Well all was looking good until just now, I turned on the monitor and there was savetheinformation.com and the pop ups again. This could have been caused by me not replying soon enough yesterday, since you said some more malware was on my pc. To get to the point, I redid all the steps you gave me before and have new logs —> I hope it's enough to start where we left off wednesday..sorry for any extra trouble.
Heres the New Vundofix and Hijack log:
VundoFix V6.6.2
Checking Java version…
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.4
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 5:59:44 PM 11/22/2007
Listing files found while scanning….
C:\windows\system32\xhpnadcm.dll
C:\WINDOWS\System32\yudkzaak.dll
C:\windows\system32\yudkzaak.dllbox
Beginning removal…
Attempting to delete C:\windows\system32\xhpnadcm.dll
C:\windows\system32\xhpnadcm.dll Has been deleted!
Attempting to delete C:\WINDOWS\System32\yudkzaak.dll
C:\WINDOWS\System32\yudkzaak.dll Could not be deleted.
Attempting to delete C:\windows\system32\yudkzaak.dllbox
C:\windows\system32\yudkzaak.dllbox Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal…
Attempting to delete C:\WINDOWS\System32\yudkzaak.dll
C:\WINDOWS\System32\yudkzaak.dll Has been deleted!
Performing Repairs to the registry.
Done!
Logfile of HijackThis v1.99.1
Scan saved at 6:43:47 PM, on 11/22/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\qdwclhnl.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\mrofinu572.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Insider\Insider.exe
C:\Documents and Settings\Owner\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\ckjkufj.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {f1348e8f-7a1c-7429-35a4-d495b5a033b6} - {6b330a5b-594d-4a53-9247-c1a7f8e8431f} - C:\WINDOWS\System32\evatupkm.dll
O2 - BHO: (no name) - {6D350BE7-3630-4C77-8B4D-C08281546092} - C:\WINDOWS\System32\mllmm.dll (file missing)
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: (no name) - {8F9F61A0-6BEA-44AF-B739-CF10C81EF3D0} - C:\WINDOWS\System32\ddaby.dll
O2 - BHO: (no name) - {92F8F316-37FB-4522-8B58-4AE600830396} - C:\WINDOWS\System32\rrzcqag.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\System32\vtuvwuu.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu572.exe 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\AntiSpywareSuite\bm.exe" dm=http://antispywaresuite.com; ad=http://antispywaresuite.com
O4 - HKLM\..\Run: [rtasks] C:\Program Files\AntiSpywareSuite\rtasks.exe
O4 - HKLM\..\Run: [482cd4e4] rundll32.exe "C:\WINDOWS\System32\aekttrty.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Pior] "C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Insider] C:\Program Files\Insider\Insider.exe
O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\Owner\Application Data\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [SfKg6w] C:\Documents and Settings\Owner\Application Data\Microsoft\Windows\ckjkufj.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1194905372609
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vtuvwuu - C:\WINDOWS\SYSTEM32\vtuvwuu.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DomainService - - C:\WINDOWS\System32\qdwclhnl.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Heres the New Combofix and Hijackthis logs:
ComboFix 07-11-19.3 - Owner 2007-11-22 18:50:21.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.55 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Owner\Application Data\PPATCH~1
C:\Documents and Settings\Owner\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\Owner\Application Data\WinTouch\WinTouch.exe
C:\Documents and Settings\Owner\Application Data\WinTouch\WTUninstaller.exe
C:\Program Files\AntiSpywareSuite
C:\Program Files\AntiSpywareSuite\history.db
C:\Program Files\AntiSpywareSuite\ResErrors.log
C:\Program Files\Common Files\mqzo
C:\Program Files\Common Files\mqzo\mqzoa.exe
C:\Program Files\Common Files\mqzo\mqzoa.lck
C:\Program Files\Common Files\mqzo\mqzod\class-barrel
C:\Program Files\Common Files\mqzo\mqzod\mqzoc.dll
C:\Program Files\Common Files\mqzo\mqzod\vocabulary
C:\Program Files\Common Files\mqzo\mqzol.exe
C:\Program Files\Common Files\mqzo\mqzol.lck
C:\Program Files\Common Files\mqzo\mqzom.lck
C:\Program Files\Common Files\mqzo\mqzop.exe
C:\Program Files\Common Files\mqzo\mqzop.lck
C:\Program Files\inetget2
C:\Program Files\Insider
C:\Program Files\Insider\Insider.exe
C:\Program Files\Insider\UnInstall.exe
C:\Program Files\network monitor
C:\Program Files\network monitor\netmon.exe
C:\Program Files\WindowsUpdate\rtelebipr.html
C:\UGA6P
C:\WINDOWS\b104.exe
C:\WINDOWS\b111.exe
C:\WINDOWS\b128.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b147.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\IA
C:\WINDOWS\IA\KE.vbs
C:\WINDOWS\mqzo
C:\WINDOWS\mqzo\mqzo.dat
C:\WINDOWS\mqzo\wu
C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\winnb58.dll
C:\WINDOWS\system32\ybadd.ini
C:\WINDOWS\system32\ybadd.ini2
C:\WINDOWS\system32\yudkzaak.dllbox
C:\WINDOWS\uninstall_nmon.vbs
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_CMDSERVICE
——-\LEGACY_DOMAINSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\cmdService
——-\DomainService
((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 )))))))))))))))))))))))))))))))
.
2007-11-22 18:52 20,810 —hs—- C:\WINDOWS\system32\gdqrjiln.dllbox
2007-11-22 18:51 145,984 –a—— C:\WINDOWS\system32\gdqrjiln.dll
2007-11-22 18:39 79,936 –a—— C:\WINDOWS\system32\evatupkm.dll
2007-11-22 18:36 1,841,657 –ahs—- C:\WINDOWS\system32\ytrttkea.ini
2007-11-22 18:36 85,056 –a—— C:\WINDOWS\system32\aekttrty.dll
2007-11-22 18:36 71,232 –a—— C:\WINDOWS\system32\eewdssov.exe
2007-11-22 17:25 1,843,829 –ahs—- C:\WINDOWS\system32\dypaftdt.ini
2007-11-22 17:19 79,936 –a—— C:\WINDOWS\system32\uhofgyrq.dll
2007-11-22 17:16 71,232 –a—— C:\WINDOWS\system32\qdwclhnl.exe
2007-11-21 17:02 36,864 –a—— C:\WINDOWS\system32\vtusqno.dll
2007-11-21 17:01 36,864 –a—— C:\WINDOWS\system32\ssqrrpq.dll
2007-11-21 17:01 35,840 –a—— C:\WINDOWS\17PHolmes572.exe
2007-11-21 16:59 d——– C:\Documents and Settings\Owner\Application Data\AntiSpywareSuite
2007-11-21 16:58 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2007-11-21 16:58 499,712 –a—— C:\WINDOWS\system32\msvcp71.dll
2007-11-21 16:58 348,160 –a—— C:\WINDOWS\system32\msvcr71.dll
2007-11-21 16:58 89,088 –a—— C:\WINDOWS\system32\atl71.dll
2007-11-21 16:58 24,064 –a—— C:\WINDOWS\system32\msxml3a.dll
2007-11-21 16:57 35,840 –a—— C:\WINDOWS\mrofinu572.exe
2007-11-21 16:56 36,864 –a—— C:\WINDOWS\system32\rqrrppq.dll
2007-11-21 12:38 d——– C:\VundoFix Backups
2007-11-21 03:52 71,232 –a—— C:\WINDOWS\system32\togavrkn.exe
2007-11-20 03:57 84,544 –a—— C:\WINDOWS\system32\amsswaah.dll
2007-11-20 03:54 688,812 –ahs—- C:\WINDOWS\system32\sjntdvtd.ini
2007-11-20 03:54 85,056 –a—— C:\WINDOWS\system32\dtvdtnjs.dll
2007-11-20 03:49 71,232 –a—— C:\WINDOWS\system32\qcnqttaj.exe
2007-11-18 22:44 79,424 –a—— C:\WINDOWS\system32\ypxlxatb.dll
2007-11-18 22:41 688,660 –ahs—- C:\WINDOWS\system32\edcphxqi.ini
2007-11-18 22:38 71,232 –a—— C:\WINDOWS\system32\yonkmexx.exe
2007-11-17 23:41 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-17 22:47 85,056 –a—— C:\WINDOWS\system32\tbmxuxtk.dll
2007-11-17 15:12 2,238 –a—— C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
2007-11-17 08:28 d——– C:\Program Files\QdrModule
2007-11-17 08:27 d——– C:\Program Files\QdrDrive
2007-11-17 08:27 36,352 –a—— C:\WINDOWS\system32\vtuvwuu.dll
2007-11-17 08:27 35,840 –a—— C:\WINDOWS\mrofinu72.exe
2007-11-13 23:27 d——– C:\Program Files\SymNetDrv
2007-11-13 05:56 593,408 –a–c— C:\WINDOWS\system32\dllcache\xpsp2res.dll
2007-11-13 05:43 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-11-13 05:43 134,272 –a–c— C:\WINDOWS\system32\dllcache\portcls.sys
2007-11-13 05:43 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-11-13 05:40 831,519 –a—— C:\WINDOWS\system32\mswdat10.dll
2007-11-13 05:40 831,519 –a–c— C:\WINDOWS\system32\dllcache\mswdat10.dll
2007-11-13 05:40 614,431 –a—— C:\WINDOWS\system32\mswstr10.dll
2007-11-13 05:40 614,431 –a–c— C:\WINDOWS\system32\dllcache\mswstr10.dll
2007-11-13 05:40 380,957 –a—— C:\WINDOWS\system32\expsrv.dll
2007-11-13 05:40 348,189 –a—— C:\WINDOWS\system32\msxbde40.dll
2007-11-13 05:40 348,189 –a–c— C:\WINDOWS\system32\dllcache\msxbde40.dll
2007-11-13 05:40 258,077 –a—— C:\WINDOWS\system32\mstext40.dll
2007-11-13 05:40 258,077 –a–c— C:\WINDOWS\system32\dllcache\mstext40.dll
2007-11-13 05:40 30,749 –a—— C:\WINDOWS\system32\vbajet32.dll
2007-11-13 05:40 30,749 –a–c— C:\WINDOWS\system32\dllcache\vbajet32.dll
2007-11-12 22:05 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-12 17:54 209,280 –a–c— C:\WINDOWS\system32\dllcache\update.sys
2007-11-12 17:53 991,232 –a—— C:\WINDOWS\system32\esent.dll
2007-11-12 17:50 595,968 –a—— C:\WINDOWS\system32\xpsp2res.dll
2007-11-12 17:50 307,200 –a–c— C:\WINDOWS\system32\dllcache\netapi32.dll
2007-11-12 17:50 260,096 –a—— C:\WINDOWS\system32\mstask.dll
2007-11-12 17:50 260,096 –a–c— C:\WINDOWS\system32\dllcache\mstask.dll
2007-11-12 17:50 172,544 –a—— C:\WINDOWS\system32\schedsvc.dll
2007-11-12 17:50 172,544 –a–c— C:\WINDOWS\system32\dllcache\schedsvc.dll
2007-11-12 17:50 10,752 –a—— C:\WINDOWS\system32\mstinit.exe
2007-11-12 17:50 10,752 –a–c— C:\WINDOWS\system32\dllcache\mstinit.exe
2007-11-12 17:40 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2007-11-12 17:40 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2007-11-12 17:18 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2007-11-12 17:16 d——– C:\WINDOWS\system32\bits
2007-11-12 17:13 361,984 –a–c— C:\WINDOWS\system32\dllcache\qmgr.dll
2007-11-12 17:13 331,776 –a—— C:\WINDOWS\system32\winhttp.dll
2007-11-12 17:13 331,776 –a–c— C:\WINDOWS\system32\dllcache\winhttp.dll
2007-11-12 17:13 17,408 –a—— C:\WINDOWS\system32\qmgrprxy.dll
2007-11-12 17:13 17,408 –a–c— C:\WINDOWS\system32\dllcache\qmgrprxy.dll
2007-11-12 17:13 7,680 –a–c— C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-11-12 17:13 7,680 –a—— C:\WINDOWS\system32\bitsprx2.dll
2007-11-12 17:13 7,168 –a–c— C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-11-12 17:13 7,168 –a—— C:\WINDOWS\system32\bitsprx3.dll
2007-11-12 17:10 549,720 –a—— C:\WINDOWS\system32\wuapi.dll
2007-11-12 17:10 325,976 –a—— C:\WINDOWS\system32\wucltui.dll
2007-11-12 17:10 216,408 –a—— C:\WINDOWS\system32\wuaucpl.cpl
2007-11-12 17:10 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-11-12 17:10 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2007-11-12 17:10 33,624 –a—— C:\WINDOWS\system32\wups.dll
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-11-12 17:10 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2007-11-12 17:10 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-11-11 18:06 208,896 –a—— C:\WINDOWS\system32\wmpns.dll
2007-11-11 16:48 d——– C:\Documents and Settings\Owner\Application Data\Musicmatch
2007-11-11 16:13 d——– C:\Documents and Settings\Owner\Shared
2007-11-11 16:11 d——– C:\Documents and Settings\Owner\Incomplete
2007-11-11 16:05 3,620 -rahs—- C:\WINDOWS\system32\drivers\HP_PC130A-ABA SR1111NX NA430_YC_Pres_QMXQ422_E43NAheREG3_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J40_7Intel_8Celeron_92.53_1_N10EC8139_P_Z_
K_A808624C5_U808624C2.MRK
2007-11-11 16:03 d——– C:\WINDOWS\system32\config\systemprofile\WINDOWS
2007-11-11 16:03 548,352 –a—— C:\WINDOWS\system32\rtcdll.dll
2007-11-11 16:03 548,352 –a–c— C:\WINDOWS\system32\dllcache\rtcdll.dll
2007-11-11 16:03 364,544 –a–c— C:\WINDOWS\system32\dllcache\callcont.dll
2007-11-11 16:03 253,952 –a–c— C:\WINDOWS\system32\dllcache\mst120.dll
2007-11-11 16:03 73,728 –a–c— C:\WINDOWS\system32\dllcache\nmcom.dll
2007-11-11 16:03 40,960 –a–c— C:\WINDOWS\system32\dllcache\evtgprov.dll
2007-11-11 16:02 974,336 –a—— C:\WINDOWS\system32\msdtctm.dll
2007-11-11 16:02 535,552 –a—— C:\WINDOWS\system32\rpcrt4.dll
2007-11-11 16:02 499,200 –a—— C:\WINDOWS\system32\comuid.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6b330a5b-594d-4a53-9247-c1a7f8e8431f}]
2007-11-22 18:39 79936 –a—— C:\WINDOWS\System32\evatupkm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D350BE7-3630-4C77-8B4D-C08281546092}]
C:\WINDOWS\System32\mllmm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{875A1348-7674-42aa-ADAC-B4F36A004A2D}]
C:\Program Files\QdrDrive\QdrDrive8.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92F8F316-37FB-4522-8B58-4AE600830396}]
C:\WINDOWS\System32\rrzcqag.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2007-11-22 18:51 145984 –a—— C:\WINDOWS\system32\gdqrjiln.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}]
2007-11-17 08:27 36352 –a—— C:\WINDOWS\System32\vtuvwuu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\gdqrjiln.dll [2007-11-22 18:51 145984]
[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= C:\WINDOWS\system32\gdqrjiln.dll [2007-11-22 18:51 145984]
[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2002-08-21 01:08]
"QdrModule9"="C:\Program Files\QdrModule\QdrModule9.exe" [2007-11-01 14:51]
"Pior"="C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe" []
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-17 23:42]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-04-02 03:49]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-08-20 15:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 22:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-02 04:43]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-16 22:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-13 23:43]
"VTTimer"="VTTimer.exe" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 03:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-12 22:13]
"Reminder"="C:\Windows\Creator\Remind_XP.exe" [2003-12-18 02:31]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 C:\WINDOWS\ALCXMNTR.EXE]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2004-08-20 15:55]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-11-13 23:27]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-04-02 05:04]
"482cd4e4"="C:\WINDOWS\System32\aekttrty.dll" [2007-11-22 18:36]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
IMStart.lnk - C:\Program Files\InterMute\IMStart.exe [2004-04-02 05:02:27]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 01:05:26]
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-02 19:04:03]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-17 23:41:55]
LimeWire 4.0.8.lnk - C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe [2004-07-14 13:03:16]
[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{BBB05D9E-0297-404D-A6BF-D8F2876B84A6}"= C:\WINDOWS\System32\vtuvwuu.dll [2007-11-17 08:27 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gdqrjiln]
gdqrjiln.dll 2007-11-22 18:51 145984 C:\WINDOWS\system32\gdqrjiln.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwuu]
vtuvwuu.dll 2007-11-17 08:27 36352 C:\WINDOWS\system32\vtuvwuu.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\System32\ddaby.dll
.
Contents of the 'Scheduled Tasks' folder
"2007-11-23 00:00:01 C:\WINDOWS\Tasks\AF5BC035918C71A9.job"
- c:\docume~1\owner\applic~1\stylea~1\Second Great Bags.exe
"2007-11-19 13:24:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-11-06 01:40:59 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-11-14 04:24:08 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-22 19:03:21
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-22 19:07:49 - machine was rebooted
C:\ComboFix2.txt … 2007-11-21 16:26
.
— E O F —
Logfile of HijackThis v1.99.1
Scan saved at 7:16:49 PM, on 11/22/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\Spyware.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: {f1348e8f-7a1c-7429-35a4-d495b5a033b6} - {6b330a5b-594d-4a53-9247-c1a7f8e8431f} - C:\WINDOWS\System32\evatupkm.dll
O2 - BHO: (no name) - {6D350BE7-3630-4C77-8B4D-C08281546092} - C:\WINDOWS\System32\mllmm.dll (file missing)
O2 - BHO: BndShell3 BHO Class - {875A1348-7674-42aa-ADAC-B4F36A004A2D} - C:\Program Files\QdrDrive\QdrDrive8.dll (file missing)
O2 - BHO: (no name) - {92F8F316-37FB-4522-8B58-4AE600830396} - C:\WINDOWS\System32\rrzcqag.dll (file missing)
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\gdqrjiln.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {B340E3F3-6E5F-47D9-900C-88D8E99EF786} - C:\WINDOWS\System32\vtsqn.dll
O2 - BHO: (no name) - {BBB05D9E-0297-404D-A6BF-D8F2876B84A6} - C:\WINDOWS\System32\vtuvwuu.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\gdqrjiln.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [482cd4e4] rundll32.exe "C:\WINDOWS\System32\aekttrty.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Pior] "C:\Documents and Settings\Owner\Application Data\?ymantec\??plorer.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1194905396093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftu…b?1194905372609
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O20 - Winlogon Notify: gdqrjiln - C:\WINDOWS\SYSTEM32\gdqrjiln.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: vtuvwuu - C:\WINDOWS\SYSTEM32\vtuvwuu.dll
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
this time, the trojan (toolbar, pop ups, etc.) doesn't look like it's went away
too much, unlike last time when it
looked like almost everything was gone when I used vundo.
Thankyou for any help in advance.