This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] virtumonde virus?

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello…

we noticed adware popping up on our computer. purchased webroot spysweeper. it identified many files, including the file "virtumonde.exe" we quarrantined and removed all identified files and thought we had removed the virus. next time we booted up the computer, adware popped up again. ran spysweeper and it again identified virtumonde.

here is the hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:50 AM, on 9/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.juno.com/s/sp?r=al&cf=sp&…mp;N=PL&O=A
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: JunoBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\Juno\toolbar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: JunoBar - {5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4} - C:\Program Files\Juno\Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Gamevance] "C:\Program Files\Gamevance\gamevance32.exe"
O4 - HKLM\..\Run: [8410e465] rundll32.exe "C:\WINDOWS\system32\qdualhas.dll",b
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [BM8723d7f9] Rundll32.exe "C:\WINDOWS\system32\yuucwuha.dll",s
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Juno_uoltray] "C:\Program Files\Juno\exec.exe" regrun
O4 - HKCU\..\Run: [uoltray] C:\Program Files\Juno\exec.exe regrun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0A1F5FA-52F8-4258-8109-6DC870B61A7F}: NameServer = 192.168.3.100,71.245.83.20
O20 - AppInit_DLLs: cshaqk.dll ffmrum.dll ucvwan.dll mjiaov.dll yxdeio.dll ryvjxi.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MobilePre Installer (MobilePreInstallerService) - Nemesis - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: MSCamSvc - Unknown owner - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 9024 bytes


I am grateful for any help you can offer, as we have been battling this for 2 weeks now with no luck. Also…any idea how this may have affected our computer. I thought we were pretty smart about downloading and what not.

Thank you,
Kristin
Hi kristin031204,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


A. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

B. Now we must disable some of your security programs so that they do not interfere with the running of our tools:

MCAFEE ANTIVIRUS
Please navigate to the system tray on the bottom right hand corner and look for a [external image: Posted Image] sign.
  • right-click it -> chose "Exit."
  • a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard.
You succesfully disabled the McAfee Guard.

SPY SWEEPER
  • Open Spy Sweeper and click on Options > Program Options and uncheck "load at windows startup".
  • On the left click "shields" and then uncheck everything there.
  • Uncheck "home page shield".
  • Uncheck "automatically restore default without notification".
  • Exit the program.
  • (When we are done, you can re-enable it using the same steps but this time reverse them.)


C.Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • DO NOT USE your computer for any other purpose while ComboFix is running.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks Tomk. Please note that my home computer is the one infected and I can only access the internet while at work. I will try this tonight and get back to you tomorrow. Thanks again, Kristin
Tomk:

Thanks for the patience :) I ran ComboFix, followed by HijackThis. The logs are below.

Please let me know if you have any thoughts as to what to do next. Thanks so much for your help!!!



ComboFix Log:

ComboFix 08-09-20.05 - Michael Angello 2008-09-24 14:25:35.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.259 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Michael Angello\Cookies\michael_angello@insightexpressai[1].txt
C:\Documents and Settings\Olivia Angello\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\setup.exe
C:\WINDOWS\BM8723d7f9.txt
C:\WINDOWS\BM8723d7f9.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\cgyaqncp.ini
C:\WINDOWS\system32\dmcjqqij.ini
C:\WINDOWS\system32\fvqtjuxb.ini
C:\WINDOWS\system32\hifytuho.ini
C:\WINDOWS\system32\ixvklxww.ini
C:\WINDOWS\system32\ljJBtuVp.dll
C:\WINDOWS\system32\ljJDSJda.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\SYSTEM32\moYIkUvw.ini
C:\WINDOWS\SYSTEM32\moYIkUvw.ini2
C:\WINDOWS\SYSTEM32\ninbtxql.ini
C:\WINDOWS\system32\pcchmxoy.ini
C:\WINDOWS\SYSTEM32\sahlaudq.ini
C:\WINDOWS\system32\tfsmomcu.ini
C:\WINDOWS\system32\ufpnkxvw.ini
C:\WINDOWS\system32\uojfcrtj.ini
C:\WINDOWS\system32\wvUkIYom.dll
C:\WINDOWS\system32\yxykeijv.ini

.
((((((((((((((((((((((((( Files Created from 2008-08-24 to 2008-09-24 )))))))))))))))))))))))))))))))
.

2008-09-22 13:13 . 2008-09-22 13:13 82,944 –a—— C:\WINDOWS\SYSTEM32\jiqqjcmd.dll
2008-09-22 13:07 . 2008-09-22 13:07 119,808 –a—— C:\WINDOWS\SYSTEM32\jjfhhyox.dll
2008-09-22 13:07 . 2008-09-22 13:07 119,808 –a—— C:\WINDOWS\SYSTEM32\eawntp.dll
2008-09-21 10:16 . 2008-09-21 10:16 d——– C:\Program Files\Trend Micro
2008-09-21 10:06 . 2008-09-21 10:06 119,808 –a—— C:\WINDOWS\SYSTEM32\ryvjxi.dll
2008-09-21 10:06 . 2008-09-21 10:06 119,808 –a—— C:\WINDOWS\SYSTEM32\alqponwe.dll
2008-09-21 10:02 . 2008-09-21 10:02 90,112 –a—— C:\WINDOWS\SYSTEM32\yuucwuha.dll
2008-09-19 13:26 . 2008-09-19 13:26 119,808 –a—— C:\WINDOWS\SYSTEM32\yxdeio.dll
2008-09-19 13:26 . 2008-09-19 13:26 119,808 –a—— C:\WINDOWS\SYSTEM32\vooxchny.dll
2008-09-19 13:24 . 2008-09-19 13:24 82,944 –a—— C:\WINDOWS\SYSTEM32\pcnqaygc.dll
2008-09-19 13:23 . 2008-09-19 13:23 90,112 –a—— C:\WINDOWS\SYSTEM32\kwducaem.dll
2008-09-16 13:52 . 2008-09-16 13:52 119,808 –a—— C:\WINDOWS\SYSTEM32\qfxtlagd.dll
2008-09-16 13:52 . 2008-09-16 13:52 119,808 –a—— C:\WINDOWS\SYSTEM32\mjiaov.dll
2008-09-16 13:51 . 2008-09-16 13:51 90,112 –a—— C:\WINDOWS\SYSTEM32\lcloedeo.dll
2008-09-15 08:58 . 2008-09-15 08:58 119,808 –a—— C:\WINDOWS\SYSTEM32\znzsno.dll
2008-09-15 08:58 . 2008-09-15 08:58 119,808 –a—— C:\WINDOWS\SYSTEM32\rojmimfp.dll
2008-09-13 21:23 . 2008-09-13 21:23 119,808 –a—— C:\WINDOWS\SYSTEM32\ucvwan.dll
2008-09-13 21:22 . 2008-09-13 21:23 119,808 –a—— C:\WINDOWS\SYSTEM32\rapbchvd.dll
2008-09-13 21:19 . 2008-09-13 21:20 90,112 –a—— C:\WINDOWS\SYSTEM32\sphbvoec.dll
2008-09-11 16:29 . 2008-09-11 16:29 d——– C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-09-11 08:41 . 2008-09-11 08:41 119,808 –a—— C:\WINDOWS\SYSTEM32\thfctcgk.dll
2008-09-11 08:41 . 2008-09-11 08:41 119,808 –a—— C:\WINDOWS\SYSTEM32\ffmrum.dll
2008-09-11 08:38 . 2008-09-11 08:38 119,808 –a—— C:\WINDOWS\SYSTEM32\ugbdllvv.dll
2008-09-11 08:38 . 2008-09-11 08:38 119,808 –a—— C:\WINDOWS\SYSTEM32\hkixpk.dll
2008-09-11 08:37 . 2008-09-11 08:37 89,600 –a—— C:\WINDOWS\SYSTEM32\wmcmxbvu.dll
2008-09-09 13:37 . 2008-09-09 13:37 119,808 –a—— C:\WINDOWS\SYSTEM32\ltnuegsu.dll
2008-09-09 13:37 . 2008-09-09 13:37 119,808 –a—— C:\WINDOWS\SYSTEM32\cshaqk.dll
2008-09-08 13:34 . 2008-09-08 13:34 119,808 –a—— C:\WINDOWS\SYSTEM32\olsnaova.dll
2008-09-08 13:34 . 2008-09-08 13:34 119,808 –a—— C:\WINDOWS\SYSTEM32\olcbto.dll
2008-09-08 07:38 . 2008-09-08 07:38 d——– C:\Documents and Settings\Michael Angello\Application Data\Webroot
2008-09-07 11:42 . 2008-09-07 11:42 d——– C:\Program Files\Webroot
2008-09-07 11:42 . 2008-09-07 11:42 d——– C:\Documents and Settings\LocalService\Application Data\Webroot
2008-09-07 11:42 . 2008-09-07 11:42 d——– C:\Documents and Settings\Kristin Angello\Application Data\Webroot
2008-09-07 11:42 . 2008-09-07 11:42 d——– C:\Documents and Settings\All Users\Application Data\Webroot
2008-09-07 11:42 . 2007-10-01 16:40 1,526,072 –a—— C:\WINDOWS\WRSetup.dll
2008-09-07 11:42 . 2007-10-01 16:24 163,640 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ssidrv.sys
2008-09-07 11:42 . 2007-10-01 16:24 23,864 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\sskbfd.sys
2008-09-07 11:42 . 2007-10-01 16:24 21,816 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\sshrmd.sys
2008-09-07 11:42 . 2007-10-01 16:24 20,280 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SSFS0BB9.sys
2008-09-03 16:12 . 2008-09-03 16:12 119,808 –a—— C:\WINDOWS\SYSTEM32\lubewtcb.dll
2008-09-03 16:12 . 2008-09-03 16:12 119,808 –a—— C:\WINDOWS\SYSTEM32\lmmrtk.dll
2008-09-03 16:11 . 2008-09-03 16:11 89,600 –a—— C:\WINDOWS\SYSTEM32\nqeworkk.dll
2008-09-02 09:49 . 2008-09-02 09:49 107,520 –a—— C:\WINDOWS\SYSTEM32\ducfvw.dll
2008-09-02 09:49 . 2008-09-02 09:49 107,520 –a—— C:\WINDOWS\SYSTEM32\dnlrvfny.dll
2008-09-02 09:48 . 2008-09-02 09:48 89,600 –a—— C:\WINDOWS\SYSTEM32\stgjhhpu.dll
2008-08-31 20:52 . 2008-08-31 20:52 107,520 –a—— C:\WINDOWS\SYSTEM32\mcctvxap.dll
2008-08-31 20:52 . 2008-08-31 20:52 107,520 –a—— C:\WINDOWS\SYSTEM32\ezmzsr.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-21 14:13 ——— d—–w C:\Program Files\Juno
2008-09-08 12:05 ——— d—–w C:\Program Files\Microsoft LifeCam
2008-08-31 19:15 ——— d—–w C:\Program Files\Google
2008-08-14 13:58 23,040 —-a-w C:\WINDOWS\SYSTEM32\opnolLDW.dll
2008-08-13 16:24 ——— d—–w C:\Program Files\Gamevance
2008-08-02 20:03 ——— d—–w C:\Program Files\Java
2008-07-07 20:32 253,952 —-a-w C:\WINDOWS\SYSTEM32\es.dll
2008-06-24 16:23 74,240 —-a-w C:\WINDOWS\SYSTEM32\mscms.dll
2007-08-09 13:22 23,402,288 -c–a-w C:\Program Files\AdbeRdr810_en_US.exe
2006-05-31 21:29 39,504 -c–a-w C:\Documents and Settings\Michael Angello\Application Data\GDIPFONTCACHEV1.DAT
2005-10-12 01:42 39,504 -c–a-w C:\Documents and Settings\Kristin Angello\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8fcb17b1-9d35-4e4f-a96a-e9fbbdacd46a}]
2008-09-22 13:07 119808 –a—— C:\WINDOWS\system32\eawntp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"Juno_uoltray"="C:\Program Files\Juno\exec.exe" [2004-06-23 90384]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"uoltray"="C:\Program Files\Juno\exec.exe" [2004-06-23 90384]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 202544]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-08 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2004-10-19 26112]
"VSOCheckTask"="c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2004-07-01 139264]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2004-08-17 245760]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2004-10-25 184320]
"MMTray"="C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2004-04-19 131072]
"VirusScan Online"="c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2004-08-17 180224]
"MPFExe"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-08-22 1327104]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 114688]





HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:27, on 2008-09-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Gamevance\gamevance32.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Juno\exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\M-Audio MobilePre\MPTask.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.spectrumhome.net/scripts/commo…n=1⟨=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\Juno\SearchEnh1.dll
O2 - BHO: X1IEHook Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\Juno\qsacc\X1IEBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: {a64dcadb-bf9e-a69a-f4e4-53d91b71bcf8} - {8fcb17b1-9d35-4e4f-a96a-e9fbbdacd46a} - C:\WINDOWS\system32\eawntp.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: JunoBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\Juno\toolbar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: JunoBar - {5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4} - C:\Program Files\Juno\Toolbar.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Gamevance] "C:\Program Files\Gamevance\gamevance32.exe"
O4 - HKLM\..\Run: [8410e465] rundll32.exe "C:\WINDOWS\system32\jiqqjcmd.dll",b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Juno_uoltray] "C:\Program Files\Juno\exec.exe" regrun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uoltray] C:\Program Files\Juno\exec.exe regrun
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: M-Audio MobilePre Control Panel Launcher.lnk = C:\Program Files\M-Audio MobilePre\MPTask.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\Juno\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\Juno\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/in…l/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0A1F5FA-52F8-4258-8109-6DC870B61A7F}: NameServer = 192.168.3.100,71.245.83.20
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: MobilePre Installer (MobilePreInstallerService) - Nemesis - C:\Program Files\M-Audio MobilePre\Install\MPInst.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: MSCamSvc - Unknown owner - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

–
End of file - 11525 bytes
kristin031204,

Disable your protection programs as we did before.

  • Please open HijackThis and run Do a system scan only
  • Check the boxes next to ONLY the entries listed below(if present):
    • O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
      O4 - HKLM\..\Run: [8410e465] rundll32.exe "C:\WINDOWS\system32\jiqqjcmd.dll",b
      O23 - Service: MSCamSvc - Unknown owner - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (file missing)
  • Close all programs except for HijackThis.
  • Click on Fix checked
  • A box will pop up asking you if you wish to fix the selected items. Please choose YES.
  • Once it has fixed them, please exit/close HijackThis.

Next

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    File::
    C:\WINDOWS\SYSTEM32\jiqqjcmd.dll
    C:\WINDOWS\SYSTEM32\jjfhhyox.dll
    C:\WINDOWS\SYSTEM32\eawntp.dll
    C:\WINDOWS\SYSTEM32\ryvjxi.dll
    C:\WINDOWS\SYSTEM32\alqponwe.dll
    C:\WINDOWS\SYSTEM32\yuucwuha.dll
    C:\WINDOWS\SYSTEM32\yxdeio.dll
    C:\WINDOWS\SYSTEM32\vooxchny.dll
    C:\WINDOWS\SYSTEM32\pcnqaygc.dll
    C:\WINDOWS\SYSTEM32\kwducaem.dll
    C:\WINDOWS\SYSTEM32\qfxtlagd.dll
    C:\WINDOWS\SYSTEM32\mjiaov.dll
    C:\WINDOWS\SYSTEM32\lcloedeo.dll
    C:\WINDOWS\SYSTEM32\znzsno.dll
    C:\WINDOWS\SYSTEM32\rojmimfp.dll
    C:\WINDOWS\SYSTEM32\ucvwan.dll
    C:\WINDOWS\SYSTEM32\rapbchvd.dll
    C:\WINDOWS\SYSTEM32\sphbvoec.dll
    C:\WINDOWS\SYSTEM32\thfctcgk.dll
    C:\WINDOWS\SYSTEM32\ffmrum.dll
    C:\WINDOWS\SYSTEM32\ugbdllvv.dll
    C:\WINDOWS\SYSTEM32\hkixpk.dll
    C:\WINDOWS\SYSTEM32\wmcmxbvu.dll
    C:\WINDOWS\SYSTEM32\ltnuegsu.dll
    C:\WINDOWS\SYSTEM32\cshaqk.dll
    C:\WINDOWS\SYSTEM32\olsnaova.dll
    C:\WINDOWS\SYSTEM32\olcbto.dll
    C:\WINDOWS\SYSTEM32\lubewtcb.dll
    C:\WINDOWS\SYSTEM32\lmmrtk.dll
    C:\WINDOWS\SYSTEM32\nqeworkk.dll
    C:\WINDOWS\SYSTEM32\ducfvw.dll
    C:\WINDOWS\SYSTEM32\dnlrvfny.dll
    C:\WINDOWS\SYSTEM32\stgjhhpu.dll
    C:\WINDOWS\SYSTEM32\mcctvxap.dll
    C:\WINDOWS\SYSTEM32\ezmzsr.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8fcb17b1-9d35-4e4f-a96a-e9fbbdacd46a}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

In your next reply please provide:
  • ComboFix.txt
  • Kaspersky report
  • New HijackThis log taken after everything else completed
Thanks. I'll do this tonight and post back either tonight or tomorrow.

I can't express how much I appreciate this. Geek squad wanted to charge me at least $200 to attempt to remove the virus from my computer. I swear they're in cahoots with the virus guys!!

-Kristin
oh, wait i have a question… "Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. " To do this…just follow the steps in your original "instructional" post? MCAFEE ANTIVIRUS Please navigate to the system tray on the bottom right hand corner and look for a sign. right-click it -> chose "Exit." a popup will warn that protection will now be disabled. Click on "Yes" to disable the Antivirus guard. You succesfully disabled the McAfee Guard. SPY SWEEPER Open Spy Sweeper and click on Options > Program Options and uncheck "load at windows startup". On the left click "shields" and then uncheck everything there. Uncheck "home page shield". Uncheck "automatically restore default without notification". Exit the program. (When we are done, you can re-enable it using the same steps but this time reverse them.)
sorry for the delay…even though i shut down mcafee, there is some windows protection software scheduled to install updates every sunday. it started installing in the middle of the kaspersky scan, then i had to start all over. anyway… attached are the requested logs: 1) combofix log 2) kaspersky scan log 3) hijack this log the three programs were run in that order, as requested. thanks! kristin
kristin031204,

I think we're almost done.

Using Windows Explorer (Windows Key + E), locate the following files/folders, and DELETE them:
C:\Program Files\Gamevance <–This folder
C:\Documents and Settings\Michael Angello\Desktop\Spectrum Home Services\Logo and Art\clipartfree.exe <–This file

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
deleted the free clip art file. trying to delete the gamevance32.exe folder, but got the message: "Cannot delete gamevance32.exe: Access is denied. Make sure the disk is not full or write-protected and that the file is not currently in use" no kidding it's in use!!! urgh… help?
kristin031204,

We'll just use a bigger hammer on it.


COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    KILLALL::
    
    Folder::
    C:\Program Files\Gamevance
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Then go ahead and run ATF and Mbam as previously instructed.
combofix started up , but i got the message: "current date is 2008-09-28. combofix has expired. click yes to run in reduced functionality mode, click no to exit" not to sound like an idiot…but, i'm assuming i need to delete CF and download a new copy? -k
kristin031204,

not to sound like an idiot…but, i'm assuming i need to delete CF and download a new copy?

You definitely don't sound like an idiot… and yes, drag your current CF into your recycle bin and download a new copy.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI