This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Vundo's

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I did malware bytes scan thsi is log:

Malwarebytes' Anti-Malware 1.24
Database version: 1027
Windows 5.1.2600 Service Pack 3

11:19:52 PM 8/5/2008
mbam-log-8-5-2008 (23-19-52).txt

Scan type: Quick Scan
Objects scanned: 39192
Time elapsed: 3 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 4
Registry Keys Infected: 14
Registry Values Infected: 3
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 16

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\ljJYOebY.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\tcpwgloc.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\fihdjmjr.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\geBtRlJc.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{0dc51afb-4a64-4075-8b74-adba596eb186} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{0dc51afb-4a64-4075-8b74-adba596eb186} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{28c1eefb-dd85-4227-bc29-c17d7366b27d} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{28c1eefb-dd85-4227-bc29-c17d7366b27d} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebtrljc (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brows er Helper Objects\{4206be9e-966b-4ced-bd16-ad36eb80ae34} (Trojan.BHO) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{4206be9e-966b-4ced-bd16-ad36eb80ae34} (Trojan.BHO) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\648e2693 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm67bd150f (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell ExecuteHooks\{28c1eefb-dd85-4227-bc29-c17d7366b27d} (Trojan.Vundo) -> Delete on reboot.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\ljjyoeby -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ljjyoeby -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\ljJYOebY.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\YbeOYJjl.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\YbeOYJjl.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ikchebwj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jwbehcki.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tcpwgloc.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\colgwpct.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fihdjmjr.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\geBtRlJc.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\lafokune.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\uxeswacy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Junoon\Local Settings\Temporary Internet Files\Content.IE5\324D8DLW\kb671231[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Junoon\Local Settings\Temporary Internet Files\Content.IE5\PKCMQEWD\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM67bd150f.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM67bd150f.txt (Trojan.Vundo) -> Quarantined and deleted successfully.





This is my my new hijackthis log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:40:10 PM, on 8/5/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BitDefender\bdagent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamtrayctrl.exe
C:\Program Files\BitDefender\seccenter.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\System32\svchost.exe
D:\Usman\Appz\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.internetdownloadmanager.com/welcome.html
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {4206BE9E-966B-4CED-BD16-AD36EB80AE34} - C:\WINDOWS\system32\lafokune.dll (file missing)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\IEToolbar.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\bdagent.exe"
O4 - HKLM\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s
O4 - HKUS\S-1-5-19\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\febobafi.dll
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

–
End of file - 4043 bytes
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • Save and quit any work your doing before beginning the fix.
  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!


Looks as if Malwarebytes has gotten Vundo under control.
Although there is more to do.



______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O2 - BHO: (no name) - {4206BE9E-966B-4CED-BD16-AD36EB80AE34} - C:\WINDOWS\system32\lafokune.dll (file missing)


O4 - HKLM\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s
O4 - HKUS\S-1-5-19\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s (User 'NETWORK SERVICE')

Close that.




_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste this filepath in there.
If theres is more than one file to scan, insert them 1 at a time.


C:\WINDOWS\system32\febobafi.dll


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html






__________________________
Deckard's System Scanner
Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post. in your reply




_________________________
In your next reply I would like to see:
  • The report from Jottis/Virus total
  • The report from Deckards system scanner
ok i faced some prbs..

hijack ddin fix hem:, heres he log again if u need it:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:03:05 AM, on 8/8/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamtrayctrl.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BitDefender\bdagent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\taskmgr.exe
D:\Usman\Appz\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.internetdownloadmanager.com/welcome.html
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {4206BE9E-966B-4CED-BD16-AD36EB80AE34} - C:\WINDOWS\system32\lafokune.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\IEToolbar.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\bdagent.exe"
O4 - HKLM\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\febobafi.dll
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

–
End of file - 5362 bytes


scan result of file:

Scan taken on 07 Aug 2008 21:51:41 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found DLOADER.Trojan (probable variant)
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing


and dss failed to scan, it stucked while scanning registry
1st.
Is this your post ??

http://forums.techguy.org/malware-removal-…mabe-vundo.html

If so please let them know your recieving help here.


_____________________________________



1. Download Combo fix from one of these locations.
* IMPORTANT !!! Place combofix.exe on your Desktop

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTHING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt



_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
i didnt find combofix.txt after scan but found bug.txt instead: PUSHD "C:\327882R2FWJFW\" IF NOT EXIST C:\WINDOWS\system32\cmd.exe GOTO Not_NT VER | FIND.exe "Microsoft Windows [Version 5.2.3790]" 1>nul IF NOT ERRORLEVEL 1 GOTO Not_NT VER | FIND.exe "Windows XP" 1>nul PV -o"%i\t%l" | SED "/\t.*\\nircmd\.inf$/!d; s///; s/./@pv -kfi &/" 1>temp00.bat CALL temp00.bat Killing '624' "C:\WINDOWS\System32\rundll32.exe" setupapi,InstallHinfSection DefaultInstall 132 C:\327882R2FWJFW\nircmd.inf (624) DEL temp00.bat 2>nul ============================================= ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Junoon\Application Data CFLDR=327882R2FWJFW CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=JUNOON ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Junoon KMD=CF9695.exe LOGONSERVER=\\JUNOON NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\327882R2FWJFW;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Intel\DMIX PATHEXT=.cfexe;.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 10, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=040a ProgramFiles=C:\Program Files PROMPT=$ SESSIONNAME=Console sfxname=C:\Documents and Settings\Junoon\desktop\combofix.exe SYSTEM=C:\WINDOWS\system32 SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Junoon\LOCALS~1\Temp TMP=C:\DOCUME~1\Junoon\LOCALS~1\Temp USERDOMAIN=JUNOON USERNAME=Junoon USERPROFILE=C:\Documents and Settings\Junoon windir=C:\WINDOWS ============================================= IF NOT DEFINED sfxname GOTO END IF /I "C:\327882R2FWJFW" NEQ "C:\327882R2FWJFW" GOTO Abort IF EXIST "C:\DOCUME~1\Junoon\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" DEL "C:\DOCUME~1\Junoon\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" SteelWerX Extended Configuration Access Control Lists Written by Bobbi Flekman 2006 © Ownerchange for "C:\WINDOWS\system32\cmd.exe" to Administrators group was successful COPY /y "C:\WINDOWS\system32\cmd.exe" "C:\WINDOWS\system32\CF9695.exe" 1 file(s) copied. ( SET "FileName=ComboFix" SET "FilePath=C:\Documents and Settings\Junoon\Desktop\" ) SET FileName 1>FileName 2>nul GREP -isqx "FileName=[-[:alnum:]@.]*" FileName || ( Nircmd infobox "You cannot rename ComboFix as ComboFix~n~nPlease use another name, preferbaly made up of alphanumeric characters" "" GOTO END ) DIR /ad/b C:\* | Findstr -IVX ComboFix 1>dirname00
______________________________
RUN HJT

HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked



O2 - BHO: (no name) - {4206BE9E-966B-4CED-BD16-AD36EB80AE34} - C:\WINDOWS\system32\lafokune.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s
O4 - HKUS\S-1-5-19\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s (User 'NETWORK SERVICE')

Close that.





_____________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste this filepath in there.
If theres is more than one file to scan, insert them 1 at a time.


C:\WINDOWS\system32\febobafi.dll


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

_____________________________-

Please post a new HJT log
The report from Jottis/ Virus total
___________________________________
Safe mode:
Please reboot to safe mode:
After the very first black screen start tapping the
F8 key untill prompted with a list…. choose safe
mode.

______________________________

Try running combofix from there as described.




2. Click start/run and copy and Paste this in exactly using the picture below for reference:

"%userprofile%\desktop\combofix.exe" /killall


[external image: Posted Image]

3. Combo will begin to run DO NOTHING while this is happeneing.
  • It will kill a few processes and disconnect you from the internet.
  • If by chance it stops prematurly you can re-establish your internet connection by restarting your computer.
  • This needs to be done so the program can work most efficiently for you.
Do not attempt to use the internet or anything else while it's doing its job for you.

If when it's completed you can not get on the internet just reboot the computer

Post the log from comboFix for me located in
c:\comboFix.txt
this is the log after fixing from HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:12:01 PM, on 8/8/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamtrayctrl.exe
C:\WINDOWS\sttray.exe
C:\Program Files\BitDefender\bdagent.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.internetdownloadmanager.com/welcome.html
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: (no name) - {4206BE9E-966B-4CED-BD16-AD36EB80AE34} - C:\WINDOWS\system32\lafokune.dll (file missing)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\IEToolbar.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\bdagent.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [pekohopati] Rundll32.exe "C:\WINDOWS\system32\nugedoka.dll",s
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\febobafi.dll
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

–
End of file - 5022 bytes


Scan taken on 08 Aug 2008 13:11:19 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found DLOADER.Trojan (probable variant)
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
Mr bob4 I dont think anything is working here, like again when i ran combofix, the "loading" small size window came and after that i wait 15min but nothing was there, jus a bug.txt in c: well here is ha bug.txt: PUSHD "C:\327882R2FWJFW\" IF NOT EXIST C:\WINDOWS\system32\cmd.exe GOTO Not_NT VER | FIND.exe "Microsoft Windows [Version 5.2.3790]" 1>nul IF NOT ERRORLEVEL 1 GOTO Not_NT VER | FIND.exe "Windows XP" 1>nul PV -o"%i\t%l" | SED "/\t.*\\nircmd\.inf$/!d; s///; s/./@pv -kfi &/" 1>temp00.bat CALL temp00.bat DEL temp00.bat 2>nul ============================================= ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Junoon\Application Data CFLDR=327882R2FWJFW CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=JUNOON ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Junoon KMD=CF5483.exe LOGONSERVER=\\JUNOON NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\327882R2FWJFW;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\Intel\DMIX PATHEXT=.cfexe;.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 10, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=040a ProgramFiles=C:\Program Files PROMPT=$ SESSIONNAME=Console sfxname=C:\Documents and Settings\Junoon\desktop\combofix.exe SYSTEM=C:\WINDOWS\system32 SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Junoon\LOCALS~1\Temp TMP=C:\DOCUME~1\Junoon\LOCALS~1\Temp USERDOMAIN=JUNOON USERNAME=Junoon USERPROFILE=C:\Documents and Settings\Junoon windir=C:\WINDOWS ============================================= IF NOT DEFINED sfxname GOTO END IF /I "C:\327882R2FWJFW" NEQ "C:\327882R2FWJFW" GOTO Abort IF EXIST "C:\DOCUME~1\Junoon\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" DEL "C:\DOCUME~1\Junoon\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" SteelWerX Extended Configuration Access Control Lists Written by Bobbi Flekman 2006 © Ownerchange for "C:\WINDOWS\system32\cmd.exe" to Administrators group was successful COPY /y "C:\WINDOWS\system32\cmd.exe" "C:\WINDOWS\system32\CF5483.exe" 1 file(s) copied. ( SET "FileName=ComboFix" SET "FilePath=C:\Documents and Settings\Junoon\Desktop\" ) SET FileName 1>FileName 2>nul GREP -isqx "FileName=[-[:alnum:]@.]*" FileName || ( Nircmd infobox "You cannot rename ComboFix as ComboFix~n~nPlease use another name, preferbaly made up of alphanumeric characters" "" GOTO END ) DIR /ad/b C:\* | Findstr -IVX ComboFix 1>dirname00 Findstr -LIXC:"ComboFix" dirname00 1>nul && call :NameChk
OK.
One last attempt then I will contact the developer of the tool. He will want to know we have ran into a glitch.


Please delete combofix from the desktop.
We are going to just try double clicking it to run it.
Please grab a new copy first.




Download ComboFix

Download ComboFix file from one of the three below listed places :


Link1
Link2
Link3

combofix.exe

2.Close all open windows
3. Double click combofix.exe & follow the prompts.
4. When finished, it shall produce a log for you. Post that log in your next reply . (c:\comboFix.txt)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combo fix in order to be effecient is going to disconect you from the internet. If when it is done and you can't get back on the internet just restart the computer.

______________________________

Let me know what happens.
same thing happened, small window came and then nothing. Although i see in processes, even after 5hrs findstr.exe is still running, its from combofix right.
I have contacted SuBs, the maker of combofix.

Please
1. delete combofix from the desktop
2. reboot the machine

3. download and try running it again. He is looking into our issue.

Link1
Link2
Link3

EDIT Just so you know there are new versions coming out quite often. :thumbup:
u guyz r genius, this one worked and made a log atlast:

ComboFix 08-08-09.03 - Junoon 2008-08-10 12:45:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.686 [GMT 4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
C:\WINDOWS\system32\febobafi.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

http://hqvideoporn.com
.
((((((((((((((((((((((((( Files Created from 2008-07-10 to 2008-08-10 )))))))))))))))))))))))))))))))
.

2008-08-10 00:27 . 2008-08-10 00:29 d——– C:\Program Files\Super_DVD_Creator_9.5
2008-08-09 23:32 . 2008-08-09 23:32 43,698 –a—— C:\WINDOWS\system32\xvid-uninstall.exe
2008-08-09 02:57 . 2008-08-09 21:03 d——– C:\Program Files\HD Tune Pro
2008-08-08 17:31 . 2008-08-09 14:27 d——– C:\327882R2FWJFW(2)
2008-08-08 17:28 . 2008-08-09 14:27 d——– C:\ComboFix(2)
2008-08-08 03:40 . 2008-08-08 03:40 d–h—– C:\WINDOWS\$hf_mig$
2008-08-08 03:39 . 2008-08-08 03:39 d——– C:\WINDOWS\%DownloadedProgramFiles%
2008-08-08 03:39 . 2006-05-25 10:29 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-08-08 03:38 . 2006-07-27 13:52 367 –a—— C:\WINDOWS\system32\LegitCheckControl.inf
2008-08-08 03:11 . 2008-08-08 03:11 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-08-08 03:07 . 2008-08-08 03:07 d——– C:\Program Files\Radmin.V3.0
2008-08-08 01:52 . 2008-08-08 01:52 d——– C:\Deckard
2008-08-08 01:30 . 2008-08-08 03:07 d—s—- C:\Documents and Settings\Junoon\UserData
2008-08-08 00:44 . 2008-08-08 03:07 d——– C:\Documents and Settings\Junoon\Contacts
2008-08-08 00:33 . 2008-08-08 00:33 d——– C:\Program Files\Windows Live
2008-08-07 18:41 . 2008-08-07 18:41 d——– C:\Documents and Settings\Junoon\Application Data\BitSpirit
2008-08-07 17:29 . 2008-08-08 03:07 d——– C:\Program Files\RadminV3.0
2008-08-07 12:26 . 2008-08-08 03:07 d——– C:\Program Files\Easy Video Splitter
2008-08-07 10:18 . 2008-08-08 03:07 d–h—– C:\Documents and Settings\Junoon\Recent(2)
2008-08-07 07:11 . 2008-07-04 10:34 860,160 –a—— C:\WINDOWS\system32\is-1FN2L.tmp
2008-08-07 07:11 . 2008-08-07 07:11 823,296 –a—— C:\WINDOWS\isRS-000.tmp
2008-08-07 07:09 . 2008-08-07 07:09 d——– C:\Documents and Settings\Junoon\Application Data\vlc
2008-08-07 07:07 . 2008-08-10 01:08 d——– C:\Program Files\VLC
2008-08-06 18:44 . 2008-08-09 23:31 d——– C:\Program Files\AviSynth 2.5
2008-08-06 18:43 . 2008-08-06 18:43 d——– C:\Program Files\Gabest
2008-08-06 18:42 . 2008-08-09 23:32 d——– C:\Program Files\AutoGK
2008-08-06 13:27 . 2008-08-10 12:34 49 –a—— C:\WINDOWS\NeroDigital.ini
2008-08-06 13:23 . 2008-08-06 13:23 d——– C:\VundoFix Backups
2008-08-06 12:25 . 2008-08-06 12:25 d——– C:\Documents and Settings\Junoon\Application Data\Ahead
2008-08-06 12:18 . 2008-08-06 12:25 d——– C:\Program Files\Common Files\Ahead
2008-08-06 11:38 . 2008-08-06 11:38 398,848 –a—— C:\WINDOWS\system32\keygen.exe
2008-08-06 11:33 . 2008-08-06 11:33 d——– C:\WINDOWS\system32\LogFiles
2008-08-06 05:51 . 2008-08-06 11:38 21,690,872 –a—— C:\WINDOWS\system32\nero-8.3.2.1_english_micro.exe
2008-08-05 20:25 . 2008-08-05 20:25 2,048 –a—— C:\WINDOWS\system32\bjlnctsd.exe
2008-08-05 20:23 . 2008-08-05 20:25 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-05 20:23 . 2008-08-05 20:23 d——– C:\Documents and Settings\Junoon\Application Data\Malwarebytes
2008-08-05 20:23 . 2008-08-05 20:23 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-05 20:23 . 2008-07-30 20:07 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-05 20:23 . 2008-07-30 20:07 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-05 20:22 . 2008-08-05 20:22 61,952 –a—— C:\WINDOWS\system32\ngqgwqmc.dll
2008-08-05 20:20 . 2008-04-14 00:15 26,368 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-05 18:24 . 2008-08-05 18:24 d——– C:\Documents and Settings\Junoon\Application Data\Radmin
2008-08-05 17:31 . 2008-08-05 17:31 d——– C:\Documents and Settings\Junoon\Application Data\Nero
2008-08-05 13:43 . 2008-08-05 13:43 d——– C:\Documents and Settings\Junoon\Application Data\Media Player Classic
2008-08-05 13:34 . 2008-08-05 13:34 d——– C:\Program Files\WordWeb
2008-08-05 13:34 . 2008-06-14 14:17 1,049,272 ——— C:\WINDOWS\wweb32.dll
2008-08-05 13:33 . 2008-08-05 13:33 d——– C:\Program Files\dayam NFO Viewer
2008-08-05 13:32 . 2008-08-08 03:06 d——– C:\Program Files\BitSpirit
2008-08-05 13:30 . 2008-08-08 03:07 d——– C:\Program Files\K-Lite Codec Pack
2008-08-05 13:29 . 2008-08-05 13:29 d——– C:\Program Files\Real Alternative
2008-08-05 13:17 . 2008-08-10 09:05 d——– C:\Program Files\Internet Download Manager
2008-08-05 13:17 . 2008-08-08 03:27 d——– C:\Documents and Settings\Junoon\Application Data\IDM
2008-08-05 13:17 . 2008-08-10 12:42 d——– C:\Documents and Settings\Junoon\Application Data\DMCache
2008-08-05 13:07 . 2008-08-09 14:12 d——– C:\Program Files\uTorrent
2008-08-05 13:07 . 2008-08-10 12:16 d——– C:\Documents and Settings\Junoon\Application Data\utorrent
2008-08-05 13:07 . 2008-08-05 13:07 d——– C:\Documents and Settings\Junoon\Application Data\12Voip
2008-08-05 13:05 . 2008-08-05 13:05 0 –a—— C:\WINDOWS\nsreg.dat
2008-08-05 11:58 . 2004-08-04 15:00 605,696 –a—— C:\WINDOWS\system32\getuname.dll
2008-08-05 11:57 . 2008-08-05 11:59 d——– C:\WINDOWS\system32\MsDtc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-10 08:48 81,984 —-a-w C:\WINDOWS\system32\bdod.bin
2008-08-10 08:33 ——— d—–w C:\Program Files\BitDefender
2008-08-06 08:18 ——— d—–w C:\Program Files\Nero
2008-08-06 08:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-06 08:01 ——— d—–w C:\Program Files\Common Files\Nero
2008-08-05 08:52 86,792 —-a-w C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-08-05 08:43 ——— d—–w C:\Documents and Settings\Junoon\Application Data\BitDefender
2008-08-05 08:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-08-05 08:42 ——— d—–w C:\Program Files\Common Files\BitDefender
2008-08-05 08:18 ——— d—–w C:\Program Files\SigmaTel
2008-08-05 08:17 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-05 08:17 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-08-05 08:16 ——— d—–w C:\Program Files\Intel
2008-08-05 08:12 ——— d—–w C:\Program Files\MSXML 4.0
2008-08-05 08:05 ——— d—–w C:\Program Files\microsoft frontpage
2008-06-12 18:36 7,680 —-a-w C:\WINDOWS\system32\ff_vfw.dll
2008-05-30 23:22 683,520 —-a-w C:\WINDOWS\system32\divx.dll
2008-05-22 22:22 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:19 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
2008-05-05 16:22 61,952 –sha-w C:\WINDOWS\system32\nugedoka.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 09:26 7700480]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 09:26 86016]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\IEShow.exe" [2007-10-09 15:46 61440]
"BDAgent"="C:\Program Files\BitDefender\bdagent.exe" [2008-08-05 12:51 368640]
"pekohopati"="C:\WINDOWS\system32\nugedoka.dll" [2008-05-05 20:22 61952]
"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 18:58 282624 C:\WINDOWS\sttray.exe]
"nwiz"="nwiz.exe" [2007-04-19 09:26 1626112 C:\WINDOWS\system32\nwiz.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\febobafi.dll
"LoadAppInit_DLLs"=1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli C:\WINDOWS\system32\febobafi.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\logonui.exe"=
"C:\\WINDOWS\\system32\\winlogon.exe"=
"C:\\Program Files\\Common Files\\BitDefender\\BitDefender Update Service\\livesrv.exe"=
"C:\\WINDOWS\\system32\\spoolsv.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\lsass.exe"=
"C:\\WINDOWS\\system32\\services.exe"=
"C:\\Program Files\\BitDefender\\vsserv.exe"=
"C:\\WINDOWS\\system32\\taskmgr.exe"=
"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMIndexStoreSvr.exe"=

R2 MBAMDrvService;MBAMDrvService;C:\WINDOWS\system32\drivers\mbam.sys [2008-07-30 20:07]
R2 MBAMService;MBAMService;C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2008-07-30 20:07]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-08-05 12:52]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -

BHO-{4206BE9E-966B-4CED-BD16-AD36EB80AE34} - C:\WINDOWS\system32\lafokune.dll


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Junoon\Application Data\Mozilla\Firefox\Profiles\ohrkcacj.default\


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-10 12:48:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\febobafi.dll

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\febobafi.dll
.
Completion time: 2008-08-10 12:53:17
ComboFix-quarantined-files.txt 2008-08-10 08:52:56

Pre-Run: 21,607,333,888 bytes free
Post-Run: 21,616,271,360 bytes free

174
The creator of the fix is pretty amazing at times.





________________________________________
Open notepad and copy/paste the text in the code box below into it:

http://forums.whatthetech.com/Vundos_t94249.html#entry479262

File:: 
C:\WINDOWS\system32\bjlnctsd.exe
C:\WINDOWS\system32\keygen.exe
C:\WINDOWS\system32\ngqgwqmc.dll
C:\WINDOWS\system32\nugedoka.dll
C:\WINDOWS\isRS-000.tmp
C:\WINDOWS\system32\is-1FN2L.tmp
Collect::
C:\WINDOWS\system32\febobafi.dll

Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe


**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions to copy/paste/send the requested file.



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.



+++++++++++++++++++++++++++++++++++++++++

Please post the C:\ComboFix.txt along with a new HijackThis log for further review.
When it finished it didnt open any browser or any window for sending files :mellow:

ComboFix 08-08-10.02 - Junoon 2008-08-11 9:23:06.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.658 [GMT 4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Junoon\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\isRS-000.tmp
C:\WINDOWS\system32\bjlnctsd.exe
C:\WINDOWS\system32\is-1FN2L.tmp
C:\WINDOWS\system32\keygen.exe
C:\WINDOWS\system32\ngqgwqmc.dll
C:\WINDOWS\system32\nugedoka.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\WINDOWS\isRS-000.tmp
C:\WINDOWS\system32\bjlnctsd.exe
C:\WINDOWS\system32\is-1FN2L.tmp
C:\WINDOWS\system32\keygen.exe
C:\WINDOWS\system32\ngqgwqmc.dll
C:\WINDOWS\system32\nugedoka.dll

.
((((((((((((((((((((((((( Files Created from 2008-07-11 to 2008-08-11 )))))))))))))))))))))))))))))))
.

2008-08-10 18:24 . 2008-08-10 18:24 d——– C:\Program Files\Google
2008-08-10 18:18 . 2008-08-10 18:18 d——– C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-08-10 18:17 . 2008-08-10 18:17 d——– C:\Program Files\Yahoo!
2008-08-10 00:27 . 2008-08-10 00:29 d——– C:\Program Files\Super_DVD_Creator_9.5
2008-08-09 23:32 . 2008-08-09 23:32 43,698 –a—— C:\WINDOWS\system32\xvid-uninstall.exe
2008-08-09 02:57 . 2008-08-09 21:03 d——– C:\Program Files\HD Tune Pro
2008-08-08 17:31 . 2008-08-09 14:27 d——– C:\327882R2FWJFW(2)
2008-08-08 17:28 . 2008-08-09 14:27 d——– C:\ComboFix(2)
2008-08-08 03:40 . 2008-08-08 03:40 d–h—– C:\WINDOWS\$hf_mig$
2008-08-08 03:39 . 2008-08-08 03:39 d——– C:\WINDOWS\%DownloadedProgramFiles%
2008-08-08 03:39 . 2006-05-25 10:29 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-08-08 03:38 . 2006-07-27 13:52 367 –a—— C:\WINDOWS\system32\LegitCheckControl.inf
2008-08-08 03:11 . 2008-08-08 03:11 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-08-08 03:07 . 2008-08-08 03:07 d——– C:\Program Files\Radmin.V3.0
2008-08-08 01:52 . 2008-08-08 01:52 d——– C:\Deckard
2008-08-08 01:30 . 2008-08-08 03:07 d–hs—- C:\Documents and Settings\Junoon\UserData
2008-08-08 00:44 . 2008-08-08 03:07 d——– C:\Documents and Settings\Junoon\Contacts
2008-08-08 00:33 . 2008-08-08 00:33 d——– C:\Program Files\Windows Live
2008-08-07 18:41 . 2008-08-07 18:41 d——– C:\Documents and Settings\Junoon\Application Data\BitSpirit
2008-08-07 17:29 . 2008-08-10 19:36 d——– C:\Program Files\RadminV3.0
2008-08-07 12:26 . 2008-08-10 16:18 d——– C:\Program Files\Easy Video Splitter
2008-08-07 10:18 . 2008-08-08 03:07 d–h—– C:\Documents and Settings\Junoon\Recent(2)
2008-08-07 07:09 . 2008-08-07 07:09 d——– C:\Documents and Settings\Junoon\Application Data\vlc
2008-08-07 07:07 . 2008-08-10 01:08 d——– C:\Program Files\VLC
2008-08-06 18:44 . 2008-08-09 23:31 d——– C:\Program Files\AviSynth 2.5
2008-08-06 18:43 . 2008-08-06 18:43 d——– C:\Program Files\Gabest
2008-08-06 18:42 . 2008-08-09 23:32 d——– C:\Program Files\AutoGK
2008-08-06 13:27 . 2008-08-11 00:26 49 –a—— C:\WINDOWS\NeroDigital.ini
2008-08-06 13:23 . 2008-08-06 13:23 d——– C:\VundoFix Backups
2008-08-06 12:25 . 2008-08-06 12:25 d——– C:\Documents and Settings\Junoon\Application Data\Ahead
2008-08-06 12:18 . 2008-08-10 16:51 d——– C:\Program Files\Common Files\Ahead
2008-08-06 11:33 . 2008-08-06 11:33 d——– C:\WINDOWS\system32\LogFiles
2008-08-06 05:51 . 2008-08-06 11:38 21,690,872 –a—— C:\WINDOWS\system32\nero-8.3.2.1_english_micro.exe
2008-08-05 20:23 . 2008-08-05 20:25 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-08-05 20:23 . 2008-08-05 20:23 d——– C:\Documents and Settings\Junoon\Application Data\Malwarebytes
2008-08-05 20:23 . 2008-08-05 20:23 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-05 20:23 . 2008-07-30 20:07 38,472 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-05 20:23 . 2008-07-30 20:07 17,144 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-08-05 20:20 . 2008-04-14 00:15 26,368 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2008-08-05 18:24 . 2008-08-05 18:24 d——– C:\Documents and Settings\Junoon\Application Data\Radmin
2008-08-05 17:31 . 2008-08-05 17:31 d——– C:\Documents and Settings\Junoon\Application Data\Nero
2008-08-05 13:43 . 2008-08-05 13:43 d——– C:\Documents and Settings\Junoon\Application Data\Media Player Classic
2008-08-05 13:34 . 2008-08-05 13:34 d——– C:\Program Files\WordWeb
2008-08-05 13:34 . 2008-06-14 14:17 1,049,272 ——— C:\WINDOWS\wweb32.dll
2008-08-05 13:33 . 2008-08-05 13:33 d——– C:\Program Files\dayam NFO Viewer
2008-08-05 13:32 . 2008-08-08 03:06 d——– C:\Program Files\BitSpirit
2008-08-05 13:30 . 2008-08-08 03:07 d——– C:\Program Files\K-Lite Codec Pack
2008-08-05 13:29 . 2008-08-05 13:29 d——– C:\Program Files\Real Alternative
2008-08-05 13:17 . 2008-08-10 09:05 d——– C:\Program Files\Internet Download Manager
2008-08-05 13:17 . 2008-08-08 03:27 d——– C:\Documents and Settings\Junoon\Application Data\IDM
2008-08-05 13:17 . 2008-08-11 08:58 d——– C:\Documents and Settings\Junoon\Application Data\DMCache
2008-08-05 13:07 . 2008-08-09 14:12 d——– C:\Program Files\uTorrent
2008-08-05 13:07 . 2008-08-11 09:06 d——– C:\Documents and Settings\Junoon\Application Data\utorrent
2008-08-05 13:07 . 2008-08-05 13:07 d——– C:\Documents and Settings\Junoon\Application Data\12Voip
2008-08-05 13:05 . 2008-08-05 13:05 0 –a—— C:\WINDOWS\nsreg.dat
2008-08-05 11:58 . 2004-08-04 15:00 605,696 –a—— C:\WINDOWS\system32\getuname.dll
2008-08-05 11:57 . 2008-08-05 11:59 d——– C:\WINDOWS\system32\MsDtc

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-11 05:24 81,984 —-a-w C:\WINDOWS\system32\bdod.bin
2008-08-11 05:20 ——— d—–w C:\Program Files\BitDefender
2008-08-10 12:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\Nero
2008-08-06 08:18 ——— d—–w C:\Program Files\Nero
2008-08-06 08:01 ——— d—–w C:\Program Files\Common Files\Nero
2008-08-05 08:52 86,792 —-a-w C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-08-05 08:43 ——— d—–w C:\Documents and Settings\Junoon\Application Data\BitDefender
2008-08-05 08:43 ——— d—–w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-08-05 08:42 ——— d—–w C:\Program Files\Common Files\BitDefender
2008-08-05 08:18 ——— d—–w C:\Program Files\SigmaTel
2008-08-05 08:17 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-08-05 08:17 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-08-05 08:16 ——— d—–w C:\Program Files\Intel
2008-08-05 08:12 ——— d—–w C:\Program Files\MSXML 4.0
2008-08-05 08:05 ——— d—–w C:\Program Files\microsoft frontpage
2008-06-12 18:36 7,680 —-a-w C:\WINDOWS\system32\ff_vfw.dll
2008-05-30 23:22 683,520 —-a-w C:\WINDOWS\system32\divx.dll
2008-05-22 22:22 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:19 81,920 —-a-w C:\WINDOWS\system32\dpl100.dll
.

((((((((((((((((((((((((((((( snapshot@2008-08-10_12.51.08.81 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 16:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
+ 2008-08-10 15:36:11 65,536 —-a-r C:\WINDOWS\Installer\{07D00E73-7F67-4008-A33C-80C7D53F1857}\ARPPRODUCTICON.exe
- 2008-08-06 08:22:15 25,214 —-a-r C:\WINDOWS\Installer\{AAB93551-3FFE-42B2-8315-96252BBC1033}\ARPPRODUCTICON.exe
+ 2008-08-10 13:01:36 25,214 —-a-r C:\WINDOWS\Installer\{AAB93551-3FFE-42B2-8315-96252BBC1033}\ARPPRODUCTICON.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4206BE9E-966B-4CED-BD16-AD36EB80AE34}]
C:\WINDOWS\system32\lafokune.dll [BU]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05 143360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 09:26 7700480]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 09:26 86016]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\IEShow.exe" [2007-10-09 15:46 61440]
"BDAgent"="C:\Program Files\BitDefender\bdagent.exe" [2008-08-05 12:51 368640]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-02 01:22 3739648]
"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 18:58 282624 C:\WINDOWS\sttray.exe]
"nwiz"="nwiz.exe" [2007-04-19 09:26 1626112 C:\WINDOWS\system32\nwiz.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\logonui.exe"=
"C:\\WINDOWS\\system32\\winlogon.exe"=
"C:\\Program Files\\Common Files\\BitDefender\\BitDefender Update Service\\livesrv.exe"=
"C:\\WINDOWS\\system32\\spoolsv.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\lsass.exe"=
"C:\\WINDOWS\\system32\\services.exe"=
"C:\\Program Files\\BitDefender\\vsserv.exe"=
"C:\\WINDOWS\\system32\\taskmgr.exe"=
"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMIndexStoreSvr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Documents and Settings\\Junoon\\Start Menu\\Programs\\12Voip.exe"=

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-08-05 12:52]
S2 MBAMService;MBAMService;C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2008-07-30 20:07]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-pekohopati - C:\WINDOWS\system32\nugedoka.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-11 09:24:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-08-11 9:27:00
ComboFix-quarantined-files.txt 2008-08-11 05:26:40
ComboFix2.txt 2008-08-10 08:53:18

Pre-Run: 16,797,929,472 bytes free
Post-Run: 16,799,543,296 bytes free

178

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI