This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] msn virus

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

when ever i log into msn it trys to pass on some virus i have run norton 360/avg/spyware doctor and thay all came back clean yet when every i log in msn it trys to send some virus to ppl i have uninstalled msn reinstalled it tran scans and still it does it here is the log i get using hijackthis Logfile of HijackThis v1.99.1 Scan saved at 05:36:03, on 20/10/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\quejoosoo.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\Program Files\Hijackthis\HijackThis.exe O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file) O4 - HKLM\..\RunServices: [duquy] C:\WINDOWS\system32\bouceh.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O23 - Service: PowerUtility TV Recording Reservation (aeyiztkqyaf7ci) - Unknown owner - C:\WINDOWS\system32\quejoosoo.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
Open notepad, click Format, uncheck wordwrap


Please go to UploadMalware to upload a suspicious file for analysis.
  • Enter your username from this forum in the Comments Or Further Info: box
  • Copy and paste the link to this thread in the Topic Where File Was Requested: box
  • Browse for this filename: C:\WINDOWS\system32\quejoosoo.exe
  • In the comments, please mention that I asked you to upload this file
  • Click on Send File



    Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - App Paths, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, File - Lop Check, File - Purity Scan, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
Hello

Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Processes - Safe List]
YY -> quejoosoo.exe -> %SystemRoot%\system32\quejoosoo.exe
[Win32 Services - Safe List]
YY -> (aeyiztkqyaf7ci) PowerUtility TV Recording Reservation [Win32_Own | Auto | Running] -> %SystemRoot%\system32\quejoosoo.exe
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > ->
YN -> HKEY_LOCAL_MACHINE\: URLSearchHooks\\"{EA756889-2338-43DB-8F07-D1CA6FB9C90D}" [HKLM] -> %ProgramFiles%\AOL\AIM Toolbar 5.0\aoltb.dll [AOLTBSearch Class]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {1E8A6170-7264-4D0F-BEAE-D42A53123C75} [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Value does not exist or could not be read.]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "SITEguard" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{97BCEB59-CFCD-4B16-A863-B3F72CF9F196}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{4B3803EA-5230-4DC3-A7FC-33638F3D3542}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{97BCEB59-CFCD-4B16-A863-B3F72CF9F196}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{DE9C389F-3316-41A7-809B-AA305ED9D922}" [HKLM] -> %ProgramFiles%\AOL\AIM Toolbar 5.0\aoltb.dll [AIM Toolbar]
< RunServices [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
YY -> "duquy" -> %SystemRoot%\system32\bouceh.exe [C:\WINDOWS\system32\bouceh.exe]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value does not exist or could not be read.]
YN -> CmdMapping\\"{2670000A-7350-4f3c-8081-5663EE0C6C49}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{3369AF0D-62E9-4bda-8103-B4C75499B578}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{e2e2dd38-d088-4134-82b7-f2ba38496583}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List
YN -> "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" -> C:\Program Files\Windows Live\Messenger\wlcsdk.exe [C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Messenger (Phone)]
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
YN -> "C:\Documents and Settings\Home\Desktop\photo1226.jpeg-www.myspace.com" -> C:\Documents and Settings\Home\Desktop\photo1226.jpeg-www.myspace.com [C:\Documents and Settings\Home\Desktop\photo1226.jpeg-www.myspace.com:*:Enabled:ENABLE]
YN -> "C:\WINDOWS\system32\gmds.exe" -> C:\WINDOWS\system32\gmds.exe [C:\WINDOWS\system32\gmds.exe:*:Enabled:ENABLE]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \{50e65bd0-ed21-11dc-905e-001111494794}\Shell\AutoRun\command\\"" -> E:\StartVMCLite.exe [E:\StartVMCLite.exe]
YN -> \{50e65bd5-ed21-11dc-905e-001111494794}\Shell\AutoRun\command\\"" -> E:\StartVMCLite.exe [E:\StartVMCLite.exe]
YN -> \{57e5c1da-560f-11dd-90bf-001111494794}\Shell\AutoRun\command\\"" -> E:\StartVMCLite.exe [E:\StartVMCLite.exe]
[Files/Folders - Created Within 90 Days]
NY -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> Qoobox -> %SystemDrive%\Qoobox
NY -> ComboFix -> %SystemDrive%\ComboFix
NY -> CF21522.exe -> %SystemRoot%\System32\CF21522.exe
NY -> ComboFix.exe -> %UserProfile%\Desktop\ComboFix.exe
NY -> oaku.sys -> %SystemRoot%\System32\drivers\oaku.sys
NY -> setupnt.exe -> %UserProfile%\Desktop\setupnt.exe
NY -> quejoosoo.exe -> %SystemRoot%\System32\quejoosoo.exe
NY -> bouceh.exe -> %SystemRoot%\System32\bouceh.exe
NY -> setupxv.exe -> %UserProfile%\Desktop\setupxv.exe
[Files/Folders - Modified Within 90 Days]
NY -> quejoosoo.exe -> %SystemRoot%\System32\quejoosoo.exe
NY -> bouceh.exe -> %SystemRoot%\System32\bouceh.exe
NY -> kgpcpy.cfg -> %SystemRoot%\System32\drivers\kgpcpy.cfg
[Empty Temp Folders]
[Start Explorer]
[ZipFiles]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.



This will create a zip file in the folder C:\OTScanIt\movedfiles\(name of the zip folder).zip

I need you to upload that here


Please go to UploadMalware to upload a suspicious file for analysis.
  • Enter your username from this forum in the Comments Or Further Info: box
  • Copy and paste the link to this thread in the Topic Where File Was Requested: box
  • Browse for this filename: C:\OTScanIt\movedfiles\(name of the zip folder).zip
  • In the comments, please mention that I asked you to upload this file
  • Click on Send File
this is a repost iof my problem as other topic was closed when my pc totaly crashed out on me here is the hjt log problem is every time i log into msn it automaticly sends out a so called pic reinstalling msn didnt help runing avg norton spyware doc didnt help i bought stopzila and ran it found a few things but still have this msn thing going Rorschach112 was attemptibng to help Logfile of HijackThis v1.99.1 Scan saved at 07:16:30, on 26/10/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\lekohi.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Google\Google Talk\googletalk.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\explorer.exe C:\Program Files\Hijackthis\HijackThis.exe R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) O4 - HKLM\..\Run: [duquy] C:\WINDOWS\system32\lekohi.exe O4 - HKLM\..\Run: [muwoum] C:\WINDOWS\system32\hougiwa.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\RunServices: [duquy] C:\WINDOWS\system32\lekohi.exe O4 - HKLM\..\RunServices: [muwoum] C:\WINDOWS\system32\hougiwa.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O23 - Service: Zip Backup to CD (aalfeia8ebf8tti) - Unknown owner - C:\WINDOWS\system32\lekohi.exe O23 - Service: PowerUtility TV Recording Reservation (aeyiztkqyaf7ci) - Unknown owner - C:\WINDOWS\system32\quejoosoo.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
i posted the quejoosoo.zip but when i ry to run ot scan it frezess half way thro and does not compleat the task tryed 4 times now it just refuses to compleat says its not responding
Explorer killed successfully [Processes - Safe List] Unable to kill process quejoosoo.exe . File C:\WINDOWS\system32\quejoosoo.exe not found. [Win32 Services - Safe List] Unable to stop service aeyiztkqyaf7ci . Unable to delete service aeyiztkqyaf7ci . File C:\WINDOWS\system32\quejoosoo.exe not found. [Registry - Safe List] Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EA756889-2338-43DB-8F07-D1CA6FB9C90D} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EA756889-2338-43DB-8F07-D1CA6FB9C90D}\ not found. Unable to delete registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\ . Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\SITEguard not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{97BCEB59-CFCD-4B16-A863-B3F72CF9F196} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97BCEB59-CFCD-4B16-A863-B3F72CF9F196}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{97BCEB59-CFCD-4B16-A863-B3F72CF9F196} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97BCEB59-CFCD-4B16-A863-B3F72CF9F196}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DE9C389F-3316-41A7-809B-AA305ED9D922} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DE9C389F-3316-41A7-809B-AA305ED9D922}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\\duquy not found. File C:\WINDOWS\system32\bouceh.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{2670000A-7350-4f3c-8081-5663EE0C6C49} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2670000A-7350-4f3c-8081-5663EE0C6C49}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{3369AF0D-62E9-4bda-8103-B4C75499B578} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3369AF0D-62E9-4bda-8103-B4C75499B578}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e2e2dd38-d088-4134-82b7-f2ba38496583}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Program Files\Windows Live\Messenger\wlcsdk.exe not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Documents and Settings\Home\Desktop\photo1226.jpeg-www.myspace.com not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\system32\gmds.exe not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50e65bd0-ed21-11dc-905e-001111494794}\Shell\AutoRun\command\\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{50e65bd5-ed21-11dc-905e-001111494794}\Shell\AutoRun\command\\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{57e5c1da-560f-11dd-90bf-001111494794}\Shell\AutoRun\command\\ not found. [Files/Folders - Created Within 90 Days] File C:\Qoobox not found! File C:\ComboFix not found! File C:\WINDOWS\System32\CF21522.exe not found! File C:\Documents and Settings\Home\Desktop\ComboFix.exe not found! File C:\WINDOWS\System32\drivers\oaku.sys not found! File C:\Documents and Settings\Home\Desktop\setupnt.exe not found! File C:\WINDOWS\System32\quejoosoo.exe not found! File C:\WINDOWS\System32\bouceh.exe not found! File C:\Documents and Settings\Home\Desktop\setupxv.exe not found! [Files/Folders - Modified Within 90 Days] File C:\WINDOWS\System32\quejoosoo.exe not found! File C:\WINDOWS\System32\bouceh.exe not found! File C:\WINDOWS\System32\drivers\kgpcpy.cfg not found! [Empty Temp Folders] File delete failed. C:\Documents and Settings\Home\Local Settings\Temp\etilqs_5GobG1LR4WgY1Sl4mF10 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Temp\fla267.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Temp\Perflib_Perfdata_c4c.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Temp\~DFC6BC.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Temp\~DFC6D5.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Temp\~DFC93A.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Temp\~DFCE60.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\JET1005.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\JET114D.tmp scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. RecycleBin -> emptied. Explorer started successfully < End of fix log > OTScanIt2 by OldTimer - Version 1.0.0.18b fix logfile created on 10272008_030809 Files moved on Reboot… File C:\Documents and Settings\Home\Local Settings\Temp\etilqs_5GobG1LR4WgY1Sl4mF10 not found! File C:\Documents and Settings\Home\Local Settings\Temp\fla267.tmp not found! File C:\Documents and Settings\Home\Local Settings\Temp\Perflib_Perfdata_c4c.dat not found! File C:\Documents and Settings\Home\Local Settings\Temp\~DFC6BC.tmp not found! File C:\Documents and Settings\Home\Local Settings\Temp\~DFC6D5.tmp not found! File C:\Documents and Settings\Home\Local Settings\Temp\~DFC93A.tmp not found! File C:\Documents and Settings\Home\Local Settings\Temp\~DFCE60.tmp not found! C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully. C:\WINDOWS\temp\JET1005.tmp moved successfully. C:\WINDOWS\temp\JET114D.tmp moved successfully. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Home\Local Settings\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\XUL.mfl moved successfully. i ran the hot fix you surgested and got this as a result
Logfile of HijackThis v1.99.1 Scan saved at 15:35:05, on 27/10/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\Google Talk\googletalk.exe C:\Program Files\AIM6\aolsoftware.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\cidaemon.exe C:\Documents and Settings\LocalService\Application Data\Microsoft\bouceh.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Hijackthis\HijackThis.exe R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing) O4 - HKLM\..\Run: [duquy] C:\WINDOWS\system32\bouceh.exe O4 - HKLM\..\Run: [muwoum] C:\WINDOWS\system32\hougiwa.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\RunServices: [muwoum] C:\WINDOWS\system32\hougiwa.exe O4 - HKLM\..\RunServices: [duquy] C:\WINDOWS\system32\bouceh.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O23 - Service: Zip Backup to CD (aalfeia8ebf8tti) - Unknown owner - C:\WINDOWS\system32\lekohi.exe (file missing) O23 - Service: PowerUtility TV Recording Reservation (aeyiztkqyaf7ci) - Unknown owner - C:\Documents and Settings\LocalService\Application Data\Microsoft\quejoosoo.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
Hello

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
ComboFix 08-10-27.02 - Home 2008-10-28 3:46:02.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Zumie
C:\Program Files\Zumie\Zumie_deleted_\zumie.dll
C:\Program Files\Zumie\Zumie_deleted_\zumie.exe
C:\WINDOWS\system32\cpmsky-uninst.exe
C:\WINDOWS\system32\Show Pink Zone.ico
C:\WINDOWS\system32\u2g.f

.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
.

2008-10-27 03:12 . 2008-10-14 23:37 233,472 –a—— C:\WINDOWS\system32\quejoosoo.exe
2008-10-27 03:05 . 2008-10-27 03:05 d——– C:\_OTScanIt
2008-10-27 02:23 . 2008-10-27 02:23 225,401 –a—— C:\WINDOWS\system32\quejoosoo.zip
2008-10-23 08:38 . 2008-10-23 08:38 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-23 06:21 . 2008-10-23 06:21 d——– C:\Program Files\RegCure
2008-10-23 06:20 . 2008-10-23 06:20 d–h-c— C:\Documents and Settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-10-23 04:48 . 2008-10-23 04:48 d——– C:\New Folder
2008-10-23 03:40 . 2008-10-23 03:45 d——– C:\regres
2008-10-23 03:40 . 2008-10-23 03:45 720,896 –a—— C:\WINDOWS\iun6002.exe
2008-10-21 09:56 . 2008-10-21 09:56 d——– C:\My Drivers
2008-10-21 09:55 . 2008-10-21 09:55 d——– C:\Program Files\JerMar Software Corp
2008-10-21 09:55 . 2001-11-29 08:57 110,592 –a—— C:\WINDOWS\system32\ccrpbds6.dll
2008-10-20 23:09 . 2008-07-18 21:07 210,976 –a—— C:\WINDOWS\system32\muweb.dll
2008-10-20 18:56 . 2008-10-20 21:57 d——– C:\Program Files\jZip
2008-10-20 18:15 . 2008-10-20 18:15 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-20 18:12 . 2008-10-20 18:12 774,144 –a—— C:\Program Files\RngInterstitial.dll
2008-10-20 17:54 . 2008-10-26 04:02 d——– C:\Program Files\RelevantKnowledge
2008-10-20 17:52 . 2008-10-20 17:52 d——– C:\Program Files\7-Zip
2008-10-20 17:51 . 2008-10-20 17:52 d——– C:\Program Files\Free Offers from Freeze.com
2008-10-20 05:00 . 2008-10-20 05:00 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-20 05:00 . 2008-10-20 05:00 d——– C:\Documents and Settings\Home\Application Data\Malwarebytes
2008-10-20 05:00 . 2008-10-20 05:00 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-20 05:00 . 2008-10-16 19:25 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-20 05:00 . 2008-10-16 19:25 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-18 04:52 . 2008-10-14 23:37 233,472 –a—— C:\WINDOWS\system32\hougiwa.exe
2008-10-15 17:46 . 2008-10-18 18:39 d——– C:\Documents and Settings\Home\Application Data\EurekaLog
2008-10-15 15:54 . 2008-10-15 16:00 d——– C:\N360_BACKUP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 03:16 ——— d—–w C:\Documents and Settings\Home\Application Data\OpenOffice.org2
2008-10-27 07:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-27 03:12 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-10-27 02:25 ——— d—–w C:\Program Files\GSC
2008-10-26 12:56 ——— d—–w C:\Program Files\Veoh Networks
2008-10-26 05:07 ——— d—–w C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-10-26 04:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\SITEguard
2008-10-26 03:52 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-24 02:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-21 09:55 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-10-20 18:12 ——— d—–w C:\Program Files\Real
2008-10-20 18:12 ——— d—–w C:\Program Files\Common Files\Real
2008-10-20 17:52 ——— d—–w C:\Program Files\Yahoo!
2008-10-19 07:00 ——— d—–w C:\Documents and Settings\Home\Application Data\AVG7
2008-10-15 03:27 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-15 03:22 ——— d—–w C:\Program Files\Spyware Doctor
2008-10-11 15:57 ——— d—–w C:\Program Files\Norton 360
2008-10-09 21:11 ——— d—–w C:\Program Files\Picasa2
2008-10-06 21:21 ——— d—–w C:\Program Files\Google
2008-09-26 13:08 304,160 —-a-w C:\StiImg.dat
2008-09-24 04:44 ——— d—–w C:\Program Files\Perfect Uninstaller
2008-09-24 04:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-24 04:17 ——— d—–w C:\Program Files\AIM6
2008-09-24 04:17 ——— d—–w C:\Documents and Settings\Home\Application Data\acccore
2008-09-24 04:16 ——— d—–w C:\Program Files\Viewpoint
2008-09-24 04:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-24 04:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2008-09-24 04:16 ——— d—–w C:\Documents and Settings\All Users\Application Data\acccore
2008-09-24 04:15 ——— d—–w C:\Program Files\Common Files\AOL
2008-09-16 17:09 30,080 —-a-w C:\WINDOWS\system32\drivers\RKHit.sys
2008-09-15 17:19 ——— d—–w C:\Program Files\RegistryCleanerPro
2008-09-15 17:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2008-09-13 05:44 ——— d—–w C:\Program Files\BitZipperSearch
2008-09-13 03:09 ——— d—–w C:\Documents and Settings\Home\Application Data\RegFixPro
2008-09-13 01:58 ——— d—–w C:\Program Files\Conduit
2008-09-13 01:58 ——— d—–w C:\Program Files\BitZipper
2008-09-13 01:24 ——— d—–w C:\Documents and Settings\Home\Application Data\BitZipper
2008-09-13 00:36 ——— d—–w C:\Program Files\Realtek AC97
2008-09-11 22:59 ——— d—–w C:\Program Files\Intel
2008-09-11 21:52 ——— d—–w C:\Program Files\PC Drivers HeadQuarters
2008-09-11 21:52 ——— d—–w C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
2008-09-11 11:44 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-11 11:18 ——— d—–w C:\Program Files\Canon
2008-09-11 10:53 ——— d—–w C:\Program Files\Spybot - Search & Destroy
2008-09-11 10:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-10 21:25 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-09-10 20:30 ——— d—–w C:\Program Files\Windows Live
2008-09-07 13:31 2,560 —ha-w C:\WINDOWS\system32\drivers\mchInjDrv.sys.szcpf
2008-08-29 22:57 ——— d—–w C:\Documents and Settings\Home\Application Data\Uniblue
2008-08-28 23:45 ——— d—–w C:\Documents and Settings\Home\Application Data\vlc
2008-08-28 08:33 ——— d—–w C:\Program Files\Java
2008-08-10 11:18 0 —-a-w C:\Documents and Settings\Home\jagex_runescape_preferences.dat
2004-12-01 08:49 2,264,443 —-a-w C:\Documents and Settings\MingJong3USBPCCam_v4.12.0.1_whql\MingJong3USBPCCam_v4.12.0.1_whql.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-08-12 49960]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"muwoum"="C:\WINDOWS\system32\hougiwa.exe" [2008-10-14 233472]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-29 185896]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"muwoum"="C:\WINDOWS\system32\hougiwa.exe" [2008-10-14 233472]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-20 219136]
"duquy"="C:\Documents and Settings\LocalService\Application Data\Microsoft\bouceh.exe" [2008-10-14 233472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MSIServer"=3 (0x3)
"gusvc"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 szkg5;szkg;C:\WINDOWS\system32\DRIVERS\szkg.sys [2008-05-13 34432]
S2 aalfeia8ebf8tti;Zip Backup to CD;C:\WINDOWS\system32\lekohi.exe [ ]
S2 aeyiztkqyaf7ci;PowerUtility TV Recording Reservation;C:\Documents and Settings\LocalService\Application Data\Microsoft\quejoosoo.exe [2008-10-14 233472]
S3 PAC207;SoC PC-Camer@;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 162176]
S3 RkHit;RkHit;C:\WINDOWS\system32\drivers\RKHit.sys [2008-09-16 30080]
S3 USB-100;Realtek RTL8150 USB 10/100 Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\RTL8150.SYS [2002-02-22 26505]
S4 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\StartVMCLite.exe

*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-10-24 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 13:42]

2008-10-27 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 21:21]

2008-10-23 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-04-21 21:21]

2008-10-27 C:\WINDOWS\Tasks\RegFixPro Scheduled Scan.job
- C:\Program Files\RegFixPro\RegFixPro.exe []

2008-10-27 C:\WINDOWS\Tasks\RegFixPro Scheduled Scan.job
- C:\Program Files\RegFixPro []
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-duquy - C:\WINDOWS\system32\bouceh.exe
HKLM-RunServices-duquy - C:\WINDOWS\system32\bouceh.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Documents and Settings\Home\Application Data\Mozilla\Firefox\Profiles\huj2kv5p.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/?.home=ytff
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.1.0.30716.0.dll
FF -: plugin - c:\Program Files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npgcplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Picasa2\npPicasa2.dll
FF -: plugin - C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 03:55:57
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-28 4:01:01
ComboFix-quarantined-files.txt 2008-10-28 04:00:48

Pre-Run: 51,140,894,720 bytes free
Post-Run: 51,136,966,656 bytes free

193 — E O F — 2008-10-24 02:05:45

requeated log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI