This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Vundo On My Windows Xp Machine

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I would appreciate if the authorized experts on this site help me resolve the vundo infection on my Windows XP machine.

Regards, Khilafat


I have cut/paste the HijackThis log that I ran a few minutes back:

Logfile of HijackThis v1.99.1
Scan saved at 6:50:24 PM, on 8/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe
C:\WINDOWS\TEMP\win13.tmp.exe
C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Salil\MYDOCU~1\CROSOF~1.NET\nopdb.exe
C:\WINDOWS\system32\regscan.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\1632.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\powersys.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\sv32.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\sv64.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\sv64.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\syn32.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\6432.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\win64.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\looksv.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\64agent.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\32host.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\serverserver.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\syshost.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\monsys.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\monsys.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\6432.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\looksyn.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\agentagent.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\winagent.exe
C:\DOCUME~1\Salil\LOCALS~1\Temp\monpower.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customize/ie/defaul…m/ext/search/se

arch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customize/ie/defaul…m/ext/search/se

arch.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -

C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -

c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update

Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKLM\..\Run: [sm] C:\WINDOWS\sa_exe.exe
O4 - HKLM\..\Run: [firewall_anti] C:\WINDOWS\firewall_anti.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared

Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [load32] C:\WINDOWS\system32\winldra.exe
O4 - HKLM\..\Run: [key2] C:\WINDOWS\system32\winlog.exe
O4 - HKLM\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
O4 - HKLM\..\Run: [SIE2004] "C:\Program Files\Winferno\Secure IE\SIEPulse.exe"
O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
O4 - HKLM\..\Run: [system43.exe] C:\WINDOWS\system32\system43.exe
O4 - HKLM\..\Run: [DxDialog] C:\WINDOWS\system32\dxdlg32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"

-osboot
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\Salil\LOCALS~1\Temp\MBDownloader_876919.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu361.exe

61A847B5BBF72811349A284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKLM\..\Run: [adeakdjA] C:\WINDOWS\adeakdjA.exe
O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\nwinqqdt.exe SKY009
O4 - HKLM\..\Run: [g4356cbvy63] C:\WINDOWS\g4356cbvy63
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernelwind32.exe
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware

2007\was7.exe" /min
O4 - HKLM\..\Run: [bantool] C:\WINDOWS\system32\ie_ban.exe
O4 - HKLM\..\Run: [uwas7cw] "C:\Program Files\Common Files\WinAntiSpyware

2007\uwas7cw.exe" -c
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware

2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
O4 - HKLM\..\Run: [WinCore32.exe] C:\WINDOWS\system32\WinCore32.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win13.tmp.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvfim.dll,startup
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [key2] C:\WINDOWS\system32\winlog.exe
O4 - HKCU\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe
O4 - HKCU\..\Run: [mule_st_key] C:\Documents and Settings\Salil\Application

Data\m\flec006.exe
O4 - HKCU\..\Run: [drv_st_key] C:\Documents and Settings\Salil\Application

Data\hidn\hidn2.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [drvsyskit] C:\Documents and Settings\Salil\Application Data\hidires\hidr.exe
O4 - HKCU\..\Run: [Aida] "C:\DOCUME~1\Salil\MYDOCU~1\CROSOF~1.NET\nopdb.exe" -vt yazb
O4 - HKCU\..\Run: [Rssvfu] "C:\Program Files\?ppPatch\w?nlogon.exe"
O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [Service Pack 1] C:\WINDOWS\system32\vedxg6ame4.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\nwinqqdt.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture

Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program

files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program

Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program

files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program

files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program

files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program

files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program

Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program

Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program

Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}

- C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -

C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d}

- http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) -

http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner -

C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program

Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner -

C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\adeakdj.exe (file

missing)
Hello khilafat and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.


A. I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

1. Click Start, then Settings, then click Control Panel.
2. In Control Panel, double-click Add or Remove Programs.
3. In Add or Remove Programs, Remove the Viewpoint component
4. Do the same for each Viewpoint component.



B. Some trojans have a way of masking their presence from the HijackThis program when they recognize the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file on your desktop: HijackThis.exe
Next, right click on the file and from the popup menu that appears, choose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


C. I need you to post your log in single space format instead of double space as it currently is.

To remove the double spacing in your log, please do the following:
  • Please go to Start >> Run… and type notepad.exe
  • Hit OK.
  • Now go to Format and uncheck WordWrap.
  • Close Notepad.

D. Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.

E. Now, please run the newly renamed HijackThis, click SCAN, produce a log and post that also into this topic.

Regards.

Trevuren
Hi Trevuren, Thank-you for responding so fast. I should have mentioned that I ran VundoFix.exe yesterday. It seemed to clean up some of the files. I am wondering whether that is the reason some of the files that you mentioned are not there. But even after running that tool, on start-up I get the "this machine is infected.." windows popup. There is an explorer.exe process (against my username and not Syste) that consumes 80-100% of the CPU. I also get a lot of popups every few minutes. Here is the information from the run that you had asked for (I was unable to locate the AOL tools so have not removed them for now): ABC (remove only) Ad-Aware SE Personal Adobe Acrobat - Reader 6.0.2 Update Adobe Flash Player 9 ActiveX Adobe Reader 6.0.1 ArcSoft Multimedia Email ArcSoft PhotoImpression 5 Baraha 6.0 Canon Camera Support Core Library Canon Camera WIA Driver 6.2.5 Canon Camera Window for ZoomBrowser EX Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities PhotoStitch 3.1 Canon Utilities ZoomBrowser EX Creative WebCam Center Creative WebCam Instant Driver (1.00.08.0416) Creative WebCam Instant User's Guide (English) Dell Driver Reset Tool Dell Media Experience Dell Solution Center Dell Support 5.0.0 (766) Enhanced Ads by Think-Adz removal Get Yahoo! Messenger Google Earth Google Toolbar for Internet Explorer Google Video Player Hijackthis 1.99.1 HijackThis 1.99.1 Intel® Extreme Graphics 2 Driver Intel® PRO Network Adapters and Drivers Intel® PROSet for Wired Connections Internet Explorer Default Page Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java 2 Runtime Environment, SE v1.4.2_03 Macromedia Flash Player Macromedia Shockwave Player McAfee SecurityCenter McAfee VirusScan Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft Office Professional Edition 2003 Mozilla Firefox (1.0.1) MSN Messenger 7.0 MSN Money Investment Toolbox Nortel Networks Contivity VPN Client Outerinfo Picasa 2 PowerDVD 5.1 RealPlayer Rocket Piano Bonus Software Rocket Piano eBooks Rocket Piano MP3 Audio Files Secure IE 2004 Skype 2.0 Sonic DLA Sonic RecordNow! Sonic Update Manager Sony USB Driver Spybot - Search & Destroy 1.3 Sunbelt Remote Administrator v2.1 Think-Adz Search Assistant removal Twisted Pair Computer Based Training Electronics Part 12 5.0 Update for Windows XP (KB898461) Webshots Desktop WinAntiSpyware 2007 [removed] Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Overlay Components Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WordPerfect Office 12 Yahoo! Browser Services Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Photos Easy Upload Tool Yahoo! Photos Print-at-Home Tool Yahoo! Toolbar ZoneAlarm Regards, Khilafat
Sorry I missed adding the log from HijackThis/Killer.exe. Here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 8:19:17 PM, on 8/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\mgrs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Salil\MYDOCU~1\CROSOF~1.NET\nopdb.exe
C:\Program Files\?ppPatch\w?nlogon.exe
C:\Program Files\WinPop\winpop.exe
C:\WINDOWS\system32\regscan.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\notepad.exe
c:\program files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Killer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0CA74223-CA69-4158-92E6-92642A602E3F} - C:\WINDOWS\system32\opnopon.dll
O2 - BHO: BhoApp Class - {0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2} - C:\Program Files\WinBudget\bin\matrix.dll
O2 - BHO: Editor plugin - {0EEDB1E5-5765-4a2a-9D72-CB5213D756C0} - fertbuk.dll (file missing)
O2 - BHO: (no name) - {3AEF599F-2604-491E-B777-3772BC11DC5A} - C:\Program Files\MSN\hoke4444.dll
O2 - BHO: (no name) - {42DD8BBD-130B-3FFC-7C74-38B60049F1CF} - C:\WINDOWS\system32\annhl.dll
O2 - BHO: 0 - {436394CE-7225-4DA4-6CB5-AC4F2A5D9164} - C:\Program Files\MSN Gaming Zone\lavuqa.dll
O2 - BHO: (no name) - {49EA22F7-64EB-4243-8198-AE1648E4F087} - C:\WINDOWS\system32\ssttq.dll (file missing)
O2 - BHO: (no name) - {4C55606C-A77A-4AA8-9315-C4DDB09E58C1} - C:\Program Files\MSN\hoke83122.dll
O2 - BHO: (no name) - {4F4DB14D-9BB4-4AE2-B615-E0E652C1FD36} - C:\Program Files\MSN\hoke2.dll
O2 - BHO: (no name) - {53114269-84B8-474C-A008-1C7FA12289CC} - C:\WINDOWS\system32\vturs.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\dnsersnd.dll
O2 - BHO: (no name) - {EFEA8B3C-6E43-4184-8E2D-90B97F8465B3} - \
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKLM\..\Run: [sm] C:\WINDOWS\sa_exe.exe
O4 - HKLM\..\Run: [firewall_anti] C:\WINDOWS\firewall_anti.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [load32] C:\WINDOWS\system32\winldra.exe
O4 - HKLM\..\Run: [key2] C:\WINDOWS\system32\winlog.exe
O4 - HKLM\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
O4 - HKLM\..\Run: [SIE2004] "C:\Program Files\Winferno\Secure IE\SIEPulse.exe"
O4 - HKLM\..\Run: [ms] C:\Program Files\Microsoft\svhost32.exe
O4 - HKLM\..\Run: [system43.exe] C:\WINDOWS\system32\system43.exe
O4 - HKLM\..\Run: [DxDialog] C:\WINDOWS\system32\dxdlg32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NBInstall] C:\DOCUME~1\Salil\LOCALS~1\Temp\MBDownloader_876919.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu361.exe 61A847B5BBF72811349A284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKLM\..\Run: [adeakdjA] C:\WINDOWS\adeakdjA.exe
O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\nwinqqdt.exe SKY009
O4 - HKLM\..\Run: [g4356cbvy63] C:\WINDOWS\g4356cbvy63
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernelwind32.exe
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
O4 - HKLM\..\Run: [bantool] C:\WINDOWS\system32\ie_ban.exe
O4 - HKLM\..\Run: [uwas7cw] "C:\Program Files\Common Files\WinAntiSpyware 2007\uwas7cw.exe" -c
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
O4 - HKLM\..\Run: [WinCore32.exe] C:\WINDOWS\system32\WinCore32.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win13.tmp.exe
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvfim.dll,startup
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\system32\winshost.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [key2] C:\WINDOWS\system32\winlog.exe
O4 - HKCU\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe
O4 - HKCU\..\Run: [mule_st_key] C:\Documents and Settings\Salil\Application Data\m\flec006.exe
O4 - HKCU\..\Run: [drv_st_key] C:\Documents and Settings\Salil\Application Data\hidn\hidn2.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [drvsyskit] C:\Documents and Settings\Salil\Application Data\hidires\hidr.exe
O4 - HKCU\..\Run: [Aida] "C:\DOCUME~1\Salil\MYDOCU~1\CROSOF~1.NET\nopdb.exe" -vt yazb
O4 - HKCU\..\Run: [Rssvfu] "C:\Program Files\?ppPatch\w?nlogon.exe"
O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [Service Pack 1] C:\WINDOWS\system32\vedxg6ame4.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\SYSTEM32\nwinqqdt.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documents\Settings\bot.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: opnopon - C:\WINDOWS\SYSTEM32\opnopon.dll
O20 - Winlogon Notify: vturs - C:\WINDOWS\system32\vturs.dll
O20 - Winlogon Notify: winxry32 - C:\WINDOWS\SYSTEM32\winxry32.dll
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\adeakdj.exe (file missing)
Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:

* Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
* Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
* Consider what other private information could possibly have been taken from your computer and take appropriate steps

This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.


A. Using the Add/Remove Programs module in your Control Panel, please UNINSTALL the following programs which are either really bad malware programs or a duplicate that you don't need cluttering up your system:

Enhanced Ads by Think-Adz removal
Outerinfo
WinAntiSpyware 2007 4.0.193.0
Microsoft .NET Framework 1.1



B. As a safety measure, Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally copy and save the Report.txt to Notepad for posting later on to the forum .

Please print out the following instructions as you will be working off line for the rest of the fix.


C. Please download this file - combofix.exe by sUBs
  • Save it to your Desktop
  • Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    "%userprofile%\desktop\ComboFix.exe" /KillAll


  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • Report.txt from SDFix
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Regards,

Trevuren
Hi Treverun, Thanks for the information. I have started modifying all my passwords. This has made me really concerned. I will take the action you mentioned as soon as I am home today. I plan to call my credit card company and bank. Is there any more information that you can provide me (name of trojan etc.) in case I have to give them more info in case my accounts have already been compromised. One last question - how common is for a computer to be infected by a trojan such as this one? I think I need to subscribe to Norton or McAfee. Is there one that you recommend over the other? I will provide the information you asked for this eveing ASAP. Regards, Khilafat.
These days it is quite common to find one of the trojans on an infected machine. Just telling the bank that it was a backdoor trojan will suffice and your liability usually ends there. AS far a AV, if you can spend the money, I usually recommend NOD32 by Eset or Kaspersky. Trevuren
Hi Trevuren

I am khilafat and had posted regarding problems on my machine. I am having trouble posting on this forum with my earlier user name "khilafat" - cannot reply to the topic I responsed to yesterday. We have already exchanged message on this forum (link below)

http://forums.tomcoyote.org/Vundo_Windows_…amp;hl=khilafat


I had to create another account to make a post. So khilafat_2 is same as khilafat.

You had suggested running SDFix in safe mode. I cannot start my computer in Safe mode - whenever I hit F8, the screen tells me to check for virus etc. and that the system will not start in safe mode.

What other options do I have?

Best Regards,

Khilafat
Hi Trevuren, I would like to clean up my system. I removed WinAntiSpyware 2007 4.0.193.0 Microsoft .NET Framework 1.1 as you advised but could not find the other two programs you mentioned from Add/Remove Programs. You suggested running SDFix in safe mode. I have downloaded SDFix and extracted the file. But I could not run my OS in safe mode. When I hit F8 during bootup and choose to run in safe mode I get the message that there is a virus and cannot be run in safe mode. Should I run SDFix in regular mode in this case? Regards Khilafat.
Hi Trevuren, I did not realize that I need to ComboFix as well even though SDFix is not done. I will download and run ComboFix.exe and send you the report shortly - once I reach home. I am writing from my work computer as my home computer is extremely slow (takes up almost 100% CPU) and have to spend a lot of time just to reach this message board. Regards, Khilafat
Hi Trevuren,

I did the following

(a) Started running SDFix in normal mode. When I ran the batch file, I got a menu with options 1,2,3 S and E. When I selected 1, the cmd prompt disappeared. With 2 and 3, the software downloaded programs and scanned the system and asked me to reboot. However, I did not see a report file in the C:\SDFix folder.

(B) I ran ComboFix.exe. I started it yesterday night and it got done this morning! Here is the report (The HJT report is item c)
BTW my machine works very much better now and it is as fast as below (no popups as well).


Best Regards, Khilafat

ComboFix 07-08-11 - "Salil" 2007-08-10 22:12:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.204 [GMT -4:00]
Command switches used :: /KillAll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\Abbr
C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinAntiSpyware 2007\Data\ProductCode
C:\DOCUME~1\Gauri\APPLIC~1\..\err.log
C:\DOCUME~1\Gauri\APPLIC~1\.rdr.ini
C:\DOCUME~1\LOCALS~1\APPLIC~1\install.dat
C:\DOCUME~1\NETWOR~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\NETWOR~1\APPLIC~1\install.dat
C:\DOCUME~1\Salil\APPLIC~1.\hidires
C:\DOCUME~1\Salil\APPLIC~1.\hidires\bak\hidr.exe
C:\DOCUME~1\Salil\APPLIC~1.\hidires\m_hook.sys
C:\DOCUME~1\Salil\APPLIC~1.\macromedia\Flash Player\#SharedObjects\G6PB4NBM\www.broadcaster.com
C:\DOCUME~1\Salil\APPLIC~1.\macromedia\Flash Player\#SharedObjects\G6PB4NBM\www.broadcaster.com\played_list.sol
C:\DOCUME~1\Salil\APPLIC~1.\macromedia\Flash Player\#SharedObjects\G6PB4NBM\www.broadcaster.com\video_queue.sol
C:\DOCUME~1\Salil\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\DOCUME~1\Salil\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\DOCUME~1\Salil\APPLIC~1.\winantispyware 2007
C:\DOCUME~1\Salil\APPLIC~1.\winantispyware 2007 free
C:\DOCUME~1\Salil\APPLIC~1.\winantispyware 2007 free\DownloadUWAS7.url
C:\DOCUME~1\Salil\APPLIC~1.\winantispyware 2007\Logs\update.log
C:\DOCUME~1\Salil\APPLIC~1\..\err.log
C:\DOCUME~1\Salil\APPLIC~1\install.dat
C:\DOCUME~1\Salil\APPLIC~1\WinAntiSpyware 2007 Free\DownloadUWAS7.url
C:\DOCUME~1\Salil\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\DOCUME~1\Salil\Desktop.\internet explorer.lnk
C:\DOCUME~1\Salil\Desktop\Download WinAntiSpyware 2007 Free.lnk
C:\DOCUME~1\Salil\MYDOCU~1.\crosof~1.net
C:\DOCUME~1\Salil\MYDOCU~1.\crosof~1.net\??crosoft.NET\
C:\DOCUME~1\Salil\MYDOCU~1.\crosof~1.net\nopdb.exe
C:\DOCUME~1\Salil\STARTM~1\Programs.\Outerinfo
C:\DOCUME~1\Salil\STARTM~1\Programs.\Outerinfo\Terms.lnk
C:\DOCUME~1\Salil\STARTM~1\Programs.\Outerinfo\Uninstall.lnk
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\bot.dll
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Documents and Settings\Salil\spooldr.ini
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\microsoft\svhost32.exe
C:\Program Files\MSN Gaming Zone\lavuqa.dll
C:\Program Files\MSN Gaming Zone\profsyfsy.html
C:\Program Files\MSN\hoke2.dll
C:\Program Files\MSN\hoke4444.dll
C:\Program Files\MSN\hoke83122.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\OinFP.exe
C:\Program Files\outerinfo\OiUninstaller.exe
C:\Program Files\outerinfo\outerinfo.ico
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\pppatc~1
C:\Program Files\pppatc~1\w?nlogon.exe
C:\Program Files\TTC.dll
C:\svchost.exe
C:\temp.zip
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\tn3
C:\U.exe
C:\WINDOWS\1026921.exe
C:\WINDOWS\1411937.exe
C:\WINDOWS\1450359.exe
C:\WINDOWS\16257671.exe
C:\WINDOWS\2128234.exe
C:\WINDOWS\22256812.exe
C:\WINDOWS\22344328.exe
C:\WINDOWS\22400078.exe
C:\WINDOWS\23355015.exe
C:\WINDOWS\23426812.exe
C:\WINDOWS\23738156.exe
C:\WINDOWS\24233484.exe
C:\WINDOWS\25173859.exe
C:\WINDOWS\25267796.exe
C:\WINDOWS\267000.exe
C:\WINDOWS\31741078.exe
C:\WINDOWS\3279515.exe
C:\WINDOWS\330562.exe
C:\WINDOWS\334781.exe
C:\WINDOWS\356109.exe
C:\WINDOWS\361468.exe
C:\WINDOWS\365593.exe
C:\WINDOWS\374062.exe
C:\WINDOWS\381328.exe
C:\WINDOWS\38209421.exe
C:\WINDOWS\402156.exe
C:\WINDOWS\409062.exe
C:\WINDOWS\411062.exe
C:\WINDOWS\416546.exe
C:\WINDOWS\423546.exe
C:\WINDOWS\44356687.exe
C:\WINDOWS\443734.exe
C:\WINDOWS\44439421.exe
C:\WINDOWS\45304640.exe
C:\WINDOWS\454312.exe
C:\WINDOWS\45510703.exe
C:\WINDOWS\46430531.exe
C:\WINDOWS\47007781.exe
C:\WINDOWS\47282796.exe
C:\WINDOWS\4972765.exe
C:\WINDOWS\51244500.exe
C:\WINDOWS\679343.exe
C:\WINDOWS\69290750.exe
C:\WINDOWS\9742328.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\deskcfg.dat
C:\WINDOWS\DOWNLO~1.\Temp
C:\WINDOWS\DOWNLO~1\UWA7P_0001_N91M0809NetInstaller.exe
C:\WINDOWS\mgrs.exe
C:\WINDOWS\rau001978.exe
C:\WINDOWS\s32.txt
C:\WINDOWS\system32\2342232541.dll
C:\WINDOWS\system32\23465651541.dll
C:\WINDOWS\system32\2346596241.dll
C:\WINDOWS\system32\annhl.dll
C:\WINDOWS\system32\aukmkpqy.exe
C:\WINDOWS\system32\byxvvtr.dll
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\configs
C:\WINDOWS\system32\configs\kmhp83122.exe
C:\WINDOWS\system32\dms.dll
C:\WINDOWS\system32\dnsersnd.dll
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\driver\w717.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\f02WtR\f02WtR1065.exe
C:\WINDOWS\system32\f06WtR
C:\WINDOWS\system32\f06WtR\f06WtR1083.exe
C:\WINDOWS\system32\F2
C:\WINDOWS\system32\F3
C:\WINDOWS\system32\F3\n553.exe
C:\WINDOWS\system32\gebcywv.dll
C:\WINDOWS\system32\hgorwehp.dll
C:\WINDOWS\system32\hlpsrv.exe
C:\WINDOWS\system32\install.exe
C:\WINDOWS\system32\is67718.exe
C:\WINDOWS\system32\jbhook.dll
C:\WINDOWS\system32\jbloader.dll
C:\WINDOWS\system32\KB95842.log
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\leblkyen.dll
C:\WINDOWS\SYSTEM32\neyklbel.ini
C:\WINDOWS\system32\nwslhekh.exe
C:\WINDOWS\system32\opnopon.dll
C:\WINDOWS\system32\Outerinfo-1440.exe
C:\WINDOWS\SYSTEM32\phewrogh.ini
C:\WINDOWS\system32\regscan.exe
C:\WINDOWS\SYSTEM32\rnauawsy.ini
C:\WINDOWS\system32\setup155.exe
C:\WINDOWS\system32\skna455101.exe
C:\WINDOWS\SYSTEM32\srutv.bak1
C:\WINDOWS\SYSTEM32\srutv.bak2
C:\WINDOWS\SYSTEM32\srutv.ini
C:\WINDOWS\system32\tuecykcy.dll
C:\WINDOWS\system32\user10.exe
C:\WINDOWS\system32\vturs.dll
C:\WINDOWS\system32\waverevenue.exe
C:\WINDOWS\system32\wldoruur.dll
C:\WINDOWS\system32\wnsinticomsv32.exe
C:\WINDOWS\system32\yswauanr.dll
C:\WINDOWS\TISKY009.exe
C:\WINDOWS\tk58.exe
C:\WINDOWS\TTC-4444.exe
C:\WINDOWS\uni_eh44.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\wr.txt
C:\WINDOWS\ws386.ini
C:\WINDOWS\yekwh0578.exe


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPN
——-\LEGACY_M_HOOK
——-\LEGACY_NET_AGENT
——-\LEGACY_WINDOWS_OVERLAY_COMPONENTS
——-\asc3550u
——-\core
——-\DomainService
——-\Net Agent


((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))


2007-08-10 21:22 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-08-09 23:04 d——– C:\SAV32CLI
2007-08-09 22:52 75,328 –a—— C:\WINDOWS\SYSTEM32\dkhvjrtf.exe
2007-08-05 19:48 93,696 –a—— C:\WINDOWS\SYSTEM32\drvhak.dll
2007-08-05 19:42 51,200 –a—— C:\WINDOWS\SYSTEM32\rasterx.dll
2007-08-05 19:41 51,200 –a—— C:\WINDOWS\SYSTEM32\fertbuk.dll
2007-08-05 19:40 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-08-05 19:39 89,088 –a—— C:\WINDOWS\SYSTEM32\atl71.dll
2007-08-05 19:39 400,500 –a—— C:\Temp\bass.exe
2007-08-04 17:11 d——– C:\Temp
2007-07-31 20:17 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2008-08-09 22:46 75328 –a—— C:\WINDOWS\system32\amlxuluw.exe
2008-08-09 00:01 ——— d——– C:\Program Files\McAfee.com
2008-08-08 22:03 ——— d——– C:\Program Files\Trend Micro
2008-08-08 20:11 75328 –a—— C:\WINDOWS\system32\uqpllopt.exe
2008-08-06 23:35 93696 –a—— C:\WINDOWS\system32\drvfim.dll
2007-08-10 22:19 ——— d——– C:\Program Files\MSN Gaming Zone
2007-08-10 08:17 ——— d——– C:\Program Files\Dell Support
2007-08-10 07:42 ——— d–h—– C:\DOCUME~1\Salil\APPLIC~1\m
2007-08-10 07:41 ——— d–h—– C:\DOCUME~1\Salil\APPLIC~1\hidn
2007-08-09 23:44 ——— d——– C:\Program Files\Common Files\xing shared
2007-08-09 23:43 ——— d——– C:\Program Files\Common Files\Borland Shared
2007-08-05 19:48 375296 –a—— C:\WINDOWS\system32\drivers\tcpip.sys
2007-08-05 19:45 ——— d——– C:\Program Files\Google
2007-07-07 18:24 ——— d——– C:\Program Files\Microsoft Money 2006
2007-06-16 12:56 ——— d——– C:\Program Files\Kodak
2005-07-22 22:31 29602 –a—— C:\WINDOWS\prefetch\zo3nealarm.exe

C:\WINDOWS\system32\drivers\tcpip.sys … is infected !! (additional data below)
359,936 2005-03-14 01:17:17 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
332,928 2002-08-29 10:00:00 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
359,040 2004-08-04 06:14:40 C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
359,040 2004-08-04 06:14:40 C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
359,808 2005-05-25 19:04:02 C:\WINDOWS\SoftwareDistribution\Download\bc2e08df13ade612507748ca3eefdc83\sp2gdr\tcpip.sys
359,936 2005-05-25 19:07:12 C:\WINDOWS\SoftwareDistribution\Download\bc2e08df13ade612507748ca3eefdc83\sp2qfe\tcpip.sys
340,480 2006-01-13 01:13:17 C:\WINDOWS\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP1QFE\tcpip.sys
359,808 2006-01-13 02:28:14 C:\WINDOWS\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP2GDR\tcpip.sys
360,448 2006-01-13 17:07:08 C:\WINDOWS\SoftwareDistribution\Download\e534ebaf021731fc8bec5e8193de9bb9\SP2QFE\tcpip.sys
375,296 2007-08-05 23:48:54 C:\WINDOWS\SYSTEM32\DRIVERS\tcpip.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0EEDB1E5-5765-4a2a-9D72-CB5213D756C0}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{49EA22F7-64EB-4243-8198-AE1648E4F087}]
C:\WINDOWS\system32\ssttq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EFEA8B3C-6E43-4184-8E2D-90B97F8465B3}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" []
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" []
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" []
"sm"="C:\WINDOWS\sa_exe.exe" []
"anti_troj"="C:\WINDOWS\system32\anti_troj.exe" []
"SIE2004"="C:\Program Files\Winferno\Secure IE\SIEPulse.exe" [2007-01-12 22:23]
"DxDialog"="C:\WINDOWS\system32\dxdlg32.exe" []
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-24 21:23]
"adeakdjA"="C:\WINDOWS\adeakdjA.exe" []
"{30-0A-AF-F4-ZN}"="C:\windows\system32\ppdsregr.exe" []
"WinCore32.exe"="C:\WINDOWS\system32\WinCore32.exe" []
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-02-07 17:16]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56]
"Sonic RecordNow!"="" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-03-27 15:22]
"key2"="C:\WINDOWS\system32\winlog.exe" []
"anti_troj"="C:\WINDOWS\system32\anti_troj.exe" []
"german.exe"="C:\WINDOWS\system32\wintems.exe" []
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-01-12 22:23]
"Rssvfu"="C:\Program Files\?ppPatch\w?nlogon.exe" []

C:\Documents and Settings\Salil\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2005-04-23 13:23:05]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DESKTOP.INI [2002-09-03 10:00:00]
Snapfish Picture Mover.lnk - C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe [2006-12-19 17:08:38]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
Source= C:\Program Files\MSN Gaming Zone\profsyfsy.html
FriendlyName=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winxry32]
winxry32.dll

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"

R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R2 ntrtscan;OfficeScanNT RealTime Scan;"C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe"
R2 TM_CFW;Common Firewall Driver;\??\C:\Program Files\Trend Micro\OfficeScan Client\tm_cfw.sys
R2 tmlisten;OfficeScanNT Listener;"C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe"
R2 TmPreFilter;Trend Micro PreFilter;\??\C:\Program Files\Trend Micro\OfficeScan Client\TmPreFlt.sys
R3 IPSECSHM;Nortel IPSECSHM Adapter;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
R3 PD0620VID;Creative WebCam Instant;C:\WINDOWS\system32\DRIVERS\P0620Vid.sys
S2 aspimgr;Microsoft ASPI Manager;C:\WINDOWS\system32\aspimgr.exe
S2 IPSECEXT;Nortel Extranet Access Protocol;C:\WINDOWS\system32\DRIVERS\ipsecw2k.sys
S2 r_server;Remote Administrator Service;"C:\WINDOWS\system32\r_server.exe" /service


Contents of the 'Scheduled Tasks' folder
2007-08-11 11:06:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Gauri).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2007-08-11 11:03:00 C:\WINDOWS\Tasks\McAfee.com Update Check (KODKANI-Salil).job - C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
2005-07-01 02:28:00 C:\WINDOWS\Tasks\Run Salil's Calculator.job - C:\WINDOWS\SYSTEM32\CALC.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 07:04:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-11 7:06:42 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-08-11 07:06

— E O F —


================================================================================
=




© The HJT Report is here

Logfile of HijackThis v1.99.1
Scan saved at 7:20:11 AM, on 8/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winferno\Secure IE\SIEPulse.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\TEMP\LA3.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\Killer.exe
C:\WINDOWS\SoftwareDistribution\Download\526e15b6e1b5300357490c8089b5f84e\update\update.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/mywaybiz
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Editor plugin - {0EEDB1E5-5765-4a2a-9D72-CB5213D756C0} - fertbuk.dll (file missing)
O2 - BHO: (no name) - {49EA22F7-64EB-4243-8198-AE1648E4F087} - C:\WINDOWS\system32\ssttq.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {EFEA8B3C-6E43-4184-8E2D-90B97F8465B3} - \
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [sm] C:\WINDOWS\sa_exe.exe
O4 - HKLM\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
O4 - HKLM\..\Run: [SIE2004] "C:\Program Files\Winferno\Secure IE\SIEPulse.exe"
O4 - HKLM\..\Run: [DxDialog] C:\WINDOWS\system32\dxdlg32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [adeakdjA] C:\WINDOWS\adeakdjA.exe
O4 - HKLM\..\Run: [{30-0A-AF-F4-ZN}] C:\windows\system32\ppdsregr.exe SKY009
O4 - HKLM\..\Run: [WinCore32.exe] C:\WINDOWS\system32\WinCore32.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [key2] C:\WINDOWS\system32\winlog.exe
O4 - HKCU\..\Run: [anti_troj] C:\WINDOWS\system32\anti_troj.exe
O4 - HKCU\..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Rssvfu] "C:\Program Files\?ppPatch\w?nlogon.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Snapfish Picture Mover.lnk = C:\Program Files\Snapfish Picture Mover\SnapfishPictureMover.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://moneycentral.msn.com/cabs/pmupd806.exe
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cinci.rr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winxry32 - winxry32.dll (file missing)
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI