This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Hijackthis And Vundofix Didn't Work

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am getting IE popup pages and have found now way to stop these.

Here is my HiJackThis logs one is from the Beta which finds the .dlls and the other is v1.99.1 which didn't find them.
I ran VundoFix in SafeMode which didn't identify these new .dlls but did remove the others that were listed.

tusqopn.dll
txtvggfy.dll

…and one common one which I used to find this website:

ssqro.dll

Any help would be greatly appreciated. :weee:
TIA,
Kevin

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

Logfile of HijackThis v1.99.1Scan saved at 5:21:48 PM, on 7/25/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tray Commander Lite\TC.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\InstaVerse\InstaVerse.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\KeyNote\keynote.exe
C:\Program Files\WordWeb\wweb32.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Hijackthis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Tray Commander Lite] C:\Program Files\Tray Commander Lite\TC.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [InstaVerse] C:\Program Files\InstaVerse\InstaVerse.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [MRUBlaster] C:\Program Files\MRU-Blaster\indexcleaner.exe -CACHE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - User Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - User Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - User Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Document Tree - C:\WINDOWS\web\tree.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Hide Object - res://C:\Program Files\BrowserTweaks\HideObject\hotool.dll/201
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: View Partial So&urce - C:\WINDOWS\web\source.htm
O8 - Extra context menu item: Zoom In [+] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/202
O8 - Extra context menu item: Zoom Out [-] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/203
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra 'Tools' menuitem: &Document Tree - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: (no name) - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - (no file)
O9 - Extra button: Hide Ads - {A166A42D-2759-4b41-BDF5-18D865C27DD0} - C:\Program Files\BrowserTweaks\HideAds\hideads.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

VundoFix V6.5.6

Checking Java version…

Scan started at 10:52:05 PM 7/23/2007

Listing files found while scanning….

C:\WINDOWS\System32\ddayx.dll
C:\WINDOWS\System32\xyadd.bak1
C:\WINDOWS\System32\xyadd.ini

Beginning removal…

Attempting to delete C:\WINDOWS\System32\ddayx.dll
C:\WINDOWS\System32\ddayx.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\xyadd.bak1
C:\WINDOWS\System32\xyadd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\xyadd.ini
C:\WINDOWS\System32\xyadd.ini Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Scan started at 9:03:44 PM 7/24/2007

Listing files found while scanning….

C:\WINDOWS\System32\ijllm.bak1
C:\WINDOWS\System32\ijllm.bak2
C:\WINDOWS\System32\ijllm.ini
C:\windows\system32\kpopkotb.dll
C:\WINDOWS\System32\mllji.dll

Beginning removal…

Attempting to delete C:\WINDOWS\System32\ijllm.bak1
C:\WINDOWS\System32\ijllm.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\ijllm.bak2
C:\WINDOWS\System32\ijllm.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\ijllm.ini
C:\WINDOWS\System32\ijllm.ini Has been deleted!

Attempting to delete C:\windows\system32\kpopkotb.dll
C:\windows\system32\kpopkotb.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\mllji.dll
C:\WINDOWS\System32\mllji.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\System32\ijllm.ini
C:\WINDOWS\System32\ijllm.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\mllji.dll
C:\WINDOWS\System32\mllji.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Scan started at 9:25:50 PM 7/24/2007

Listing files found while scanning….

No infected files were found.


VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 9:58:32 PM 7/24/2007

Listing files found while scanning….

C:\WINDOWS\System32\hjjlm.bak1
C:\WINDOWS\System32\hjjlm.ini
C:\WINDOWS\System32\mljjh.dll

Beginning removal…

Attempting to delete C:\WINDOWS\System32\hjjlm.bak1
C:\WINDOWS\System32\hjjlm.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\hjjlm.ini
C:\WINDOWS\System32\hjjlm.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\mljjh.dll
C:\WINDOWS\System32\mljjh.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.5.6

Checking Java version…

Sun Java not detected
Scan started at 10:09:27 PM 7/24/2007

Listing files found while scanning….

No infected files were found.

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>><<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<

BETA HiJackThis

Scan saved at 5:02:59 PM, on 7/25/2007
Platform: Windows XP (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tray Commander Lite\TC.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\InstaVerse\InstaVerse.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\KeyNote\keynote.exe
C:\Program Files\WordWeb\wweb32.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HiJackThis\HiJackThis_v2.exe

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: PopupManager Class - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - C:\Program Files\Popup Manager\PopupMgr_1.0.2.1P.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5DA31C56-E313-4078-9457-967D8546D30C} - C:\WINDOWS\System32\mljjh.dll (file missing)
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {D4DC28DB-47B7-4D44-B18F-C20B5C3F3EF6} - C:\WINDOWS\System32\ssqro.dll
O2 - BHO: (no name) - {DCD53738-C4F9-414A-A03C-C7405A4AC844} - C:\WINDOWS\system32\tusqopn.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Tray Commander Lite] C:\Program Files\Tray Commander Lite\TC.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [InstaVerse] C:\Program Files\InstaVerse\InstaVerse.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\System32\txtvggfy.dll",forkonce
O4 - HKLM\..\RunOnce: [MRUBlaster] C:\Program Files\MRU-Blaster\indexcleaner.exe -CACHE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - User Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - User Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - User Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Document Tree - C:\WINDOWS\web\tree.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Hide Object - res://C:\Program Files\BrowserTweaks\HideObject\hotool.dll/201
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: View Partial So&urce - C:\WINDOWS\web\source.htm
O8 - Extra context menu item: Zoom In [+] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/202
O8 - Extra context menu item: Zoom Out [-] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/203
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra 'Tools' menuitem: &Document Tree - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: (no name) - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - (no file)
O9 - Extra button: Hide Ads - {A166A42D-2759-4b41-BDF5-18D865C27DD0} - C:\Program Files\BrowserTweaks\HideAds\hideads.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: ssqro - C:\WINDOWS\System32\ssqro.dll
O20 - Winlogon Notify: tusqopn - C:\WINDOWS\SYSTEM32\tusqopn.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

–
End of file - 7396 bytes
Hi Kevin and welcome to the forums.

Yes, you obviously have a Vundo infection. The reason it is "hidden" from version 1.99.1 is that Vundo will hide from HijackThis.exe. If you rename HJT to something else then it will see it. That is why the new version picked it up in your case as it is named HiJackThis_v2.exe.

Vundo at times can be very stubborn to remove and takes several attempts and some different tools sometimes. Try running the VundoFix tool again and post a new Vundo log along with a new HJT log (renamed version of course). We'll go from there.

Regards,
Dave
Hi Dave,

Thanks for the help here…it is really a pain in the arse… :rant2:

OK so I ran AVG and it detected the tusqopn.dll file and moved to vault, that is why even though it shows up on the HiJack scan it says "file missing"

I ran vundofix which didn't do anything…and had to reboot in order to remove but it never did actually remove anything.

Here's the latest HiJackThis Log:…and below that the vundofix log.
Where do we go from here? :scratch:

Logfile of HijackThis v1.99.1
Scan saved at 9:32:16 PM, on 7/26/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tray Commander Lite\TC.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\InstaVerse\InstaVerse.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\KeyNote\keynote.exe
C:\WINDOWS\System32\devldr32.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\WordWeb\wweb32.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Hijackthis\scanner.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: PopupManager Class - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - C:\Program Files\Popup Manager\PopupMgr_1.0.2.1P.dll
O2 - BHO: (no name) - {1DDEDC70-8F30-4715-B684-012A253843B1} - C:\WINDOWS\System32\vtutt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {DCD53738-C4F9-414A-A03C-C7405A4AC844} - C:\WINDOWS\system32\tusqopn.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Tray Commander Lite] C:\Program Files\Tray Commander Lite\TC.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [InstaVerse] C:\Program Files\InstaVerse\InstaVerse.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MemoryManager] rundll32.exe "C:\WINDOWS\System32\ksjaayej.dll",forkonce
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [iTouch] C:\Program Files\Logitech\iTouch\iTouch.exe /RegServer
O4 - Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - User Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - User Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - User Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Document Tree - C:\WINDOWS\web\tree.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Hide Object - res://C:\Program Files\BrowserTweaks\HideObject\hotool.dll/201
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: View Partial So&urce - C:\WINDOWS\web\source.htm
O8 - Extra context menu item: Zoom In [+] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/202
O8 - Extra context menu item: Zoom Out [-] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/203
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra 'Tools' menuitem: &Document Tree - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: (no name) - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - (no file)
O9 - Extra button: Hide Ads - {A166A42D-2759-4b41-BDF5-18D865C27DD0} - C:\Program Files\BrowserTweaks\HideAds\hideads.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O20 - Winlogon Notify: tusqopn - tusqopn.dll (file missing)
O20 - Winlogon Notify: vtutt - C:\WINDOWS\System32\vtutt.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>———–<<<<<<<<<<<<<<<<<<<<<<<<<<<<

VundoFix V6.5.6

Checking Java version…

Scan started at 9:38:05 PM 7/26/2007

Listing files found while scanning….

C:\WINDOWS\System32\ttutv.bak1
C:\WINDOWS\System32\ttutv.bak2
C:\WINDOWS\System32\ttutv.ini
C:\WINDOWS\System32\vtutt.dll

Beginning removal…

Attempting to delete C:\WINDOWS\System32\ttutv.bak1
C:\WINDOWS\System32\ttutv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\ttutv.bak2
C:\WINDOWS\System32\ttutv.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\ttutv.ini
C:\WINDOWS\System32\ttutv.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\vtutt.dll
C:\WINDOWS\System32\vtutt.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\System32\ttutv.ini
C:\WINDOWS\System32\ttutv.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\vtutt.dll
C:\WINDOWS\System32\vtutt.dll Could not be deleted.

Performing Repairs to the registry.
Done!
Hi oneking,

Yes, Vundo is being very stubborn here…let's try this:

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a New HijackThis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Ok I think ComboFix did something good…still more work?

Thanks again for your help Dave.

Here's ComboFix Log: HiJackThis Log is below

"DefaultUser" - 2007-07-27 19:59:00 - ComboFix 07-07-23.6 FAT32


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\ttutv.ini
C:\WINDOWS\system32\vtutt.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\MabryObj.dll


((((((((((((((((((((((((( Files Created from 2007-06-28 to 2007-07-28 )))))))))))))))))))))))))))))))


2007-07-27 06:42 d——– C:\Program Files\WindowsUpdate
2007-07-27 05:43 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-26 22:06 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2007-07-26 22:06 50,944 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-07-26 22:06 33,152 –a—— C:\WINDOWS\system32\drivers\hidclass.sys
2007-07-26 22:06 23,680 –a—— C:\WINDOWS\system32\drivers\hidparse.sys
2007-07-26 22:06 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-07-26 21:35 d——– C:\WINDOWS\pss
2007-07-26 21:13 22,016 –a—— C:\WINDOWS\system32\drivers\mouclass.sys
2007-07-26 21:13 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2007-07-26 21:11 13,952 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2007-07-26 21:11 12,953 –a—— C:\WINDOWS\system32\drivers\itchfltr.sys
2007-07-26 20:51 126,016 –a—— C:\WINDOWS\system32\ksjaayej.dll
2007-07-25 20:59 d——– C:\Program Files\Lavasoft
2007-07-25 20:59 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-25 11:16 126,016 –a—— C:\WINDOWS\system32\txtvggfy.dll
2007-07-24 21:03 d——– C:\VundoFix Backups
2007-07-24 06:56 d–hs—- C:\FOUND.001
2007-07-21 13:53 d——– C:\Program Files\LiquidIcon
2007-07-21 13:43 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2007-07-21 13:43 1,047,552 –a—— C:\WINDOWS\system32\mfc71u.dll
2007-07-21 13:43 d——– C:\Program Files\WinMerge
2007-07-21 13:39 737,280 –a—— C:\WINDOWS\iun6002.exe
2007-07-10 10:44 d——– C:\Program Files\QuickTime
2007-07-10 10:42 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-07-02 00:01 d——– C:\DOCUME~1\DEFAUL~1\APPLIC~1\DivX
2007-07-01 23:49 d——– C:\Program Files\DivX
2007-07-01 21:09 99,328 ——— C:\WINDOWS\system32\ltfil90n.DLL
2007-07-01 21:09 88,576 ——— C:\WINDOWS\system32\lffpx90n.dll
2007-07-01 21:09 64,512 ——— C:\WINDOWS\system32\lffax90n.dll
2007-07-01 21:09 6,144 ——— C:\WINDOWS\system32\AWDCXC32.DLL
2007-07-01 21:09 58,880 ——— C:\WINDOWS\system32\npplg90N.dll
2007-07-01 21:09 46,592 ——— C:\WINDOWS\system32\LFICA90N.DLL
2007-07-01 21:09 40,960 ——— C:\WINDOWS\system32\LTNET90N.DLL
2007-07-01 21:09 39,936 ——— C:\WINDOWS\system32\lfgif90n.dll
2007-07-01 21:09 38,400 ——— C:\WINDOWS\system32\ltisi90n.dll
2007-07-01 21:09 36,864 ——— C:\WINDOWS\system32\LTWND90n.DLL
2007-07-01 21:09 35,840 ——— C:\WINDOWS\system32\LFLMA90N.DLL
2007-07-01 21:09 344,064 ——— C:\WINDOWS\system32\LFFPX7.DLL
2007-07-01 21:09 33,792 ——— C:\WINDOWS\system32\lfbmp90n.dll
2007-07-01 21:09 31,232 ——— C:\WINDOWS\system32\lfpcx90n.dll
2007-07-01 21:09 31,232 ——— C:\WINDOWS\system32\lfpct90n.dll
2007-07-01 21:09 31,232 ——— C:\WINDOWS\system32\LFLMB90N.DLL
2007-07-01 21:09 31,232 ——— C:\WINDOWS\system32\LFEPS90N.DLL
2007-07-01 21:09 3,824 ——— C:\WINDOWS\system32\ltthk90w.dll
2007-07-01 21:09 290,304 ——— C:\WINDOWS\system32\ltkrn90n.dll
2007-07-01 21:09 29,184 ——— C:\WINDOWS\system32\lfpsd90n.dll
2007-07-01 21:09 28,672 ——— C:\WINDOWS\system32\LFWMF90N.DLL
2007-07-01 21:09 28,672 ——— C:\WINDOWS\system32\lfawd90n.dll
2007-07-01 21:09 28,160 ——— C:\WINDOWS\system32\LFTGA90N.DLL
2007-07-01 21:09 27,648 ——— C:\WINDOWS\system32\LFWPG90N.DLL
2007-07-01 21:09 27,136 ——— C:\WINDOWS\system32\LFIMG90N.DLL
2007-07-01 21:09 27,136 ——— C:\WINDOWS\system32\LFCAL90N.DLL
2007-07-01 21:09 26,624 ——— C:\WINDOWS\system32\LFPCD90N.DLL
2007-07-01 21:09 26,624 ——— C:\WINDOWS\system32\AWRESX32.DLL
2007-07-01 21:09 26,112 ——— C:\WINDOWS\system32\LFRAS90N.DLL
2007-07-01 21:09 26,112 ——— C:\WINDOWS\system32\LFMSP90N.DLL
2007-07-01 21:09 25,600 ——— C:\WINDOWS\system32\LFWFX90N.DLL
2007-07-01 21:09 25,600 ——— C:\WINDOWS\system32\LFMAC90N.DLL
2007-07-01 21:09 24,576 ——— C:\WINDOWS\system32\AWCODC32.DLL
2007-07-01 21:09 235,008 ——— C:\WINDOWS\system32\LFCMP90n.DLL
2007-07-01 21:09 220,160 ——— C:\WINDOWS\system32\LTDIS90n.dll
2007-07-01 21:09 148,480 ——— C:\WINDOWS\system32\LTVID90N.DLL
2007-07-01 21:09 146,432 ——— C:\WINDOWS\system32\ltefx90n.dll
2007-07-01 21:09 145,920 ——— C:\WINDOWS\system32\ltdlg90n.dll
2007-07-01 21:09 133,632 ——— C:\WINDOWS\system32\lfpng90n.dll
2007-07-01 21:09 122,880 ——— C:\WINDOWS\system32\LFKODAK.DLL
2007-07-01 21:09 118,272 ——— C:\WINDOWS\system32\lftif90n.dll
2007-07-01 21:09 11,776 ——— C:\WINDOWS\system32\AWDENC32.DLL
2007-07-01 21:09 104,448 ——— C:\WINDOWS\system32\ltimg90n.dll
2007-07-01 21:09 10,240 ——— C:\WINDOWS\system32\AWVIEW32.DLL
2007-07-01 21:09 d——– C:\Program Files\Hemera Photo-Objects 50,000
2007-06-30 10:16 d——– C:\Program Files\jruler
2007-06-29 19:53 162,592 –a—— C:\DOCUME~1\DEFAUL~1\APPLIC~1\GDIPFONTCACHEV1.DAT


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-25 23:15:50 1,407 —-a-w C:\WINDOWS\mozver.dat
2007-07-24 13:48:54 262,144 —-a-w C:\ntuser.dat
2007-06-25 22:28:20 ——– d—–w C:\Program Files\KODAK
2007-06-25 22:28:20 ——– d—–w C:\Program Files\Common Files\Kodak
2007-06-23 18:02:56 ——– d—–w C:\DOCUME~1\DEFAUL~1\APPLIC~1\SFTech
2007-06-23 17:39:38 ——– d—–w C:\Program Files\gs
2007-06-23 17:35:14 ——– d—–w C:\Program Files\SFTech
2007-06-09 17:50:16 ——– d—–w C:\Program Files\JRTwine Software
2007-06-09 17:49:56 ——– d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-09 17:31:12 ——– d—–w C:\Program Files\GiPo@Utilities
2007-06-09 17:31:12 ——– d—–w C:\Program Files\Common Files\Gibinsoft Shared
2007-06-07 18:44:34 ——– d—–w C:\Program Files\Avenger
2007-06-04 22:18:48 9,344 —-a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 22:17:02 8,320 —-a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 22:14:56 6,272 —-a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-31 06:45:08 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-31 06:44:56 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 06:44:56 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 06:44:56 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 06:44:56 740,442 —-a-w C:\WINDOWS\system32\DivX.dll
2007-04-29 23:12:24 426 —-a-w C:\WINDOWS\system32\AutoPartNt.scr
2007-04-29 23:12:24 1,082,880 —-a-w C:\WINDOWS\system32\AutoPartNt.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1DDEDC70-8F30-4715-B684-012A253843B1}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B25090D1-2ACC-4062-94FF-9398D8794657}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Tray Commander Lite"="C:\Program Files\Tray Commander Lite\TC.exe" [2003-05-12 03:51]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-04-17 07:21]
"InstaVerse"="C:\Program Files\InstaVerse\InstaVerse.exe" [2007-03-23 13:44]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-06-25 19:03]

C:\Documents and Settings\DefaultUser\Start Menu\Programs\Startup\
KeyNote.lnk - C:\Program Files\KeyNote\keynote.exe [2003-11-13 23:16:52]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-28 16:45:56]
WordWeb.lnk - C:\Program Files\WordWeb\wweb32.exe [2007-03-18 09:21:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"=01000000
"NoSMMyDocs"=01000000
"NoSMMyPictures"=01000000
"NoRecentDocsMenu"=1 (0x1)
"NoStartMenuEjectPC"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoStartMenuPinnedList"=1 (0x1)
"NoStartMenuMFUProgramsList"=1 (0x1)
"NoStartMenuMorePrograms"=1 (0x1)
"NoRecentDocsHistory"=1 (0x1)
"NoRecentDocsFolder"=1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoStartBanner"=1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tusqopn]
tusqopn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 relog_ap

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\System32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\System32\DRIVERS\timntr.sys
R1 BANTExt;Belarc SMBios Access;C:\WINDOWS\System32\Drivers\BANTExt.sys
R1 DcCam;Kodak Camera Proxy;C:\WINDOWS\System32\DRIVERS\DcCam.sys
R1 NetworkX;NetworkX;C:\WINDOWS\System32\ckldrv.sys
R1 vdrv7000;vdrv7000;C:\WINDOWS\System32\DRIVERS\vdrv7000.sys
R2 DCFS2K;DCFS2K;C:\WINDOWS\System32\drivers\dcfs2k.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\System32\DRIVERS\tifsfilt.sys
R2 VC7SecS;Virtual CD v7 Management Service;C:\Program Files\HHVcdV7Sys\VC7SecS.exe
R3 ADPTEHCD;Adaptec USB 2.0 Enhanced Host Controller Driver;C:\WINDOWS\System32\DRIVERS\aehcd.sys
R3 ADPTHUBD;Adaptec USB 2.0 Hub Driver;C:\WINDOWS\System32\DRIVERS\ausb2hub.sys
R3 AUSBD_FilterService;Adaptec USB 2.0 Port Enumeration Driver;C:\WINDOWS\System32\DRIVERS\ausbd.sys
R3 ctljystk;Creative SBLive! Gameport;C:\WINDOWS\System32\DRIVERS\ctljystk.sys
R3 DM9102;DAVICOM 9102(A) PCI Fast Ethernet Based NT Driver;C:\WINDOWS\System32\DRIVERS\DM9PCI5.SYS
R3 PptpMiniport;WAN Miniport (PPTP);C:\WINDOWS\System32\DRIVERS\raspptp.sys
R3 RasPppoe;Remote Access PPPOE Driver;C:\WINDOWS\System32\DRIVERS\raspppoe.sys
R3 Raspti;Direct Parallel;C:\WINDOWS\System32\DRIVERS\raspti.sys
S1 Exportit;Exportit;C:\WINDOWS\System32\DRIVERS\exportit.sys
S2 MSFtpsvc;FTP Publishing;C:\WINDOWS\System32\inetsrv\inetinfo.exe
S2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\System32\inetsrv\inetinfo.exe
S2 W3SVC;World Wide Web Publishing;C:\WINDOWS\System32\inetsrv\inetinfo.exe
S3 atimtag;atimtag;C:\WINDOWS\System32\DRIVERS\atimtag.sys
S3 DcFpoint;DcFpoint;C:\WINDOWS\System32\DRIVERS\DcFpoint.sys
S3 DcLps;Legacy Polling Service;C:\WINDOWS\System32\DRIVERS\DcLps.sys
S3 DcPTP;dcptp;C:\WINDOWS\System32\DRIVERS\DcPTP.sys
S3 Mouc24xase;Mouc24xase;C:\WINDOWS\System32\drivers\nwlnkfwd.sys
S3 Perpsrver;Perpsrver;C:\WINDOWS\System32\drivers\pcmcia.sys
S3 StillCam;Still Serial Digital Camera Driver;C:\WINDOWS\System32\DRIVERS\serscan.sys
S4 IISADMIN;IIS Admin;C:\WINDOWS\System32\inetsrv\inetinfo.exe


HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}
rundll32 iesetup.dll,IEAccessUserInst

Contents of the 'Scheduled Tasks' folder
2007-07-28 03:01:02 C:\WINDOWS\tasks\At1.job

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-27 20:01:06
Windows 5.1.2600 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-27 20:01:30 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-07-27 20:01

— E O F —

>>>>>>>>>>>>>>>>>>>>>>>>>>>——————————-<<<<<<<<<<<<<<<<<<

Logfile of HijackThis v1.99.1
Scan saved at 8:03:56 PM, on 7/27/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\Program Files\Tray Commander Lite\TC.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\InstaVerse\InstaVerse.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\KeyNote\keynote.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Hijackthis\scanner.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: PopupManager Class - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - C:\Program Files\Popup Manager\PopupMgr_1.0.2.1P.dll
O2 - BHO: (no name) - {1DDEDC70-8F30-4715-B684-012A253843B1} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {B25090D1-2ACC-4062-94FF-9398D8794657} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Tray Commander Lite] C:\Program Files\Tray Commander Lite\TC.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [InstaVerse] C:\Program Files\InstaVerse\InstaVerse.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - User Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - User Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - User Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Document Tree - C:\WINDOWS\web\tree.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Hide Object - res://C:\Program Files\BrowserTweaks\HideObject\hotool.dll/201
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: View Partial So&urce - C:\WINDOWS\web\source.htm
O8 - Extra context menu item: Zoom In [+] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/202
O8 - Extra context menu item: Zoom Out [-] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/203
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra 'Tools' menuitem: &Document Tree - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: (no name) - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - (no file)
O9 - Extra button: Hide Ads - {A166A42D-2759-4b41-BDF5-18D865C27DD0} - C:\Program Files\BrowserTweaks\HideAds\hideads.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - Winlogon Notify: tusqopn - tusqopn.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe
Hi oneking,

Yes, combofix comes through again. Just some cleanup and a couple scans to make sure all is well I think now.

STEP 1:

This item:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

This is a restriction. When you run HJT leave it unchecked if it was set by you using a software like Spybot Search & Destroy, SpywareBlaster or another similar protection software, or if these were set by your system administrator. Otherwise check/fix it with Highjackthis.

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: (no name) - {1DDEDC70-8F30-4715-B684-012A253843B1} - (no file)
O2 - BHO: (no name) - {B25090D1-2ACC-4062-94FF-9398D8794657} - (no file)
O20 - Winlogon Notify: tusqopn - tusqopn.dll (file missing)

Then close all windows except this one and press Fix checked.

STEP 2:

Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

STEP 3:

You will need to run this with Internet Explorer.
Run Panda's ActiveScan from here and perform a full system scan.
  • Once you are on the Panda site click the "Scan your PC" button
  • A new window will open…click the big "Check Now" button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
  • If you are on a slow connection it will take about 15 minuites for the scanner to load.
  • Click on "Local Disks" to start the scan
  • Once scan is done, click "see report" then "save report"
  • Save the log someplace you can find
  • Reboot
  • Post the Panda scan results in your next reply
STEP 4:

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.

http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file.
Make sure that AVG Anti-Spyware is closed before installing the update.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon,
    some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Once in Safe Mode:

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot back into Normal Mode

So please provide the reports and a new HJT log for review. Also let me know how it's running.

Dave
Hi Dave

Looks like we got it all…
The strange thing is I run AD-Watch and AVG continuous and AVG caught the virus but didn't repair, remove or quarantine it?

Step 1
As far as this:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

I run both Spybot and Spyware Blaster. So I understand this…

Concerning these:
O2 - BHO: (no name) - {1DDEDC70-8F30-4715-B684-012A253843B1} - (no file)

O2 - BHO: (no name) - {B25090D1-2ACC-4062-94FF-9398D8794657} - (no file)


I ran SpyBot BHO and removed them. Also did a scan of the registry and removed all references manually.

Step 2
I did download ATF Cleaner and used? it. I prefer CrapCleaner it appears to be a lot more comprehensive and I've been using it for almost a year now.

Step 3
Didn't do this as I'm not one to give out email address unless absolutely necessary and don't like online tools actively accessing my computer. Regardless of how "secure" they might be.

Step 4
Ok I use Ad-Aware/Ad-Watch….I also run AVG Anti-Virus…along with the others I mentioned above…forking out another $30 for another spyware program is just beyond my means…Pretty soon we're going to have more "cleaning" apps on our computers then actual applications for computer use. ;-)

So I didn't do this step but did run Ad-Aware and Spy-Bot in safe mode along with AVG…they all came back clean.
Plus the search of the registry for all references to all the files…(I've been in computers for 18 years so I don't mind attacking the registry at all).

One final question is I am assuming I can remove the remains left by VundoFix and ComboFix - specifically their folders they use to "backup" what they find…I can remove these right?

Thanks again for all your help…I certainly wish these virus idiots would stop this madness as serves no purpose at all.
I'd like to ask them if this really is the best they can think of to do with their lives?

Oh well now I can get back to real computer work.

Here's the last HiJackThis scan:
Logfile of HijackThis v1.99.1
Scan saved at 1:49:02 PM, on 7/28/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tray Commander Lite\TC.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\InstaVerse\InstaVerse.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\KeyNote\keynote.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\WordWeb\wweb32.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\HHVcdV7Sys\VC7SecS.exe
C:\Program Files\Hijackthis\scanner.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: PopupManager Class - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - C:\Program Files\Popup Manager\PopupMgr_1.0.2.1P.dllF
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Tray Commander Lite] C:\Program Files\Tray Commander Lite\TC.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [InstaVerse] C:\Program Files\InstaVerse\InstaVerse.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - User Startup: KeyNote.lnk = C:\Program Files\KeyNote\keynote.exe
O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - User Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - User Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Document Tree - C:\WINDOWS\web\tree.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: Hide Object - res://C:\Program Files\BrowserTweaks\HideObject\hotool.dll/201
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: View Partial So&urce - C:\WINDOWS\web\source.htm
O8 - Extra context menu item: Zoom In [+] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/202
O8 - Extra context menu item: Zoom Out [-] - res://C:\Program Files\BrowserTweaks\PictureMagnifier\ztool.dll/203
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra 'Tools' menuitem: &Document Tree - {438AFBA1-B0CB-11d2-9214-00104B3BCE5F} - C:\WINDOWS\web\tree.htm
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Hide Ads - {A166A42D-2759-4b41-BDF5-18D865C27DD0} - C:\Program Files\BrowserTweaks\HideAds\hideads.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.intuit.com
O15 - Trusted Zone: http://*.turbotax.com
O15 - Trusted Zone: *.verizonwireless.com
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Virtual CD v7 Management Service (VC7SecS) - H+H Software GmbH - C:\Program Files\HHVcdV7Sys\VC7SecS.exe
Hi oneking,

OK, yes, looks like you got it. I'll answer questions next and then I just noticed something I should have picked up on at the beginning of the fix. No have absolutely No Windows Service Pack Updates. You need to update to at least SP1 ASAP and then when you are declared clean update to SP2(as SP2 has problems if Malware is present).

Click here for SP1: http://www.microsoft.com/windowsxp/downloa…p1/default.mspx

Step 2
I did download ATF Cleaner and used? it. I prefer CrapCleaner it appears to be a lot more comprehensive and I've been using it for almost a year now.


To each his own…that's fine.

Step 3
Didn't do this as I'm not one to give out email address unless absolutely necessary and don't like online tools actively accessing my computer. Regardless of how "secure" they might be.


Understood. You could use one of the other ones. This one is pretty simple. I would like this because while AVG is a pretty good free AV it is not as "robust" as some of the others.

Please go Here and do an online scan. Let it fix any infections.
Let me know what is found.

Step 4
Ok I use Ad-Aware/Ad-Watch….I also run AVG Anti-Virus…along with the others I mentioned above…forking out another $30 for another spyware program is just beyond my means…Pretty soon we're going to have more "cleaning" apps on our computers then actual applications for computer use. ;-)


AVG AS is free to download. The only thing is real time protection is only good for 30 days. But I find it a much more comprehensive cleaner than Adaware or Spybot S&D. As do many experts in these forums. But it's up to you.

So I didn't do this step but did run Ad-Aware and Spy-Bot in safe mode along with AVG…they all came back clean.
Plus the search of the registry for all references to all the files…(I've been in computers for 18 years so I don't mind attacking the registry at all).


Excellent!

One final question is I am assuming I can remove the remains left by VundoFix and ComboFix - specifically their folders they use to "backup" what they find…I can remove these right?


Yes, they can and should be removed. Even if you did need them again they are constantly updated so you would want the most recent version.

Thanks again for all your help…I certainly wish these virus idiots would stop this madness as serves no purpose at all.
I'd like to ask them if this really is the best they can think of to do with their lives?


On the contrary, it does serve a purpose for the Malware developers. It is profit based nowadays. Many of these people push rogue Anti-Malware programs and get good $$ for them from unsuspecting "victims".

Oh well now I can get back to real computer work.


Not quite. Running without the Service Packs and the most recent security updates will get you re-infected real quick. Do the updates and post a fresh log if you would still like help.

Regards,
Dave
Dave

Thanks again for your help…it is appreciated.
As far as addressing the issues you raised, the least I can do is answer your questions. :weee:

You have absolutely No Windows Service Pack Updates. You need to update to at least SP1 ASAP and then when you are declared clean update to SP2(as SP2 has problems if Malware is present).

Absolutely NOT! I have been running WindowsXP RAW for well…since it came out. I refuse to get on the "Bloatware Bandwagon" and play to MS's tune of more more more…I'll "upgrade" when they decide to actually fix their applications not just add more to them…which will probably never happen. This is the first time I've ever been "hit"…I could go on and on but I won't…Windows is NOT SECURE regardless of how many SPs and Updates you apply…so why apply them? :scratch:

AVG AS is free to download. The only thing is real time protection is only good for 30 days. But I find it a much more comprehensive cleaner than Adaware or Spybot S&D. As do many experts in these forums. But it's up to you.

I'll go ahead and try it…if it proves worth the money then I'm sure I'll purchase it…and would then get rid of Ad-Aware and maybe SpyBot…I realize the major problem here is that there isn't ONE GOOD COMPREHENSIVE APP covering all the bases. But I'd rather run as few as possible instead of as many as possible.

…I would like this because while AVG is a pretty good free AV it is not as "robust" as some of the others.

I have purchased the AVG AV…and it does realtime. I can't see that anything else is any better or worse. Like my statement above…I'm just gonna run 1 AV program.

On the contrary, it does serve a purpose for the Malware developers. It is profit based nowadays. Many of these people push rogue Anti-Malware programs and get good $$ for them from unsuspecting "victims".

So what you are saying is that malware creators are being paid by rogue Anti-Malware programs to proliferate their crapola.
Virtual insanity….for sure.

Not quite. Running without the Service Packs and the most recent security updates will get you re-infected real quick. Do the updates and post a fresh log if you would still like help.

:) Please don't misuderstand me as I do appreciate your help believe me. Next time (if there is - once in 7 years is not too much to handle)…I'll know better how to handle this type of issue. I learn real quick. As stated above I'm not anymore susceptible to this garbage than anyone else running any other Windows version.

And tell me you haven't seen the MAC commercials?
Why would I want to put myself through all that "Security"…it is surely more annoyance than it is "REAL" Security :wall:

Have a great Day and thanks again!

Kevin
OK Kevin…points taken. :thumbup: Sounds like you have a pretty good handle on things. I know there is no one security solution(s) that will guarantee that you stay clean. Even with all the "bloat" that the SP's carry there are many known security holes that do get patched, as I'm sure your aware. And no this won't guarantee that you stay clean either. It is a balancing act between performance and security. You can have too much security in place (ie Norton, McAfee). I can't tell you how many people come here complaining of poor performance and their PC is clean but has one of those bloated beasts bogging them down. All that for 60 bucks or whatever they charge now. I'll be honest with you. I don't spend a penny on any of my security, and doing this kind of "work" takes me to some pretty unsavory places at times. I have said this before, one of the best "security apps" is what I like to call Common Sense Security Suite 200X. Sounds like you have that in place. Good luck, Dave
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI