This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] All sorts of problems

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am trying to fix my mothers computer for her, and I am almost computer illiterate as she is. Her IE has stopped working unless I access it through her AT&T yahoo mail icon. The IE just stops and closes after a few secs of a white screen. I downloaded firefox, but she will want it removed before I give it back. Spybot keeps finding the same problem every time it scans, even if scanned in safe mode. It is something called "Virtumonde" I now have a flashing warning icon from something that got downloaded pretending to be a virus removal tool. Two new icons appeared from nowhere just now called "Online Security Guide" and "Live Saftey Center" They are giving popups asking to help with the virus every few secs or so.

Here is the Hijack this log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:53:12 PM, on 11/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\jrycdprl.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Documents and Settings\Lerman\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\fsjefivl.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\jrycdprl.exe
O23 - Service: ICF - Unknown owner - C:\WINDOWS\System32\svchost.exe:exe.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 4600 bytes


Please help. Thank you
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Have you fixed any items with HijackThis yourself?

Step 1

Please download ATF Cleaner. Double-click on ATF-Cleaner.exe to start the program.
  • Under the Main tab, put a check next to Select All.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Firefox browser:
    Click on Firefox at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
  • If you use the Opera browser:
    Click on Opera at the top and put a check next to Select All.
    If you would like to keep your saved passwords, click No at the prompt.
    Click the Empty Selected button. (Note: if you remove cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck Cookies)
Step 2

Please download Combofix:
Double-click on combofix.exe and follow the prompts.
When finished, it will produce a log for you. Save it to a convenient location.

Note: Do not mouseclick Combofix's window whilst it's running. That may cause it to stall.

Step 3

Please download SmitfraudFix (by S!ri).
  • Double-click on SmitfraudFix.exe. A screen will pop up. Select Option 1 (Search) by typing 1 and hit Enter. A text file will appear, which will list the infected files. Save it to a convenient location.
  • The log will also be saved here: C:\rapport.txt
Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Step 4

Please download and install CCleaner.
  • Open CCleaner. In the Left Pane, click Tools.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save.
  • Exit Ccleaner by clicking on the X button in the upper right of the CCleaner window.
Step 5

In your next reply, please post:
  • whether you fixed items in HijackThis
  • the Combofix log (C:\Combofix.txt)
  • the SmitfraudFix log (C:\rapport.txt)
  • the Uninstall List from CCleaner
  • a new HijackThis log
I have not previously fixed anything with the Hijack this program. I only knew about it because I used it on my computer a year or two ago, and am not smart enough to use it without specific instructins on what I am doing. I have a red computer, and that is about all I know about it.

Step 1. . .Didn't go so well. I was able to download the program. I was able to do the Firefox part, but when tried to delete the on the main page, it would just freeze up over and over.My mother uses IE, but I had to download Firefox to get the stuff working. IE is where I think most of the problems are.

Step 2 went fine, but took almost 2 hours. I got a popup advising me that the yahoo toolbar was altered during this process.

Step 3 went fine

Step 4 went fine

Combofix log is as follows:

ComboFix 07-11-08.1 - Lerman 2007-11-13 18:22:05.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Lerman\Application Data\PCTurbo Pro Free
C:\Documents and Settings\Lerman\Application Data\PCTurbo Pro Free\Logs\update.log
C:\Documents and Settings\Lerman\Application Data\RACLE~1
C:\Documents and Settings\Lerman\Application Data\RACLE~1\?racle\
C:\Documents and Settings\Lerman\Application Data\RACLE~1\spool32.exe
C:\Documents and Settings\Lerman\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Lerman\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Lerman\err.log
C:\Documents and Settings\Lerman\Favorites\Online Security Guide.lnk
C:\Documents and Settings\Lerman\ResErrors.log
C:\Documents and Settings\Lerman\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Lerman\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Lerman\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Program Files\Common Files\pppatc~1
C:\Program Files\Common Files\pppatc~1\m?dtc.exe
C:\Program Files\Common Files\qugavaja.dll
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\PCTurboPro_Free
C:\Program Files\PCTurboPro_Free\bnlink.dat
C:\Program Files\PCTurboPro_Free\err.log
C:\Program Files\PCTurboPro_Free\lapv.dat
C:\Program Files\PCTurboPro_Free\License.rtf
C:\Program Files\PCTurboPro_Free\manual.chm
C:\Program Files\PCTurboPro_Free\pctp.url
C:\Program Files\PCTurboPro_Free\pctp.xml
C:\Program Files\PCTurboPro_Free\pv.dat
C:\Program Files\PCTurboPro_Free\ResErrors.log
C:\Program Files\PCTurboPro_Free\server.dat
C:\Program Files\PCTurboPro_Free\sr.log
C:\Program Files\PCTurboPro_Free\unins000.dat
C:\Program Files\PCTurboPro_Free\updater.dat
C:\Program Files\SecCenter
C:\Program Files\SecCenter\scprot4.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\Downloaded Program Files\UPCTP_0001_91M1101NetInstaller.exe
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\a1\rarndrll2.exe
C:\WINDOWS\system32\bvgevqai
C:\WINDOWS\system32\bvgevqai\bg1.gif
C:\WINDOWS\system32\bvgevqai\bgtop.gif
C:\WINDOWS\system32\bvgevqai\bottom1.gif
C:\WINDOWS\system32\bvgevqai\bvgevqai1.exe
C:\WINDOWS\system32\bvgevqai\bvgevqai2.exe
C:\WINDOWS\system32\bvgevqai\bvgevqai3.exe
C:\WINDOWS\system32\bvgevqai\essentials.gif
C:\WINDOWS\system32\bvgevqai\icon1.ico
C:\WINDOWS\system32\bvgevqai\install1.gif
C:\WINDOWS\system32\bvgevqai\left1.gif
C:\WINDOWS\system32\bvgevqai\li.gif
C:\WINDOWS\system32\bvgevqai\logo.gif
C:\WINDOWS\system32\bvgevqai\main.htm
C:\WINDOWS\system32\bvgevqai\mainframe.htm
C:\WINDOWS\system32\bvgevqai\reinstall1.gif
C:\WINDOWS\system32\bvgevqai\right1.gif
C:\WINDOWS\system32\bvgevqai\s1.htm
C:\WINDOWS\system32\bvgevqai\s2.htm
C:\WINDOWS\system32\bvgevqai\s3.htm
C:\WINDOWS\system32\bvgevqai\SMTop1.gif
C:\WINDOWS\system32\bvgevqai\SMTop2.gif
C:\WINDOWS\system32\bvgevqai\SMTop3.gif
C:\WINDOWS\system32\bvgevqai\SMTop4.gif
C:\WINDOWS\system32\bvgevqai\soft1_off.gif
C:\WINDOWS\system32\bvgevqai\soft1_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft1_on.gif
C:\WINDOWS\system32\bvgevqai\soft1_on_ext.gif
C:\WINDOWS\system32\bvgevqai\soft2_off.gif
C:\WINDOWS\system32\bvgevqai\soft2_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft2_on.gif
C:\WINDOWS\system32\bvgevqai\soft2_on_ext.gif
C:\WINDOWS\system32\bvgevqai\soft3_off.gif
C:\WINDOWS\system32\bvgevqai\soft3_off_ext.gif
C:\WINDOWS\system32\bvgevqai\soft3_on.gif
C:\WINDOWS\system32\bvgevqai\soft3_on_ext.gif
C:\WINDOWS\system32\bvgevqai\softbottom_off.gif
C:\WINDOWS\system32\bvgevqai\softbottom_on.gif
C:\WINDOWS\system32\bvgevqai\softleft_off.gif
C:\WINDOWS\system32\bvgevqai\softleft_on.gif
C:\WINDOWS\system32\bvgevqai\top1.gif
C:\WINDOWS\system32\bvgevqai\top2.gif
C:\WINDOWS\system32\bvgevqai\turnoff1.gif
C:\WINDOWS\system32\bvgevqai\turnon1.gif
C:\WINDOWS\System32\ddayy.dll
C:\WINDOWS\system32\drivers\blank.gif
C:\WINDOWS\system32\drivers\box_1.gif
C:\WINDOWS\system32\drivers\box_2.gif
C:\WINDOWS\system32\drivers\box_3.gif
C:\WINDOWS\system32\drivers\button_buynow.gif
C:\WINDOWS\system32\drivers\button_freescan.gif
C:\WINDOWS\system32\drivers\cell_bg.gif
C:\WINDOWS\system32\drivers\cell_footer.gif
C:\WINDOWS\system32\drivers\cell_header_block.gif
C:\WINDOWS\system32\drivers\cell_header_remove.gif
C:\WINDOWS\system32\drivers\cell_header_scan.gif
C:\WINDOWS\system32\drivers\detect.htm
C:\WINDOWS\system32\drivers\download_box.gif
C:\WINDOWS\system32\drivers\download_btn.jpg
C:\WINDOWS\system32\drivers\download_now_btn.gif
C:\WINDOWS\system32\drivers\footer_back.jpg
C:\WINDOWS\system32\drivers\header_1.gif
C:\WINDOWS\system32\drivers\header_2.gif
C:\WINDOWS\system32\drivers\header_3.gif
C:\WINDOWS\system32\drivers\header_4.gif
C:\WINDOWS\system32\drivers\header_red_bg.gif
C:\WINDOWS\system32\drivers\header_red_free_scan.gif
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif
C:\WINDOWS\system32\drivers\infected.gif
C:\WINDOWS\system32\drivers\main_back.gif
C:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg
C:\WINDOWS\system32\drivers\product_1_header.gif
C:\WINDOWS\system32\drivers\product_1_name_small.gif
C:\WINDOWS\system32\drivers\product_2_header.gif
C:\WINDOWS\system32\drivers\product_2_name_small.gif
C:\WINDOWS\system32\drivers\product_3_header.gif
C:\WINDOWS\system32\drivers\product_3_name_small.gif
C:\WINDOWS\system32\drivers\product_features.gif
C:\WINDOWS\system32\drivers\pt.htm
C:\WINDOWS\system32\drivers\rating.gif
C:\WINDOWS\system32\drivers\s_detect.htm
C:\WINDOWS\system32\drivers\screenshot.jpg
C:\WINDOWS\system32\drivers\sep_hor.gif
C:\WINDOWS\system32\drivers\sep_vert.gif
C:\WINDOWS\system32\drivers\shadow.jpg
C:\WINDOWS\system32\drivers\shadow_bg.gif
C:\WINDOWS\system32\drivers\spacer.gif
C:\WINDOWS\system32\drivers\spy_away_box.jpg
C:\WINDOWS\system32\drivers\star.gif
C:\WINDOWS\system32\drivers\star_gray.gif
C:\WINDOWS\system32\drivers\star_gray_small.gif
C:\WINDOWS\system32\drivers\star_small.gif
C:\WINDOWS\system32\drivers\style.css
C:\WINDOWS\system32\drivers\v.gif
C:\WINDOWS\system32\drivers\warning_icon.gif
C:\WINDOWS\system32\drivers\win_logo.gif
C:\WINDOWS\system32\drivers\x.gif
C:\WINDOWS\system32\drvpijr.dll
C:\WINDOWS\system32\fsjefivl.dllbox
C:\WINDOWS\system32\g2
C:\WINDOWS\system32\g2\caws83122.exe
C:\WINDOWS\system32\ldinfo.ldr
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\r2
C:\WINDOWS\system32\r2\wr31drs.exe
C:\WINDOWS\system32\smsnfi.dll
C:\WINDOWS\system32\winetn32.dll
C:\WINDOWS\system32\wnscpsu32.exe
C:\WINDOWS\SYSTEM32\yyadd.bak1
C:\WINDOWS\SYSTEM32\yyadd.bak2
C:\WINDOWS\SYSTEM32\yyadd.ini
C:\WINDOWS\tk58.exe
C:\WINDOWS\TTC-4444.exe
C:\WINDOWS\winshow.exe
C:\windows\xpupdate.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_ICF
——-\LEGACY_NETWORK_MONITOR
——-\DomainService
——-\ICF


((((((((((((((((((((((((( Files Created from 2007-10-14 to 2007-11-14 )))))))))))))))))))))))))))))))
.

2007-11-13 18:12 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-13 18:05 85,056 –a—— C:\WINDOWS\SYSTEM32\uylwhgbj.dll
2007-11-13 17:59 80,448 –a—— C:\WINDOWS\SYSTEM32\qshgxqis.dll
2007-11-13 17:56 71,232 –a—— C:\WINDOWS\SYSTEM32\upcdgwde.exe
2007-11-12 22:43 d——– C:\Program Files\Spyware Doctor
2007-11-12 22:43 d——– C:\Documents and Settings\Lerman\Application Data\PC Tools
2007-11-12 22:43 79,688 –a—— C:\WINDOWS\SYSTEM32\drivers\iksyssec.sys
2007-11-12 22:43 62,280 –a—— C:\WINDOWS\SYSTEM32\drivers\iksysflt.sys
2007-11-12 22:43 41,288 –a—— C:\WINDOWS\SYSTEM32\drivers\ikfilesec.sys
2007-11-12 22:43 29,000 –a—— C:\WINDOWS\SYSTEM32\drivers\kcom.sys
2007-11-12 22:42 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-11-12 17:32 89,664 –a—— C:\WINDOWS\SYSTEM32\xtwqkwix.dll
2007-11-12 17:29 81,472 –a—— C:\WINDOWS\SYSTEM32\brspxiwn.dll
2007-11-12 17:24 144,480 –a—— C:\WINDOWS\SYSTEM32\fsjefivl.dll
2007-11-12 17:23 144,480 –a—— C:\WINDOWS\SYSTEM32\yauqmelj.dll
2007-11-12 17:19 71,232 –a—— C:\WINDOWS\SYSTEM32\pllqlasr.exe
2007-11-12 02:31 1,277 –a—— C:\WINDOWS\mozver.dat
2007-11-11 17:20 79,936 –a—— C:\WINDOWS\SYSTEM32\wssagxxa.dll
2007-11-11 17:17 71,232 –a—— C:\WINDOWS\SYSTEM32\sqmrstlo.exe
2007-11-10 17:23 81,472 –a—— C:\WINDOWS\SYSTEM32\inmuntyy.dll
2007-11-10 17:17 71,232 –a—— C:\WINDOWS\SYSTEM32\wbcwrihb.exe
2007-11-09 17:20 77,888 –a—— C:\WINDOWS\SYSTEM32\fksjyutq.dll
2007-11-09 17:17 71,232 –a—— C:\WINDOWS\SYSTEM32\vusqfuxm.exe
2007-11-08 17:23 80,448 –a—— C:\WINDOWS\SYSTEM32\shpcxgqj.dll
2007-11-08 17:17 71,232 –a—— C:\WINDOWS\SYSTEM32\cqjbcusg.exe
2007-11-07 17:26 79,936 –a—— C:\WINDOWS\SYSTEM32\wyattrbj.dll
2007-11-07 17:17 71,232 –a—— C:\WINDOWS\SYSTEM32\jrycdprl.exe
2007-11-06 23:07 128,896 —–c— C:\WINDOWS\SYSTEM32\dllcache\fltmgr.sys
2007-11-06 23:07 23,040 —–c— C:\WINDOWS\SYSTEM32\dllcache\fltmc.exe
2007-11-06 23:07 16,896 —–c— C:\WINDOWS\SYSTEM32\dllcache\fltlib.dll
2007-11-06 22:56 582,656 —–c— C:\WINDOWS\SYSTEM32\dllcache\rpcrt4.dll
2007-11-06 22:21 6,058,496 —–c— C:\WINDOWS\SYSTEM32\dllcache\ieframe.dll
2007-11-06 22:21 2,455,488 —–c— C:\WINDOWS\SYSTEM32\dllcache\ieapfltr.dat
2007-11-06 22:21 459,264 —–c— C:\WINDOWS\SYSTEM32\dllcache\msfeeds.dll
2007-11-06 22:21 383,488 —–c— C:\WINDOWS\SYSTEM32\dllcache\ieapfltr.dll
2007-11-06 22:21 267,776 —–c— C:\WINDOWS\SYSTEM32\dllcache\iertutil.dll
2007-11-06 22:21 63,488 —–c— C:\WINDOWS\SYSTEM32\dllcache\icardie.dll
2007-11-06 22:21 52,224 —–c— C:\WINDOWS\SYSTEM32\dllcache\msfeedsbs.dll
2007-11-06 22:21 13,824 —–c— C:\WINDOWS\SYSTEM32\dllcache\ieudinit.exe
2007-11-06 22:20 33,792 –a–c— C:\WINDOWS\SYSTEM32\dllcache\custsat.dll
2007-11-06 20:18 11,776 –a—— C:\WINDOWS\SYSTEM32\spnpinst.exe
2007-11-06 20:18 4,569 –a—— C:\WINDOWS\SYSTEM32\secupd.dat
2007-11-06 19:58 d——– C:\Program Files\Yahoo! Games
2007-11-06 18:01 614,912 –a—— C:\WINDOWS\SYSTEM32\h323msp.dll
2007-11-06 18:01 331,264 –a—— C:\WINDOWS\SYSTEM32\ipnathlp.dll
2007-11-06 18:01 40,960 —–c— C:\WINDOWS\SYSTEM32\dllcache\evtgprov.dll
2007-11-06 18:01 26,112 –a—— C:\WINDOWS\SYSTEM32\xpsp1hfm.exe
2007-11-06 17:24 87,104 –a—— C:\WINDOWS\SYSTEM32\lukhwajm.dll
2007-11-06 17:21 81,472 –a—— C:\WINDOWS\SYSTEM32\sqtbmbxa.dll
2007-11-06 17:18 71,232 –a—— C:\WINDOWS\SYSTEM32\oajxxnui.exe
2007-11-06 17:17 276,184 –a—— C:\WINDOWS\SYSTEM32\rasphone.dll
2007-11-06 17:03 1,082,368 –a—— C:\WINDOWS\SYSTEM32\esent.dll
2007-11-06 15:39 351,232 –a—— C:\WINDOWS\SYSTEM32\winhttp.dll
2007-11-06 15:39 18,944 –a—— C:\WINDOWS\SYSTEM32\qmgrprxy.dll
2007-11-06 15:39 8,192 –a—— C:\WINDOWS\SYSTEM32\bitsprx2.dll
2007-11-06 15:39 7,168 –a—— C:\WINDOWS\SYSTEM32\bitsprx3.dll
2007-11-06 08:25 549,720 –a—— C:\WINDOWS\SYSTEM32\wuapi.dll
2007-11-06 08:25 325,976 –a—— C:\WINDOWS\SYSTEM32\wucltui.dll
2007-11-06 08:25 203,096 –a—— C:\WINDOWS\SYSTEM32\wuweb.dll
2007-11-06 08:25 186,136 –a—— C:\WINDOWS\SYSTEM32\wuaueng1.dll
2007-11-06 08:25 167,704 –a—— C:\WINDOWS\SYSTEM32\wuauclt1.exe
2007-11-06 08:25 33,624 –a—— C:\WINDOWS\SYSTEM32\wups.dll
2007-11-06 05:43 444 –a—— C:\WINDOWS\SYSTEM32\d3d8caps.dat
2007-11-06 05:03 d——– C:\Documents and Settings\Lerman\Application Data\MSN6
2007-11-06 04:47 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-11-06 04:36 36,352 –a—— C:\WINDOWS\SYSTEM32\opnopnl.dll
2007-11-06 04:35 d——– C:\Program Files\Tophdcme
2007-11-06 04:34 d——– C:\Program Files\xulwxgxs
2007-11-06 04:34 d——– C:\Program Files\MalwareAlarm
2007-11-06 04:34 104,960 –a—— C:\WINDOWS\SYSTEM32\drvpij.dll
2007-11-06 04:34 35,328 –a—— C:\WINDOWS\SYSTEM32\urqrqro.dll
2007-11-06 04:33 21,504 –a—— C:\WINDOWS\SYSTEM32\aivskurq.dll
2007-11-06 04:33 0 –a—— C:\WINDOWS\SYSTEM32\vvgeowbv.exe
2007-11-06 04:30 d–hs—- C:\WINDOWS\UmhvbmRhIExlcm1hbg
2007-11-06 04:30 d——– C:\WINDOWS\SYSTEM32\Mz08r
2007-11-06 04:30 d——– C:\Temp\mZOr
2007-11-06 04:30 36,352 –a—— C:\WINDOWS\SYSTEM32\khffdcy.dll
2007-11-06 04:30 35,840 –a—— C:\WINDOWS\mrofinu77.exe
2007-11-06 04:30 35,840 –a—— C:\WINDOWS\mrofinu1000106.exe
2007-11-04 06:02 4,096 –a—— C:\WINDOWS\d3dx.dat
2007-11-03 22:57 d——– C:\Documents and Settings\Lerman\Application Data\Chicken Chase
2007-11-02 20:04 313 –a—— C:\WINDOWS\bbbconfig.dat
2007-11-01 05:42 755,200 -ra—— C:\WINDOWS\SYSTEM32\ir50_32.dll
2007-11-01 05:42 239,616 –a—— C:\WINDOWS\SYSTEM32\Hdk3ctnt.dll
2007-11-01 05:42 255 –a—— C:\WINDOWS\PowerReg.dat
2007-11-01 04:10 d——– C:\Documents and Settings\Lerman\Application Data\Sandlot Games
2007-11-01 04:10 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Sandlot Games
2007-11-01 04:09 d–hs—- C:\WINDOWS\ftpcache
2007-11-01 03:59 d——– C:\Documents and Settings\Lerman\Application Data\Gamelab
2007-11-01 02:52 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Legacy Interactive
2007-10-31 00:07 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Trymedia
2007-10-31 00:07 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\HipSoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 00:21 246 —-a-w C:\Program Files\Common Files\qugavaja
2007-11-12 08:49 ——— d—–w C:\Program Files\Java
2007-11-06 10:33 ——— d—–w C:\Program Files\Detto
2007-10-31 06:01 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2007-10-25 17:46 142 —-a-w C:\Program Files\Common Files\rteprekyco.html
2007-10-22 09:39 267,272 —-a-w C:\WINDOWS\SYSTEM32\xactengine2_10.dll
2007-10-22 09:37 17,928 —-a-w C:\WINDOWS\SYSTEM32\X3DAudio1_2.dll
2007-10-12 21:14 3,734,536 —-a-w C:\WINDOWS\SYSTEM32\d3dx9_36.dll
2007-10-12 21:14 1,374,232 —-a-w C:\WINDOWS\SYSTEM32\D3DCompiler_36.dll
2007-10-02 15:56 444,776 —-a-w C:\WINDOWS\SYSTEM32\d3dx10_36.dll
2007-10-01 12:45 ——— d—–w C:\Documents and Settings\Lerman\Application Data\RegSweep
2007-09-22 03:04 ——— d—–w C:\Program Files\ItsDeductible2006
2007-09-22 03:00 ——— d—–w C:\Program Files\Common Files\PCTurboPro Free
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\SYSTEM32\inetcomm.dll
2007-08-14 00:54 413,696 —-a-w C:\WINDOWS\SYSTEM32\vbscript.dll
2007-08-14 00:54 156,160 —-a-w C:\WINDOWS\SYSTEM32\msls31.dll
2007-08-14 00:45 78,336 —-a-w C:\WINDOWS\SYSTEM32\ieencode.dll
2007-08-14 00:44 40,960 —-a-w C:\WINDOWS\SYSTEM32\licmgr10.dll
2007-08-14 00:39 71,680 —-a-w C:\WINDOWS\SYSTEM32\admparse.dll
2007-08-14 00:39 55,296 —-a-w C:\WINDOWS\SYSTEM32\iesetup.dll
2007-08-14 00:36 36,352 —-a-w C:\WINDOWS\SYSTEM32\imgutil.dll
2007-08-14 00:32 45,568 —-a-w C:\WINDOWS\SYSTEM32\mshta.exe
2007-08-14 00:01 48,128 —-a-w C:\WINDOWS\SYSTEM32\mshtmler.dll
1998-03-25 23:36 2,606 -c–a-w C:\Program Files\UNINSTAL.INS
1998-02-03 20:32 11 -c–a-w C:\Program Files\UNINSTAL.INI
1998-02-02 21:27 18,330 -c–a-w C:\Program Files\UNINSTAL.LIB
1998-02-02 20:45 44,976 -c–a-w C:\Program Files\UNINSTAL.EXE
2005-08-02 22:46:54 187,904 –sha-r C:\WINDOWS\UmhvbmRhIExlcm1hbg\asappsrv.dll
2005-07-29 22:24:26 472 –sha-r C:\WINDOWS\UmhvbmRhIExlcm1hbg\oA1SvAl1KHU5wAY1v0.vbs
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{391B174C-A6B7-C9D7-6743-01F7A0D663D6}]
C:\Program Files\Tophdcme\lcnygscg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F8FC91D-E762-484A-A3A1-015B08D565CB}]
2007-11-13 19:00 313440 –a—— C:\WINDOWS\system32\ddcca.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{634BBAB7-3F60-4426-944F-A62B9007F67F}]
2007-11-06 04:30 36352 –a—— C:\WINDOWS\System32\khffdcy.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{84CFF553-9131-4ECE-9B6E-718014878F2B}]
2007-08-02 07:43 282624 –a—— C:\Program Files\Detto\metoco555077.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A56216C9-51AE-4B78-8757-028159CB9855}]
2007-08-02 07:43 282624 –a—— C:\Program Files\Detto\metoco4444.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-12 17:24 144480 –a—— C:\WINDOWS\system32\fsjefivl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AC083C2C-7E70-4D1F-8DDE-E3413F0C319F}]
2007-08-02 07:43 282624 –a—— C:\Program Files\Detto\metoco83122.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bbc2319b-5cf7-4750-9277-6b1f7d89f364}]
2007-11-13 17:59 80448 –a—— C:\WINDOWS\system32\qshgxqis.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\fsjefivl.dll [2007-11-12 17:24 144480]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\fsjefivl.dll [2007-11-12 17:24 144480]

[HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"5c97b767"="C:\WINDOWS\system32\uylwhgbj.dll" [2007-11-13 18:05]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{634BBAB7-3F60-4426-944F-A62B9007F67F}"= C:\WINDOWS\System32\khffdcy.dll [2007-11-06 04:30 36352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsjefivl]
fsjefivl.dll 2007-11-12 17:24 144480 C:\WINDOWS\SYSTEM32\fsjefivl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khffdcy]
khffdcy.dll 2007-11-06 04:30 36352 C:\WINDOWS\SYSTEM32\khffdcy.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddcca.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lerman^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Lerman\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\5c97b767]
rundll32.exe "C:\WINDOWS\system32\xtwqkwix.dll",b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\TEMP\win3351.tmp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bijopcbg]
regsvr32 /u "C:\Documents and Settings\All Users.WINDOWS\Application Data\bijopcbg.dll"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CaAvTray]
"C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAVRID]
"C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
rundll32.exe C:\WINDOWS\System32\drvpij.dll,startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gylgn]
"C:\Program Files\Common Files\?ppPatch\m?dtc.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MalwareAlarm]
C:\Program Files\MalwareAlarm\MalwareAlarm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\mrofinu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
C:\Program Files\SecCenter\scprot4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
"C:\Program Files\Spyware Doctor\SDTrayApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Towo]
"C:\DOCUME~1\Lerman\APPLIC~1\RACLE~1\spool32.exe" -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
C:\Windows\xpupdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winshow]
"C:\WINDOWS\winshow.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wtqpohqf]
rundll32.exe "C:\Program Files\xulwxgxs\fyziryjg.dll",Init

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{7B-B7-7C-C8-ZN}]
C:\DOCUME~1\Lerman\LOCALS~1\Temp\T0CHD001.exe CHD001


.
Contents of the 'Scheduled Tasks' folder
"2007-11-12 09:30:01 C:\WINDOWS\Tasks\RegSweep Scheduled Scan.job"
- C:\Program Files\RegSweep\RegSweep.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-13 18:57:57
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\ddcca.dll 313440 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2007-11-13 19:12:42 - machine was rebooted
.
— E O F —





SmitfraudFix log is as follows:

SmitFraudFix v2.253

Scan done at 21:12:03.76, Tue 11/13/2007
Run from C:\Documents and Settings\Lerman\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lerman


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lerman\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Lerman\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Realtek RTL8139 Family PCI Fast Ethernet NIC - Packet Scheduler Miniport
DNS Server Search Order: 204.127.203.135
DNS Server Search Order: 216.148.225.135

HKLM\SYSTEM\CCS\Services\Tcpip\..\{3CDC3FCE-F070-43D0-B586-C89A069472A0}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{3CDC3FCE-F070-43D0-B586-C89A069472A0}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\..\{3CDC3FCE-F070-43D0-B586-C89A069472A0}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End





Uninstall List is as follows:

Adobe Flash Player 9 ActiveX
Adobe Shockwave Player
AT&T Yahoo! Applications
Best of Slots II
BroadJump Client Foundation
CCleaner (remove only)
HijackThis 2.0.2
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows Media Format SDK (KB910998)
Hotfix for Windows XP (KB914440)
Java™ 6 Update 3
Lexmark Z600 Series
Microsoft Visual C++ 2005 Redistributable
Monopoly
Mozilla Firefox (2.0.0.9)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 8 (KB917734)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Spybot - Search & Destroy
Spyware Doctor 5.1
TurboTax ItsDeductible 2005
TurboTax Premier 2005
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
WebFldrs XP
WexTech AnswerWorks
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
Yahoo! Toolbar



New Hijack this Log is as follows:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:15 PM, on 11/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Documents and Settings\Lerman\Desktop\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\fsjefivl.dll
O4 - HKLM\..\Run: [5c97b767] rundll32.exe "C:\WINDOWS\system32\uylwhgbj.dll",b
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 4884 bytes




Thank you again for your help. I really appriciate it.
Hi :)

Step 1. . .Didn't go so well. I was able to download the program. I was able to do the Firefox part, but when tried to delete the on the main page, it would just freeze up over and over.My mother uses IE, but I had to download Firefox to get the stuff working. IE is where I think most of the problems are.


How long did you wait? ATF Cleaner can take a while if it needs to delete a lot of stuff.

Step 2 went fine, but took almost 2 hours. I got a popup advising me that the yahoo toolbar was altered during this process.


That shouldn't take so long :o It removed a lot though, so that could be the cause.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CaAvTray]
"C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAVRID]
"C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"


Why have you disabled your Anti-Virus protection?

Step 1

Please disable Spyware Doctor OnGuard, as it may interfere with the fix.
  • From within Spyware Doctor, click the OnGuard button on the left side.
  • Uncheck Activate OnGuard.
  • Reboot your computer to complete the process.
Note: Be sure to enable Spyware Doctor OnGuard when you are clean!

Step 2

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s) (if present):
  • MalwareAlarm
  • PCTurboPro
Step 3

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\SYSTEM32\uylwhgbj.dll
C:\WINDOWS\SYSTEM32\qshgxqis.dll
C:\WINDOWS\SYSTEM32\upcdgwde.exe
C:\WINDOWS\SYSTEM32\xtwqkwix.dll
C:\WINDOWS\SYSTEM32\brspxiwn.dll
C:\WINDOWS\SYSTEM32\fsjefivl.dll
C:\WINDOWS\SYSTEM32\yauqmelj.dll
C:\WINDOWS\SYSTEM32\pllqlasr.exe
C:\WINDOWS\SYSTEM32\wssagxxa.dll
C:\WINDOWS\SYSTEM32\sqmrstlo.exe
C:\WINDOWS\SYSTEM32\inmuntyy.dll
C:\WINDOWS\SYSTEM32\wbcwrihb.exe
C:\WINDOWS\SYSTEM32\fksjyutq.dll
C:\WINDOWS\SYSTEM32\vusqfuxm.exe
C:\WINDOWS\SYSTEM32\shpcxgqj.dll
C:\WINDOWS\SYSTEM32\cqjbcusg.exe
C:\WINDOWS\SYSTEM32\wyattrbj.dll
C:\WINDOWS\SYSTEM32\jrycdprl.exe
C:\WINDOWS\SYSTEM32\lukhwajm.dll
C:\WINDOWS\SYSTEM32\sqtbmbxa.dll
C:\WINDOWS\SYSTEM32\oajxxnui.exe
C:\WINDOWS\SYSTEM32\rasphone.dll
C:\WINDOWS\SYSTEM32\opnopnl.dll
C:\WINDOWS\SYSTEM32\drvpij.dll
C:\WINDOWS\SYSTEM32\urqrqro.dll
C:\WINDOWS\SYSTEM32\aivskurq.dll
C:\WINDOWS\SYSTEM32\vvgeowbv.exe
C:\WINDOWS\SYSTEM32\khffdcy.dll
C:\WINDOWS\mrofinu77.exe
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\d3dx.dat
C:\Program Files\Common Files\rteprekyco.html
C:\Program Files\Detto\metoco555077.dll
C:\Program Files\Detto\metoco4444.dll
C:\Documents and Settings\Lerman\Start Menu\Programs\Startup\TA_Start.lnk
C:\WINDOWS\TEMP\win3351.tmp.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\bijopcbg.dll
C:\DOCUME~1\Lerman\APPLIC~1\RACLE~1\spool32.exe
C:\WINDOWS\winshow.exe
C:\DOCUME~1\Lerman\LOCALS~1\Temp\T0CHD001.exe
C:\WINDOWS\system32\ddcca.dll

DirLook::

C:\Program Files\Common Files\qugavaja

Folder::

C:\Program Files\xulwxgxs
C:\WINDOWS\UmhvbmRhIExlcm1hbg
C:\WINDOWS\SYSTEM32\Mz08r
C:\Temp\mZOr
C:\Program Files\Common Files\PCTurboPro Free
C:\Program Files\Tophdcme
C:\Program Files\Common Files\?ppPatch
C:\Program Files\SecCenter

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{391B174C-A6B7-C9D7-6743-01F7A0D663D6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3F8FC91D-E762-484A-A3A1-015B08D565CB}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{634BBAB7-3F60-4426-944F-A62B9007F67F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{84CFF553-9131-4ECE-9B6E-718014878F2B}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A56216C9-51AE-4B78-8757-028159CB9855}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AC083C2C-7E70-4D1F-8DDE-E3413F0C319F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bbc2319b-5cf7-4750-9277-6b1f7d89f364}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"=-
[-HKEY_CLASSES_ROOT\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"5c97b767"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{634BBAB7-3F60-4426-944F-A62B9007F67F}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsjefivl]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\khffdcy]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Lerman^Start Menu^Programs^Startup^TA_Start.lnk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\5c97b767]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bijopcbg]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gylgn]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MalwareAlarm]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SC2]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Towo]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winshow]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wtqpohqf]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{7B-B7-7C-C8-ZN}]

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 4

Please do an online scan with Kaspersky WebScanner.

Click on Kaspersky Online Scanner. On the welcome screen, click Accept.

You will be promted to install an ActiveX component from Kaspersky, click Install.
  • The program will launch and then begin downloading the latest definition files.
  • Once the files have been downloaded click on Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
  • Scan using the following Anti-Virus database:

    Extended (if available, otherwise Standard)
  • Scan Options:

    Scan Archives
    Scan Mail Bases
  • Click OK.
  • Now under Select a Target to Scan:

    Select My Computer.
  • The program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button and save the file to your desktop.
Step 5

In your next reply, please post:
  • the Combofix log (C:\Combofix.txt)
  • the Kaspersky Online Scan report
  • a new HijackThis log
I tried the ATF cleaner several times and waited between 15 and 45 minutes depending on the attmpt. I finally did get it to clen up after my last post, but I had to check each thing sepperatly, and let it do its work like that.

I only mentioned the 2 hours it took to clean up on the other program because it said it should take 10 minutes or doubble that for a badly infected computer. It never became unresponsive though, so I let it keep running.

I don't know why the anti-virus protection was dissabled on this computer to begin with. It is my mother computer, and she is out of state on work, so I can't just ask her. I know it probably remaines that way because soething is pretending to be a virus protection program and adding icons to the desktop, so I did my best to get rid of whatever it is, and dissable it. Unfortunatly I don't know what program is real and what isn't anymore on this, so I probably took out the good with the bad.

Step 1: I already did disable it. It was something I tried to get things fixed with, but it was not registered, and seamed to be doing very little good. Because at the end my mother wont tolerate any extra programs left on her computer (to my dismay) I had to remove it.

Step 2: Neither Program was found on the Add/Remove list.


Step 3: Compleated sucessfully

Step 4: IE seams to be functioning again. I am getting a ton of popups with it, but was able to use it for the online virus scan. Apprently it does not function with Firefox. Got it done though

Step 5: Combofix log is as follows



ComboFix 07-11-08.1 - Lerman 2007-11-14 20:06:58.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.59 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lerman\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\DOCUME~1\Lerman\APPLIC~1\RACLE~1\spool32.exe
C:\DOCUME~1\Lerman\LOCALS~1\Temp\T0CHD001.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\bijopcbg.dll
C:\Documents and Settings\Lerman\Start Menu\Programs\Startup\TA_Start.lnk
C:\Program Files\Common Files\rteprekyco.html
C:\Program Files\Detto\metoco4444.dll
C:\Program Files\Detto\metoco555077.dll
C:\WINDOWS\d3dx.dat
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu77.exe
C:\WINDOWS\SYSTEM32\aivskurq.dll
C:\WINDOWS\SYSTEM32\brspxiwn.dll
C:\WINDOWS\SYSTEM32\cqjbcusg.exe
C:\WINDOWS\system32\ddcca.dll
C:\WINDOWS\SYSTEM32\drvpij.dll
C:\WINDOWS\SYSTEM32\fksjyutq.dll
C:\WINDOWS\SYSTEM32\fsjefivl.dll
C:\WINDOWS\SYSTEM32\inmuntyy.dll
C:\WINDOWS\SYSTEM32\jrycdprl.exe
C:\WINDOWS\SYSTEM32\khffdcy.dll
C:\WINDOWS\SYSTEM32\lukhwajm.dll
C:\WINDOWS\SYSTEM32\oajxxnui.exe
C:\WINDOWS\SYSTEM32\opnopnl.dll
C:\WINDOWS\SYSTEM32\pllqlasr.exe
C:\WINDOWS\SYSTEM32\qshgxqis.dll
C:\WINDOWS\SYSTEM32\rasphone.dll
C:\WINDOWS\SYSTEM32\shpcxgqj.dll
C:\WINDOWS\SYSTEM32\sqmrstlo.exe
C:\WINDOWS\SYSTEM32\sqtbmbxa.dll
C:\WINDOWS\SYSTEM32\upcdgwde.exe
C:\WINDOWS\SYSTEM32\urqrqro.dll
C:\WINDOWS\SYSTEM32\uylwhgbj.dll
C:\WINDOWS\SYSTEM32\vusqfuxm.exe
C:\WINDOWS\SYSTEM32\vvgeowbv.exe
C:\WINDOWS\SYSTEM32\wbcwrihb.exe
C:\WINDOWS\SYSTEM32\wssagxxa.dll
C:\WINDOWS\SYSTEM32\wyattrbj.dll
C:\WINDOWS\SYSTEM32\xtwqkwix.dll
C:\WINDOWS\SYSTEM32\yauqmelj.dll
C:\WINDOWS\TEMP\win3351.tmp.exe
C:\WINDOWS\winshow.exe
.

Unable to gain System Privileges

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Lerman\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Lerman\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Lerman\Favorites\Online Security Guide.lnk
C:\Program Files\Common Files\PCTurboPro Free
C:\Program Files\Common Files\PCTurboPro Free\up.dat
C:\Program Files\Common Files\rteprekyco.html
C:\Program Files\Detto\metoco4444.dll
C:\Program Files\Detto\metoco555077.dll
C:\Program Files\Tophdcme
C:\Program Files\Tophdcme\lcnygscg.xxx
C:\Program Files\xulwxgxs
C:\Program Files\xulwxgxs\fyziryjg.dll
C:\Temp\mZOr
C:\Temp\mZOr\tOasF.log
C:\WINDOWS\d3dx.dat
C:\WINDOWS\mrofinu1000106.exe
C:\WINDOWS\mrofinu77.exe
C:\WINDOWS\SYSTEM32\accdd.ini
C:\WINDOWS\SYSTEM32\accdd.ini2
C:\WINDOWS\SYSTEM32\aivskurq.dll
C:\WINDOWS\SYSTEM32\brspxiwn.dll
C:\WINDOWS\SYSTEM32\cqjbcusg.exe
C:\WINDOWS\system32\ddcca.dll
C:\WINDOWS\SYSTEM32\drvpij.dll
C:\WINDOWS\SYSTEM32\fksjyutq.dll
C:\WINDOWS\SYSTEM32\fsjefivl.dll
C:\WINDOWS\system32\fsjefivl.dllbox
C:\WINDOWS\SYSTEM32\inmuntyy.dll
C:\WINDOWS\SYSTEM32\jrycdprl.exe
C:\WINDOWS\SYSTEM32\khffdcy.dll
C:\WINDOWS\SYSTEM32\lukhwajm.dll
C:\WINDOWS\SYSTEM32\Mz08r
C:\WINDOWS\SYSTEM32\oajxxnui.exe
C:\WINDOWS\SYSTEM32\opnopnl.dll
C:\WINDOWS\SYSTEM32\pllqlasr.exe
C:\WINDOWS\SYSTEM32\qshgxqis.dll
C:\WINDOWS\SYSTEM32\rasphone.dll
C:\WINDOWS\SYSTEM32\shpcxgqj.dll
C:\WINDOWS\SYSTEM32\sqmrstlo.exe
C:\WINDOWS\SYSTEM32\sqtbmbxa.dll
C:\WINDOWS\SYSTEM32\upcdgwde.exe
C:\WINDOWS\SYSTEM32\urqrqro.dll
C:\WINDOWS\SYSTEM32\uylwhgbj.dll
C:\WINDOWS\SYSTEM32\vusqfuxm.exe
C:\WINDOWS\SYSTEM32\vvgeowbv.exe
C:\WINDOWS\SYSTEM32\wbcwrihb.exe
C:\WINDOWS\SYSTEM32\wssagxxa.dll
C:\WINDOWS\SYSTEM32\wyattrbj.dll
C:\WINDOWS\SYSTEM32\xtwqkwix.dll
C:\WINDOWS\SYSTEM32\yauqmelj.dll
C:\WINDOWS\UmhvbmRhIExlcm1hbg
C:\WINDOWS\UmhvbmRhIExlcm1hbg\asappsrv.dll
C:\WINDOWS\UmhvbmRhIExlcm1hbg\oA1SvAl1KHU5wAY1v0.vbs

.
((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.

2007-11-13 21:15 d——– C:\Program Files\CCleaner
2007-11-13 21:12 482 –a—— C:\WINDOWS\SYSTEM32\tmp.reg
2007-11-13 21:10 289,144 –a—— C:\WINDOWS\SYSTEM32\VCCLSID.exe
2007-11-13 21:10 288,417 –a—— C:\WINDOWS\SYSTEM32\SrchSTS.exe
2007-11-13 21:10 53,248 –a—— C:\WINDOWS\SYSTEM32\Process.exe
2007-11-13 21:10 51,200 –a—— C:\WINDOWS\SYSTEM32\dumphive.exe
2007-11-13 21:10 25,600 –a—— C:\WINDOWS\SYSTEM32\WS2Fix.exe
2007-11-13 18:12 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-12 22:42 626,688 –a—— C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-11-12 02:31 1,277 –a—— C:\WINDOWS\mozver.dat
2007-11-06 23:07 128,896 —–c— C:\WINDOWS\SYSTEM32\dllcache\fltmgr.sys
2007-11-06 23:07 23,040 —–c— C:\WINDOWS\SYSTEM32\dllcache\fltmc.exe
2007-11-06 23:07 16,896 —–c— C:\WINDOWS\SYSTEM32\dllcache\fltlib.dll
2007-11-06 22:56 582,656 —–c— C:\WINDOWS\SYSTEM32\dllcache\rpcrt4.dll
2007-11-06 22:21 6,058,496 —–c— C:\WINDOWS\SYSTEM32\dllcache\ieframe.dll
2007-11-06 22:21 2,455,488 —–c— C:\WINDOWS\SYSTEM32\dllcache\ieapfltr.dat
2007-11-06 22:21 459,264 —–c— C:\WINDOWS\SYSTEM32\dllcache\msfeeds.dll
2007-11-06 22:21 383,488 —–c— C:\WINDOWS\SYSTEM32\dllcache\ieapfltr.dll
2007-11-06 22:21 267,776 —–c— C:\WINDOWS\SYSTEM32\dllcache\iertutil.dll
2007-11-06 22:21 63,488 —–c— C:\WINDOWS\SYSTEM32\dllcache\icardie.dll
2007-11-06 22:21 52,224 —–c— C:\WINDOWS\SYSTEM32\dllcache\msfeedsbs.dll
2007-11-06 22:21 13,824 —–c— C:\WINDOWS\SYSTEM32\dllcache\ieudinit.exe
2007-11-06 22:20 33,792 –a–c— C:\WINDOWS\SYSTEM32\dllcache\custsat.dll
2007-11-06 20:18 11,776 –a—— C:\WINDOWS\SYSTEM32\spnpinst.exe
2007-11-06 20:18 4,569 –a—— C:\WINDOWS\SYSTEM32\secupd.dat
2007-11-06 19:58 d——– C:\Program Files\Yahoo! Games
2007-11-06 18:01 614,912 –a—— C:\WINDOWS\SYSTEM32\h323msp.dll
2007-11-06 18:01 331,264 –a—— C:\WINDOWS\SYSTEM32\ipnathlp.dll
2007-11-06 18:01 40,960 —–c— C:\WINDOWS\SYSTEM32\dllcache\evtgprov.dll
2007-11-06 18:01 26,112 –a—— C:\WINDOWS\SYSTEM32\xpsp1hfm.exe
2007-11-06 17:03 1,082,368 –a—— C:\WINDOWS\SYSTEM32\esent.dll
2007-11-06 15:39 351,232 –a—— C:\WINDOWS\SYSTEM32\winhttp.dll
2007-11-06 15:39 18,944 –a—— C:\WINDOWS\SYSTEM32\qmgrprxy.dll
2007-11-06 15:39 8,192 –a—— C:\WINDOWS\SYSTEM32\bitsprx2.dll
2007-11-06 15:39 7,168 –a—— C:\WINDOWS\SYSTEM32\bitsprx3.dll
2007-11-06 08:25 549,720 –a—— C:\WINDOWS\SYSTEM32\wuapi.dll
2007-11-06 08:25 325,976 –a—— C:\WINDOWS\SYSTEM32\wucltui.dll
2007-11-06 08:25 203,096 –a—— C:\WINDOWS\SYSTEM32\wuweb.dll
2007-11-06 08:25 186,136 –a—— C:\WINDOWS\SYSTEM32\wuaueng1.dll
2007-11-06 08:25 167,704 –a—— C:\WINDOWS\SYSTEM32\wuauclt1.exe
2007-11-06 08:25 33,624 –a—— C:\WINDOWS\SYSTEM32\wups.dll
2007-11-06 05:43 444 –a—— C:\WINDOWS\SYSTEM32\d3d8caps.dat
2007-11-06 05:03 d——– C:\Documents and Settings\Lerman\Application Data\MSN6
2007-11-06 04:47 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-11-06 04:34 d——– C:\Program Files\MalwareAlarm
2007-11-03 22:57 d——– C:\Documents and Settings\Lerman\Application Data\Chicken Chase
2007-11-02 20:04 313 –a—— C:\WINDOWS\bbbconfig.dat
2007-11-01 05:42 755,200 -ra—— C:\WINDOWS\SYSTEM32\ir50_32.dll
2007-11-01 05:42 239,616 –a—— C:\WINDOWS\SYSTEM32\Hdk3ctnt.dll
2007-11-01 05:42 255 –a—— C:\WINDOWS\PowerReg.dat
2007-11-01 04:10 d——– C:\Documents and Settings\Lerman\Application Data\Sandlot Games
2007-11-01 04:10 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Sandlot Games
2007-11-01 04:09 d–hs—- C:\WINDOWS\ftpcache
2007-11-01 03:59 d——– C:\Documents and Settings\Lerman\Application Data\Gamelab
2007-11-01 02:52 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Legacy Interactive
2007-10-31 00:07 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Trymedia
2007-10-31 00:07 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\HipSoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 02:13 ——— d—–w C:\Program Files\Detto
2007-11-14 00:21 246 —-a-w C:\Program Files\Common Files\qugavaja
2007-11-12 08:49 ——— d—–w C:\Program Files\Java
2007-10-31 06:01 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2007-10-01 12:45 ——— d—–w C:\Documents and Settings\Lerman\Application Data\RegSweep
2007-09-22 03:04 ——— d—–w C:\Program Files\ItsDeductible2006
1998-03-25 23:36 2,606 -c–a-w C:\Program Files\UNINSTAL.INS
1998-02-03 20:32 11 -c–a-w C:\Program Files\UNINSTAL.INI
1998-02-02 21:27 18,330 -c–a-w C:\Program Files\UNINSTAL.LIB
1998-02-02 20:45 44,976 -c–a-w C:\Program Files\UNINSTAL.EXE
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Program Files\Common Files\qugavaja —-

C:\Program Files\Common Files\qugavaja\


((((((((((((((((((((((((((((( snapshot@2007-11-13_19.06.50.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-09-28 04:19:40 18,089,592 —-a-w C:\WINDOWS\SYSTEM32\MRT.exe
+ 2007-11-02 07:12:57 18,238,072 —-a-w C:\WINDOWS\SYSTEM32\MRT.exe
- 2007-03-06 01:22:36 14,048 —-a-w C:\WINDOWS\SYSTEM32\spmsg.dll
+ 2007-03-06 01:22:33 14,048 —-a-w C:\WINDOWS\SYSTEM32\spmsg.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CaAvTray]
"C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CAVRID]
"C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]
"C:\Program Files\Spyware Doctor\SDTrayApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart


.
Contents of the 'Scheduled Tasks' folder
"2007-11-12 09:30:01 C:\WINDOWS\Tasks\RegSweep Scheduled Scan.job"
- C:\Program Files\RegSweep\RegSweep.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-14 20:19:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

**************************************************************************
.
Completion time: 2007-11-14 20:23:40 - machine was rebooted
.
— E O F —



Kaspersky Online Scan report is as follows:



KASPERSKY ONLINE SCANNER REPORT
Thursday, November 15, 2007 12:32:22 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/11/2007
Kaspersky Anti-Virus database records: 459694



Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 134358
Number of viruses found 23
Number of infected objects 73
Number of suspicious objects 2
Duration of the scan process 02:54:47

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip/Yazzle1162OinUninstaller.exe Suspicious: Password-protected-EXE skipped

C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip ZIP: suspicious - 1 skipped

C:\Documents and Settings\Lerman\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\cert8.db Object is locked skipped

C:\Documents and Settings\Lerman\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\history.dat Object is locked skipped

C:\Documents and Settings\Lerman\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\key3.db Object is locked skipped

C:\Documents and Settings\Lerman\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\parent.lock Object is locked skipped

C:\Documents and Settings\Lerman\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\search.sqlite Object is locked skipped

C:\Documents and Settings\Lerman\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\urlclassifier2.sqlite Object is locked skipped

C:\Documents and Settings\Lerman\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Lerman\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\Lerman\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\Lerman\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Documents and Settings\Lerman\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped

C:\Documents and Settings\Lerman\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\Cache\_CACHE_001_ Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\Cache\_CACHE_002_ Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\Cache\_CACHE_003_ Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\Application Data\Mozilla\Firefox\Profiles\dhfttezq.default\Cache\_CACHE_MAP_ Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\History\History.IE5\MSHist012007111420071115\index.dat Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Lerman\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Lerman\ntuser.dat Object is locked skipped

C:\Documents and Settings\Lerman\NTUSER.DAT.LOG Object is locked skipped

C:\Documents and Settings\Lerman\UserData\index.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat Object is locked skipped

C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat Object is locked skipped

C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Detto\metoco83122.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped

C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll Infected: not-a-virus:AdWare.Win32.Agent.ac skipped

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9B.tmp Infected: not-a-virus:AdWare.Win32.Thumper.a skipped

C:\qoobox\Quarantine\C\Documents and Settings\Lerman\Application Data\RACLE~1\spool32.exe.vir Infected: Trojan-Downloader.Win32.PurityScan.ey skipped

C:\qoobox\Quarantine\C\Program Files\Common Files\qugavaja.dll.vir Infected: Trojan.Win32.BHO.ab skipped

C:\qoobox\Quarantine\C\Program Files\Detto\metoco4444.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\qoobox\Quarantine\C\Program Files\Detto\metoco555077.dll.vir Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\qoobox\Quarantine\C\Program Files\Outerinfo\FF\components\FF.dll.vir Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped

C:\qoobox\Quarantine\C\WINDOWS\Downloaded Program Files\UPCTP_0001_91M1101NetInstaller.exe.vir Infected: not-a-virus:Downloader.Win32.WinFixer.i skipped

C:\qoobox\Quarantine\C\WINDOWS\mrofinu1000106.exe.vir Infected: Trojan-Downloader.Win32.Agent.emo skipped

C:\qoobox\Quarantine\C\WINDOWS\mrofinu77.exe.vir Infected: Trojan-Downloader.Win32.Agent.emo skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\a1\rarndrll2.exe.vir Infected: Trojan-Downloader.Win32.Small.buy skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\aivskurq.dll.vir Infected: Trojan-Downloader.Win32.VB.bpt skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\bvgevqai\bvgevqai2.exe.vir Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\cqjbcusg.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\drvpij.dll.vir Infected: Trojan.Win32.Dialer.qn skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\g2\caws83122.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\g2\caws83122.exe.vir NSIS: infected - 1 skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\jrycdprl.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\oajxxnui.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\opnopnl.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aju skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\pllqlasr.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\r2\wr31drs.exe.vir Infected: Trojan-Downloader.Win32.Small.gll skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\rasphone.dll.vir Infected: Trojan-Spy.Win32.BZub.btt skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\sqmrstlo.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\upcdgwde.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vusqfuxm.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\wbcwrihb.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped

C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\winetn32.dll.vir Infected: Trojan.Win32.Agent.qt skipped

C:\qoobox\Quarantine\C\WINDOWS\tk58.exe.vir Infected: Trojan.Win32.BHO.ab skipped

C:\qoobox\Quarantine\C\WINDOWS\TTC-4444.exe.vir/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\qoobox\Quarantine\C\WINDOWS\TTC-4444.exe.vir NSIS: infected - 1 skipped

C:\qoobox\Quarantine\C\WINDOWS\UmhvbmRhIExlcm1hbg\asappsrv.dll.vir Infected: not-a-virus:AdWare.Win32.CommAd.a skipped

C:\qoobox\Quarantine\C\WINDOWS\xpupdate.exe.vir Infected: not-virus:Hoax.Win32.Renos.hx skipped

C:\qoobox\Quarantine\catchme2007-11-14_201937.60.zip/khffdcy.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aju skipped

C:\qoobox\Quarantine\catchme2007-11-14_201937.60.zip ZIP: infected - 1 skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP224\A0015072.exe Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017364.exe Infected: not-a-virus:FraudTool.Win32.UltimateDefender.v skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017368.dll Infected: Trojan.Win32.BHO.ab skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017369.dll Infected: Trojan.Win32.Agent.qt skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017373.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017374.exe Infected: Trojan-Downloader.Win32.PurityScan.ey skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017377.exe Infected: Trojan-Downloader.Win32.Small.buy skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017378.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017378.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017379.exe Infected: Trojan-Downloader.Win32.Small.gll skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017381.exe Infected: not-virus:Hoax.Win32.Renos.hx skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017382.exe Infected: Trojan.Win32.BHO.ab skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017383.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP225\A0017383.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018656.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018658.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018659.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018660.exe Infected: Trojan-Downloader.Win32.Agent.emo skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018661.exe Infected: Trojan-Downloader.Win32.Agent.emo skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018662.dll Infected: Trojan-Downloader.Win32.VB.bpt skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018664.exe Infected: Trojan.Win32.Obfuscated.kp skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018665.dll Infected: Trojan.Win32.Dialer.qn skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018668.exe Infected: Trojan.Win32.Obfuscated.kp skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018670.exe Infected: Trojan.Win32.Obfuscated.kp skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018671.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aju skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018672.exe Infected: Trojan.Win32.Obfuscated.kp skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018674.dll Infected: Trojan-Spy.Win32.BZub.btt skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018676.exe Infected: Trojan.Win32.Obfuscated.kp skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018678.exe Infected: Trojan.Win32.Obfuscated.kp skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018681.exe Infected: Trojan.Win32.Obfuscated.kp skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018683.exe Infected: Trojan.Win32.Obfuscated.kp skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\A0018693.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aju skipped

C:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\EventCache\{C6B2923E-456D-4E2E-A60A-57F733CD7179}.bin Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\config\default Object is locked skipped

C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\config\Internet.evt Object is locked skipped

C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped

C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped

C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\config\software Object is locked skipped

C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\SYSTEM32\config\system Object is locked skipped

C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped

C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped

C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

D:\System Volume Information\_restore{5B0E3F23-0614-4DF2-B520-B1A1E154C02B}\RP228\change.log Object is locked skipped

D:\WINDOWS\$NtUninstallQ309521$\dxmasf.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ309521$\lsasrv.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ309521$\msdxm.ocx Object is locked skipped

D:\WINDOWS\$NtUninstallQ309521$\sfcfiles.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ309521$\spuninst\spuninst.exe Object is locked skipped

D:\WINDOWS\$NtUninstallQ309521$\spuninst\spuninst.inf Object is locked skipped

D:\WINDOWS\$NtUninstallQ311889$\spuninst\spuninst.exe Object is locked skipped

D:\WINDOWS\$NtUninstallQ311889$\spuninst\spuninst.inf Object is locked skipped

D:\WINDOWS\$NtUninstallQ311889$\termsrv.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\acgenral.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\aclayers.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\aclua.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\acspecfc.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\acverfyr.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\acxtrnal.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\apphelp.sdb Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\apps.chm Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\d3d8.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\drvmain.sdb Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\msimain.sdb Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\qdvd.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\spuninst\spuninst.exe Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\spuninst\spuninst.inf Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\sysmain.sdb Object is locked skipped

D:\WINDOWS\$NtUninstallQ313484$\udfs.sys Object is locked skipped

D:\WINDOWS\$NtUninstallQ314862$\qmgr.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ314862$\spuninst\spuninst.exe Object is locked skipped

D:\WINDOWS\$NtUninstallQ314862$\spuninst\spuninst.inf Object is locked skipped

D:\WINDOWS\$NtUninstallQ315000$\netsetup.exe Object is locked skipped

D:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.exe Object is locked skipped

D:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.inf Object is locked skipped

D:\WINDOWS\$NtUninstallQ315000$\ssdpapi.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ315000$\ssdpsrv.dll Object is locked skipped

D:\WINDOWS\$NtUninstallQ315000$\upnp.dll Object is locked skipped

Scan process completed.

The new Hijackthis log is as follows


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:10 AM, on 11/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Documents and Settings\Lerman\Desktop\HiJackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AT&T; Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 4674 bytes



Thank you sorry for the long time in replying. The scan took almost 4 hours.
Hi :)

I don't know why the anti-virus protection was dissabled on this computer to begin with. It is my mother computer, and she is out of state on work, so I can't just ask her. I know it probably remaines that way because soething is pretending to be a virus protection program and adding icons to the desktop, so I did my best to get rid of whatever it is, and dissable it. Unfortunatly I don't know what program is real and what isn't anymore on this, so I probably took out the good with the bad.

Please go to Start > Run… and type in MSConfig.
Click on the Startup tab. Select these items to run at startup:

CaAvTray
CAVRID


An anti-virus program is very important for the security of your computer.

Step 1: I already did disable it. It was something I tried to get things fixed with, but it was not registered, and seamed to be doing very little good. Because at the end my mother wont tolerate any extra programs left on her computer (to my dismay) I had to remove it.

That's fine. I will, however, give you some prevention tips when the computer is clean. I strongly encourage you and your mother to use them, as they decrease the change of reinfection a lot.

I am getting a ton of popups with it

That shouldn't be happening anymore :D Can you tell me what the pop ups are advertising for, or what they are saying?

We'll dig a little deeper. Please do the following:

Step 1

Open HijackThis, perform a scan and put a check next to the following items (if present):

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com


Close all programs except HijackThis and click on Fix checked.

Step 2

Download F-Secure Blacklight to your desktop.
  • Double-click on fsbl.exe to open the program, select I accept the agreement and click Next.
  • Click Scan.
  • After the scan is complete, click Next, then Exit.
  • It will create a log on the desktop named fsbl-xxxxxxx.log (the xxxxxxx will be the date and time of the scan).
Step 3

In your next reply, please post:
  • the Blacklight log
  • a new HijackThis log
CaAvTray and CAVRID enabled

I dont mind useing the antivirus programs on my computer. I would have several actually if they didn't give my WoW and EQ such problems.

You are correct! The popups are gone, and the little yellow triangle in the lower right hand corner that was flashing has dissappeared WOOT! Thanks!

Step 1: Complete, both targets found

Step 2: done

11/16/07 14:22:44 [Info]: BlackLight Engine 1.0.67 initialized
11/16/07 14:22:44 [Info]: OS: 5.1 build 2600 (Service Pack 2)
11/16/07 14:22:44 [Note]: 7019 4
11/16/07 14:22:44 [Note]: 7005 0
11/16/07 14:22:46 [Note]: 7006 0
11/16/07 14:22:46 [Note]: 7011 1832
11/16/07 14:22:47 [Note]: 7026 0
11/16/07 14:22:47 [Note]: 7026 0
11/16/07 14:22:50 [Note]: FSRAW library version 1.7.1024
11/16/07 14:37:39 [Note]: 2000 1012
11/16/07 15:32:08 [Note]: 7007 0


hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:32:54 PM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Lerman\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 4405 bytes


:) thanks again
Hi :)

Congratulations, your log looks clean. Please advise of any problems you are still experiencing, or follow these simple steps to keep your computer clean in the future:

Click Start then Run….
  • Type Combofix /u in the runbox and click OK. (Note: The space between the x and the /u needs to be there)

    [external image: Posted Image]
  • When shown the disclaimer, select 2.
Disable and Enable System Restore - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

Step 1: Turn off System Restore:
  • On the desktop, right-click My Computer
  • Click Properties
  • Click the System Restore tab
  • Check Turn off System Restore
  • Click Apply, and then click OK
Step 2: Reboot your computer.

Step 3: Turn on System Restore:
  • On the desktop, right-click My Computer
  • Click Properties
  • Click the System Restore tab
  • Uncheck Turn off System Restore
  • Click Apply, and then click OK
Note: Only do this once, NOT on a regular basis!

Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt.
  • Change the Download unsigned ActiveX controls to Disable.
  • Change the Initialise and script ActiveX controls not marked as safe to Disable.
  • Change the Installation of desktop items to Prompt.
  • Change the Launching programs and files in an IFRAME to Prompt.
  • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Update your Anti-Virus Software - It is very imprtant that you update your anti-virus software at least once a week (even more if you wish). If you do not update your anti-virus software then it will not be able to catch any of the new variants that will come out.

Use a Firewall - Without a firewall your computer is susceptible to being hacked and taken over. The Windows firewall isn't sufficient as it only monitors incoming connections.

Here are a few (free) firewalls, please download and install one of them:
Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

Install Ad-Aware - Download and install Ad-Aware. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
Computer Safety on line - Anti-Malware

Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Stand Up and Be Counted! - Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints: Malware Complaints. You have to be registered to post. After registering just find your country room and register your complaint. The infections you had were Vundo (Virtumundo) and Smitfraud.
I don't know of any other problems. I have been to afraid to use the computer more than to check in here, and follow your directions. I didn't want things to get worse. If you say it looks clean I will trust you. Thanks so very much. It is much appreciated.
Hi, The logs you have posted look clean, though I cannot say whether there are still problems without seeing the computer itself. I will leave this topic open for a couple of days, so you use the computer for a while and post back to me if there are remaining problems :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI