This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Why Me All The Tiem

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

To quote an old movie "why me all the time"

I just rebuilt my system with a motherboard, os, memory and chip. We went online to download the AVG virus scanner. And some how we picked up trojans and pop-up issues.

Here is the HJT log. (and we won't talk about the problems I had with saving it using HJT 1.99.1:

Logfile of HijackThis v1.99.1
Scan saved at 6:30:14 PM, on 7/17/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\ZONELABS\vsmon.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
D:\Program Files\AMD\Cool'n'Quiet\gemback.exe
D:\WINNT\system32\nvsvc32.exe
D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
D:\PROGRA~1\NTS\ENTERN~1\app\EnterNetFolder.Exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\Explorer.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\WINNT\system32\wuauclt.exe
D:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINNT\system32\NOTEPAD.EXE
D:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.netscape.com/home/winsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453485656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453476843
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: AMD PowerNow! ™ Technology Service (GemServ) - Advanced Micro Devices - D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINNT\system32\ZONELABS\vsmon.exe
Hi Wulfrenne and welcome to the Forums here at Tom Coyote.

I need you to rename Hijackthis because I suspect that you may have the Vundo infection that can hide some entries in your log.
  • Please go to the folder where you saved Hijackthis.exe:
  • Right-click on it, then select Rename.
  • Name it something like: FindVundo.exe (or whatever you want)
  • Then double-click the renamed HJT to scan and then post the new logfile.
Regards,
Dave
Thanks, that trick worked.

Here is the new log. I also ran the AVG spyware program and it says there are trojans in the system, PurityScan for one.

Logfile of HijackThis v1.99.1
Scan saved at 12:58:07 PM, on 7/18/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\ZONELABS\vsmon.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
D:\Program Files\AMD\Cool'n'Quiet\gemback.exe
D:\WINNT\system32\nvsvc32.exe
D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\Explorer.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINNT\system32\wuauclt.exe
D:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
D:\WINNT\system32\drwtsn32.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Hijackthis\Snafu.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.netscape.com/home/winsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3F480B1F-E8B4-45E6-A772-36923302CEBA} - D:\WINNT\system32\geeba.dll
O2 - BHO: (no name) - {3F4F125D-F31E-4D37-AC35-E50128670469} - D:\WINNT\system32\fccabax.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5660AE6D-7A5D-4011-8935-1950353C8D24} - D:\WINNT\system32\ddcyy.dll (file missing)
O2 - BHO: (no name) - {938A8A03-A938-4019-B764-03FF8D167D79} - D:\WINNT\system32\lnexjbfm.dll
O2 - BHO: (no name) - {F41DD7C4-3413-4436-BAA2-C2E3F5A6752B} - D:\WINNT\system32\awvvw.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453485656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453476843
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O20 - Winlogon Notify: fccabax - fccabax.dll (file missing)
O20 - Winlogon Notify: geeba - D:\WINNT\system32\geeba.dll
O20 - Winlogon Notify: nnnkjhg - D:\WINNT\SYSTEM32\nnnkjhg.dll
O20 - Winlogon Notify: winwil32 - D:\WINNT\SYSTEM32\winwil32.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: AMD PowerNow! ™ Technology Service (GemServ) - Advanced Micro Devices - D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINNT\system32\ZONELABS\vsmon.exe
Yes, Vundo is very much present here…so let's go.

Please download
VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click Yes
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from Click the Scan for Vundo button when VundoFix appears at reboot.
(whine) This not the way I wanted to spend my vacation (/whine)

Thanks for the help.

Here is the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 1:53:22 PM, on 7/18/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\ZONELABS\vsmon.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
D:\Program Files\AMD\Cool'n'Quiet\gemback.exe
D:\WINNT\system32\nvsvc32.exe
D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
D:\PROGRA~1\NTS\ENTERN~1\app\EnterNetFolder.Exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\Explorer.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINNT\system32\wuauclt.exe
D:\Program Files\Hijackthis\Snafu.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.netscape.com/home/winsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1FB63E52-4D6E-48C1-A08F-F630FE50F337} - D:\WINNT\system32\nnnkjhg.dll
O2 - BHO: (no name) - {3F480B1F-E8B4-45E6-A772-36923302CEBA} - D:\WINNT\system32\geeba.dll (file missing)
O2 - BHO: (no name) - {3F4F125D-F31E-4D37-AC35-E50128670469} - D:\WINNT\system32\fccabax.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5660AE6D-7A5D-4011-8935-1950353C8D24} - D:\WINNT\system32\ddcyy.dll (file missing)
O2 - BHO: (no name) - {F41DD7C4-3413-4436-BAA2-C2E3F5A6752B} - D:\WINNT\system32\awvvw.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453485656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453476843
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O20 - Winlogon Notify: fccabax - fccabax.dll (file missing)
O20 - Winlogon Notify: nnnkjhg - D:\WINNT\SYSTEM32\nnnkjhg.dll
O20 - Winlogon Notify: winwil32 - D:\WINNT\SYSTEM32\winwil32.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: AMD PowerNow! ™ Technology Service (GemServ) - Advanced Micro Devices - D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINNT\system32\ZONELABS\vsmon.exe

When the fix had finished removing the bad files I got the following message:

Cannot import D:\VundoFix.reg: Error in opening the file. There maybe a disk or file system error.

The VundoFix log:

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 4:39:15 PM 7/16/2007

Listing files found while scanning….

D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\wvvwa.bak1
D:\WINNT\system32\wvvwa.ini

Beginning removal…

Attempting to delete D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\awvvw.dll Could not be deleted.

Attempting to delete D:\WINNT\system32\wvvwa.bak1
D:\WINNT\system32\wvvwa.bak1 Has been deleted!

Attempting to delete D:\WINNT\system32\wvvwa.ini
D:\WINNT\system32\wvvwa.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 4:42:05 PM 7/16/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 4:43:29 PM 7/16/2007

Listing files found while scanning….

D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\wvvwa.ini

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 4:50:36 PM 7/16/2007

Listing files found while scanning….

D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\wvvwa.ini

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 12:33:16 PM 7/17/2007

Listing files found while scanning….

D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\dneftltp.ini
D:\WINNT\system32\ptltfend.dll
D:\WINNT\system32\uegxigxi.dll
D:\WINNT\system32\wvvwa.bak2
D:\WINNT\system32\wvvwa.ini

Beginning removal…

Attempting to delete D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\awvvw.dll Has been deleted!

Attempting to delete D:\WINNT\system32\dneftltp.ini
D:\WINNT\system32\dneftltp.ini Has been deleted!

Attempting to delete D:\WINNT\system32\ptltfend.dll
D:\WINNT\system32\ptltfend.dll Has been deleted!

Attempting to delete D:\WINNT\system32\uegxigxi.dll
D:\WINNT\system32\uegxigxi.dll Has been deleted!

Attempting to delete D:\WINNT\system32\wvvwa.bak2
D:\WINNT\system32\wvvwa.bak2 Has been deleted!

Attempting to delete D:\WINNT\system32\wvvwa.ini
D:\WINNT\system32\wvvwa.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 12:41:57 PM 7/17/2007

Listing files found while scanning….

No infected files were found.


VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 1:44:58 PM 7/17/2007

Listing files found while scanning….

D:\WINNT\system32\ddcyy.dll
D:\WINNT\system32\yycdd.bak1
D:\WINNT\system32\yycdd.ini

Beginning removal…

Attempting to delete D:\WINNT\system32\ddcyy.dll
D:\WINNT\system32\ddcyy.dll Has been deleted!

Attempting to delete D:\WINNT\system32\yycdd.bak1
D:\WINNT\system32\yycdd.bak1 Has been deleted!

Attempting to delete D:\WINNT\system32\yycdd.ini
D:\WINNT\system32\yycdd.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 1:46:17 PM 7/18/2007

Listing files found while scanning….

D:\WINNT\system32\abeeg.bak1
D:\WINNT\system32\abeeg.bak2
D:\WINNT\system32\abeeg.ini
D:\WINNT\system32\geeba.dll
D:\WINNT\system32\lnexjbfm.dll

Beginning removal…

Attempting to delete D:\WINNT\system32\abeeg.bak1
D:\WINNT\system32\abeeg.bak1 Has been deleted!

Attempting to delete D:\WINNT\system32\abeeg.bak2
D:\WINNT\system32\abeeg.bak2 Has been deleted!

Attempting to delete D:\WINNT\system32\abeeg.ini
D:\WINNT\system32\abeeg.ini Has been deleted!

Attempting to delete D:\WINNT\system32\geeba.dll
D:\WINNT\system32\geeba.dll Has been deleted!

Attempting to delete D:\WINNT\system32\lnexjbfm.dll
D:\WINNT\system32\lnexjbfm.dll Has been deleted!

Performing Repairs to the registry.
Done!
VundoFix is a wonderful tool and most of the time it works without a hitch. But it looks to be struggling with this Vundo variation. Let's try this and go from here. This may take a few posts but we'll get it, and you can hopefully get back to your vacation.

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Here are the two new logs:

ComboFix:

"Blue Meanie" - 07/18/2007 16:17:55 - ComboFix 07-07-14.6 - Service Pack 4 FAT32


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


D:\WINNT\system32\gebbaab.dll
D:\WINNT\system32\nnnnoop.dll
D:\WINNT\system32\gebbaab.dll
D:\WINNT\system32\nnnnoop.dll
D:\WINNT\system32\winwil32.dll
D:\WINNT\system32\prutv.bak1
D:\WINNT\system32\prutv.ini
D:\WINNT\system32\nnnkjhg.dll
D:\WINNT\system32\vturp.dll
D:\WINNT\system32\nnnkjhg.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


D:\Program Files\Common Files\Yazzle1162OinAdmin.exe
D:\Program Files\Common Files\Yazzle1162OinUninstaller.exe


((((((((((((((((((((((((( Files Created from 2007-06-18 to 2007-07-18 )))))))))))))))))))))))))))))))


2007-07-18 16:13 51,200 –a—— D:\WINNT\nircmd.exe
2007-07-17 14:08 10,872 –a—— D:\WINNT\system32\drivers\AvgAsCln.sys
2007-07-17 12:53 d——– D:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-17 10:55 819,200 –a—— D:\WINNT\system32\wmpcore.dll
2007-07-17 10:55 66,048 –a—— D:\WINNT\system32\wmerrenu.dll
2007-07-17 10:55 53,248 –a—— D:\WINNT\system32\mspmspsv.exe
2007-07-17 10:55 466,944 –a—— D:\WINNT\system32\wmv8dmoe.dll
2007-07-17 10:55 368,710 –a—— D:\WINNT\system32\msisam11.dll
2007-07-17 10:55 32,768 –a—— D:\WINNT\system32\asferror.dll
2007-07-17 10:55 309,584 –a—— D:\WINNT\system32\wmv8dmod.dll
2007-07-17 10:55 270,336 –a—— D:\WINNT\system32\pdbrowse.dll
2007-07-17 10:55 241,725 –a—— D:\WINNT\system32\msuni11.dll
2007-07-17 10:55 24,064 –a—— D:\WINNT\system32\wmdmlog.dll
2007-07-17 10:55 221,184 –a—— D:\WINNT\system32\msscp.dll
2007-07-17 10:55 188,416 –a—— D:\WINNT\system32\mspmsp.dll
2007-07-17 10:55 184,320 –a—— D:\WINNT\system32\wmpcd.dll
2007-07-17 10:55 163,840 –a—— D:\WINNT\system32\mindex.dll
2007-07-17 10:55 16,384 –a—— D:\WINNT\system32\wmdmps.dll
2007-07-17 10:55 159,744 –a—— D:\WINNT\system32\mswmdm.dll
2007-07-17 10:55 147,456 –a—— D:\WINNT\system32\CEWMDM.dll
2007-07-17 10:55 1,290,240 –a—— D:\WINNT\system32\wmploc.dll
2007-07-17 10:55 1,118,208 –a—— D:\WINNT\system32\wmpui.dll
2007-07-16 19:48 499,712 –a—— D:\WINNT\system32\msvcp71.dll
2007-07-16 19:48 348,160 –a—— D:\WINNT\system32\msvcr71.dll
2007-07-16 19:47 26,944 –a—— D:\WINNT\system32\drivers\avg7rsnt.sys
2007-07-16 17:23 11,973 –a—— D:\WINNT\system32\drivers\SECDRV.SYS
2007-07-16 16:39 d——– D:\VundoFix Backups
2007-07-16 15:44 d——– D:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-07-16 13:26 d——– D:\WINNT\winsxs
2007-07-15 19:24 45,056 –a—— D:\WINNT\system32\cdrtc.dll
2007-07-15 19:24 45,056 –a—— D:\WINNT\system32\cdral.dll
2007-07-15 19:24 40,960 –a—— D:\WINNT\uneng.exe
2007-07-15 19:24 d——– D:\Program Files\Common Files\Adaptec Shared
2007-07-15 19:24 d——– D:\Program Files\Adaptec
2007-07-15 15:08 940,544 –a—— D:\WINNT\system32\wmspdmoe.dll
2007-07-15 15:08 9,464 ——— D:\WINNT\system32\drivers\cdralw2k.sys
2007-07-15 15:08 9,336 ——— D:\WINNT\system32\drivers\cdr4_2k.sys
2007-07-15 15:08 895,736 –a—— D:\WINNT\system32\wmvdmod.dll
2007-07-15 15:08 87,040 –a—— D:\WINNT\system32\drmstor.dll
2007-07-15 15:08 774,904 –a—— D:\WINNT\system32\wmsdmod.dll
2007-07-15 15:08 43,528 ——— D:\WINNT\system32\drivers\PxHelp20.sys
2007-07-15 15:08 413,944 –a—— D:\WINNT\system32\wmspdmod.dll
2007-07-15 15:08 384,512 –a—— D:\WINNT\system32\mp4sdmod.dll
2007-07-15 15:08 317,176 –a—— D:\WINNT\system32\mp43dmod.dll
2007-07-15 15:08 306,424 –a—— D:\WINNT\system32\drmclien.dll
2007-07-15 15:08 240,640 –a—— D:\WINNT\system32\mpg4dmod.dll
2007-07-15 15:08 151,552 –a—— D:\WINNT\system32\wmidx.dll
2007-07-15 15:08 129,784 ——— D:\WINNT\system32\pxafs.dll
2007-07-15 15:08 1,119,744 –a—— D:\WINNT\system32\wmsdmoe2.dll
2007-07-15 15:08 1,003,008 –a—— D:\WINNT\system32\wmvdmoe2.dll
2007-07-15 15:07 d——– D:\Program Files\Winamp
2007-07-15 14:46 d——– D:\Program Files\Mozilla Thunderbird
2007-07-15 14:46 d——– D:\DOCUME~1\BLUEME~1\APPLIC~1\Thunderbird
2007-07-14 18:08 95,232 –a—— D:\WINNT\system32\Lfkodak.dll
2007-07-14 18:08 93,184 –a—— D:\WINNT\system32\lftif70n.dll
2007-07-14 18:08 90,112 –a—— D:\WINNT\system32\hpsjvset.dll
2007-07-14 18:08 77,824 –a—— D:\WINNT\system32\ipeapi12.dll
2007-07-14 18:08 667,648 –a—— D:\WINNT\system32\ipeistor12.dll
2007-07-14 18:08 55,808 –a—— D:\WINNT\system32\lffax70n.dll
2007-07-14 18:08 55,296 –a—— D:\WINNT\system32\ltfil70n.DLL
2007-07-14 18:08 49,152 –a—— D:\WINNT\system32\Hpgdtppg.dll
2007-07-14 18:08 350,208 –a—— D:\WINNT\system32\ltkrn70n.dll
2007-07-14 18:08 35,328 –a—— D:\WINNT\system32\lffpx70n.dll
2007-07-14 18:08 331,776 –a—— D:\WINNT\system32\ipebase12.dll
2007-07-14 18:08 32,768 –a—— D:\WINNT\system32\lfgif70n.dll
2007-07-14 18:08 32,768 –a—— D:\WINNT\system32\hpgreg32.dll
2007-07-14 18:08 32,768 –a—— D:\WINNT\system32\hpgdtuu.dll
2007-07-14 18:08 306,688 –a—— D:\WINNT\system32\Lffpx7.dll
2007-07-14 18:08 28,432 –a—— D:\WINNT\system32\hpsj32.dll
2007-07-14 18:08 24,576 –a—— D:\WINNT\system32\lfpcx70n.dll
2007-07-14 18:08 224,768 –a—— D:\WINNT\system32\LFCMP70n.DLL
2007-07-14 18:08 131,072 –a—— D:\WINNT\system32\hpgdtt.dll
2007-07-14 18:08 12,592 –a—— D:\WINNT\system32\drivers\usbscan.sys
2007-07-14 18:08 111,104 –a—— D:\WINNT\system32\lfpng70n.dll
2007-07-14 18:08 1,080 –a—— D:\WINNT\AUTOLNCH.REG
2007-07-14 18:08 d——– D:\Program Files\Hewlett-Packard
2007-07-14 16:44 d——– D:\DOCUME~1\BLUEME~1\APPLIC~1\Help
2007-07-14 16:17 d–h—– D:\WINNT\$SQLUninstallMDAC25SP3-KB927779-x86-ENU$
2007-07-14 16:14 d——– D:\WINNT\mui
2007-07-14 16:11 d——– D:\WINNT\system32\Windows Media
2007-07-14 16:10 947,472 –a—— D:\WINNT\system32\msjava.dll
2007-07-14 16:10 63,248 –a—— D:\WINNT\system32\javaprxy.dll
2007-07-14 16:10 6,550 –a—— D:\WINNT\jautoexp.dat
2007-07-14 16:10 49,424 –a—— D:\WINNT\system32\clspack.exe
2007-07-14 16:10 46,352 –a—— D:\WINNT\setdebug.exe
2007-07-14 16:10 404,752 –a—— D:\WINNT\system32\javart.dll
2007-07-14 16:10 313,856 –a—— D:\WINNT\system32\dx3j.dll
2007-07-14 16:10 286,992 –a—— D:\WINNT\system32\vmhelper.dll
2007-07-14 16:10 21,264 –a—— D:\WINNT\system32\msjdbc10.dll
2007-07-14 16:10 187,152 –a—— D:\WINNT\system32\javacypt.dll
2007-07-14 16:10 172,304 –a—— D:\WINNT\system32\jview.exe
2007-07-14 16:10 171,792 –a—— D:\WINNT\system32\wjview.exe
2007-07-14 16:10 171,280 –a—— D:\WINNT\system32\jit.dll
2007-07-14 16:10 154,384 –a—— D:\WINNT\system32\msawt.dll
2007-07-14 16:10 15,120 –a—— D:\WINNT\system32\jdbgmgr.exe
2007-07-14 16:10 139,536 –a—— D:\WINNT\system32\javaee.dll
2007-07-14 16:10 113 –a—— D:\WINNT\system32\zonedon.reg
2007-07-14 16:10 113 –a—— D:\WINNT\system32\zonedoff.reg
2007-07-14 16:10 d–h—– D:\WINNT\$NtUpdateRollupPackUninstall$
2007-07-14 16:10 d——– D:\WINNT\msiinst.tmp


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-16 02:25:22 99,686 —-a-w D:\WINNT\system32\drivers\pwd_2K.sys
2007-07-16 02:25:22 24,950 —-a-w D:\WINNT\system32\drivers\Mmc_2k.sys
2007-07-16 02:25:22 24,086 —-a-w D:\WINNT\system32\drivers\Dvd_2k.sys
2007-07-16 02:25:22 229,664 —-a-w D:\WINNT\system32\drivers\Cdudf.sys
2007-07-16 02:25:22 213,248 —-a-w D:\WINNT\system32\drivers\UdfReadr.sys
2007-07-12 15:08:22 9,344 —-a-w D:\WINNT\system32\drivers\NSDriver.sys
2007-07-12 15:08:22 7,808 —-a-w D:\WINNT\system32\drivers\AWRTRD.sys
2007-07-12 15:08:22 5,376 —-a-w D:\WINNT\system32\drivers\AWRTPD.sys
2007-07-12 01:52:40 271 —h–w D:\Program Files\desktop.ini
2007-07-12 01:52:40 21,952 —h–w D:\Program Files\folder.htt
2007-04-25 07:52:16 147,216 —-a-w D:\WINNT\system32\SCHANNEL.DLL
2007-04-23 06:22:02 939,280 —-a-w D:\WINNT\system32\ntdsa.dll
2007-04-19 05:06:32 6,239,232 —-a-w D:\WINNT\system32\sp3res.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
06-10-22 23:08 62080 –a—— D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F480B1F-E8B4-45E6-A772-36923302CEBA}]
D:\WINNT\system32\geeba.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F4F125D-F31E-4D37-AC35-E50128670469}]
D:\WINNT\system32\fccabax.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
05-05-31 01:04 853672 –a—— D:\PROGRA~1\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5660AE6D-7A5D-4011-8935-1950353C8D24}]
D:\WINNT\system32\ddcyy.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F41DD7C4-3413-4436-BAA2-C2E3F5A6752B}]
D:\WINNT\system32\awvvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [07-06-11 02:25 ]
"AVG7_CC"="D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [07-07-17 09:55 ]
"AdaptecDirectCD"="D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [07-07-15 19:25 ]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [07-05-11 03:06 ]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 D:\WINNT\system32\mobsync.exe]
"ZoneAlarm Client"="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [07-03-09 00:02 ]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=D:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{3F4F125D-F31E-4D37-AC35-E50128670469}"="D:\WINNT\system32\fccabax.dll" []
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [07-05-30 05:29 ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fccabax]
fccabax.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvCplDaemon"=RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE D:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
"SoundMan"=SOUNDMAN.EXE
"Synchronization Manager"=mobsync.exe /logon
"WinampAgent"=D:\Program Files\Winamp\winampa.exe
"ZoneAlarm Client"="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-18 16:22:26
Windows 5.0.2195 Service Pack 4 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-18 16:23:03 - machine was rebooted
D:\ComboFix-quarantined-files.txt … 07-07-18 16:23

— E O F —

HJT:
Logfile of HijackThis v1.99.1
Scan saved at 4:29:11 PM, on 7/18/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\ZONELABS\vsmon.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
D:\Program Files\AMD\Cool'n'Quiet\gemback.exe
D:\WINNT\system32\nvsvc32.exe
D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\Explorer.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\WINNT\system32\wuauclt.exe
D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINNT\system32\notepad.exe
D:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
D:\Program Files\Hijackthis\Snafu.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.netscape.com/home/winsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3F480B1F-E8B4-45E6-A772-36923302CEBA} - D:\WINNT\system32\geeba.dll (file missing)
O2 - BHO: (no name) - {3F4F125D-F31E-4D37-AC35-E50128670469} - D:\WINNT\system32\fccabax.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5660AE6D-7A5D-4011-8935-1950353C8D24} - D:\WINNT\system32\ddcyy.dll (file missing)
O2 - BHO: (no name) - {F41DD7C4-3413-4436-BAA2-C2E3F5A6752B} - D:\WINNT\system32\awvvw.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453485656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453476843
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O20 - Winlogon Notify: fccabax - fccabax.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: AMD PowerNow! ™ Technology Service (GemServ) - Advanced Micro Devices - D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINNT\system32\ZONELABS\vsmon.exe
Hi Wulfrenne,

STEP 1:

We need to make sure all hidden files are showing so please:
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

STEP 2:

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: (no name) - {3F480B1F-E8B4-45E6-A772-36923302CEBA} - D:\WINNT\system32\geeba.dll (file missing)
O2 - BHO: (no name) - {3F4F125D-F31E-4D37-AC35-E50128670469} - D:\WINNT\system32\fccabax.dll (file missing)
O2 - BHO: (no name) - {5660AE6D-7A5D-4011-8935-1950353C8D24} - D:\WINNT\system32\ddcyy.dll (file missing)
O2 - BHO: (no name) - {F41DD7C4-3413-4436-BAA2-C2E3F5A6752B} - D:\WINNT\system32\awvvw.dll (file missing)
O20 - Winlogon Notify: fccabax - fccabax.dll (file missing)

Then close all windows except this one and press Fix checked.

STEP 3:

Using Windows Explorer delete the following files if present:

D:\WINNT\system32\geeba.dll
D:\WINNT\system32\fccabax.dll
D:\WINNT\system32\ddcyy.dll
D:\WINNT\system32\awvvw.dll

STEP 4:

Let's run VundoFix again to make sure it is hopefully gone.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click Yes
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from Click the Scan for Vundo button when VundoFix appears at reboot.

Regards,
Dave
Hi Dave,

It looks really good now.

Here is the Vundo log:
VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 4:39:15 PM 7/16/2007

Listing files found while scanning….

D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\wvvwa.bak1
D:\WINNT\system32\wvvwa.ini

Beginning removal…

Attempting to delete D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\awvvw.dll Could not be deleted.

Attempting to delete D:\WINNT\system32\wvvwa.bak1
D:\WINNT\system32\wvvwa.bak1 Has been deleted!

Attempting to delete D:\WINNT\system32\wvvwa.ini
D:\WINNT\system32\wvvwa.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 4:42:05 PM 7/16/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 4:43:29 PM 7/16/2007

Listing files found while scanning….

D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\wvvwa.ini

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 4:50:36 PM 7/16/2007

Listing files found while scanning….

D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\wvvwa.ini

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 12:33:16 PM 7/17/2007

Listing files found while scanning….

D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\dneftltp.ini
D:\WINNT\system32\ptltfend.dll
D:\WINNT\system32\uegxigxi.dll
D:\WINNT\system32\wvvwa.bak2
D:\WINNT\system32\wvvwa.ini

Beginning removal…

Attempting to delete D:\WINNT\system32\awvvw.dll
D:\WINNT\system32\awvvw.dll Has been deleted!

Attempting to delete D:\WINNT\system32\dneftltp.ini
D:\WINNT\system32\dneftltp.ini Has been deleted!

Attempting to delete D:\WINNT\system32\ptltfend.dll
D:\WINNT\system32\ptltfend.dll Has been deleted!

Attempting to delete D:\WINNT\system32\uegxigxi.dll
D:\WINNT\system32\uegxigxi.dll Has been deleted!

Attempting to delete D:\WINNT\system32\wvvwa.bak2
D:\WINNT\system32\wvvwa.bak2 Has been deleted!

Attempting to delete D:\WINNT\system32\wvvwa.ini
D:\WINNT\system32\wvvwa.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 12:41:57 PM 7/17/2007

Listing files found while scanning….

No infected files were found.


VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 1:44:58 PM 7/17/2007

Listing files found while scanning….

D:\WINNT\system32\ddcyy.dll
D:\WINNT\system32\yycdd.bak1
D:\WINNT\system32\yycdd.ini

Beginning removal…

Attempting to delete D:\WINNT\system32\ddcyy.dll
D:\WINNT\system32\ddcyy.dll Has been deleted!

Attempting to delete D:\WINNT\system32\yycdd.bak1
D:\WINNT\system32\yycdd.bak1 Has been deleted!

Attempting to delete D:\WINNT\system32\yycdd.ini
D:\WINNT\system32\yycdd.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 1:46:17 PM 7/18/2007

Listing files found while scanning….

D:\WINNT\system32\abeeg.bak1
D:\WINNT\system32\abeeg.bak2
D:\WINNT\system32\abeeg.ini
D:\WINNT\system32\geeba.dll
D:\WINNT\system32\lnexjbfm.dll

Beginning removal…

Attempting to delete D:\WINNT\system32\abeeg.bak1
D:\WINNT\system32\abeeg.bak1 Has been deleted!

Attempting to delete D:\WINNT\system32\abeeg.bak2
D:\WINNT\system32\abeeg.bak2 Has been deleted!

Attempting to delete D:\WINNT\system32\abeeg.ini
D:\WINNT\system32\abeeg.ini Has been deleted!

Attempting to delete D:\WINNT\system32\geeba.dll
D:\WINNT\system32\geeba.dll Has been deleted!

Attempting to delete D:\WINNT\system32\lnexjbfm.dll
D:\WINNT\system32\lnexjbfm.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 11:02:54 AM 7/19/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

Here is the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:05:52 AM, on 7/19/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\ZONELABS\vsmon.exe
D:\WINNT\system32\spoolsv.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
D:\WINNT\System32\svchost.exe
D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
D:\Program Files\AMD\Cool'n'Quiet\gemback.exe
D:\WINNT\system32\nvsvc32.exe
D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\system32\stisvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\system32\mspmspsv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\Explorer.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
D:\WINNT\system32\wuauclt.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\PROGRA~1\NTS\ENTERN~1\app\EnterNet.exe
D:\Program Files\Hijackthis\Snafu.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.netscape.com/home/winsearch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.netscape.com/home/winsearch200.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://home.netscape.com/home/winsearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AdaptecDirectCD] "D:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453485656
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1184453476843
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: AMD PowerNow! ™ Technology Service (GemServ) - Advanced Micro Devices - D:\Program Files\AMD\Cool'n'Quiet\GemServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - D:\PROGRA~1\NTS\ENTERN~1\app\pppoeservice.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINNT\system32\ZONELABS\vsmon.exe
Yes, things look better. How is it running? I would like to have you run AVG AS in Safe Mode and provide a report in your next post. Please make sure you update AVG first and then follow these instructions to run it:

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon,
    some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Once in Safe Mode:

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot back into Normal Mode

So please post the AVG report and a new HJT log. Also let me know how it's runnng.

Dave

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI