This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] My Hjt Log. Any Suggestions?

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer seems to be running fine. I have no pop-ups and have cleaned the system with anti-spyware programs. My only problem is that my desktop does not load on startup and remains blank. Also when I scan using HJT i get this error message:

An unexpected error has occured at procedure: ModMain_CheckOther1Item()
Error #5- Invalid procedure call or argument

The error message pops up in the middle of the scan and when I click OK the scan continues. Here is my log-

Logfile of HijackThis v1.99.1
Scan saved at 1:56:41 AM, on 9/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: (no name) - {F4002052-AB29-4B33-8C8D-0E99084564EC} - C:\WINDOWS\system32\iifeddd.dll
O4 - HKLM\..\Run: [System Updater Machine] system.exe
O4 - HKLM\..\Run: [Microsoft Update Machine] winsys.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\qxocrmwv.dll",forkonce
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunServices: [System Updater Machine] system.exe
O4 - HKLM\..\RunServices: [Microsoft Update Machine] winsys.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Microsoft Update Machine] winsys.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\RunServices: [Microsoft Update Machine] winsys.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1189398523015
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/…login-devel.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: iifeddd - C:\WINDOWS\SYSTEM32\iifeddd.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Unknown owner - C:\Program Files\Norton AntiVirus\isPwdSvc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Unknown owner - C:\Program Files\Intel\NCS\Sync\NetSvc.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



Can anyone tell me if they see any problems with this? I am sure that I have some problems but I just don't know what to do. Any help is appreciated. Thanks.
gpalm05,

Welcome to the forum, you still have TWO major infections on this computer, this is what we need to do.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log



Download VundoFix to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.


C:\Program Files\Hijackthis\ <– Go here and delete the entire folder and download and install the newer version by Trendmicro.


Download and install Trendmicros Hijackthis

Download the Trendmicro Hijackthis Installer, follow defauts and it will install in C:\Program Files\Trendmicro\Hijackthis and this is exactly where we want it to be.
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Format and make sure Wordwrap is Unchecked
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread by using the Post Reply and not start a New Thread.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.

This is important
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe<– Right click on Hijackthis.exe ( looks like a man with a spyglass )and rename it to Scanner.exe


This is what I need to see.
1. SDBot fix report
2. Vundo Report
3 New HJT log from Trendmicro renamed to Scanner.exe
Thanks for the help so far. I did what you said to do with the SDFix, Vundo, and HJT but I think I may have even more problems now. My new HJT log is a lot different than the last. SDFix Log- SDFix: Version 1.103 Run by [removed] on Tue 09/11/2007 at 06:43 AM Microsoft Windows XP [Version 5.1.2600] Running From: C:\DOCUME~1\GREGP~1\Desktop\SDFix Safe Mode: Checking Services: Name: DomainService ImagePath: C:\WINDOWS\system32\jvhfphgt.exe /service DomainService - Deleted Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting… Normal Mode: Checking Files: Trojan Files Found: C:\d.exe - Deleted C:\WINDOWS\b122.exe - Deleted C:\WINDOWS\system32\alog.txt - Deleted C:\WINDOWS\system32\help.txt - Deleted C:\WINDOWS\system32\koos.exe - Deleted C:\WINDOWS\system32\ps.dat - Deleted C:\WINDOWS\system32\winsys.exe - Deleted C:\WINDOWS\system32\xpdx.sys - Deleted Folder C:\Temp\fse - Removed Removing Temp Files… ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: Remaining Services: —————— Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer" "C:\\Program Files\\Yahoo! Games\\Inspector Parker\\Parker.exe"="C:\\Program Files\\Yahoo! Games\\Inspector Parker\\Parker.exe:*:Enabled:Inspector Parker Game Executable" "C:\\Program Files\\Yahoo! Games\\Yahoo! Ten Pin Championship Bowling\\Yahoo Ten Pin Championship Bowling.exe"="C:\\Program Files\\Yahoo! Games\\Yahoo! Ten Pin Championship Bowling\\Yahoo Ten Pin Championship Bowling.exe:*:Enabled:Skyworks Ten Pin Championship Bowling" "C:\\Program Files\\Kazaa\\kazaa.exe"="C:\\Program Files\\Kazaa\\kazaa.exe:*:Enabled:Kazaa" "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype" "C:\\Program Files\\Yahoo! Games\\JEOPARDY!\\JEOPARDY!.exe"="C:\\Program Files\\Yahoo! Games\\JEOPARDY!\\JEOPARDY!.exe:*:Enabled:JEOPARDY!" "C:\\Program Files\\Yahoo! Games\\Wheel of Fortune\\Wheel of Fortune.exe"="C:\\Program Files\\Yahoo! Games\\Wheel of Fortune\\Wheel of Fortune.exe:*:Enabled:Wheel of Fortune" "C:\\Program Files\\Games\\JEOPARDY!\\JEOPARDY!.exe"="C:\\Program Files\\Games\\JEOPARDY!\\JEOPARDY!.exe:*:Enabled:JEOPARDY!" "C:\\Program Files\\iWin.com\\Rock and Roll JEOPARDY!\\Rock & Roll JEOPARDY!.exe"="C:\\Program Files\\iWin.com\\Rock and Roll JEOPARDY!\\Rock & Roll JEOPARDY!.exe:*:Enabled:Rock & Roll JEOPARDY!" "C:\\Program Files\\Yahoo! Games\\BeTrapped!\\BeTrapped.exe"="C:\\Program Files\\Yahoo! Games\\BeTrapped!\\BeTrapped.exe:*:Enabled:BeTrapped Game Executable" "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger" "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\Common Files\\AOL\\1149826902\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1149826902\\ee\\aolsoftware.exe:*:Enabled:AOL Services" "C:\\Program Files\\Common Files\\AOL\\1149826902\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1149826902\\ee\\aim6.exe:*:Enabled:AIM" "C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client" "C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"="C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe:*:Enabled:Nero Home" "C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"="C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe:*:Enabled:Nero ShowTime" "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\WINDOWS\\system32\\mmc.exe"="C:\\WINDOWS\\system32\\mmc.exe:*:Enabled:Microsoft Management Console" "C:\\Program Files\\BearFlix\\bearflix.exe"="C:\\Program Files\\BearFlix\\bearflix.exe:*:Enabled:BearFlix" "C:\\Program Files\\netGangsters\\simGangster (RETAIL-TM)\\simGangster.exe"="C:\\Program Files\\netGangsters\\simGangster (RETAIL-TM)\\simGangster.exe:*:Enabled:simGangster" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\Program Files\\Total War\\Medieval - Total War\\Medieval_TW.exe"="C:\\Program Files\\Total War\\Medieval - Total War\\Medieval_TW.exe:*:Enabled:Medieval_TW" "C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG7\\avginet.exe:*:Enabled:avginet.exe" "C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe:*:Enabled:avgamsvr.exe" "C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe:*:Enabled:avgcc.exe" "C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe:*:Enabled:avgemc.exe" "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\WINDOWS\\system32\\system.exe"="C:\\WINDOWS\\system32\\system.exe:*:Disabled:system" "C:\\WINDOWS\\system32\\jvhfphgt.exe"="C:\\WINDOWS\\system32\\jvh" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" Remaining Files: ————— File Backups: - C:\DOCUME~1\GREGP~1\Desktop\SDFix\backups\backups.zip Files with Hidden Attributes: C:\WINDOWS\system32\gebyy.dll C:\Program Files\Outlook Express\msimn.exe C:\System Volume Information\_restore{F6EA782D-6BFA-45D8-A182-DA8FFA498FD1}\RP657\A0112625.exe C:\WINDOWS\R3JlZyBQYWxtZXI\command.exe~ C:\WINDOWS\system32\system.exe~ C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp C:\Documents and Settings\Greg P\My Documents\My Music\iTunes\iTunes Music\Downloads\Podcasts\Episode XV(15) - Season 2 Ep. 4 - Th.tmp\AlbumArtSmall.jpg C:\Documents and Settings\Greg P\My Documents\My Music\iTunes\iTunes Music\Downloads\Podcasts\Episode XV(15) - Season 2 Ep. 4 - Th.tmp\Folder.jpg C:\WINDOWS\system32\qqtss.tmp C:\WINDOWS\system32\stutv.tmp C:\System Volume Information\_restore{F6EA782D-6BFA-45D8-A182-DA8FFA498FD1}\RP652\A0110476.vbs C:\WINDOWS\R3JlZyBQYWxtZXI\laL5tV1ksqUQtrK.vbs Finished!
Here is the VundoFix- VundoFix V6.3.23 Checking Java version… Java version is 1.5.0.6 Old versions of java are exploitable and should be removed. Java version is 1.5.0.9 Old versions of java are exploitable and should be removed. Java version is 1.5.0.11 Scan started at 3:38:41 AM 5/18/2007 Listing files found while scanning…. C:\WINDOWS\system32\atwhgeit.dll C:\WINDOWS\system32\auvfqcdl.dll C:\WINDOWS\system32\bbrfupuc.dll C:\WINDOWS\system32\bnsoloht.dll C:\WINDOWS\system32\dqgmjoic.dll C:\WINDOWS\system32\dvedwxrd.dll C:\WINDOWS\system32\flaoxwlg.dll C:\WINDOWS\system32\ghvaaoxr.dll C:\WINDOWS\system32\gspnbdrl.dll C:\WINDOWS\system32\jvplclxl.dll C:\WINDOWS\system32\lrdbnpsg.ini C:\WINDOWS\system32\lxlclpvj.ini C:\WINDOWS\system32\mwqmvndd.dll C:\WINDOWS\system32\owvbuojt.dll C:\WINDOWS\system32\paxykqpw.dll C:\WINDOWS\system32\peauyixr.dll C:\WINDOWS\system32\qknpqimc.dll C:\WINDOWS\system32\rqstv.bak1 C:\WINDOWS\system32\rqstv.bak2 C:\WINDOWS\system32\rqstv.ini C:\WINDOWS\system32\srmtiwii.dll C:\WINDOWS\system32\tieghwta.ini C:\WINDOWS\system32\vtsqr.dll C:\WINDOWS\system32\vturppm.dll C:\WINDOWS\system32\wpqkyxap.ini C:\WINDOWS\system32\yqqdpulu.dll Beginning removal… Attempting to delete C:\WINDOWS\system32\atwhgeit.dll C:\WINDOWS\system32\atwhgeit.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\auvfqcdl.dll C:\WINDOWS\system32\auvfqcdl.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\bbrfupuc.dll C:\WINDOWS\system32\bbrfupuc.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\bnsoloht.dll C:\WINDOWS\system32\bnsoloht.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\dqgmjoic.dll C:\WINDOWS\system32\dqgmjoic.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\dvedwxrd.dll C:\WINDOWS\system32\dvedwxrd.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\flaoxwlg.dll C:\WINDOWS\system32\flaoxwlg.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\ghvaaoxr.dll C:\WINDOWS\system32\ghvaaoxr.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\gspnbdrl.dll C:\WINDOWS\system32\gspnbdrl.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\jvplclxl.dll C:\WINDOWS\system32\jvplclxl.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\lrdbnpsg.ini C:\WINDOWS\system32\lrdbnpsg.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\lxlclpvj.ini C:\WINDOWS\system32\lxlclpvj.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\mwqmvndd.dll C:\WINDOWS\system32\mwqmvndd.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\owvbuojt.dll C:\WINDOWS\system32\owvbuojt.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\paxykqpw.dll C:\WINDOWS\system32\paxykqpw.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\peauyixr.dll C:\WINDOWS\system32\peauyixr.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\qknpqimc.dll C:\WINDOWS\system32\qknpqimc.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\rqstv.bak1 C:\WINDOWS\system32\rqstv.bak1 Has been deleted! Attempting to delete C:\WINDOWS\system32\rqstv.bak2 C:\WINDOWS\system32\rqstv.bak2 Has been deleted! Attempting to delete C:\WINDOWS\system32\rqstv.ini C:\WINDOWS\system32\rqstv.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\srmtiwii.dll C:\WINDOWS\system32\srmtiwii.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\tieghwta.ini C:\WINDOWS\system32\tieghwta.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\vtsqr.dll C:\WINDOWS\system32\vtsqr.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\vturppm.dll C:\WINDOWS\system32\vturppm.dll Could not be deleted. Attempting to delete C:\WINDOWS\system32\wpqkyxap.ini C:\WINDOWS\system32\wpqkyxap.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\yqqdpulu.dll C:\WINDOWS\system32\yqqdpulu.dll Has been deleted! Performing Repairs to the registry. Done! Beginning removal… Attempting to delete C:\WINDOWS\system32\vturppm.dll C:\WINDOWS\system32\vturppm.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.3.23 Checking Java version… Java version is 1.5.0.6 Old versions of java are exploitable and should be removed. Java version is 1.5.0.9 Old versions of java are exploitable and should be removed. Java version is 1.5.0.11 Scan started at 11:36:57 PM 9/9/2007 Listing files found while scanning…. VundoFix V6.3.23 Checking Java version… Java version is 1.5.0.6 Old versions of java are exploitable and should be removed. Java version is 1.5.0.9 Old versions of java are exploitable and should be removed. Java version is 1.5.0.11 Scan started at 11:55:03 PM 9/9/2007 Listing files found while scanning…. C:\WINDOWS\system32\dfhkj.bak1 C:\WINDOWS\system32\dfhkj.ini C:\WINDOWS\system32\jkhfd.dll C:\WINDOWS\system32\mwhwltwu.dll Beginning removal… Attempting to delete C:\WINDOWS\system32\dfhkj.bak1 C:\WINDOWS\system32\dfhkj.bak1 Has been deleted! Attempting to delete C:\WINDOWS\system32\dfhkj.ini C:\WINDOWS\system32\dfhkj.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\jkhfd.dll C:\WINDOWS\system32\jkhfd.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\mwhwltwu.dll C:\WINDOWS\system32\mwhwltwu.dll Has been deleted! Performing Repairs to the registry. Done! VundoFix V6.3.23 Checking Java version… Java version is 1.5.0.6 Old versions of java are exploitable and should be removed. Java version is 1.5.0.9 Old versions of java are exploitable and should be removed. Java version is 1.5.0.11 Scan started at 12:05:33 AM 9/10/2007 Listing files found while scanning…. No infected files were found. Beginning removal… VundoFix V6.5.8 Checking Java version… Java version is 1.5.0.6 Old versions of java are exploitable and should be removed. Java version is 1.5.0.9 Old versions of java are exploitable and should be removed. Java version is 1.5.0.11 Scan started at 7:06:31 AM 9/11/2007 Listing files found while scanning…. C:\windows\system32\edroivmi.ini C:\windows\system32\edroivmi.tmp C:\windows\system32\ftqiecnf.dll C:\WINDOWS\system32\gebyy.dll C:\WINDOWS\system32\hhusivmg.dll C:\windows\system32\htgjocfw.ini C:\WINDOWS\system32\iifeddd.dll C:\windows\system32\imviorde.dll C:\WINDOWS\system32\vtuts.dll C:\windows\system32\vwmvfxfi.dll C:\WINDOWS\system32\wfcojgth.dll C:\windows\system32\xdwtceih.exe C:\windows\system32\xxywvvw.dll C:\windows\system32\yybeg.bak1 C:\windows\system32\yybeg.ini Beginning removal… Attempting to delete C:\windows\system32\edroivmi.ini C:\windows\system32\edroivmi.ini Has been deleted! Attempting to delete C:\windows\system32\edroivmi.tmp C:\windows\system32\edroivmi.tmp Has been deleted! Attempting to delete C:\windows\system32\ftqiecnf.dll C:\windows\system32\ftqiecnf.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\gebyy.dll C:\WINDOWS\system32\gebyy.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\hhusivmg.dll C:\WINDOWS\system32\hhusivmg.dll Has been deleted! Attempting to delete C:\windows\system32\htgjocfw.ini C:\windows\system32\htgjocfw.ini Has been deleted! Attempting to delete C:\WINDOWS\system32\iifeddd.dll C:\WINDOWS\system32\iifeddd.dll Has been deleted! Attempting to delete C:\windows\system32\imviorde.dll C:\windows\system32\imviorde.dll Has been deleted! Attempting to delete C:\windows\system32\vwmvfxfi.dll C:\windows\system32\vwmvfxfi.dll Has been deleted! Attempting to delete C:\WINDOWS\system32\wfcojgth.dll C:\WINDOWS\system32\wfcojgth.dll Has been deleted! Attempting to delete C:\windows\system32\xdwtceih.exe C:\windows\system32\xdwtceih.exe Has been deleted! Attempting to delete C:\windows\system32\xxywvvw.dll C:\windows\system32\xxywvvw.dll Has been deleted! Attempting to delete C:\windows\system32\yybeg.bak1 C:\windows\system32\yybeg.bak1 Has been deleted! Attempting to delete C:\windows\system32\yybeg.ini C:\windows\system32\yybeg.ini Has been deleted! Performing Repairs to the registry. Done!
HJT-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:16:01 AM, on 9/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\pipmon.exe
C:\WINDOWS\system32\pipmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Greg P\Desktop\HiJackThis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {29C43852-CBFE-4407-97AB-65BDDEBABA48} - C:\WINDOWS\system32\fsuyrytp.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {70A8626C-0B5C-4581-808E-78970D1A870C} - C:\WINDOWS\system32\vtuts.dll (file missing)
O2 - BHO: (no name) - {75EB7A01-6A46-43BE-99F4-AD8CB0FD8EC1} - C:\WINDOWS\system32\gebyy.dll (file missing)
O2 - BHO: 0 - {8928F543-A79B-45D5-A8B5-832633E252D2} - C:\Program Files\Windows NT\qujatik.dll (file missing)
O2 - BHO: Editor plugin - {9F1D47EA-80B7-4f21-A9D3-3738F20596EE} - mountr.dll (file missing)
O2 - BHO: (no name) - {A3DA978E-2733-4E18-BAAF-3C3772F56670} - C:\WINDOWS\system32\fsuyrytp.dll
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - (no file)
O2 - BHO: (no name) - {F4002052-AB29-4B33-8C8D-0E99084564EC} - (no file)
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [pipmon] pipmon.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\wfcojgth.dll",forkonce
O4 - HKLM\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1189398523015
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/…login-devel.cab
O20 - Winlogon Notify: gebyy - C:\WINDOWS\
O20 - Winlogon Notify: iifeddd - C:\WINDOWS\
O20 - Winlogon Notify: vtuts - C:\WINDOWS\system32\vtuts.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Unknown owner - C:\Program Files\Norton AntiVirus\isPwdSvc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Unknown owner - C:\Program Files\Intel\NCS\Sync\NetSvc.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows NT\rterejed.html

–
End of file - 4945 bytes
Good Morning,

You were infected with Vundo and the SDBot worm, most of it is gone, just some more to do.

Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: (no name) - {29C43852-CBFE-4407-97AB-65BDDEBABA48} - C:\WINDOWS\system32\fsuyrytp.dll
O2 - BHO: (no name) - {70A8626C-0B5C-4581-808E-78970D1A870C} - C:\WINDOWS\system32\vtuts.dll (file missing)
O2 - BHO: (no name) - {75EB7A01-6A46-43BE-99F4-AD8CB0FD8EC1} - C:\WINDOWS\system32\gebyy.dll (file missing)
O2 - BHO: 0 - {8928F543-A79B-45D5-A8B5-832633E252D2} - C:\Program Files\Windows NT\qujatik.dll (file missing)
O2 - BHO: Editor plugin - {9F1D47EA-80B7-4f21-A9D3-3738F20596EE} - mountr.dll (file missing)
O2 - BHO: (no name) - {A3DA978E-2733-4E18-BAAF-3C3772F56670} - C:\WINDOWS\system32\fsuyrytp.dll
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - (no file)
O2 - BHO: (no name) - {F4002052-AB29-4B33-8C8D-0E99084564EC} - (no file)
O4 - HKLM\..\Run: [pipmon] pipmon.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\wfcojgth.dll",forkonce
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/…login-devel.cab
O20 - Winlogon Notify: gebyy - C:\WINDOWS\
O20 - Winlogon Notify: iifeddd - C:\WINDOWS\
O20 - Winlogon Notify: vtuts - C:\WINDOWS\system32\vtuts.dll (file missing)




1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to Delete:
C:\WINDOWS\system32\pipmon.exe
C:\WINDOWS\system32\fsuyrytp.dll
C:\WINDOWS\system32\wfcojgth.dll

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply



Please download ATF Cleaner by Atribune to your desktop.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up


Post the Avenger log and a New HJT log
Avenger-

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\ebvvclqe

*******************

Script file located at: \??\C:\WINDOWS\nulnbune.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\pipmon.exe deleted successfully.
File C:\WINDOWS\system32\fsuyrytp.dll deleted successfully.


File C:\WINDOWS\system32\wfcojgth.dll not found!
Deletion of file C:\WINDOWS\system32\wfcojgth.dll failed!

Could not process line:
C:\WINDOWS\system32\wfcojgth.dll
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.










HJT-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:56:28 AM, on 9/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Greg P\Desktop\HiJackThis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {29C43852-CBFE-4407-97AB-65BDDEBABA48} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {70A8626C-0B5C-4581-808E-78970D1A870C} - (no file)
O2 - BHO: (no name) - {75EB7A01-6A46-43BE-99F4-AD8CB0FD8EC1} - (no file)
O2 - BHO: (no name) - {8928F543-A79B-45D5-A8B5-832633E252D2} - (no file)
O2 - BHO: (no name) - {9F1D47EA-80B7-4f21-A9D3-3738F20596EE} - (no file)
O2 - BHO: (no name) - {A3DA978E-2733-4E18-BAAF-3C3772F56670} - (no file)
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - (no file)
O2 - BHO: (no name) - {F4002052-AB29-4B33-8C8D-0E99084564EC} - (no file)
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKLM\..\Run: [pipmon] pipmon.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\wfcojgth.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1189398523015
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} -
O20 - Winlogon Notify: gebyy - C:\WINDOWS\
O20 - Winlogon Notify: iifeddd - C:\WINDOWS\
O20 - Winlogon Notify: vtuts - C:\WINDOWS\
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Unknown owner - C:\Program Files\Norton AntiVirus\isPwdSvc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Unknown owner - C:\Program Files\Intel\NCS\Sync\NetSvc.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows NT\rterejed.html

–
End of file - 4510 bytes
These may be preventing the deletion of those entries.

We need to disable the Tea Timer in Spybot Search and Destroy as to not interfere with the fix.
  • Open Spybot and go to Mode> Advanced Mode> Tools> Resident and take the checkmark out of Tea Timer

Open up AVG Antispyware and on the main page click on the Resident Shield and make it inactive



Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: (no name) - {29C43852-CBFE-4407-97AB-65BDDEBABA48} - (no file)
O2 - BHO: (no name) - {70A8626C-0B5C-4581-808E-78970D1A870C} - (no file)
O2 - BHO: (no name) - {75EB7A01-6A46-43BE-99F4-AD8CB0FD8EC1} - (no file)
O2 - BHO: (no name) - {8928F543-A79B-45D5-A8B5-832633E252D2} - (no file)
O2 - BHO: (no name) - {9F1D47EA-80B7-4f21-A9D3-3738F20596EE} - (no file)
O2 - BHO: (no name) - {A3DA978E-2733-4E18-BAAF-3C3772F56670} - (no file)
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - (no file)
O2 - BHO: (no name) - {F4002052-AB29-4B33-8C8D-0E99084564EC} - (no file)

O4 - HKLM\..\Run: [pipmon] pipmon.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\wfcojgth.dll",forkonce

O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} -

O20 - Winlogon Notify: gebyy - C:\WINDOWS\
O20 - Winlogon Notify: iifeddd - C:\WINDOWS\
O20 - Winlogon Notify: vtuts - C:\WINDOWS\




Download OTMoveIt and save it to your desktop
  • Open OTMoveIt.exe.
  • In the left pane where it says: "Paste List of Files/Folders to be Moved", copy and paste the files in the quote box including the full path

    C:\WINDOWS\system32\pipmon.exe
    C:\WINDOWS\system32\wfcojgth.dll

  • Then click the MoveIt button below.
  • In case you get a "Bad Image" error, just click OK at the promt. It will move the file anyway.
  • When done, it will create a log (********_******.log – * stands for date and time) in next folder: C:\_OTMoveIt\MovedFiles.
  • Copy and paste this log in your next reply.
Post the OTMoveIt log and a New HJT log please.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:55:53 PM, on 9/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\pipmon.exe
C:\WINDOWS\system32\pipmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Documents and Settings\Greg P\Desktop\HiJackThis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: rightonadz browser optimizer - {36A91CEC-6C71-4758-B492-397BFC8E96A2} - C:\WINDOWS\system32\gzmrotate.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: adssite - {F31B3634-12AA-41ca-B021-0685C3B3E4CA} - C:\WINDOWS\system32\nsy1D.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
O4 - HKLM\..\Run: [pipmon] pipmon.exe
O4 - HKLM\..\Run: [hid_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\gzmrotate.dll" DllVerify
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1189398523015
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Unknown owner - C:\Program Files\Norton AntiVirus\isPwdSvc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Unknown owner - C:\Program Files\Intel\NCS\Sync\NetSvc.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Windows NT\rterejed.html

–
End of file - 4056 bytes





Movelt-

C:\WINDOWS\system32\pipmon.exe moved successfully.
File/Folder C:\WINDOWS\system32\wfcojgth.dll not found.

Created on 09/11/2007 15:55:13
C:\WINDOWS\system32\pipmon.exe It keeps getting deleted but comes back.



Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post the Combofix log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall


Please run Trend Micro House Call
  • Click Scan now. It's free!
  • Read and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • Under "Browser plug-in" Installing and using Housecall kernel, click the Starting HouseCall>> button.
  • You may receive a prompt to install the ActiveX, click install.
  • If you are taken back to the main page, click Launching HouseCall>> button again.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.
  • When the scan is finished, please restart your computer.


Let me see the Combofix log , the Housecall report and a New HJT log , I need to do some research on that file and see why it won't go away

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI