The Vundo stuff
The Check_LSA7 text file
My Firefox lags insanely, freezes up every while..
And all these other pop ups... Which I assume are the Vundo things..
I've googled up many solutions but none of them seem to work..
I've came upon this thread:
http://forums.whatth...way_t83040.html
But the problem is that ComboFix shows all these "Send Error Reports" for things like REG.EXE 5 times before telling me I'm not the administrator of the computer (which I am). The VundoFix wasn't able to delete all the files even after rebooting 3 times.
Well, enough chit-chat, I really want to get this fixed..
Here's my HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 4:25:20 PM, on 01/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Documents and Settings\Crispitos\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.ca/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.ca/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\bkglfyek.dll",sitypnow
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
Thanks in advance guys.
Ah, I restarted my computer and tried ComboFix again, here's the log..
ComboFix 07-10-02.2 - Crispitos 2007-10-01 16:48:52.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.589 [GMT -4:00]
Running from: C:\Documents and Settings\Crispitos\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ijllm.bak2
C:\WINDOWS\system32\ijllm.ini
C:\WINDOWS\system32\mllji.dll
C:\WINDOWS\system32\opnnkkh.dll
C:\WINDOWS\system32\winzwr32.dll
.
((((((((((((((((((((((((( Files Created from 2007-09-02 to 2007-10-02 )))))))))))))))))))))))))))))))
.
2007-10-01 16:48 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-01 16:08 87,104 --a------ C:\WINDOWS\system32\bkglfyek.dll
2007-10-01 15:32 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-09-30 22:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-09-30 22:34 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2007-09-30 17:55 <DIR> d-a------ C:\Program Files\SurvivalProject
2007-09-30 17:49 <DIR> d-------- C:\Program Files\Ventrilo
2007-09-30 17:38 <DIR> d-------- C:\Program Files\Ares
2007-09-30 17:25 <DIR> d-------- C:\Program Files\Microsoft Works
2007-09-30 17:24 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-09-30 17:21 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-09-30 17:18 <DIR> dr-h----- C:\MSOCache
2007-09-30 16:26 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-09-30 16:26 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-09-30 16:24 676,224 --a------ C:\WINDOWS\system32\OGACheckControl.dll
2007-09-30 16:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-09-30 16:11 <DIR> d-------- C:\Program Files\DAEMON Tools
2007-09-30 16:06 <DIR> d-------- C:\Documents and Settings\Crispitos\Application Data\Ventrilo
2007-09-30 16:03 <DIR> d--h----- C:\WINDOWS\PIF
2007-09-30 16:03 <DIR> d-------- C:\Program Files\VentSrv
2007-09-30 16:03 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-09-30 16:02 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-09-30 12:05 <DIR> d-------- C:\Program Files\Steam
2007-09-30 12:00 <DIR> d-------- C:\WINDOWS\pss
2007-09-30 11:58 23,040 --------- C:\WINDOWS\system32\dllcache\fltmc.exe
2007-09-30 11:58 16,896 --------- C:\WINDOWS\system32\dllcache\fltlib.dll
2007-09-30 11:58 128,896 --------- C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-09-30 11:58 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2007-09-30 11:47 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-09-30 11:47 <DIR> d-------- C:\Program Files\MSN Messenger
2007-09-30 11:47 <DIR> d-------- C:\Documents and Settings\Crispitos\Contacts
2007-09-30 11:45 <DIR> d---s---- C:\Documents and Settings\Crispitos\UserData
2007-09-30 11:42 <DIR> d--h----- C:\Documents and Settings\Crispitos\Application Data\Gtek
2007-09-30 11:42 <DIR> d-------- C:\Documents and Settings\Crispitos\Application Data\You've Got Pictures Screensaver
2007-09-30 11:42 <DIR> d-------- C:\Documents and Settings\Crispitos\Application Data\McAfee.com Personal Firewall
2007-09-30 11:40 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2007-09-30 11:39 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-09-30 11:39 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-09-30 11:33 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-09-30 11:33 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-09-30 11:33 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-09-30 11:31 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-09-30 11:29 <DIR> d-------- C:\Documents and Settings\Crispitos\Application Data\WinRAR
2007-09-30 11:26 1,156 --a------ C:\WINDOWS\mozver.dat
2007-09-30 11:26 <DIR> d-------- C:\Program Files\DellSupport
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-30 17:55 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-09-30 12:06 --------- d-------- C:\Program Files\Common Files\Real
2007-09-30 11:50 --------- d-------- C:\Program Files\Dell
2007-09-30 11:43 --------- d-------- C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
2007-09-30 11:37 --------- d-------- C:\Documents and Settings\All Users\Application Data\GTek
2007-09-30 11:19 --------- d-------- C:\Documents and Settings\All Users\Application Data\AOL
2007-07-30 22:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 22:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 22:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 22:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 22:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 22:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 22:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 22:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 22:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 22:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 22:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 22:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 22:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 22:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 22:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-14 21:49]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-14 21:46]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-14 21:50]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 18:48]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" []
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-09-30 11:33]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 06:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 06:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 06:00]
"SearchIndexer"="C:\WINDOWS\system32\bkglfyek.dll" [2007-10-01 16:08]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-10-01 16:40]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 14:09]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-09-18 10:16]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
"C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
S3 IOIDDEV;IOIDDEV;\??\C:\Program Files\SurvivalProject\config\ioid.sys
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-02 16:52:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-02 16:54:14 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-10-02 16:54
.
--- E O F ---