This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infested computer

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have tried to attach the HJT log however I keep getting redirected telling me to use Hijackthis 2.02. I have done this and still get redirected - what do I need to do to get this log to you? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:29:58 PM, on 11/23/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal
[external image: Posted Image]

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.




Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Thank you! Here is the log without the header (do I don't get redirected again, you have the information above.)


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\regsvr32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\TEMP\stf1.tmp
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {5241B121-05B9-4FB5-8D5D-8E81082960D1} - C:\WINDOWS\system32\awturQKA.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {A3E63A35-3B42-440D-913A-686C96CBADA8} - C:\WINDOWS\system32\opnlMgeE.dll (file missing)
O2 - BHO: {617a393c-a74c-0a0b-9c34-dadec9592eea} - {aee2959c-edad-43c9-b0a0-c47ac393a716} - C:\WINDOWS\system32\zxuvut.dll
O2 - BHO: adsoftinc browser enhancer - {B4E97EF6-D3F1-E0E0-C75F-3490B28D64CC} - C:\WINDOWS\system32\xlahokrtxquki.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Antivirus Pro 2009] "C:\Program Files\AntivirusPro2009\AntivirusPro2009.exe" /hide
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [wdckiezgjfdjofedp] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\xlahokrtxquki.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
O4 - HKCU\..\Run: [Twain] C:\WINDOWS\system32\config\systemprofile\Application Data\Twain\Twain.exe
O4 - HKCU\..\Run: [SpeedRunner] C:\WINDOWS\system32\config\systemprofile\Application Data\SpeedRunner\SpeedRunner.exe
O4 - HKCU\..\Run: [gadcom] "C:\WINDOWS\system32\config\systemprofile\Application Data\gadcom\gadcom.exe" 61A847B5BBF72815308B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKUS\S-1-5-19\..\Run: [GetModule27] C:\Program Files\GetModule\GetModule27.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [MSServer] rundll32.exe C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\hgGxXrQK.dll,#1 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227054735773
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: heocut.dll,akatvk.dll,yljcux.dll,avgrsstx.dll zxuvut.dll
O20 - Winlogon Notify: khfCrssP - khfCrssP.dll (file missing)
O20 - Winlogon Notify: ljJASihg - ljJASihg.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

–
End of file - 7212 bytes
Well you have some back infections there. From what you said in chat, that pc is real slow and you're posting from another pc. You could try System Restore. 1. Click Start. 2. Point to All Programs. 3. Point to Accessories. 4. Point to System Tools. 5. Click System Restore. 6. Follow the instructions on the wizard. See if you can find a date the the PC worked. If that doesn't work, you'll need to download those programs to something like a flash drive and install them on the infected pc. Then run per instructions
I had thought of that, however, a number of the "restore" files were infected and I have no idea how long this computer has been having problems. This is NOT my computer - it is my bosses which I offered to clean up. I will download and run the other programs you suggested and re-run the log. I will not be able to update the programs, will have to use them as is :(

I had thought of that, however, a number of the "restore" files were infected and I have no idea how long this computer has been having problems. This is NOT my computer - it is my bosses which I offered to clean up.

I will download and run the other programs you suggested and re-run the log. I will not be able to update the programs, will have to use them as is :(

OK. Just skip the update for now.
Have run the programs successfully. While Malware was running AVG found two virus' that I moved to the Vault (both times).

After running Malwarebytes' Anti-Malware, I was able to successfully update AVG (couldn't before), then I updated Malwarebytes and re-ran. Will post both logs below. I re-ran HJT after both updated and re-runs and will only post the most recent log. I rebooted between Malware scans due to files needing delete on reboot.

System seems to be running a bit faster, but it is still sluggish. I tried to go to the default internet home page (www.google.com)

If you notice any programs that should be removed from the computer, let me know and I will do so immediately.

malwarebytes log #1
Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 5.1.2600 Service Pack 3

11/23/2008 3:30:04 PM
mbam-log-2008-11-23 (15-30-04).txt

Scan type: Quick Scan
Objects scanned: 51617
Time elapsed: 14 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 12
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 5
Files Infected: 20

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\awturQKA.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\zxuvut.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5241b121-05b9-4fb5-8d5d-8e81082960d1} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{5241b121-05b9-4fb5-8d5d-8e81082960d1} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{aee2959c-edad-43c9-b0a0-c47ac393a716} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{aee2959c-edad-43c9-b0a0-c47ac393a716} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\7c673a5b871b8cd419f47dd0de5a6d18 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7c673a5b871b8cd419f47dd0de5a6d18 (Rogue.AdwareAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\antiviruspro2009 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus pro 2009 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\awturqka -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\awturqka -> Delete on reboot.

Folders Infected:
C:\Program Files\Webtools (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\GetModule (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009 (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\data (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT (Rogue.Antivirus2008) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\awturQKA.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\AKQrutwa.ini (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\AKQrutwa.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\zxuvut.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\olfacbjc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cjbcaflo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pwclcjjl.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljjclcwp.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ngrngauj.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\AntivirusPro2009.cfg (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\htmlayout.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\pthreadVC2.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\data\daily.cvd (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT\msvcm80.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT\msvcp80.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\AntivirusPro2009\Microsoft.VC80.CRT\msvcr80.dll (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro2009.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Application Data\bajulyzu.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winlogon.old (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.


malwarebytes #2
Malwarebytes' Anti-Malware 1.30
Database version: 1419
Windows 5.1.2600 Service Pack 3

11/23/2008 4:01:13 PM
mbam-log-2008-11-23 (16-01-13).txt

Scan type: Quick Scan
Objects scanned: 53322
Time elapsed: 13 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 8

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{a63e645f-13bd-45ed-b15f-6e8c1bd57279} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b0b3393c-62d1-44d8-abf5-08e0f067f29e} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b0b3393c-62d1-44d8-abf5-08e0f067f29e} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b4e97ef6-d3f1-e0e0-c75f-3490b28d64cc} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b4e97ef6-d3f1-e0e0-c75f-3490b28d64cc} (Adware.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{a63e645f-13bd-45ed-b15f-6e8c1bd57279} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{b0b3393c-62d1-44d8-abf5-08e0f067f29e} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gadcom (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wdckiezgjfdjofedp (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Owner\Application Data\gadcom (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Start Menu\Programs\AntivirusPro2009 (Rogue.AntivirusPro2009) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\Owner\Application Data\gadcom\gadcom.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Start Menu\Programs\AntivirusPro2009\AntivirusPro2009.lnk (Rogue.AntivirusPro2009) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Start Menu\Programs\AntivirusPro2009\Uninstall.lnk (Rogue.AntivirusPro2009) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xlahokrtxquki.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\wini1087100.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\wrdwn6 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\wrdwn7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\wrdwn9 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Hijack
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:08:43 PM, on 11/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Easy SpyRemover\EasySpyRemover.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {A3E63A35-3B42-440D-913A-686C96CBADA8} - C:\WINDOWS\system32\opnlMgeE.dll (file missing)
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
O4 - HKCU\..\Run: [Twain] C:\WINDOWS\system32\config\systemprofile\Application Data\Twain\Twain.exe
O4 - HKCU\..\Run: [SpeedRunner] C:\WINDOWS\system32\config\systemprofile\Application Data\SpeedRunner\SpeedRunner.exe
O4 - HKUS\S-1-5-19\..\Run: [GetModule27] C:\Program Files\GetModule\GetModule27.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [brastk] C:\WINDOWS\system32\brastk.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [MSServer] rundll32.exe C:\DOCUME~1\LOCALS~1\LOCALS~1\Temp\hgGxXrQK.dll,#1 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227054735773
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: heocut.dll,akatvk.dll,yljcux.dll,avgrsstx.dll zxuvut.dll
O20 - Winlogon Notify: khfCrssP - khfCrssP.dll (file missing)
O20 - Winlogon Notify: ljJASihg - ljJASihg.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

–
End of file - 6345 bytes
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
I tried to post the link to the re-direct when I tried going to default homepage but it was removed upon posting (so removed the h…….) avg.urlseek.vmn.net/search.php?lg=en&mkt=en&type=dns&tb=ie&tbn=avg&q=www%2Egoogle%2Ecom
Here are the new logs……FYI - one of the spyware removal programs tried running after reboot, I shut it down right away…. :(

Once the Combfix log was created a message appeared that said: F1: the filename, directory name or volumn label syntax is incorrect.

Checked IE, desktop shortcut took me to the re-direct again, however, direct typing in www.yahoo.com and www.google.com worked fine, no pop ups or redirects. Still seems slow tho.


ComboFix 08-11-22.02 - Owner 2008-11-23 16:40:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.75 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\Owner\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\Owner\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\daluwybuz._sy
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\dohy.dl
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\ilelysiduz._dl
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\ticojyna.vbs
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\uhumiximo.inf
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\ulina.scr
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\zekupy.ban
C:\installerwnusnewer.exe
c:\windows\IA
c:\windows\system32\EegMlnpo.ini
c:\windows\system32\EegMlnpo.ini2
c:\windows\system32\fnts~1
c:\windows\system32\heggchux.ini
c:\windows\system32\hhpfqoxx.ini
c:\windows\system32\iryqwdkb.ini
c:\windows\system32\khnokdxc.ini
c:\windows\system32\tcnohhal.ini
c:\windows\system32\wnsapisv.exe
c:\windows\system32\ymante~1
c:\windows\system32\ymante~1\?ymantec\
c:\windows\wiaserviv.log

.
((((((((((((((((((((((((( Files Created from 2008-10-23 to 2008-11-23 )))))))))))))))))))))))))))))))
.

2008-11-23 16:54 . 2008-11-23 16:56 d——– c:\windows\LastGood
2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-23 15:11 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-23 15:11 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-23 14:28 . 2008-11-23 14:28 d——– c:\program files\Trend Micro
2008-11-23 13:58 . 2008-11-23 14:30 d——– C:\HIJACK LOG
2008-11-23 12:45 . 2008-11-23 12:45 d——– c:\program files\NoAdware
2008-11-23 11:36 . 2008-11-23 11:37 d——– c:\program files\Easy SpyRemover
2008-11-23 11:35 . 2008-11-23 11:35 d——– c:\program files\ERUNT
2008-11-19 23:38 . 2008-11-23 15:20 d–h—– C:\$AVG8.VAULT$
2008-11-19 22:07 . 2008-11-19 22:07 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-11-19 22:07 . 2008-11-19 22:07 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-11-19 22:06 . 2008-11-23 15:45 d——– c:\windows\system32\drivers\Avg
2008-11-19 22:06 . 2008-11-19 22:06 d——– c:\program files\AVG
2008-11-19 22:06 . 2008-11-23 10:53 d——– c:\documents and settings\Owner\Application Data\AVGTOOLBAR
2008-11-19 22:06 . 2008-11-19 22:06 d——– c:\documents and settings\All Users\Application Data\avg8
2008-11-19 21:39 . 2008-11-19 21:39 d——– c:\documents and settings\All Users\Application Data\America Online
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\system32\scripting
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\system32\en
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\l2schemas
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\SDHelper (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-11-18 18:16 . 2008-11-18 18:22 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-18 18:13 . 2008-11-18 18:13 d——– c:\program files\Common Files\Wise Installation Wizard
2008-11-18 16:38 . 2008-11-18 16:38 53,938 –a—— c:\windows\system32\cont_adsoftinc-remove.exe
2008-11-18 16:38 . 2008-11-20 16:53 47,575 –a—— c:\windows\system32\eenoxaxygwxxbywp.exe
2008-11-18 16:36 . 2008-04-13 12:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-11-09 01:43 . 2008-11-09 01:43 19,632 –a—— c:\windows\fewuk._sy
2008-11-09 01:43 . 2008-11-09 01:43 19,295 –a—— c:\documents and settings\Owner\Application Data\zenitulise.com
2008-11-09 01:43 . 2008-11-09 01:43 19,125 –a—— c:\windows\etuqevef.ban
2008-11-09 01:43 . 2008-11-09 01:43 18,822 –a—— c:\windows\system32\ibifi.pif
2008-11-09 01:43 . 2008-11-09 01:43 16,720 –a—— c:\windows\ycijyryxo.inf
2008-11-09 01:43 . 2008-11-09 01:43 16,244 –a—— c:\program files\Common Files\gipacykyte.vbs
2008-11-09 01:43 . 2008-11-09 01:43 14,684 –a—— c:\windows\system32\zyzetodek.pif
2008-11-09 01:43 . 2008-11-09 01:43 12,635 –a—— c:\documents and settings\All Users\Application Data\oquc.com
2008-11-09 01:43 . 2008-11-09 01:43 12,617 –a—— c:\windows\ovokozepyz.dat
2008-11-09 01:43 . 2008-11-09 01:43 11,937 –a—— c:\windows\system32\olusyxove.bin
2008-11-09 01:43 . 2008-11-09 01:43 11,884 –a—— c:\windows\byfele.scr
2008-11-09 01:43 . 2008-11-09 01:43 11,767 –a—— c:\windows\duwig.reg
2008-11-09 01:43 . 2008-11-09 01:43 11,150 –a—— c:\program files\Common Files\upiqofoh.reg
2008-11-09 01:43 . 2008-11-09 01:43 10,057 –a—— c:\windows\system32\qejiq.lib
2008-11-08 23:52 . 2008-11-08 23:52 18,816 –a—— c:\windows\jygikexop.reg
2008-11-08 23:52 . 2008-11-08 23:52 18,681 –a—— c:\documents and settings\Owner\Application Data\matakeku.exe
2008-11-08 23:52 . 2008-11-08 23:52 18,457 –a—— c:\windows\hafagiga.sys
2008-11-08 23:52 . 2008-11-08 23:52 18,208 –a—— c:\windows\saluwebi.dat
2008-11-08 23:52 . 2008-11-08 23:52 17,742 –a—— c:\windows\system32\vuqywinuc._sy
2008-11-08 23:52 . 2008-11-08 23:52 17,658 –a—— c:\windows\ygih.exe
2008-11-08 23:52 . 2008-11-08 23:52 17,321 –a—— c:\windows\tiqajypyne.db
2008-11-08 23:52 . 2008-11-08 23:52 16,946 –a—— c:\windows\system32\uzasihener.com
2008-11-08 23:52 . 2008-11-08 23:52 16,156 –a—— c:\windows\emivyqoru.com
2008-11-08 23:52 . 2008-11-08 23:52 15,941 –a—— c:\windows\system32\lymoh.exe
2008-11-08 23:52 . 2008-11-08 23:52 15,136 –a—— c:\windows\system32\ivymokib._sy
2008-11-08 23:52 . 2008-11-08 23:52 14,073 –a—— c:\windows\vexywobo.exe
2008-11-08 23:52 . 2008-11-08 23:52 13,371 –a—— c:\program files\Common Files\diferosol.dat
2008-11-08 23:52 . 2008-11-08 23:52 12,585 –a—— c:\windows\gykutyfyb.exe
2008-11-07 09:25 . 2008-11-23 11:01 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-07 09:25 . 2008-11-07 09:25 1,409 –a—— c:\windows\QTFont.for
2008-11-07 08:02 . 2008-11-07 08:02 118 –a—— c:\windows\system32\MRT.INI
2008-11-07 07:56 . 2008-11-07 07:56 19,760 –a—— c:\windows\nyzuti.scr
2008-11-07 07:56 . 2008-11-07 07:56 14,896 –a—— c:\documents and settings\All Users\Application Data\yvoreje.pif
2008-11-07 07:56 . 2008-11-07 07:56 14,493 –a—— c:\program files\Common Files\jorozaqugi.vbs
2008-11-07 07:56 . 2008-11-07 07:56 13,061 –a—— c:\windows\dagomite.inf
2008-11-07 07:56 . 2008-11-07 07:56 12,093 –a—— c:\windows\ejyg.pif
2008-11-07 07:56 . 2008-11-07 07:56 12,026 –a—— c:\windows\adevaxirow.lib
2008-11-07 07:56 . 2008-11-07 07:56 10,396 –a—— c:\windows\vybemo._dl
2008-11-07 07:55 . 2008-11-07 07:56 16,933 –a—— c:\windows\system32\uvakijohar._sy
2008-11-07 07:55 . 2008-11-07 07:55 15,719 –a—— c:\windows\eminoloq.bin
2008-11-07 07:55 . 2008-11-07 07:55 14,061 –a—— c:\windows\system32\joheben.reg
2008-11-07 07:38 . 2008-11-07 07:38 14,387 –a—— c:\documents and settings\Owner\Application Data\qymaxy.com
2008-11-06 22:38 . 2008-11-06 22:38 19,859 –a—— c:\documents and settings\Owner\Application Data\enuwa.sys
2008-11-06 22:38 . 2008-11-06 22:38 19,120 –a—— c:\program files\Common Files\joso.exe
2008-11-06 22:38 . 2008-11-06 22:38 18,968 –a—— c:\documents and settings\Owner\Application Data\asorogaj.bin
2008-11-06 22:38 . 2008-11-06 22:38 17,796 –a—— c:\documents and settings\Owner\Application Data\rixugiko.bat
2008-11-06 22:38 . 2008-11-06 22:38 15,932 –a—— c:\windows\system32\adejebarur.dat
2008-11-06 22:38 . 2008-11-06 22:38 14,691 –a—— c:\program files\Common Files\vupo.vbs
2008-11-06 22:38 . 2008-11-06 22:38 11,973 –a—— c:\windows\system32\qesaf._sy
2008-11-06 22:38 . 2008-11-06 22:38 11,397 –a—— c:\windows\system32\ecurocyx.sys
2008-11-06 22:38 . 2008-11-06 22:38 10,564 –a—— c:\windows\nucero.com
2008-10-28 09:20 . 2008-10-28 09:20 555,008 –a—— c:\windows\system32\nsk1E.dll
2008-10-24 03:33 . 2008-10-15 10:34 337,408 –a–c— c:\windows\system32\dllcache\netapi32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 00:13 49,152 —-a-w c:\windows\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin\PCHI18N.dll
2008-11-20 00:13 420,432 —-a-w c:\windows\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin\pchplugin.zip
2008-11-20 00:13 155,907 —-a-w c:\windows\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin\PCHButton.exe
2008-11-20 00:13 127,235 —-a-w c:\windows\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin\ContentUpdater.exe
2008-11-20 00:13 122,880 —-a-w c:\windows\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin\SearchCtrl.dll
2008-11-20 00:12 77,824 —-a-w c:\windows\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin\WinVerifyTrust.dll
2008-11-20 00:12 731,136 —-a-w c:\windows\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin\motdeusr.zip
2008-11-20 00:12 106,496 —-a-w c:\windows\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\bin\PluginCtrl.dll
2008-11-19 05:49 ——— d—–w c:\program files\Java
2008-11-19 03:41 ——— d—–w c:\program files\SpywareGuard
2008-11-19 03:37 ——— d—–w c:\documents and settings\Owner\Application Data\Apple Computer
2008-11-19 00:19 ——— d—–w c:\program files\Lavasoft
2008-11-19 00:19 ——— d—–w c:\documents and settings\Owner\Application Data\Lavasoft
2008-11-11 20:27 ——— d—–w c:\program files\Zune
2008-11-09 18:29 30 —-a-w c:\documents and settings\Owner\jagex_runescape_preferences.dat
2008-11-09 05:52 11,054 —-a-w c:\program files\Common Files\domohidup.lib
2008-11-07 13:56 14,052 —-a-w c:\program files\Common Files\yruxyf.lib
2008-10-25 16:54 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-10 12:02 ——— d—–w c:\documents and settings\Owner\Application Data\U3
2008-09-30 22:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-15 12:12 1,846,400 —-a-w c:\windows\system32\win32k.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-19 1234712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"Easy SpyRemover"="c:\program files\Easy SpyRemover\EasySpyRemover.exe" [2008-11-18 4011760]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CompuServe 2000 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CompuServe 2000 Tray Icon.lnk
backup=c:\windows\pss\CompuServe 2000 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
backup=c:\windows\pss\hp center UI.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
–a—— 2002-06-18 00:11 69632 c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\checktime]
–a–c— 2002-01-26 14:05 45056 c:\program files\HPSelect\frontend\ct.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a—— 2002-05-15 04:29 155648 c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-03-30 09:36 267048 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
–a—— 2001-07-06 22:56 61440 c:\hp\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-09-22 18:20 53248 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
–a—— 2002-06-14 17:39 81920 c:\windows\system32\ps2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 22:37 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2003-11-16 08:46 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2001-12-19 00:39 212992 c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
–a—— 2002-05-09 09:01 155648 c:\program files\VERITAS Software\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
"28938:TCP"= 28938:TCP:*:Disabled:SolidNetworkManager
"28938:UDP"= 28938:UDP:*:Disabled:SolidNetworkManager


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0846921c-ceb1-11db-8e86-00402b4b6c81}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0846921d-ceb1-11db-8e86-00402b4b6c81}]
\Shell\AutoRun\command - AUTORUN\AUTORUN.EXE
.
Contents of the 'Scheduled Tasks' folder

2008-11-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

2007-01-19 c:\windows\Tasks\easy Internet sign-up.job
- c:\program files\Hewlett-Packard\EZ Internet Signup\HPSdpApp.exe [2002-04-19 22:10]
.
- - - - ORPHANS REMOVED - - - -

BHO-{A3E63A35-3B42-440D-913A-686C96CBADA8} - c:\windows\system32\opnlMgeE.dll
Notify-khfCrssP - khfCrssP.dll
Notify-ljJASihg - ljJASihg.dll
Notify-WgaLogon - (no file)
MSConfigStartUp-DDCActiveMenu - c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe
MSConfigStartUp-DDCM - c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe
MSConfigStartUp-wdckiezgjfdjofedp - c:\windows\system32\xlahokrtxquki.dll


.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-23 16:55:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\KB951978.log 1978 bytes
c:\windows\system32\SETF.tmp 1106944 bytes executable

scan completed successfully
hidden files: 2

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\PackethSvc.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\windows\system32\snmp.exe
c:\windows\system32\fxssvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\SoftwareDistribution\Download\Install\windows-kb890830-v2.4-delta.exe
c:\21c40c37a899bbc24f2b\mrtstub.exe
c:\windows\system32\MRT.exe
.
**************************************************************************
.
Completion time: 2008-11-23 17:14:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-23 23:13:41

Pre-Run: 12,369,772,544 bytes free
Post-Run: 12,389,400,576 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

284 — E O F — 2008-11-20 00:40:10


HJT log (after combofix run)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:19:40 PM, on 11/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\windows\system\hpsysdrv.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\SoftwareDistribution\Download\Install\windows-kb890830-v2.4-delta.exe
c:\21c40c37a899bbc24f2b\mrtstub.exe
C:\WINDOWS\system32\MRT.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Easy SpyRemover] C:\Program Files\Easy SpyRemover\EasySpyRemover.exe /smart
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227054735773
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

–
End of file - 5816 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\eenoxaxygwxxbywp.exe
c:\windows\fewuk._sy
c:\documents and settings\Owner\Application Data\zenitulise.com
c:\windows\etuqevef.ban
c:\windows\system32\ibifi.pif
c:\windows\ycijyryxo.inf
c:\program files\Common Files\gipacykyte.vbs
c:\windows\system32\zyzetodek.pif
c:\documents and settings\All Users\Application Data\oquc.com
c:\windows\ovokozepyz.dat
c:\windows\system32\olusyxove.bin
c:\windows\byfele.scr
c:\windows\duwig.reg
c:\program files\Common Files\upiqofoh.reg
c:\windows\system32\qejiq.lib
c:\windows\jygikexop.reg
c:\documents and settings\Owner\Application Data\matakeku.exe
c:\windows\hafagiga.sys
c:\windows\saluwebi.dat
c:\windows\system32\vuqywinuc._sy
c:\windows\ygih.exe
c:\windows\tiqajypyne.db
c:\windows\system32\uzasihener.com
c:\windows\emivyqoru.com
c:\windows\system32\lymoh.exe
c:\windows\system32\ivymokib._sy
c:\windows\vexywobo.exe
c:\program files\Common Files\diferosol.dat
c:\windows\gykutyfyb.exe
c:\windows\nyzuti.scr
c:\documents and settings\All Users\Application Data\yvoreje.pif
c:\program files\Common Files\jorozaqugi.vbs
c:\windows\dagomite.inf
c:\windows\ejyg.pif
c:\windows\adevaxirow.lib
c:\windows\vybemo._dl
c:\windows\system32\uvakijohar._sy
c:\windows\eminoloq.bin
c:\windows\system32\joheben.reg
c:\documents and settings\Owner\Application Data\qymaxy.com
c:\documents and settings\Owner\Application Data\enuwa.sys
c:\program files\Common Files\joso.exe
c:\documents and settings\Owner\Application Data\asorogaj.bin
c:\documents and settings\Owner\Application Data\rixugiko.bat
c:\windows\system32\adejebarur.dat
c:\program files\Common Files\vupo.vbs
c:\windows\system32\qesaf._sy
c:\windows\system32\ecurocyx.sys
c:\windows\nucero.com
c:\windows\system32\nsk1E.dll
c:\program files\Common Files\domohidup.lib
c:\program files\Common Files\yruxyf.lib

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0846921d-ceb1-11db-8e86-00402b4b6c81}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Good news! No virus alerts popped up :) Still get redirected using Desktop shortcut for IE. However, direct typing in www.dogpile.com, www.yahoo.com works fine. Speed is increasing when opening programs.

Did as instructed - moved the file to combofix.exe, ran and ran HJT. Heeeeere's the logs (think the John Carson Show when you read that…. LOL)

ComboFix 08-11-22.02 - Owner 2008-11-23 18:07:32.2 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-10-24 to 2008-11-24 )))))))))))))))))))))))))))))))
.

2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-11-23 15:11 . 2008-11-23 15:11 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-23 15:11 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-23 15:11 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-23 14:28 . 2008-11-23 14:28 d——– c:\program files\Trend Micro
2008-11-23 13:58 . 2008-11-23 14:30 d——– C:\HIJACK LOG
2008-11-23 12:45 . 2008-11-23 12:45 d——– c:\program files\NoAdware
2008-11-23 11:36 . 2008-11-23 11:37 d——– c:\program files\Easy SpyRemover
2008-11-23 11:35 . 2008-11-23 11:35 d——– c:\program files\ERUNT
2008-11-19 23:38 . 2008-11-23 15:20 d–h—– C:\$AVG8.VAULT$
2008-11-19 22:07 . 2008-11-19 22:07 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2008-11-19 22:07 . 2008-11-19 22:07 10,520 –a—— c:\windows\system32\avgrsstx.dll
2008-11-19 22:06 . 2008-11-23 15:45 d——– c:\windows\system32\drivers\Avg
2008-11-19 22:06 . 2008-11-19 22:06 d——– c:\program files\AVG
2008-11-19 22:06 . 2008-11-23 10:53 d——– c:\documents and settings\Owner\Application Data\AVGTOOLBAR
2008-11-19 22:06 . 2008-11-19 22:06 d——– c:\documents and settings\All Users\Application Data\avg8
2008-11-19 21:39 . 2008-11-19 21:39 d——– c:\documents and settings\All Users\Application Data\America Online
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\system32\scripting
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\system32\en
2008-11-19 18:07 . 2008-11-19 18:07 d——– c:\windows\l2schemas
2008-11-19 17:27 . 2008-09-04 11:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-19 17:27 . 2008-10-24 05:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\TeaTimer (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\SDHelper (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-11-18 22:10 . 2008-11-18 22:10 d——– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-11-18 18:16 . 2008-11-18 18:22 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-18 18:13 . 2008-11-18 18:13 d——– c:\program files\Common Files\Wise Installation Wizard
2008-11-18 16:38 . 2008-11-18 16:38 53,938 –a—— c:\windows\system32\cont_adsoftinc-remove.exe
2008-11-18 16:38 . 2008-11-20 16:53 47,575 –a—— c:\windows\system32\eenoxaxygwxxbywp.exe
2008-11-18 16:36 . 2008-04-13 12:47 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-11-09 01:43 . 2008-11-09 01:43 19,632 –a—— c:\windows\fewuk._sy
2008-11-09 01:43 . 2008-11-09 01:43 19,295 –a—— c:\documents and settings\Owner\Application Data\zenitulise.com
2008-11-09 01:43 . 2008-11-09 01:43 19,125 –a—— c:\windows\etuqevef.ban
2008-11-09 01:43 . 2008-11-09 01:43 18,822 –a—— c:\windows\system32\ibifi.pif
2008-11-09 01:43 . 2008-11-09 01:43 16,720 –a—— c:\windows\ycijyryxo.inf
2008-11-09 01:43 . 2008-11-09 01:43 16,244 –a—— c:\program files\Common Files\gipacykyte.vbs
2008-11-09 01:43 . 2008-11-09 01:43 14,684 –a—— c:\windows\system32\zyzetodek.pif
2008-11-09 01:43 . 2008-11-09 01:43 12,635 –a—— c:\documents and settings\All Users\Application Data\oquc.com
2008-11-09 01:43 . 2008-11-09 01:43 12,617 –a—— c:\windows\ovokozepyz.dat
2008-11-09 01:43 . 2008-11-09 01:43 11,937 –a—— c:\windows\system32\olusyxove.bin
2008-11-09 01:43 . 2008-11-09 01:43 11,884 –a—— c:\windows\byfele.scr
2008-11-09 01:43 . 2008-11-09 01:43 11,767 –a—— c:\windows\duwig.reg
2008-11-09 01:43 . 2008-11-09 01:43 11,150 –a—— c:\program files\Common Files\upiqofoh.reg
2008-11-09 01:43 . 2008-11-09 01:43 10,057 –a—— c:\windows\system32\qejiq.lib
2008-11-08 23:52 . 2008-11-08 23:52 18,816 –a—— c:\windows\jygikexop.reg
2008-11-08 23:52 . 2008-11-08 23:52 18,681 –a—— c:\documents and settings\Owner\Application Data\matakeku.exe
2008-11-08 23:52 . 2008-11-08 23:52 18,457 –a—— c:\windows\hafagiga.sys
2008-11-08 23:52 . 2008-11-08 23:52 18,208 –a—— c:\windows\saluwebi.dat
2008-11-08 23:52 . 2008-11-08 23:52 17,742 –a—— c:\windows\system32\vuqywinuc._sy
2008-11-08 23:52 . 2008-11-08 23:52 17,658 –a—— c:\windows\ygih.exe
2008-11-08 23:52 . 2008-11-08 23:52 17,321 –a—— c:\windows\tiqajypyne.db
2008-11-08 23:52 . 2008-11-08 23:52 16,946 –a—— c:\windows\system32\uzasihener.com
2008-11-08 23:52 . 2008-11-08 23:52 16,156 –a—— c:\windows\emivyqoru.com
2008-11-08 23:52 . 2008-11-08 23:52 15,941 –a—— c:\windows\system32\lymoh.exe
2008-11-08 23:52 . 2008-11-08 23:52 15,136 –a—— c:\windows\system32\ivymokib._sy
2008-11-08 23:52 . 2008-11-08 23:52 14,073 –a—— c:\windows\vexywobo.exe
2008-11-08 23:52 . 2008-11-08 23:52 13,371 –a—— c:\program files\Common Files\diferosol.dat
2008-11-08 23:52 . 2008-11-08 23:52 12,585 –a—— c:\windows\gykutyfyb.exe
2008-11-07 09:25 . 2008-11-23 11:01 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-07 09:25 . 2008-11-07 09:25 1,409 –a—— c:\windows\QTFont.for
2008-11-07 08:02 . 2008-11-07 08:02 118 –a—— c:\windows\system32\MRT.INI
2008-11-07 07:56 . 2008-11-07 07:56 19,760 –a—— c:\windows\nyzuti.scr
2008-11-07 07:56 . 2008-11-07 07:56 14,896 –a—— c:\documents and settings\All Users\Application Data\yvoreje.pif
2008-11-07 07:56 . 2008-11-07 07:56 14,493 –a—— c:\program files\Common Files\jorozaqugi.vbs
2008-11-07 07:56 . 2008-11-07 07:56 13,061 –a—— c:\windows\dagomite.inf
2008-11-07 07:56 . 2008-11-07 07:56 12,093 –a—— c:\windows\ejyg.pif
2008-11-07 07:56 . 2008-11-07 07:56 12,026 –a—— c:\windows\adevaxirow.lib
2008-11-07 07:56 . 2008-11-07 07:56 10,396 –a—— c:\windows\vybemo._dl
2008-11-07 07:55 . 2008-11-07 07:56 16,933 –a—— c:\windows\system32\uvakijohar._sy
2008-11-07 07:55 . 2008-11-07 07:55 15,719 –a—— c:\windows\eminoloq.bin
2008-11-07 07:55 . 2008-11-07 07:55 14,061 –a—— c:\windows\system32\joheben.reg
2008-11-07 07:38 . 2008-11-07 07:38 14,387 –a—— c:\documents and settings\Owner\Application Data\qymaxy.com
2008-11-06 22:38 . 2008-11-06 22:38 19,859 –a—— c:\documents and settings\Owner\Application Data\enuwa.sys
2008-11-06 22:38 . 2008-11-06 22:38 19,120 –a—— c:\program files\Common Files\joso.exe
2008-11-06 22:38 . 2008-11-06 22:38 18,968 –a—— c:\documents and settings\Owner\Application Data\asorogaj.bin
2008-11-06 22:38 . 2008-11-06 22:38 17,796 –a—— c:\documents and settings\Owner\Application Data\rixugiko.bat
2008-11-06 22:38 . 2008-11-06 22:38 15,932 –a—— c:\windows\system32\adejebarur.dat
2008-11-06 22:38 . 2008-11-06 22:38 14,691 –a—— c:\program files\Common Files\vupo.vbs
2008-11-06 22:38 . 2008-11-06 22:38 11,973 –a—— c:\windows\system32\qesaf._sy
2008-11-06 22:38 . 2008-11-06 22:38 11,397 –a—— c:\windows\system32\ecurocyx.sys
2008-11-06 22:38 . 2008-11-06 22:38 10,564 –a—— c:\windows\nucero.com
2008-10-28 09:20 . 2008-10-28 09:20 555,008 –a—— c:\windows\system32\nsk1E.dll
2008-10-24 03:33 . 2008-10-15 10:34 337,408 –a–c— c:\windows\system32\dllcache\netapi32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 05:49 ——— d—–w c:\program files\Java
2008-11-19 03:41 ——— d—–w c:\program files\SpywareGuard
2008-11-19 03:37 ——— d—–w c:\documents and settings\Owner\Application Data\Apple Computer
2008-11-19 00:19 ——— d—–w c:\program files\Lavasoft
2008-11-19 00:19 ——— d—–w c:\documents and settings\Owner\Application Data\Lavasoft
2008-11-11 20:27 ——— d—–w c:\program files\Zune
2008-11-09 18:29 30 —-a-w c:\documents and settings\Owner\jagex_runescape_preferences.dat
2008-11-09 05:52 11,054 —-a-w c:\program files\Common Files\domohidup.lib
2008-11-07 13:56 14,052 —-a-w c:\program files\Common Files\yruxyf.lib
2008-10-25 16:54 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-10 12:02 ——— d—–w c:\documents and settings\Owner\Application Data\U3
.

((((((((((((((((((((((((((((( snapshot@2008-11-23_17.09.40.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-24 11:21:09 455,296 ——w c:\windows\Driver Cache\i386\mrxsmb.sys
- 2008-10-07 18:19:42 16,721,856 —-a-w c:\windows\system32\MRT.exe
+ 2008-11-04 00:10:25 17,318,336 —-a-w c:\windows\system32\MRT.exe
- 2008-04-14 00:12:01 1,104,896 —-a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 17:15:04 1,106,944 —-a-w c:\windows\system32\msxml3.dll
- 2007-11-30 11:18:51 17,272 —-a-w c:\windows\system32\spmsg.dll
+ 2008-07-08 13:02:01 17,272 ——w c:\windows\system32\spmsg.dll
+ 2008-11-23 23:41:24 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_660.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-19 1234712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2008-04-13 169984]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CompuServe 2000 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\CompuServe 2000 Tray Icon.lnk
backup=c:\windows\pss\CompuServe 2000 Tray Icon.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
backup=c:\windows\pss\hp center UI.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CamMonitor]
–a—— 2002-06-18 00:11 69632 c:\program files\Hewlett-Packard\Digital Imaging\Unload\HpqCmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\checktime]
–a–c— 2002-01-26 14:05 45056 c:\program files\HPSelect\frontend\ct.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy SpyRemover]
–a—— 2008-11-18 14:20 4011760 c:\program files\Easy SpyRemover\EasySpyRemover.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a—— 2002-05-15 04:29 155648 c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-03-30 09:36 267048 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
–a—— 2001-07-06 22:56 61440 c:\hp\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
–a—— 2004-09-22 18:20 53248 c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
–a—— 2002-06-14 17:39 81920 c:\windows\system32\ps2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-03-28 22:37 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2003-11-16 08:46 26112 c:\program files\Real\RealPlayer\realplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2001-12-19 00:39 212992 c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
–a—— 2002-05-09 09:01 155648 c:\program files\VERITAS Software\Update Manager\sgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SonicWALL\\SonicWALL Global VPN Client\\SWGVpnClient.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
"28938:TCP"= 28938:TCP:*:Disabled:SolidNetworkManager
"28938:UDP"= 28938:UDP:*:Disabled:SolidNetworkManager

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-11-19 97928]
R1 RCFOX;SonicWALL IPsec Driver;\??\c:\windows\system32\Drivers\RCFOX.sys [2008-05-17 101528]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-19 231704]
R2 PackethSvc;Virtual NIC Service;c:\windows\system32\PackethSvc.exe [2003-11-16 64512]
R2 zumbus;Zune Bus Enumerator Driver;c:\windows\system32\DRIVERS\zumbus.sys [2008-01-11 40832]
R3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\DRIVERS\rcvpn.sys [2008-05-17 24876]
S4 hpt3xx;hpt3xx; []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0846921c-ceb1-11db-8e86-00402b4b6c81}]
\Shell\AutoRun\command - F:\LaunchU3.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0846921d-ceb1-11db-8e86-00402b4b6c81}]
\Shell\AutoRun\command - AUTORUN\AUTORUN.EXE
.
Contents of the 'Scheduled Tasks' folder

2008-11-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]

2007-01-19 c:\windows\Tasks\easy Internet sign-up.job
- c:\program files\Hewlett-Packard\EZ Internet Signup\HPSdpApp.exe [2002-04-19 22:10]
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Yahoo;! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary; - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps; - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS; - file:///c:\program files\Yahoo!\Common/ycsms.htm

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-23 18:17:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-11-23 18:23:22
ComboFix-quarantined-files.txt 2008-11-24 00:23:00
ComboFix2.txt 2008-11-23 23:14:50

Pre-Run: 12,416,589,824 bytes free
Post-Run: 12,399,067,136 bytes free

235 — E O F — 2008-11-23 23:23:06


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:30:46 PM, on 11/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227054735773
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - https://disney.go.com/games/downloads/gamem…GameManager.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\system32\PackethSvc.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe

–
End of file - 5624 bytes
Try that again. It didn't remove the bad files.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\eenoxaxygwxxbywp.exe
c:\windows\fewuk._sy
c:\documents and settings\Owner\Application Data\zenitulise.com
c:\windows\etuqevef.ban
c:\windows\system32\ibifi.pif
c:\windows\ycijyryxo.inf
c:\program files\Common Files\gipacykyte.vbs
c:\windows\system32\zyzetodek.pif
c:\documents and settings\All Users\Application Data\oquc.com
c:\windows\ovokozepyz.dat
c:\windows\system32\olusyxove.bin
c:\windows\byfele.scr
c:\windows\duwig.reg
c:\program files\Common Files\upiqofoh.reg
c:\windows\system32\qejiq.lib
c:\windows\jygikexop.reg
c:\documents and settings\Owner\Application Data\matakeku.exe
c:\windows\hafagiga.sys
c:\windows\saluwebi.dat
c:\windows\system32\vuqywinuc._sy
c:\windows\ygih.exe
c:\windows\tiqajypyne.db
c:\windows\system32\uzasihener.com
c:\windows\emivyqoru.com
c:\windows\system32\lymoh.exe
c:\windows\system32\ivymokib._sy
c:\windows\vexywobo.exe
c:\program files\Common Files\diferosol.dat
c:\windows\gykutyfyb.exe
c:\windows\nyzuti.scr
c:\documents and settings\All Users\Application Data\yvoreje.pif
c:\program files\Common Files\jorozaqugi.vbs
c:\windows\dagomite.inf
c:\windows\ejyg.pif
c:\windows\adevaxirow.lib
c:\windows\vybemo._dl
c:\windows\system32\uvakijohar._sy
c:\windows\eminoloq.bin
c:\windows\system32\joheben.reg
c:\documents and settings\Owner\Application Data\qymaxy.com
c:\documents and settings\Owner\Application Data\enuwa.sys
c:\program files\Common Files\joso.exe
c:\documents and settings\Owner\Application Data\asorogaj.bin
c:\documents and settings\Owner\Application Data\rixugiko.bat
c:\windows\system32\adejebarur.dat
c:\program files\Common Files\vupo.vbs
c:\windows\system32\qesaf._sy
c:\windows\system32\ecurocyx.sys
c:\windows\nucero.com
c:\windows\system32\nsk1E.dll
c:\program files\Common Files\domohidup.lib
c:\program files\Common Files\yruxyf.lib

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0846921d-ceb1-11db-8e86-00402b4b6c81}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I copied the code file as instructed and saved to thumb drive then drug the CFScript.txt to Combofix.exe from the thumb drive…(4 times cuz I wasn't sure it was working) each time the combofix progress bar came up, but I had to manually start Combofix after. Do you think there is another issue/problem or should I try it directly on that computer - not use the thumb drive?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI