This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Awola Antivirus+ Other Minor Trojans

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been having a major problem with awola anti-virus lately. I also have been having othe problems most likely caused by viruses. I recently switched over from norton antivirus to trend micro PC-cillin. I want to see if my computer is still in a repairable condition, or if I have to reload windows XP.

Heres my log from 9/8/07:

Logfile of HijackThis v1.99.1
Scan saved at 9:32:44 PM, on 9/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\taskmgr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\regscan.exe
C:\Documents and Settings\usr1\Application Data\bfdwzd.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
c:\program files\aim6\anotify.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\qlsxoeyb.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\dwwin.exe
C:\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
F3 - REG:win.ini: load=C:\WINDOWS\taskmgr.exe,
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mqdikqjA] C:\WINDOWS\mqdikqjA.exe
O4 - HKLM\..\Run: [{A5-5F-F1-13-ZN}] c:\windows\system32\nodsrngs.exe SKY009
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu1000106.exe 61A847B5BBF72813329B385772FF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310F3
1DC7E4638E8323A15806F97BDE4417E70CE7C0726B954E2C2832213329D26033AAC
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinpodt.exe SKY009
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [g4356cbvy63] C:\WINDOWS\g4356cbvy63
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [orsbabqp] rundll32.exe "C:\Program Files\orsbabqp\gjkvsxwt.dll",Init
O4 - HKLM\..\Run: [nolazetu] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\nolazetu.dll"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\fmlrgmys.dll",forkonce
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\usr1\Application Data\bfdwzd.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\nodsrngs.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinpodt.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188755419687
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188755409078
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Unknown owner - c:\Program Files\Norton Internet Security\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DomainService - - C:\WINDOWS\system32\qlsxoeyb.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing)
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: WINDOWS MSI Installer Application (WIN_MSIEXEC) - Unknown owner - C:\WINDOWS\Security\msiexec.exe (file missing)

I cannot seem to get the new HJT to work??? This log is from an old version, 1.99.1 —–The new version wouldnt start correctly?
I'm sure theres a lot to be done with this :unsure:

-viruseslikeme-
Hello and welcome to the forum

HJT version v1.99.1 will work just fine. I like it better myself.

Please follow the steps below exactly in the order they are written:

Step #1

1. Please download ATF Cleaner by Atribune.


2. Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

If you are unable to run scan with AVG Anti-Spyware in Safe Mode, Click the next link http://fileserver.ewido.net/public.cgi?id=20990 and download AVG_Anti-Spyware_7.5.1.36_Safe_Mode_Registry_Patch.reg to your desktop. It should look like this -> [external image: Posted Image] double click on it. You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer "Yes" and wait for a message to appear similar to "Merged Successfully".

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
I downloaded the programs. Whenever I log into safe mode after a few seconds-minutes the computer totally cuts out. This has happened 10 times now. The scanner was almost done working and the computer just crashes. Should I just give it time to cool down? -viruseslikeme-
Done with the current instructions. I scanned AVG in normal mode and set all to quarantine, when I clicked apply all actions the program would not let me save the report?
New HJT log: 9/9/07
_________________________

Logfile of HijackThis v1.99.1
Scan saved at 3:39:24 PM, on 9/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\taskmgr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\regscan.exe
C:\Documents and Settings\usr1\Application Data\bfdwzd.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
F3 - REG:win.ini: load=C:\WINDOWS\taskmgr.exe,
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mqdikqjA] C:\WINDOWS\mqdikqjA.exe
O4 - HKLM\..\Run: [{A5-5F-F1-13-ZN}] c:\windows\system32\nodsrngs.exe SKY009
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinpodt.exe SKY009
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [g4356cbvy63] C:\WINDOWS\g4356cbvy63
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [orsbabqp] rundll32.exe "C:\Program Files\orsbabqp\gjkvsxwt.dll",Init
O4 - HKLM\..\Run: [nolazetu] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\nolazetu.dll"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\tmtewcnt.dll",forkonce
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\usr1\Application Data\bfdwzd.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\nodsrngs.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinpodt.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188755419687
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188755409078
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Unknown owner - c:\Program Files\Norton Internet Security\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qlsxoeyb.exe (file missing)
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing)
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: WINDOWS MSI Installer Application (WIN_MSIEXEC) - Unknown owner - C:\WINDOWS\Security\msiexec.exe (file missing)
Only for Windows XP and Windows 2000


Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.exe
Double Click SmitfraudFix.exe on your Desktop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter


This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named:
c:\rapport.txt


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Please post:
C:\rapport.txt
SmitFraudFix v2.221 Scan done at 15:59:39.43, Sun 09/09/2007 Run from C:\Documents and Settings\usr1\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\WINDOWS\taskmgr.exe C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\regsvr32.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\system32\regscan.exe C:\Documents and Settings\usr1\Application Data\bfdwzd.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\AIM6\aolsoftware.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe C:\Program Files\Vongo\VongoService.exe C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE C:\HijackThis.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\cmd.exe C:\PROGRA~1\TRENDM~1\INTERN~1\tsc.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\svchost.exe FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\usr1 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\usr1\Application Data C:\Documents and Settings\usr1\Application Data\Install.dat FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\usr1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\MW\ FOUND ! C:\Program Files\Video ActiveX Access\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="C:\\Program Files\\Common Files\\fsoxyrt.html" "SubscribedURL"="" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Broadcom 802.11b/g WLAN - Packet Scheduler Miniport DNS Server Search Order: 167.206.251.4 DNS Server Search Order: 167.206.251.68 HKLM\SYSTEM\CCS\Services\Tcpip\..\{F0B8B0F0-B3DB-4A10-84E9-08BB0423B133}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{F0B8B0F0-B3DB-4A10-84E9-08BB0423B133}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{F0B8B0F0-B3DB-4A10-84E9-08BB0423B133}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Running the Clean

Warning: running option #2 on a non infected computer will remove your Desktop background.


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Please post:
1.c:\rapport.txt
2.A new HijackThis log
Logfile of HijackThis v1.99.1
Scan saved at 4:26:54 PM, on 9/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\taskmgr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AIM6\aim6.exe
C:\WINDOWS\system32\regscan.exe
C:\Documents and Settings\usr1\Application Data\bfdwzd.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Vongo\VongoService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tsc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
F3 - REG:win.ini: load=C:\WINDOWS\taskmgr.exe,
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mqdikqjA] C:\WINDOWS\mqdikqjA.exe
O4 - HKLM\..\Run: [{A5-5F-F1-13-ZN}] c:\windows\system32\nodsrngs.exe SKY009
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\twinpodt.exe SKY009
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [g4356cbvy63] C:\WINDOWS\g4356cbvy63
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [orsbabqp] rundll32.exe "C:\Program Files\orsbabqp\gjkvsxwt.dll",Init
O4 - HKLM\..\Run: [nolazetu] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\nolazetu.dll"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\tmtewcnt.dll",forkonce
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [Microsft Windows Adapter 5.1.3013] C:\Documents and Settings\usr1\Application Data\bfdwzd.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\nodsrngs.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\twinpodt.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavilion&pf=laptop
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188755419687
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1188755409078
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Unknown owner - c:\Program Files\Norton Internet Security\ccPwdSvc.exe (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qlsxoeyb.exe (file missing)
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing)
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Vongo Service - Starz Entertainment Group LLC - C:\Program Files\Vongo\VongoService.exe
O23 - Service: WINDOWS MSI Installer Application (WIN_MSIEXEC) - Unknown owner - C:\WINDOWS\Security\msiexec.exe (file missing)
SmitFraudFix v2.221 Scan done at 16:17:04.12, Sun 09/09/2007 Run from C:\Documents and Settings\usr1\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\svchost.exe Deleted C:\Documents and Settings\usr1\Application Data\Install.dat Deleted C:\Program Files\MW\ Deleted C:\Program Files\Video ActiveX Access\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{F0B8B0F0-B3DB-4A10-84E9-08BB0423B133}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{F0B8B0F0-B3DB-4A10-84E9-08BB0423B133}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{F0B8B0F0-B3DB-4A10-84E9-08BB0423B133}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
You still have infections.

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
combofix log:
_______________________-
ComboFix 07-09-09.5 - "usr1" 2007-09-09 16:44:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1259 [GMT -4:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\ALLUSE~1\APPLIC~1.\nolazetu.dll
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\DOCUME~1\LOCALS~1\Desktop\searchus.exe
C:\DOCUME~1\NETWOR~1\APPLIC~1\.rdr.ini
C:\DOCUME~1\NETWOR~1\Desktop\searchus.exe
C:\DOCUME~1\usr1\APPLIC~1\.rdr.ini
C:\DOCUME~1\usr1\APPLIC~1\SKS~1
C:\DOCUME~1\usr1\MYDOCU~1\YSTEM3~1
C:\DOCUME~1\usr1\STARTM~1\Programs\Startup.\TA_Start.lnk
C:\DOCUME~1\usr1\STARTM~1\Programs\Startup\ta_start.lnk
C:\DOCUME~1\usr1\STARTM~1\Programs\Startup\think-adz.lnk
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\HP\wodemaseg4444.dll
C:\Program Files\Kfuhhnxk
C:\Program Files\Kfuhhnxk\ysobegyq.dll
C:\Program Files\orsbabqp
C:\Program Files\orsbabqp\gjkvsxwt.dll
C:\Program Files\pppatc~1
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe.bak
C:\Program Files\web buying
C:\Program Files\web buying\v1.8.0\wbuninst.exe
C:\Program Files\winantispyware 2007
C:\Program Files\WinAntiSpyware 2007\msvcp71.dll
C:\Program Files\winantispyware 2007\msvcp71.dll
C:\Program Files\winantispyware 2007\msvcr71.dll
C:\Program Files\WinAntiSpyware 2007\msvcr71.dll
C:\Program Files\WinAntiSpyware 2007\shellext.dll
C:\Program Files\winantispyware 2007\shellext.dll
C:\tempc2
C:\tempc2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\UGA6P
C:\WINDOWS\cookies.ini
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\ajikaji.dll
C:\WINDOWS\system32\ajikaji.dll.bak
C:\WINDOWS\system32\awvvs.dll
C:\WINDOWS\system32\aygdfpri.exe
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b06FdUe
C:\WINDOWS\system32\B1
C:\WINDOWS\system32\bkliuxyu.ini
C:\WINDOWS\system32\bmwhdjax.exe
C:\WINDOWS\system32\config\systemprofile\application data\.rdr.ini
C:\WINDOWS\system32\ddayy.dll
C:\WINDOWS\system32\drincdbl.exe
C:\WINDOWS\system32\drivers\ApiMon.sys
C:\WINDOWS\system32\drivers\asc3550.sys
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\drivers\jwaxykhj.sys
C:\WINDOWS\system32\dsofxqno.exe
C:\WINDOWS\system32\dwxhagri.exe
C:\WINDOWS\system32\eqwesumo.dll
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\fbaoeonw.exe
C:\WINDOWS\system32\foyglabd.exe
C:\WINDOWS\system32\gebcc.dll
C:\WINDOWS\system32\gebya.dll
C:\WINDOWS\system32\gebyw.dll
C:\WINDOWS\system32\gexomwfb.exe
C:\WINDOWS\system32\gngsubra.exe
C:\WINDOWS\system32\grjftcwl.exe
C:\WINDOWS\system32\guebibih.dll
C:\WINDOWS\system32\hibibeug.ini
C:\WINDOWS\system32\hlhkkktb.exe
C:\WINDOWS\system32\icomncfq.exe
C:\WINDOWS\system32\ijjlm.bak1
C:\WINDOWS\system32\ijjlm.bak2
C:\WINDOWS\system32\ijjlm.ini
C:\WINDOWS\system32\ijjlm.ini2
C:\WINDOWS\system32\ijjlm.tmp
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\jkhhh.dll
C:\WINDOWS\system32\jkhhi.dll
C:\WINDOWS\system32\jkkji.dll
C:\WINDOWS\system32\jkkll.dll
C:\WINDOWS\system32\jlrmpkmy.exe
C:\WINDOWS\system32\kajaejqo.ini
C:\WINDOWS\system32\khfgebb.dll
C:\WINDOWS\system32\L1
C:\WINDOWS\system32\L11
C:\WINDOWS\system32\L3
C:\WINDOWS\system32\L5
C:\WINDOWS\system32\L7
C:\WINDOWS\system32\L9
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\ljveipkw.exe
C:\WINDOWS\system32\lpisblcc.exe
C:\WINDOWS\system32\lutygrjq.exe
C:\WINDOWS\system32\mhmwbvvy.exe
C:\WINDOWS\system32\mljgd.dll
C:\WINDOWS\system32\mljji.dll
C:\WINDOWS\system32\mljjj.dll
C:\WINDOWS\system32\mllji.dll
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\n.ini
C:\WINDOWS\system32\nabqnswx.exe
C:\WINDOWS\system32\ngiklfva.exe
C:\WINDOWS\system32\nrulyrjr.exe
C:\WINDOWS\system32\ollnlpcv.dll
C:\WINDOWS\system32\oqjeajak.dll
C:\WINDOWS\system32\pfuybcvt.exe
C:\WINDOWS\system32\pmnno.dll
C:\WINDOWS\system32\povauiar.dll
C:\WINDOWS\system32\prigqmmg.exe
C:\WINDOWS\system32\prktflvq.dll
C:\WINDOWS\system32\pxrjrvon.exe
C:\WINDOWS\system32\qvlftkrp.ini
C:\WINDOWS\system32\qxtmljav.dll
C:\WINDOWS\system32\qykupcex.exe
C:\WINDOWS\system32\raiuavop.ini
C:\WINDOWS\system32\rbbqrhxk.exe
C:\WINDOWS\system32\regscan.exe
C:\WINDOWS\system32\rwqxyvcj.exe
C:\WINDOWS\system32\ssqqnol.dll
C:\WINDOWS\system32\tmtewcnt.dll
C:\WINDOWS\system32\tncwetmt.ini
C:\WINDOWS\system32\uyxuilkb.dll
C:\WINDOWS\system32\vajlmtxq.ini
C:\WINDOWS\system32\vcplnllo.ini
C:\WINDOWS\system32\vtstu.dll
C:\WINDOWS\system32\vtutq.dll
C:\WINDOWS\system32\wgbnrwfu.exe
C:\WINDOWS\system32\womgsbnf.exe
C:\WINDOWS\system32\wrsujopy.exe
C:\WINDOWS\system32\X1
C:\WINDOWS\system32\xefkruig.exe
C:\WINDOWS\system32\xguspmod.dll
C:\WINDOWS\system32\yayvfkwn.exe
C:\WINDOWS\system32\ytpkhixw.exe
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\taskmgr.exe
C:\WINDOWS\uni_eh44.exe
C:\WINDOWS\uninst1014.exe
C:\WINDOWS\uninst2.htm
C:\WINDOWS\unist1.htm
C:\WINDOWS\wr.txt
D:\Autorun.inf


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CORE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPF
——-\LEGACY_FOPN
——-\LEGACY_NET_AGENT
——-\LEGACY_NQSGBJAC
——-\LEGACY_WINDOWS_OVERLAY_COMPONENTS
——-\LEGACY_XQPUOZDW
——-\ApiMon
——-\core
——-\DomainService
——-\fopn
——-\Net Agent
——-\nqsgbjac
——-\xqpuozdw


((((((((((((((((((((((((( Files Created from 2007-08-09 to 2007-09-09 )))))))))))))))))))))))))))))))
.

2007-09-09 16:43 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-09 15:59 6,034 –a—— C:\WINDOWS\system32\tmp.reg
2007-09-09 13:18 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-09 13:16 12,413,440 –a—— C:\avgantispy.exe
2007-09-09 13:14 50,688 –a—— C:\ATF-Cleaner.exe
2007-09-08 21:32 218,112 –a—— C:\HijackThis.exe
2007-09-04 22:04 101,154 –a—— C:\WINDOWS\system32\vkgwkame.dll
2007-09-02 13:58 d——– C:\Program Files\Microsoft Games
2007-09-02 13:31 474,112 –a—— C:\WINDOWS\svchost_tmp.exe
2007-08-30 21:40 d——– C:\WINDOWS\system32\wowrlegl
2007-08-28 21:03 8,286 –a—— C:\WINDOWS\system32\pmkhh.dll
2007-08-28 16:25 8,286 –a—— C:\WINDOWS\system32\vtsqo.dll
2007-08-27 10:18 8,286 –a—— C:\WINDOWS\system32\ddcyv.dll
2007-08-26 23:14 8,286 –a—— C:\WINDOWS\system32\mlljj.dll
2007-08-24 22:04 8,286 –a—— C:\WINDOWS\system32\gebcb.dll
2007-08-24 21:01 8,286 –a—— C:\WINDOWS\system32\pmnlk.dll
2007-08-23 17:45 8,286 –a—— C:\WINDOWS\system32\pmnnn.dll
2007-08-20 18:17 8,286 –a—— C:\WINDOWS\system32\vtutr.dll
2007-08-20 17:17 8,286 –a—— C:\WINDOWS\system32\ddccy.dll
2007-08-19 00:11 8,286 –a—— C:\WINDOWS\system32\pmkhg.dll
2007-08-18 22:32 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-08-18 21:42 10,752 –a—— C:\WINDOWS\DCEBoot.exe
2007-08-18 18:59 75,088 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2007-08-18 18:59 36,112 –a—— C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-08-18 18:59 288,848 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2007-08-18 18:59 203,024 –a—— C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-08-18 18:59 111,888 –a—— C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2007-08-18 18:59 1,126,328 –a—— C:\WINDOWS\system32\drivers\vsapint.sys
2007-08-18 18:59 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-08-18 18:57 d——– C:\Program Files\Trend Micro
2007-08-17 17:50 15,360 –a—— C:\DOCUME~1\usr1\APPLIC~1\bfdwzd.exe
2007-08-13 21:32 d——– C:\WINDOWS\system32\checkdll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-09 16:50 ——— d——– C:\Program Files\HP
2007-09-07 23:50 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-09-07 23:48 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
2007-09-02 19:20 12400 –a—— C:\WINDOWS\system32\drivers\secdrv.sys
2007-08-19 21:01 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-08-14 19:50 ——— d——– C:\Program Files\DivX
2007-08-14 15:53 ——— d——– C:\Program Files\Google
2007-07-28 12:05 85995 –a—— C:\WINDOWS\b128.exe.bin
2007-07-20 21:02 ——— d——– C:\DOCUME~1\usr1\APPLIC~1\Apple Computer
2007-07-13 22:38 ——— d——– C:\DOCUME~1\usr1\APPLIC~1\Talkback
2005-09-24 11:49 12288 –a—— C:\WINDOWS\Fonts\RandFont.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{009BD3FC-15E0-487C-93E1-96028D41497C}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{020A0EBF-CC33-4109-880F-E50134811539}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0266ED75-0A35-4E07-A12F-D65FF85E17D5}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0822A694-470B-4D15-8047-A79305DA675F}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D48CADB-9C18-4BFF-98B9-26432E653B40}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{151CED90-9222-4098-BEB2-E3F944F69FBA}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1A758A87-E5D6-419C-8616-3BDB6297BA5E}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E62138E-A8AA-43EA-83FF-52806AD13F60}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1F09FEB6-6622-43A4-A19E-C18813EC480C}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2015D85D-8CDD-401C-849D-E155A1C8C5BE}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27E0AF89-D747-4D4C-BEBE-BA1FCA180727}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{28A2A90E-3DFF-48CA-AAAD-14299098E07C}]
C:\WINDOWS\system32\ssqpp.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{290185DA-A93C-478B-A94E-764C81A57C49}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{299531FC-A3CA-40D7-B886-96E1DA5EEE53}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2A8A06F2-28B3-48FF-8D3B-664E71EA7ED9}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2CC7A76A-1FDA-43BF-9D73-BAD33A28E296}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2EBB0318-BA7F-46D5-923D-D64536489FFC}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2FFEBCAB-9F98-4A97-9D99-53483AB1ECDD}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4410F20C-F462-4246-BBC3-173888205C49}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{44911C47-28DF-4C17-A41D-3710386451F9}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{472FA2DF-E6AE-4C4D-B7C9-191FED3EEA07}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4BD11318-C346-4796-931C-A11B5812F49D}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C7CD23D-E8E1-47CC-9ACC-CE46F7CFBD1B}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5235A308-7B9C-4DC8-8290-B37BC4D07BA4}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{65708F7C-52E8-47BB-8C82-0EEE6234EB64}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{67843535-7C6D-48C1-9FC3-B52AE2710459}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6933EAC8-DC6A-4408-B15F-766EB4F6227D}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{69C61F8F-F9CE-42D3-916E-C4D83159F82C}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F8A5F1D-5535-424F-9238-CAD5DED7CA5D}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{713B0314-0859-4C3F-BF1B-48488857453A}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7594101A-A288-4855-A42D-2C6B9530416E}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{76A3DC3B-9F60-465B-82EE-D638AAED88B1}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7ab73986-a2e4-4ba9-a66f-287381f2d1c4}]
C:\WINDOWS\system32\mgjokho.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C176586-1372-4A8D-993A-BFB7187C7020}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8EE9CBF5-9371-4E9A-BB41-6928B3F2FF3B}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9387A289-9190-4E1F-A442-FC511A8C02B1}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{99B565BD-6449-4C7F-A013-606175D308BC}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A90A527-46E7-4810-8192-01EDD80DD2C8}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C53810C-A8B6-48AE-A534-AFA6DD7BB440}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9DDE7DB6-B65B-4ADB-A585-692BC075B294}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0576F8A-0309-4B39-8BC8-BFDFE4359841}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A19FD35F-E4E3-4105-8DFF-59FD813844E1}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6843117-2E3D-4D23-AA86-64BC40C225C3}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A73E096C-140E-4E5E-9D40-7F0A74F27E96}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AACF1B79-C387-47B1-A478-D9D95D70A33A}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AD5D097C-7CE0-48FF-94D7-1914C03647AF}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ADDC7049-4BB3-4769-B7D3-C735A64D59AB}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF5A193E-264C-4191-8791-F2728999D020}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B1EE4DE7-6E7D-4648-AF60-CBF010061033}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE4D771F-7ABB-42F5-A166-049B06FD2658}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C2CE3978-A621-4851-809B-248F8ED21196}]
2007-09-07 20:09 67584 –a—— c:\windows\system32\kamsecch.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C594F42D-FE34-4B69-8782-CC8B5FD3E515}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CC04C792-7441-42DB-82D7-4A9744133E38}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E70BE6BF-A454-4B97-9B64-DA2BAB4AAE89}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EE9038C6-D489-48A3-A39A-773E53446419}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EF4FEF8E-30D0-494A-83D6-D32832F1C774}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EF699601-4CBA-43EA-AE53-4F7F91D2CE0F}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F23E4E38-EF80-48A8-A93E-CA71B087B0B7}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F7C6330E-6031-4528-A21C-0845554C0763}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F7E40CA5-1091-4CEA-B0BD-69AAD546EB72}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD34C170-19FF-4313-953E-F5938D9008B1}]
c:\windows\system32\ajikaji.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 01:58]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-26 15:48]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-26 15:48]
"nwiz"="nwiz.exe" []
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-17 16:29 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"ccApp"="-" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 01:01]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-04-12 00:54]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 02:11]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 19:30]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 19:30]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 17:38]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-02 13:36]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" []
"Reminder"="C:\Windows\CREATOR\Remind_XP.exe" [2006-02-09 12:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-28 21:17]
"mqdikqjA"="C:\WINDOWS\mqdikqjA.exe" []
"{A5-5F-F1-13-ZN}"="c:\windows\system32\nodsrngs.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2007-01-23 02:26]
"nolazetu"="regsvr32 /u C:\Documents and Settings\All Users\Application Data\nolazetu.dll" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 17:17]
"Microsft Windows Adapter 5.1.3013"="C:\Documents and Settings\usr1\Application Data\bfdwzd.exe" [2007-09-08 22:30]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 12:39:30]

C:\DOCUME~1\DEFAUL~1\STARTM~1\Programs\Startup\
Vongo Tray.lnk - C:\Program Files\Vongo\Tray.exe [2006-03-30 19:18:32]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4567AB12-B980-44A5-B259-9B09EBEA6331}"= C:\Program Files\WinAntiSpyware 2007\shellext.dll [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtqnkh]
awtqnkh.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqpp]
C:\WINDOWS\system32\ssqpp.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winopn32]
winopn32.dll

R2 tmxpflt;tmxpflt;C:\WINDOWS\system32\DRIVERS\tmxpflt.sys
R3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;C:\WINDOWS\system32\Drivers\5U870CAP.sys
R3 HBtnKey;HBtnKey;C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys
S2 WIN_MSIEXEC;WINDOWS MSI Installer Application;"C:\WINDOWS\Security\msiexec.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\setupSNK.exe

.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-09 16:53:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????????,?@? ????X??????R?@?????,?@

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-09 16:56:08 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-09 16:56
.
— E O F —

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI