This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] W32/SillyDi.YQ Virus, Virtumonde & W32.trojandownl

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello:

I have spent hours trying to track down this problem. I have Windows XP Professional completely updated - new computer built a week ago. CA AntiVirus 2008 - Lavasoft Adaware 2008 both completely updated. Pop-ups are occuring trying to get me to download AntiMalware Guard and adware like that. I did a system on Ewido on-line but it came up clean. When scanning with Ewido on-line my desktop icons and taskbar completely disappeared in response to the scan. Earlier in the day it appeared as though whatever is infecting the computer was trying to get to the internet but couldn't because I pulled the wireless connection. I was getting screens from Internet Explorer and was prompted whether or not I wanted to view the page off-line.

CA Antivirus identifies and supposedly detected and deleted a virus called W32/SillyDi.YQ - I cannot find any information on this virus, ie. how it infects and what it does

AdAware 2008 - first system scan found - virtumonde - so I ran Vundofix.exe and also Virtumundobegone - appears as though it finds stuff and deletes them but I am still having trouble.

Whatever is infecting my system takes out AdAware - meaning it keeps shutting it down, or it won't invoke. I have added and removed it and updated it a few times and it is then that I get these other infections:

W32.trojandownloader.homles and then just the same icon for the infection with no name

Here is the Hijack This log - Any help in solving this would be greatly appreciated:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:06 AM, on 7/31/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [38f50dad] rundll32.exe "C:\WINDOWS\system32\phrfdmfr.dll",b
O4 - HKLM\..\Run: [BM3bc63e31] Rundll32.exe "C:\WINDOWS\system32\lpqcoqqs.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1216603637562
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 6796 bytes

Thanks,
MsCoy
Hello

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.



Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
Hello Rorschach 112:

Thanks for the help, unfortunately things are beginning to look grim. I did another system virus scan in safe mode first and it found Win32/VMalum.DQEX and is currently quantined. I "fixed" the two suspect entries in the HiJackThis log. I ran VundoFix.exe and it didn't find anything. I downloaded and tried to run the dss.exe file and had no luck. I got an error "…encountered an unexpected error…etc. and it closed. I tried running the program in normal mode, safe mode and I also renamed the program and it still shut down on me. I then ran an AdAware scan and it found "1" item which is unknown - same icon as before… Then I downloaded DSS again and tried it again in and this time I had success. Here are the log files. Please note that anything that has been edited, it was done by me so as to not identify the computer completely. If you see "_______" that is where I took out the name.

Thank you so much for all your help, I hope we can get to the bottom of this.

MsCoy

Main.txt
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-31 22:12:25
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–



– Last 2 Restore Point(s) –
2: 2008-08-01 02:39:36 UTC - RP2 - Deckard's System Scanner Restore Point
1: 2008-08-01 02:25:29 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as ________.exe) ——————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:02 PM, on 7/31/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Documents and Settings\________\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\______~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: {1fbbd642-76fb-6e4a-b4b4-b3d5ec59b76a} - {a67b95ce-5d3b-4b4b-a4e6-bf67246dbbf1} - C:\WINDOWS\system32\dpfrqt.dll
O2 - BHO: (no name) - {AE4BE19D-7DBA-4481-AE40-EE6BCDC6D8B6} - C:\WINDOWS\system32\wvUlJddb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [BM3bc63e31] Rundll32.exe "C:\WINDOWS\system32\gpavnpeh.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1216603637562
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 6911 bytes

– HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ———–

backup-20080731-193259-233 O4 - HKLM\..\Run: [38f50dad] rundll32.exe "C:\WINDOWS\system32\frpwcvax.dll",b
backup-20080731-193259-922 O4 - HKLM\..\Run: [BM3bc63e31] Rundll32.exe "C:\WINDOWS\system32\gpavnpeh.dll",s

– File Associations ———————————————————–

.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R3 L1e (Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller) - c:\windows\system32\drivers\l1e51x86.sys
Hello

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\WINDOWS\system32\frpwcvax.dll
    C:\WINDOWS\system32\dpfrqt.dll
    C:\WINDOWS\system32\cxwkllur.dll
    C:\WINDOWS\system32\gpavnpeh.dll
    C:\WINDOWS\system32\vfrcos.dll
    C:\WINDOWS\system32\dxppkpra.dll
    C:\WINDOWS\system32\lpqcoqqs.dll
    C:\WINDOWS\system32\voztak.dll
    C:\WINDOWS\system32\yelngeyt.dll
    C:\WINDOWS\system32\bddJlUvw.ini2
    C:\WINDOWS\system32\wvUlJddb.dll
    C:\WINDOWS\system32\spt
    C:\WINDOWS\system32\ex2
    C:\WINDOWS\system32\qoMefCtu.dll
    C:\WINDOWS\system32\kBin19
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dce5a68e-56c8-11dd-9481-001fc66e90ab}
    E:\CA_Install.exe
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Also post a new DSS log
Hello Rorschach112:

I think we made some major progress this time. Thank you so much. I still have a registry entry to deal with though - on the boot it is trying to load C:\windows\system32\gpavnpeh.dll which was on the list to terminate. One thing to note is that DSS only produced one log this time, no extra log. I ran it twice and both times it only gave me the main log, which again I edited - you will see "_____________" where I took out the company name. I think next time when I format the computer I will just use numbers so the company/computer can't be identified.

Malbytes log is showing that the files were quarantined and deleted but the program is showing them as quarantined and still sitting there, do I try to delete these? This program is awesome, is it freeware and can it be used on removeable disks? ie. flashdrives and CD's

Here are the logs:

OTMove It

Explorer killed successfully
DllUnregisterServer procedure not found in C:\WINDOWS\system32\frpwcvax.dll
C:\WINDOWS\system32\frpwcvax.dll NOT unregistered.
C:\WINDOWS\system32\frpwcvax.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\dpfrqt.dll
C:\WINDOWS\system32\dpfrqt.dll NOT unregistered.
C:\WINDOWS\system32\dpfrqt.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\cxwkllur.dll
C:\WINDOWS\system32\cxwkllur.dll NOT unregistered.
C:\WINDOWS\system32\cxwkllur.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\gpavnpeh.dll
C:\WINDOWS\system32\gpavnpeh.dll NOT unregistered.
C:\WINDOWS\system32\gpavnpeh.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vfrcos.dll
C:\WINDOWS\system32\vfrcos.dll NOT unregistered.
C:\WINDOWS\system32\vfrcos.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\dxppkpra.dll
C:\WINDOWS\system32\dxppkpra.dll NOT unregistered.
C:\WINDOWS\system32\dxppkpra.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\lpqcoqqs.dll
C:\WINDOWS\system32\lpqcoqqs.dll NOT unregistered.
C:\WINDOWS\system32\lpqcoqqs.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\voztak.dll
C:\WINDOWS\system32\voztak.dll NOT unregistered.
C:\WINDOWS\system32\voztak.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yelngeyt.dll
C:\WINDOWS\system32\yelngeyt.dll NOT unregistered.
C:\WINDOWS\system32\yelngeyt.dll moved successfully.
C:\WINDOWS\system32\bddJlUvw.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\wvUlJddb.dll
C:\WINDOWS\system32\wvUlJddb.dll NOT unregistered.
C:\WINDOWS\system32\wvUlJddb.dll moved successfully.
C:\WINDOWS\system32\spt moved successfully.
C:\WINDOWS\system32\ex2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\qoMefCtu.dll
C:\WINDOWS\system32\qoMefCtu.dll NOT unregistered.
C:\WINDOWS\system32\qoMefCtu.dll moved successfully.
C:\WINDOWS\system32\kBin19 moved successfully.
< HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dce5a68e-56c8-11dd-9481-001fc66e90ab} >
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dce5a68e-56c8-11dd-9481-001fc66e90ab}\\ deleted successfully.
File/Folder E:\CA_Install.exe not found.
< purity >
< EmptyTemp >
File delete failed. C:\DOCUME~1\________\LOCALS~1\Temp\~DFE407.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\_______\LOCALS~1\Temp\~DFF01D.tmp scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08012008_212644

Files moved on Reboot…
C:\DOCUME~1\_______\LOCALS~1\Temp\~DFE407.tmp moved successfully.
C:\DOCUME~1\_________\LOCALS~1\Temp\~DFF01D.tmp moved successfully.


Now Malwarebytes Log:

Malwarebytes' Anti-Malware 1.24
Database version: 1015
Windows 5.1.2600 Service Pack 3

9:49:23 PM 8/1/2008
mbam-log-8-1-2008 (21-49-23).txt

Scan type: Full Scan (C:\|)
Objects scanned: 71318
Time elapsed: 13 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 12
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a67b95ce-5d3b-4b4b-a4e6-bf67246dbbf1} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a67b95ce-5d3b-4b4b-a4e6-bf67246dbbf1} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpfrqt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM3bc63e31.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM3bc63e31.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

Here is the DSS log:

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-08-01 21:57:11
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as _______.exe) ——————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:57:22 PM, on 8/1/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Documents and Settings\__________\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\____________.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {4CA5E5E3-DE37-4D75-94E9-0CFC044FED5C} - C:\WINDOWS\system32\wvUlJddb.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [BM3bc63e31] Rundll32.exe "C:\WINDOWS\system32\gpavnpeh.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1216603637562
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 6858 bytes

– Files created between 2008-07-01 and 2008-08-01 —————————–

2008-08-01 21:31:31 0 d——– C:\Documents and Settings\_________\Application Data\Malwarebytes
2008-08-01 21:31:26 0 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-01 21:31:26 0 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\Templates
2008-07-31 19:35:12 0 dr——- C:\Documents and Settings\Administrator\Start Menu
2008-07-31 19:35:12 0 dr-h—– C:\Documents and Settings\Administrator\SendTo
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\Recent
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\PrintHood
2008-07-31 19:35:12 786432 –ah—– C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\NetHood
2008-07-31 19:35:12 0 d——– C:\Documents and Settings\Administrator\My Documents
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\Local Settings
2008-07-31 19:35:12 0 d——– C:\Documents and Settings\Administrator\Favorites
2008-07-31 19:35:12 0 d——– C:\Documents and Settings\Administrator\Desktop
2008-07-31 19:35:12 0 d–hs—- C:\Documents and Settings\Administrator\Cookies
2008-07-31 19:35:12 0 dr-h—– C:\Documents and Settings\Administrator\Application Data
2008-07-31 19:35:12 0 d—s—- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-31 12:48:01 0 d——– C:\___________________ Aug 01
2008-07-31 00:38:13 0 d——– C:\Program Files\Trend Micro
2008-07-31 00:13:33 0 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-07-30 23:35:41 0 d——– C:\Program Files\Lavasoft
2008-07-30 23:32:56 0 d——– C:\WINDOWS\system32\appmgmt
2008-07-30 22:48:00 0 d——– C:\VundoFix Backups
2008-07-30 11:29:22 0 d——– C:\_______________
2008-07-22 20:40:00 0 d——– C:\Forms
2008-07-22 20:39:51 0 d——– C:\Notes
2008-07-22 20:39:13 0 d——– C:\Brochures
2008-07-22 20:38:53 0 d——– C:\Manual
2008-07-22 20:37:42 0 d——– C:\Stuff
2008-07-22 20:23:07 0 d——– C:\FILE
2008-07-22 20:22:56 0 d——– C:\Out
2008-07-22 20:22:48 0 d——– C:\In
2008-07-22 20:22:42 0 d——– C:\_______Stuff
2008-07-22 20:18:53 0 d——– C:\WINDOWS\system32\NtmsData
2008-07-22 20:15:10 0 d——– C:\Visit
2008-07-22 20:15:10 0 d——– C:\Visits
2008-07-22 20:14:56 0 d——– C:\Invoice Template
2008-07-22 19:42:34 0 d–h—– C:\WINDOWS\PIF
2008-07-22 19:42:32 41504 –a—— C:\WINDOWS\system32\remote.exe
2008-07-22 19:42:32 0 d——– C:\WINDOWS\Profiles
2008-07-22 19:42:28 250128 –a—— C:\WINDOWS\system32\MSPDOX35.DLL
Yes its freeware, not sure about the USB question

Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe



Now we need to fix your problems by making a .reg file. Copy the code below into a Notepad file. Name the file as fix.reg, change the "Save as Type" to "All files" and save it on the desktop.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,\
00


Then double click on the fix.reg file, when it prompts to merge click "Yes".




1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {4CA5E5E3-DE37-4D75-94E9-0CFC044FED5C} - C:\WINDOWS\system32\wvUlJddb.dll (file missing)
O4 - HKLM\..\Run: [BM3bc63e31] Rundll32.exe "C:\WINDOWS\system32\gpavnpeh.dll",s


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




Reboot and do this


Please do an online scan with Kaspersky WebScanner

Make sure you are using Internet Explorer for this. Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


Also post a new DSS log
Hello Again:

It looks like things are still infected, I had hoped that it would only take a few regedits today and all would be good, apparently not. After some fiddling I figured out that Malabytes Malware will scan flash drives and CD's - you just have to have a disk in the drive, or flashdrive in the USB port when you start up the program. It will ask you what drives to scan.

Since this is a work computer, are we at the give up the chase and reformat stage? I would like to continue on because if I have to reformat I would like to know that what I am saving from the computer is clean so it won't reinfect the clean format when I put it back. I really haven't figured out what has infected this computer so I don't know how it was compromised so would a reformat be required at some point regardless?

Thanks so much again for your help…I build and format computers and do simple virus and spyware removal but I can't do anything like this, so you definitely have talents that are being used correctly.

Here are the scans:

Hi-Jack this - those entries were still there and "fixed"

Kaspersky On-line Scan
——————————————————————————
KASPERSKY ONLINE SCANNER REPORT
August 02, 2008 4:47:41 PM
Operating System: Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 2/08/2008
Kaspersky Anti-Virus database records: 1045039
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
Z:\

Scan Statistics:
Total number of scanned objects: 40187
Number of viruses found: 6
Number of infected objects: 14
Number of suspicious objects: 0
Duration of the scan process: 00:32:11

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\_______\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\_______\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\________\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\_________\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\_________\Local Settings\Temp\~DFDCEF.tmp Object is locked skipped
C:\Documents and Settings\_________\Local Settings\Temp\~DFE064.tmp Object is locked skipped
C:\Documents and Settings\_________\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\_________\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\_________\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Downloads\crossloopsetup.exe/file057 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.h skipped
C:\Downloads\crossloopsetup.exe/file058 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\Downloads\crossloopsetup.exe Inno: infected - 2 skipped
C:\Program Files\CrossLoop\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\Program Files\CrossLoop\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.h skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{8E51CFD7-F623-4625-A230-C1C1FE5665AA}\RP3\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\awtsQKeE.dll.vir Infected: Trojan.Win32.Monderb.agl skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\_OTMoveIt\MovedFiles\08012008_212644\WINDOWS\system32\cxwkllur.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.byt skipped
C:\_OTMoveIt\MovedFiles\08012008_212644\WINDOWS\system32\dpfrqt.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.byt skipped
C:\_OTMoveIt\MovedFiles\08012008_212644\WINDOWS\system32\dxppkpra.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bwk skipped
C:\_OTMoveIt\MovedFiles\08012008_212644\WINDOWS\system32\frpwcvax.dll Infected: Trojan.Win32.Monder.brq skipped
C:\_OTMoveIt\MovedFiles\08012008_212644\WINDOWS\system32\qoMefCtu.dll Infected: Trojan.Win32.Monderb.agl skipped
C:\_OTMoveIt\MovedFiles\08012008_212644\WINDOWS\system32\vfrcos.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bwk skipped
C:\_OTMoveIt\MovedFiles\08012008_212644\WINDOWS\system32\voztak.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bwk skipped
C:\_OTMoveIt\MovedFiles\08012008_212644\WINDOWS\system32\yelngeyt.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.bwk skipped

Scan process completed.


DSS Scan
Deckard's System Scanner v20071014.68
Run by [removed] on 2008-08-02 16:50:11
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as- _________.exe) ——————————————-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:50:23 PM, on 8/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Documents and Settings\_________\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\___________~1.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/ka…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1216603637562
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 6742 bytes

– Files created between 2008-07-02 and 2008-08-02 —————————–

2008-08-02 15:40:58 0 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-08-02 15:40:57 0 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-08-02 15:40:55 0 d——– C:\WINDOWS\LastGood
2008-08-01 21:31:31 0 d——– C:\Documents and Settings\______________\Application Data\Malwarebytes
2008-08-01 21:31:26 0 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-01 21:31:26 0 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\Templates
2008-07-31 19:35:12 0 dr——- C:\Documents and Settings\Administrator\Start Menu
2008-07-31 19:35:12 0 dr-h—– C:\Documents and Settings\Administrator\SendTo
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\Recent
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\PrintHood
2008-07-31 19:35:12 786432 –ah—– C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\NetHood
2008-07-31 19:35:12 0 d——– C:\Documents and Settings\Administrator\My Documents
2008-07-31 19:35:12 0 d–h—– C:\Documents and Settings\Administrator\Local Settings
2008-07-31 19:35:12 0 d——– C:\Documents and Settings\Administrator\Favorites
2008-07-31 19:35:12 0 d——– C:\Documents and Settings\Administrator\Desktop
2008-07-31 19:35:12 0 d–hs—- C:\Documents and Settings\Administrator\Cookies
2008-07-31 19:35:12 0 dr-h—– C:\Documents and Settings\Administrator\Application Data
2008-07-31 19:35:12 0 d—s—- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-31 12:48:01 0 d——– C:\new Program _____Plus Aug 01
2008-07-31 00:38:13 0 d——– C:\Program Files\Trend Micro
2008-07-31 00:13:33 0 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-07-30 23:35:41 0 d——– C:\Program Files\Lavasoft
2008-07-30 23:32:56 0 d——– C:\WINDOWS\system32\appmgmt
2008-07-30 11:29:22 0 d——– C:\____________Plus
2008-07-22 20:40:00 0 d——– C:\Forms
2008-07-22 20:39:51 0 d——– C:\Forms 2
2008-07-22 20:39:13 0 d——– C:\Brochures
2008-07-22 20:38:53 0 d——– C:\Manual
2008-07-22 20:37:42 0 d——– C:\She's Stuff
2008-07-22 20:23:07 0 d——– C:\_________
2008-07-22 20:22:56 0 d——– C:\Out
2008-07-22 20:22:48 0 d——– C:\In
2008-07-22 20:22:42 0 d——– C:\Stuff
2008-07-22 20:18:53 0 d——– C:\WINDOWS\system32\NtmsData
2008-07-22 20:15:10 0 d——– C:\Visit
2008-07-22 20:15:10 0 d——– C:\Visits
2008-07-22 20:14:56 0 d——– C:\Invoice Template
2008-07-22 19:42:34 0 d–h—– C:\WINDOWS\PIF
2008-07-22 19:42:32 41504 –a—— C:\WINDOWS\system32\remote.exe
2008-07-22 19:42:32 0 d——– C:\WINDOWS\Profiles
2008-07-22 19:42:28 250128 –a—— C:\WINDOWS\system32\MSPDOX35.DLL
We are nearly done

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\WINDOWS\system32\awtsQKeE.dll.vir
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Please download DirLook by jpshortstuff from here.
  • Double-click DirLook.exe to run it.
  • Ensure that Show Hidden Files/Folders and BBCode Ouput are both checked.
  • Copy the content of the following codebox into the main textfield:

    C:\Downloads
  • Click the DirLook button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply. (Note: The log can also be found at C:\dl_log.txt)
Note: Scanning may take longer for large folders.
Hello:

You didn't ask for any system scans this time. Here are the two logs you wanted though. I again edited the name out of the files. FYI the contents of C:\Downloads is where I put the back-ups of the business software programs and files brought from the old computer when I did the format when the computer was built. I edited the names of the programs from the file name for privacy .

Explorer killed successfully
C:\WINDOWS\system32\awtsQKeE.dll.vir moved successfully.
< purity >
< EmptyTemp >
File delete failed. C:\DOCUME~1\______~1\LOCALS~1\Temp\~DFED2D.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\_______~1\LOCALS~1\Temp\~DFF80C.tmp scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08032008_124133

Files moved on Reboot…
C:\DOCUME~1\_______~1\LOCALS~1\Temp\~DFED2D.tmp moved successfully.
C:\DOCUME~1\________~1\LOCALS~1\Temp\~DFF80C.tmp moved successfully.


DirLook Scan
DirLook.exe by jpshortstuff
Log created at 12:59:41 on Sun 08/03/2008

==============================

Contents of "C:\Downloads" (inc. hidden/system files/folders)

—FOLDERS—

Office 2003 Updates (created: 07/20/2008 05:21 PM) d——–

—FILES—

aaw2008.exe (19153264 bytes, created: 07/20/2008 08:20 PM) –a——
______ Backup.zip (46789631 bytes, created: 07/12/2006 08:29 PM) –a——
_______July 22.zip (82020955 bytes, created: 07/22/2008 06:10 PM) –a——
________Full July 20.zip (58146757 bytes, created: 07/20/2008 08:56 PM) –a——
crossloopsetup.exe (2492688 bytes, created: 07/20/2008 08:42 PM) –a——
_________.zip (439385670 bytes, created: 07/22/2008 05:56 PM) –a——
HJTInstall.exe (812344 bytes, created: 07/31/2008 12:36 AM) –a——
mbam-setup.exe (1885120 bytes, created: 08/01/2008 07:38 PM) –a——
Saturn Desktop.jpg (547857 bytes, created: 09/22/2006 12:44 AM) –a——
skysong2.jpg (128279 bytes, created: 10/31/2007 09:40 PM) –a——
wg111t_2_1_setup.exe (9755457 bytes, created: 06/29/2008 05:34 PM) –a——
Windows XP Service Pack 3.exe (331805736 bytes, created: 05/29/2008 10:26 PM) –a——
Windows XP SP2.exe (278927592 bytes, created: 08/12/2004 11:02 PM) –a——

==============================

=EOF=
Your logs are clean

  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it.
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.
Hello: I will do what you said in the last post but I wanted to quickly point out that there are viruses showing still from the Kaspersky scan that you ask me to do yesterday. Just curious about that… Just finished doing the last things you said and went to the Kaspersky on-line scan and it is still showing viruses and infected files…. Please help, I don't think we're done yet. Thanks, MsCoy
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI