\system32\bbadd.bak2
C:\WINDOWS\system32\bbadd.ini
C:\WINDOWS\system32\bbadd.ini2
C:\WINDOWS\system32\bbadd.tmp
C:\WINDOWS\system32\bbadd.bak1
C:\WINDOWS\system32\bbadd.bak2
C:\WINDOWS\system32\bbadd.ini
C:\WINDOWS\system32\bbadd.ini2
C:\WINDOWS\system32\bbadd.tmp
C:\WINDOWS\system32\bbadd.bak1
C:\WINDOWS\system32\bbadd.bak2
C:\WINDOWS\system32\bbadd.ini
C:\WINDOWS\system32\bbadd.ini2
C:\WINDOWS\system32\bbadd.tmp
C:\WINDOWS\system32\ddabb.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
C:\DOCUME~1\Mike\APPLIC~1\Install.dat
C:\DOCUME~1\Mike\Desktop\internet.lnk
C:\DOCUME~1\Mike\MYDOCU~1.\sembly~1
C:\DOCUME~1\Mike\MYDOCU~1.\sembly~1\dexplore.exe
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\icroso~1.net\n?tdde.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\newdotnet
C:\Program Files\newdotnet\newdotnet7_48.dll
C:\Program Files\newdotnet\uninstall7_48.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\WINDOWS\avp.exe
C:\WINDOWS\NDNuninstall7_48.exe
C:\WINDOWS\system32\driver.exe
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\winsys64.exe
C:\WINDOWS\system32\wnsapiisv32.exe
C:\WINDOWS\wr.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_NEW_DRV
——-\new_drv


((((((((((((((((((((((((( Files Created from 2007-06-02 to 2007-07-02 )))))))))))))))))))))))))))))))


2007-07-02 16:00 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-07-01 20:15 128,576 –a—— C:\WINDOWS\system32\baeyyksx.dll
2007-07-01 20:09 60,928 –a—— C:\WINDOWS\system32\djgdbj.dll
2007-07-01 20:09 122,944 –a—— C:\WINDOWS\system32\ljtgworb.exe
2007-07-01 20:04 8,192 –a—— C:\WINDOWS\system32\arpl.exe
2007-07-01 14:05 122,944 –a—— C:\WINDOWS\system32\kedkbbhq.exe
2007-06-30 03:13 56,832 –a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\dyfmvipo.exe
2007-06-30 03:13 31,254 –a—— C:\WINDOWS\system32\mljjihi.dll
2007-06-29 11:12 31,254 –a—— C:\WINDOWS\system32\cbxyxyy.dll
2007-06-29 08:42 66,112 –a—— C:\WINDOWS\system32\skoxudrk.dll
2007-06-28 20:34 56,832 –a—— C:\DOCUME~1\ALLUSE~1\APPLIC~1\xiladgte.exe
2007-06-28 20:34 31,254 –a—— C:\WINDOWS\system32\iiffdde.dll
2007-06-28 20:18 d——– C:\Program Files\ClamWin
2007-06-28 20:18 d——– C:\DOCUME~1\Mike\APPLIC~1\.clamwin
2007-06-28 20:18 d——– C:\DOCUME~1\ALLUSE~1\.clamwin
2007-06-28 15:24 31,254 –a—— C:\WINDOWS\system32\qomkiii.dll
2007-06-28 15:24 31,254 –a—— C:\WINDOWS\system32\gebxxwu.dll
2007-06-26 05:39 2 –a—— C:\DOCUME~1\Mike\APPLIC~1\xxx.exe
2007-06-26 05:39 14,848 –a—— C:\WINDOWS\system32\append.dll
2007-06-26 05:39 d——– C:\DOCUME~1\Mike\APPLIC~1\tiny
2007-06-21 22:10 d——– C:\Program Files\Defcon
2007-06-21 19:16 d——– C:\Program Files\Alex Feinman
2007-06-07 15:30 9,506 –a—— C:\DOCUME~1\Mike\APPLIC~1\antivirus.exe
2007-06-03 17:28 d——– C:\DOCUME~1\Mike\APPLIC~1\vlc
2007-06-03 16:20 d——– C:\Program Files\VideoLAN


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-02 21:11:37 ——– d-s—w C:\Program Files\Xfire
2007-07-02 10:15:29 ——– d—–w C:\Program Files\Zoom Player
2007-07-02 01:09:30 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\Xfire
2007-06-30 00:37:08 ——– d–h–w C:\Program Files\WindowsUpdate
2007-06-30 00:33:14 ——– d—–w C:\Program Files\Morpheus
2007-06-29 01:32:12 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\ultra
2007-06-29 01:26:02 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\.clamwin
2007-06-04 16:00:40 ——– d—–w C:\Program Files\MorpheusBar
2007-06-02 01:23:55 ——– d—–w C:\Program Files\iTunes
2007-06-02 01:23:47 ——– d—–w C:\Program Files\iPod
2007-05-26 14:18:23 ——– d—–w C:\Program Files\QuickTime
2007-05-23 01:45:06 ——– d—–w C:\Program Files\Common Files\AOL
2007-05-23 01:44:51 ——– d—–w C:\Program Files\Yahoo!
2007-05-23 01:42:20 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-05-22 21:52:08 ——– d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-05-22 20:34:49 ——– d—–w C:\Program Files\AIM
2007-05-22 20:32:58 ——– d—–w C:\Program Files\AOD
2007-05-20 19:46:02 1,417 -c–a-w C:\WINDOWS\eReg.dat
2007-05-20 19:41:53 ——– d—–w C:\Program Files\EA GAMES
2007-05-19 00:38:59 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\iPodder
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-14 21:40:11 21,840 —-atw C:\WINDOWS\system32\SIntfNT.dll
2007-05-14 21:40:11 17,212 —-atw C:\WINDOWS\system32\SIntf32.dll
2007-05-14 21:40:11 12,067 —-atw C:\WINDOWS\system32\SIntf16.dll
2007-05-12 18:18:46 ——– d—–w C:\Program Files\Combined Community Codec Pack
2007-05-12 17:45:51 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\Media Player Classic
2007-05-12 15:53:18 ——– d—–w C:\Program Files\FileZilla
2007-05-11 19:56:06 ——– d—–w C:\Program Files\BitTorrent
2007-05-10 23:23:18 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\PrivacyProtector Free
2007-05-10 23:02:08 ——– d—–w C:\Program Files\Tunebite
2007-05-10 09:56:47 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\tunebite
2007-05-10 08:13:54 322,872 —-a-w C:\DOCUME~1\Mike\APPLIC~1\privprotect.exe
2007-05-08 20:44:49 ——– d—–w C:\Program Files\AviSynth 2.5
2007-05-08 20:44:03 ——– d—–w C:\Program Files\eRightSoft
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 03:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-12 10:45:28 237,568 —-a-w C:\Program Files\Uninstall Morpheus Toolbar.dll
2005-05-13 22:12:00 217,073 –sha-r C:\WINDOWS\meta4.exe
2005-10-24 16:13:58 66,560 –sha-r C:\WINDOWS\MOTA113.exe
2005-10-14 02:27:00 422,400 –sha-r C:\WINDOWS\x2.64.exe
2005-10-08 00:14:52 308,224 –sha-r C:\WINDOWS\system32\avisynth.dll
2005-07-14 17:31:20 27,648 –sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 20:32:28 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 03:37:42 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
2004-01-25 05:00:00 70,656 –sha-r C:\WINDOWS\system32\i420vfw.dll
2006-04-27 15:24:24 2,945,024 –sha-r C:\WINDOWS\system32\Smab.dll
2005-02-28 18:16:22 240,128 –sha-r C:\WINDOWS\system32\x.264.exe
2004-01-25 05:00:00 70,656 –sha-r C:\WINDOWS\system32\yv12vfw.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{1F6581D5-AA53-4b73-A6F9-41420C6B61F1}=C:\WINDOWS\system32\skoxudrk.dll [2007-06-29 08:42]
{3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9}=C:\Program Files\MorpheusBar\bar\3.bin\MORPHBAR.DLL [2007-06-04 11:00]
{6F3F46F8-A91B-DB94-1B1B-FB8DCB57D5CF}=C:\WINDOWS\system32\djgdbj.dll [2007-06-20 09:49]
{A6807262-1D7A-44AB-947B-23B71E97915C}=C:\WINDOWS\system32\qomkiii.dll [2007-06-28 15:24]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll [2007-05-09 08:18]
{D73F49B1-B51B-4d32-A3B7-BD04B8342F53}=C:\Program Files\MorpheusBar\SrchAstt\3.bin\MBSRCAS.DLL [2007-06-04 11:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2003-03-21 14:50]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2003-03-18 15:53]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2003-08-04 20:25]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2003-07-02 21:32]
"Repair Registry Pro"="C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe" []
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2003-03-21 14:52]
"HostManager"="C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe" [2006-05-09 19:24]
"ViewMgr"="C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [2007-01-04 16:38]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 01:46]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-02-20 20:18]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-28 12:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 12:45]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2007-05-27 20:48]
"xiladgte.exe"="C:\Documents and Settings\All Users\Application Data\xiladgte.exe" [2007-06-28 20:34]
"dyfmvipo.exe"="C:\Documents and Settings\All Users\Application Data\dyfmvipo.exe" [2007-06-30 03:13]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2006-05-09 19:24]
"EA Core"="C:\Program Files\Electronic Arts\EA Downloader\Core.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-02 20:14]
"Ncao"="C:\DOCUME~1\Mike\MYDOCU~1\SEMBLY~1\dexplore.exe" []
"Fepolcd"="C:\Program Files\Common Files\?icrosoft.NET\n?tdde.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{A6807262-1D7A-44AB-947B-23B71E97915C}"="C:\WINDOWS\system32\qomkiii.dll" [2007-06-28 15:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomkiii]
qomkiii.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
C:\Program Files\BroadJump\Client Foundation\CFD.exe


Contents of the 'Scheduled Tasks' folder
2007-06-30 01:03:13 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-02 21:10:21 C:\WINDOWS\tasks\McAfee.com Update Check (FAMILY-Mike).job
2007-07-02 21:12:01 C:\WINDOWS\tasks\McAfee.com Update Check (MIKE-C7MGGZWNUB-Mike).job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-02 16:10:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-02 16:13:38 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-02 16:13

— E O F —
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\winhab32.dll
C:\WINDOWS\system32\bbadd.bak1
C:\WINDOWS\system32\bbadd.bak2
C:\WINDOWS\system32\bbadd.ini
C:\WINDOWS\system32\bbadd.ini2
C:\WINDOWS\system32\bbadd.tmp
C:\WINDOWS\system32\bbadd.bak1
C:\WINDOWS\system32\bbadd.bak2
C:\WINDOWS\system32\bbadd.ini
C:\WINDOWS\system32\bbadd.ini2
C:\WINDOWS\system32\bbadd.tmp
C:\WINDOWS\system32\bbadd.bak1
C:\WINDOWS\system32\bbadd.bak2
C:\WINDOWS\system32\bbadd.ini
C:\WINDOWS\system32\bbadd.ini2
C:\WINDOWS\system32\bbadd.tmp
C:\WINDOWS\system32\ddabb.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
C:\DOCUME~1\Mike\APPLIC~1\Install.dat
C:\DOCUME~1\Mike\Desktop\internet.lnk
C:\DOCUME~1\Mike\MYDOCU~1.\sembly~1
C:\DOCUME~1\Mike\MYDOCU~1.\sembly~1\dexplore.exe
C:\Program Files\Common Files\icroso~1.net
C:\Program Files\Common Files\icroso~1.net\n?tdde.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\newdotnet
C:\Program Files\newdotnet\newdotnet7_48.dll
C:\Program Files\newdotnet\uninstall7_48.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\WINDOWS\avp.exe
C:\WINDOWS\NDNuninstall7_48.exe
C:\WINDOWS\system32\driver.exe
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\winsys64.exe
C:\WINDOWS\system32\wnsapiisv32.exe
C:\WINDOWS\wr.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_NEW_DRV
——-\new_drv


((((((((((((((((((((((((( Files Created from 2007-06-02 to 2007-07-02 )))))))))))))))))))))))))))))))
Here is the new Hijackthis Logfile after running the first 2 programs:

Logfile of HijackThis v1.99.1
Scan saved at 16:18, on 2007-07-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Documents and Settings\All Users\Application Data\xiladgte.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\ComboFix\catchme.cfexe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Mike\Desktop\HijackThis.exe

R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\3.bin\MBSRCAS.DLL
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Repair Registry Pro] C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe -s
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKLM\..\Run: [xiladgte.exe] C:\Documents and Settings\All Users\Application Data\xiladgte.exe
O4 - HKLM\..\Run: [dyfmvipo.exe] C:\Documents and Settings\All Users\Application Data\dyfmvipo.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EA Downloader\Core.exe -silent
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Ncao] "C:\DOCUME~1\Mike\MYDOCU~1\SEMBLY~1\dexplore.exe" -vt yazb
O4 - HKCU\..\Run: [Fepolcd] "C:\Program Files\Common Files\?icrosoft.NET\n?tdde.exe"
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\kfowpleu.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Uninstall List: Ad-Aware SE Personal Adobe Flash Player Plugin Adobe Reader 8 Adobe Photoshop Album Starter Edition 3.0 America's Army AOL Instant Messenger AOL Unistaller Apple Software Update Battlefield 1942 Battlefield 1942: Secret Weapons of WWII Battlefield 1942: The Road to Rome Battlefield 2™ Battlefield 2: Special Forces Battlefield Vietnam BitTorrent 5.0.7 Broadcom Advanced Control Suite Broadcom Driver Installer BrodJump Client Foundation ClamWin Free Anitvirus 0.90.2.1 Combined Community Codec Pack 2007-02-22 Core AAC Decoder (remove only) CoreVorbis Audio Decoder (remove only) Defcon v1.42 Dell ResourceCD Digital Line Detect exPressit S.E. 2.2 ffdshow (remove only) FileZilla (remove only) Freeze Clip Art Google Updater Hijackthis 1.99.1 Intel® PRO Network Adapters and Drivers ISO Recorder iTunes Java 2 Runtime Environment, SE v1.4.2 Logitech Gaming Software Macromedia Shockwave Player Matroska (remove only) McAfee Personal Firewall Plus McAfee Security Center McAfee VirusScan Online Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 (Beta2) Modem Helper Morpheus Toolbar Mozilla Firefox (2.0.0.1) Mozilla Firefox (2.0.0.4) MSN Music Assistant My Wal-Mart Digital Photo Center NetWaiting NVIDIA Drivers OpenSource OFF Splitter (remove only) Outerinfo Picasa 22 PowerDVD PunkBuster for Battlefield 1942 PunkBuster for Battlefied Vietnam QuickTime RealPlayer Rhapsody Player Engine Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) SoundMAX SUPER © Version 2006.19 (FIX) The Print Shop® 6.0 Deluxe The Weather Channel Desktop TI Connect 1.6 Tiny soft Ultra soft Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Ventrilo Client VideoLAN VLC media player 0.8.6b Viewpoint Manager (Remove Only) Viewpoint Media Player Weather Services Who Wants To Be A Millionaire Windows Installer 3.1 (KB893803) Windows Media Format 11 runtime Windows Media Format 11 runtime Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Service Pack 2 Winferno Registry Power Cleaner WordPerfect Office 11 Xfire (remove only) Xvid 1.1 final uninstall Zoom Player (remove only)
HI sparhawk814
Please keep your internet surfing to a minimum until all clean.


Download and install AVG Anti-Spyware v7.5
  • After download, double click on the file to launch the install process.
  • Choose a language, click "OK" and then click "Next".
  • Read the "License Agreement" and click "I Agree".
  • Accept default installation path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5, click "Next", then click "Install".
  • After setup completes, click "Finish" to start the program automatically or launch AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray.
  • The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. As AVG Anti-Spyware may interfere with some of our other fixes, we are temporarily disabling it's active protection features until your system is clean, then you can reenable them.
  • Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
  • Go to Start > Run and type: services.msc
  • Press "OK".
  • Click the "Extended tab" and scroll down the list to find AVG Anti-Spyware guard.
  • When you find the guard service, double-click on it.
  • In the Properties Window > General Tab that opens, click the "Stop" button.
  • From the drop-down menu next to "Startup Type", click on "Manual".
  • Now click "Apply", then "OK" and close the Services window.
  • Connect to the Internet, go back to AVG Anti-Spyware, select the "Update" button and click "Start update". Wait until you see the "Update successful" message. If you are having problems with the updater, manually update with the AVG Anti-Spyware Full database installer from here.
  • Exit AVG Anti-Spyware when done - DO NOT perform a scan yet.
*========================*

Remove Programs
Please Click Start > Control Panel > Add/Remove Programs

Remove these programs by clicking Remove

Java 2 Runtime Environment, SE v1.4.2
Outerinfo << May prompt you that uninstaller cannoit be found and remove from list. Say Yes

If some programs listed are not present, please do not panic
*=========================*

Open Notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\baeyyksx.dll
C:\WINDOWS\system32\djgdbj.dll
C:\WINDOWS\system32\ljtgworb.exe
C:\WINDOWS\system32\arpl.exe
C:\WINDOWS\system32\kedkbbhq.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\dyfmvipo.exe
C:\WINDOWS\system32\mljjihi.dll
C:\DOCUME~1\ALLUSE~1\APPLIC~1\xiladgte.exe
C:\WINDOWS\system32\iiffdde.dll
C:\WINDOWS\system32\qomkiii.dll
C:\WINDOWS\system32\gebxxwu.dll
C:\DOCUME~1\Mike\APPLIC~1\xxx.exe
C:\WINDOWS\system32\skoxudrk.dll
C:\WINDOWS\system32\djgdbj.dll
C:\WINDOWS\system32\qomkiii.dll
C:\Documents and Settings\All Users\Application Data\xiladgte.exe
C:\Documents and Settings\All Users\Application Data\dyfmvipo.exe
C:\WINDOWS\system32\kfowpleu.exe

Driver::
DomainService

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{1F6581D5-AA53-4b73-A6F9-41420C6B61F1}"=-
"{6F3F46F8-A91B-DB94-1B1B-FB8DCB57D5CF}"=-
"{A6807262-1D7A-44AB-947B-23B71E97915C}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"xiladgte.exe"=-
"dyfmvipo.exe"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EA Core"=-
"Ncao"=-
"Fepolcd"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{A6807262-1D7A-44AB-947B-23B71E97915C}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomkiii]

Save this as ComboFix-Do.txt
Then drag the ComboFix-Do.txt into ComboFix.exe as you see in the screenshot below.
[external image: Posted Image]

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.
*=========================*

Please update Java Runtime Environment

[*]The current version can be downloaded from Sun here: http://java.sun.com/javase/downloads/index.jsp Scroll down the page to 'Java Runtime Environment (JRE) 6u1'

Selcted either Windows Online or Windows Offline download and press the 'Download' button. On the new web page, click the 'Accept License Agreement' button. Then select 'Windows Offline Installation, Multi-language' in the Windows Platform area just below the Accept button.
*=========================*

Scan with AVG Anti-Spyware as follows:
  • Click on the "Scanner" button and choose the "Settings" tab.
  • Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
  • Under "How to Scan?", "Possibly unwanted software", and What to Scan?" leave all the default settings.
  • Under "Reports" select "Automatically generate report after every scan" and UNcheck "Only if threats were found".
  • Click the "Scan" tab to return to scanning options.
  • Click "Complete System Scan" to start.
  • When the scan has finished you will be presented with a list of infected objects found. Click "Apply all actions" to place the files in Quarantine.
  • Click on "Report" button to view all completed scans.
  • Click on the most recent scan you just performed and select "Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt.
  • Save to your desktop. A copy of each report will also be saved in C:\Documents and Settings\Your User Name\Application Data\Grisoft\AVG Antispyware 7.5\Reports
  • Exit AVG Anti-Spyware when done, reboot normally and submit the log report in your next response.
*=========================*

Run Kapersky Online AV Scanner
Using Internet Explore Go to http://www.kaspersky.com/virusscanner and click the Kaspersky Online Scanner button.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded, click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log and a description of how your PC is behaving.
*=========================*

Please post the following;

combofix.txt
new Hijackthis log
AVG AntiSpyware log
kapersky log

Thanks
Rogue
ComboFix Log:
ComboFix 07-06-18.2 - C:\Documents and Settings\Mike\Desktop\ComboFix.exe
"Mike" - 2007-07-02 22:48:47 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Mike\Desktop\ComboFix-Do.txt


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\jjjlm.bak1
C:\WINDOWS\system32\jjjlm.ini
C:\WINDOWS\system32\mljjj.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1\dyfmvipo.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\xiladgte.exe
C:\DOCUME~1\Mike\APPLIC~1\xxx.exe
C:\WINDOWS\system32\arpl.exe
C:\WINDOWS\system32\baeyyksx.dll
C:\WINDOWS\system32\djgdbj.dll
C:\WINDOWS\system32\gebxxwu.dll
C:\WINDOWS\system32\iiffdde.dll
C:\WINDOWS\system32\kedkbbhq.exe
C:\WINDOWS\system32\ljtgworb.exe
C:\WINDOWS\system32\mljjihi.dll
C:\WINDOWS\system32\qomkiii.dll
C:\WINDOWS\system32\skoxudrk.dll


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-06-03 to 2007-07-03 )))))))))))))))))))))))))))))))


2007-07-02 22:58 8,192 –a—— C:\WINDOWS\system32\arpl.exe
2007-07-02 22:31 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-02 16:00 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-06-29 11:12 31,254 –a—— C:\WINDOWS\system32\cbxyxyy.dll
2007-06-28 20:18 d——– C:\Program Files\ClamWin
2007-06-28 20:18 d——– C:\DOCUME~1\Mike\APPLIC~1\.clamwin
2007-06-28 20:18 d——– C:\DOCUME~1\ALLUSE~1\.clamwin
2007-06-26 05:39 14,848 –a—— C:\WINDOWS\system32\append.dll
2007-06-26 05:39 d——– C:\DOCUME~1\Mike\APPLIC~1\tiny
2007-06-21 22:10 d——– C:\Program Files\Defcon
2007-06-21 19:16 d——– C:\Program Files\Alex Feinman
2007-06-07 15:30 9,506 –a—— C:\DOCUME~1\Mike\APPLIC~1\antivirus.exe
2007-06-03 17:28 d——– C:\DOCUME~1\Mike\APPLIC~1\vlc
2007-06-03 16:20 d——– C:\Program Files\VideoLAN


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-03 03:46:06 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\Xfire
2007-07-03 03:45:36 ——– d-s—w C:\Program Files\Xfire
2007-07-02 10:15:29 ——– d—–w C:\Program Files\Zoom Player
2007-06-30 00:37:08 ——– d–h–w C:\Program Files\WindowsUpdate
2007-06-30 00:33:14 ——– d—–w C:\Program Files\Morpheus
2007-06-29 01:32:12 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\ultra
2007-06-29 01:26:02 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\.clamwin
2007-06-04 16:00:40 ——– d—–w C:\Program Files\MorpheusBar
2007-06-02 01:23:55 ——– d—–w C:\Program Files\iTunes
2007-06-02 01:23:47 ——– d—–w C:\Program Files\iPod
2007-05-26 14:18:23 ——– d—–w C:\Program Files\QuickTime
2007-05-23 01:45:06 ——– d—–w C:\Program Files\Common Files\AOL
2007-05-23 01:44:51 ——– d—–w C:\Program Files\Yahoo!
2007-05-23 01:42:20 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-05-22 21:52:08 ——– d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-05-22 20:34:49 ——– d—–w C:\Program Files\AIM
2007-05-22 20:32:58 ——– d—–w C:\Program Files\AOD
2007-05-20 19:46:02 1,417 -c–a-w C:\WINDOWS\eReg.dat
2007-05-20 19:41:53 ——– d—–w C:\Program Files\EA GAMES
2007-05-19 00:38:59 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\iPodder
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-14 21:40:11 21,840 —-atw C:\WINDOWS\system32\SIntfNT.dll
2007-05-14 21:40:11 17,212 —-atw C:\WINDOWS\system32\SIntf32.dll
2007-05-14 21:40:11 12,067 —-atw C:\WINDOWS\system32\SIntf16.dll
2007-05-12 18:18:46 ——– d—–w C:\Program Files\Combined Community Codec Pack
2007-05-12 17:45:51 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\Media Player Classic
2007-05-12 15:53:18 ——– d—–w C:\Program Files\FileZilla
2007-05-11 19:56:06 ——– d—–w C:\Program Files\BitTorrent
2007-05-10 23:23:18 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\PrivacyProtector Free
2007-05-10 23:02:08 ——– d—–w C:\Program Files\Tunebite
2007-05-10 09:56:47 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\tunebite
2007-05-10 08:13:54 322,872 —-a-w C:\DOCUME~1\Mike\APPLIC~1\privprotect.exe
2007-05-08 20:44:49 ——– d—–w C:\Program Files\AviSynth 2.5
2007-05-08 20:44:03 ——– d—–w C:\Program Files\eRightSoft
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 03:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-12 10:45:28 237,568 —-a-w C:\Program Files\Uninstall Morpheus Toolbar.dll
2005-05-13 22:12:00 217,073 –sha-r C:\WINDOWS\meta4.exe
2005-10-24 16:13:58 66,560 –sha-r C:\WINDOWS\MOTA113.exe
2005-10-14 02:27:00 422,400 –sha-r C:\WINDOWS\x2.64.exe
2005-10-08 00:14:52 308,224 –sha-r C:\WINDOWS\system32\avisynth.dll
2005-07-14 17:31:20 27,648 –sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 20:32:28 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 03:37:42 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
2004-01-25 05:00:00 70,656 –sha-r C:\WINDOWS\system32\i420vfw.dll
2006-04-27 15:24:24 2,945,024 –sha-r C:\WINDOWS\system32\Smab.dll
2005-02-28 18:16:22 240,128 –sha-r C:\WINDOWS\system32\x.264.exe
2004-01-25 05:00:00 70,656 –sha-r C:\WINDOWS\system32\yv12vfw.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{1F6581D5-AA53-4b73-A6F9-41420C6B61F1}=C:\WINDOWS\system32\skoxudrk.dll []
{3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9}=C:\Program Files\MorpheusBar\bar\3.bin\MORPHBAR.DLL [2007-06-04 11:00]
{6F3F46F8-A91B-DB94-1B1B-FB8DCB57D5CF}=C:\WINDOWS\system32\djgdbj.dll []
{A6807262-1D7A-44AB-947B-23B71E97915C}=C:\WINDOWS\system32\qomkiii.dll []
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll [2007-05-09 08:18]
{D73F49B1-B51B-4d32-A3B7-BD04B8342F53}=C:\Program Files\MorpheusBar\SrchAstt\3.bin\MBSRCAS.DLL [2007-06-04 11:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2003-03-21 14:50]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2003-03-18 15:53]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2003-08-04 20:25]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2003-07-02 21:32]
"Repair Registry Pro"="C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe" []
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2003-03-21 14:52]
"HostManager"="C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe" [2006-05-09 19:24]
"ViewMgr"="C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [2007-01-04 16:38]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 01:46]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-02-20 20:18]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-28 12:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 12:45]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2007-05-27 20:48]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2006-05-09 19:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-02 20:14]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-07-02 22:40]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
C:\Program Files\BroadJump\Client Foundation\CFD.exe


Contents of the 'Scheduled Tasks' folder
2007-06-30 01:03:13 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-03 03:59:20 C:\WINDOWS\tasks\McAfee.com Update Check (FAMILY-Mike).job
2007-07-03 03:57:00 C:\WINDOWS\tasks\McAfee.com Update Check (MIKE-C7MGGZWNUB-Mike).job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-02 22:59:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-07-02 23:02:47 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-02 23:02
C:\ComboFix2.txt … 2007-07-02 16:15

— E O F —
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\jjjlm.bak1
C:\WINDOWS\system32\jjjlm.ini
C:\WINDOWS\system32\mljjj.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1\dyfmvipo.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\xiladgte.exe
C:\DOCUME~1\Mike\APPLIC~1\xxx.exe
C:\WINDOWS\system32\arpl.exe
C:\WINDOWS\system32\baeyyksx.dll
C:\WINDOWS\system32\djgdbj.dll
C:\WINDOWS\system32\gebxxwu.dll
C:\WINDOWS\system32\iiffdde.dll
C:\WINDOWS\system32\kedkbbhq.exe
C:\WINDOWS\system32\ljtgworb.exe
C:\WINDOWS\system32\mljjihi.dll
C:\WINDOWS\system32\qomkiii.dll
C:\WINDOWS\system32\skoxudrk.dll


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-06-03 to 2007-07-03 )))))))))))))))))))))))))))))))


2007-06-28 20:18 d——– C:\DOCUME~1\Mike\APPLIC~1\.clamwin
2007-06-28 20:18 d——– C:\DOCUME~1\ALLUSE~1\.clamwin


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-03 04:01:16 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\Xfire
2007-07-03 04:00:17 ——– d-s—w C:\Program Files\Xfire
2007-07-02 10:15:29 ——– d—–w C:\Program Files\Zoom Player
2007-06-30 00:37:08 ——– d–h–w C:\Program Files\WindowsUpdate
2007-06-30 00:33:14 ——– d—–w C:\Program Files\Morpheus
2007-06-29 01:32:12 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\ultra
2007-06-29 01:26:02 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\.clamwin
2007-06-04 16:00:40 ——– d—–w C:\Program Files\MorpheusBar
2007-06-02 01:23:55 ——– d—–w C:\Program Files\iTunes
2007-06-02 01:23:47 ——– d—–w C:\Program Files\iPod
2007-05-26 14:18:23 ——– d—–w C:\Program Files\QuickTime
2007-05-23 01:45:06 ——– d—–w C:\Program Files\Common Files\AOL
2007-05-23 01:44:51 ——– d—–w C:\Program Files\Yahoo!
2007-05-23 01:42:20 ——– d–h–w C:\Program Files\InstallShield Installation Information
2007-05-22 21:52:08 ——– d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-05-22 20:34:49 ——– d—–w C:\Program Files\AIM
2007-05-22 20:32:58 ——– d—–w C:\Program Files\AOD
2007-05-20 19:46:02 1,417 -c–a-w C:\WINDOWS\eReg.dat
2007-05-20 19:41:53 ——– d—–w C:\Program Files\EA GAMES
2007-05-19 00:38:59 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\iPodder
2007-05-16 15:12:02 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-14 21:40:11 21,840 —-atw C:\WINDOWS\system32\SIntfNT.dll
2007-05-14 21:40:11 17,212 —-atw C:\WINDOWS\system32\SIntf32.dll
2007-05-14 21:40:11 12,067 —-atw C:\WINDOWS\system32\SIntf16.dll
2007-05-12 18:18:46 ——– d—–w C:\Program Files\Combined Community Codec Pack
2007-05-12 17:45:51 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\Media Player Classic
2007-05-12 15:53:18 ——– d—–w C:\Program Files\FileZilla
2007-05-11 19:56:06 ——– d—–w C:\Program Files\BitTorrent
2007-05-10 23:23:18 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\PrivacyProtector Free
2007-05-10 23:02:08 ——– d—–w C:\Program Files\Tunebite
2007-05-10 09:56:47 ——– d—–w C:\DOCUME~1\Mike\APPLIC~1\tunebite
2007-05-10 08:13:54 322,872 —-a-w C:\DOCUME~1\Mike\APPLIC~1\privprotect.exe
2007-05-08 20:44:49 ——– d—–w C:\Program Files\AviSynth 2.5
2007-05-08 20:44:03 ——– d—–w C:\Program Files\eRightSoft
2007-04-25 14:21:15 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-17 03:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-04-12 10:45:28 237,568 —-a-w C:\Program Files\Uninstall Morpheus Toolbar.dll
2005-05-13 22:12:00 217,073 –sha-r C:\WINDOWS\meta4.exe
2005-10-24 16:13:58 66,560 –sha-r C:\WINDOWS\MOTA113.exe
2005-10-14 02:27:00 422,400 –sha-r C:\WINDOWS\x2.64.exe
2005-10-08 00:14:52 308,224 –sha-r C:\WINDOWS\system32\avisynth.dll
2005-07-14 17:31:20 27,648 –sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 20:32:28 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-22 03:37:42 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
2004-01-25 05:00:00 70,656 –sha-r C:\WINDOWS\system32\i420vfw.dll
2006-04-27 15:24:24 2,945,024 –sha-r C:\WINDOWS\system32\Smab.dll
2005-02-28 18:16:22 240,128 –sha-r C:\WINDOWS\system32\x.264.exe
2004-01-25 05:00:00 70,656 –sha-r C:\WINDOWS\system32\yv12vfw.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{1F6581D5-AA53-4b73-A6F9-41420C6B61F1}=C:\WINDOWS\system32\skoxudrk.dll []
{3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9}=C:\Program Files\MorpheusBar\bar\3.bin\MORPHBAR.DLL [2007-06-04 11:00]
{6F3F46F8-A91B-DB94-1B1B-FB8DCB57D5CF}=C:\WINDOWS\system32\djgdbj.dll []
{A6807262-1D7A-44AB-947B-23B71E97915C}=C:\WINDOWS\system32\qomkiii.dll []
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll [2007-05-09 08:18]
{D73F49B1-B51B-4d32-A3B7-BD04B8342F53}=C:\Program Files\MorpheusBar\SrchAstt\3.bin\MBSRCAS.DLL [2007-06-04 11:00]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2003-03-21 14:50]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2003-03-18 15:53]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2003-08-04 20:25]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2003-07-02 21:32]
"Repair Registry Pro"="C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe" []
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2003-03-21 14:52]
"HostManager"="C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe" [2006-05-09 19:24]
"ViewMgr"="C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [2007-01-04 16:38]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 01:46]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 11:59]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-02-20 20:18]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-28 12:38]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 12:45]
"ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2007-05-27 20:48]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24]
"Aim6"="C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" [2006-05-09 19:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-02 20:14]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-07-02 22:40]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
C:\Program Files\BroadJump\Client Foundation\CFD.exe


Contents of the 'Scheduled Tasks' folder
2007-06-30 01:03:13 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-03 04:04:00 C:\WINDOWS\tasks\McAfee.com Update Check (FAMILY-Mike).job
2007-07-03 04:02:00 C:\WINDOWS\tasks\McAfee.com Update Check (MIKE-C7MGGZWNUB-Mike).job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-02 23:03:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************

Completion time: 2007-07-02 23:05:09 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-02 23:05
C:\ComboFix2.txt … 2007-07-02 16:15

— E O F —
hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 23:07, on 2007-07-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mike\Desktop\HijackThis.exe

R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\3.bin\MBSRCAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1F6581D5-AA53-4b73-A6F9-41420C6B61F1} - C:\WINDOWS\system32\skoxudrk.dll (file missing)
O2 - BHO: MorpheusToolbar BHO - {3F3714A1-89A4-46be-8AF3-D0C9D1FB03F9} - C:\Program Files\MorpheusBar\bar\3.bin\MORPHBAR.DLL
O2 - BHO: (no name) - {6F3F46F8-A91B-DB94-1B1B-FB8DCB57D5CF} - C:\WINDOWS\system32\djgdbj.dll (file missing)
O2 - BHO: (no name) - {A6807262-1D7A-44AB-947B-23B71E97915C} - C:\WINDOWS\system32\qomkiii.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O2 - BHO: (no name) - {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\3.bin\MBSRCAS.DLL
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Repair Registry Pro] C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe -s
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1145125183\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" –logon
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
HI sparhawk814,

Using Windows Explorer, navigate to C:\Qoobox\quarantine
Holding down the Ctrl button, then using the left mouse button highlight all of the files.
Don't worry about the Registry_backups folder
Once those are highlighted, using the right mouse button
Select Send To
Select Compressed (zip) Folder

Now please submit those files to Spykiller by clicking here
  • It will take you to your previous post.
  • Press the browse button and then navigate to & select the zip file you just created.
  • Press Post to upload the file
Let me know here when you have posted. .

*=========================*

Start HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O2 - BHO: (no name) - {1F6581D5-AA53-4b73-A6F9-41420C6B61F1} - C:\WINDOWS\system32\skoxudrk.dll (file missing)
O2 - BHO: (no name) - {6F3F46F8-A91B-DB94-1B1B-FB8DCB57D5CF} - C:\WINDOWS\system32\djgdbj.dll (file missing)
O2 - BHO: (no name) - {A6807262-1D7A-44AB-947B-23B71E97915C} - C:\WINDOWS\system32\qomkiii.dll (file missing)
O4 - HKLM\..\Run: [Repair Registry Pro] C:\Program Files\Repair Registry Pro\RepairRegistryPro.exe -s

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked
*=========================*

Im still waitng for the AVG Anti-Spyware and Kapersky Online AV scan reports.

Thanks,
Rogue
This is a log of the second AVG scan as it wouldn't allow me to save a log of the first scan. ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 14:47 2007-07-03 + Scan result: C:\QooBox\Quarantine\catchme2007-07-02_225909.85.zip/qomkiii.dll -> Adware.Virtumonde : No action taken. C:\System Volume Information\_restore{C31A8744-8C96-4701-9C6F-43E9BA905EF6}\RP560\A0048165.exe -> Not-A-Virus.Downloader.Win32.WinFixer.y : No action taken. C:\WINDOWS\system32\xlibgfl254.dll -> Trojan.Agent : No action taken. [740] C:\WINDOWS\system32\xlibgfl254.dll -> Trojan.Agent : No action taken. ::Report end
It won't allow me to zip the files. The error reads as follows: "The compression cannot be performed because the file or directory 'C:\QooBox\Quarantine\C\Program Files\Common Files\ICROSO~1.net\netdde.exe.vir' contains character in its name that Compressed (zipped) Folders cannot store: e" What should I do?
I can live without most of those. See if you can find arpl.exe and send it over. Last attempt the file was not included. Most likely because it was still in use

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI