This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] My Desktop is gone

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My desktop is gone, i have no icons on my DESKTOP.
Even when i restart my computer the DESKTOP shows up then disappears.
I cant use START because everything is gone.
The only way i got to my browser is by using the HOME key on my keyboard.
I know i have a Trojan Horse Vudo.BG but i dont know what to do.
ANY HELP?




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:40:31 PM, on 12/3/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Micro Innovations\Multimedia Keyboard Driver\KMWDSrv.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avant Browser\avant.exe
C:\Documents and Settings\Owner\Desktop\Downloaded\Yah00 stuff\avenger.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O3 - Toolbar: FreshDownload Bar - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdiebar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Micro Innovations\Multimedia Keyboard Driver\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [prunnet] "C:\WINDOWS\system32\prunnet.exe"
O4 - HKLM\..\Run: [Eguwiroq] rundll32.exe "C:\WINDOWS\Dxajipidurayape.dll",e
O4 - HKLM\..\Run: [Ydacecikot] rundll32.exe "C:\WINDOWS\atajehuc.dll",e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Yahoo Lag Killer.lnk = C:\Program Files\Yahoo Lag Killer\YahooLagKiller.exe
O8 - Extra context menu item: &Search - ?p=ZCxdm651YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: FreshDownload - {82662E8D-D582-439C-B90A-C1F86E66ABC2} - C:\Program Files\FreshDevices\FreshDownload\fd.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.avsystemcare.com
O15 - Trusted Zone: *.onerateld.com
O15 - Trusted Zone: *.safetydownload.com
O15 - Trusted Zone: *.trustedantivirus.com
O15 - Trusted Zone: *.virusschlacht.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/gs.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA3F464F-1E5F-4003-B2A8-A1A8E6EB2D7C}: NameServer = 72.14.79.9,69.60.160.203
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Micro Innovations\Multimedia Keyboard Driver\KMWDSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Stormser - Unknown owner - C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe (file missing)

–
End of file - 6666 bytes
Hello

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.
ComboFix 08-12-02.02 - Owner 2008-12-03 13:27:21.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.93 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\Downloaded\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\salesmonitor
c:\documents and settings\Owner\Application Data\gadcom
c:\documents and settings\Owner\Application Data\NI.GSCNS
c:\documents and settings\Owner\Application Data\NI.GSCNS\dl.ini
c:\documents and settings\Owner\Application Data\NI.GSCNS\settings.ini
c:\windows\system32\drivers\npf.sys
c:\windows\system32\efcyWpOE.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pmnLfdCr.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\rCdfLnmp.ini
c:\windows\system32\rCdfLnmp.ini2
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\Tasks\rspyombp.job
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-11-03 to 2008-12-03 )))))))))))))))))))))))))))))))
.

2008-12-03 12:39 . 2008-12-03 12:39 d——– c:\program files\Trend Micro
2008-12-02 11:07 . 2008-12-02 11:07 142,848 –a—— c:\windows\atajehuc.dll
2008-12-02 07:11 . 2008-12-02 07:11 38,144 –a—— C:\bflkwx.exe
2008-12-02 07:11 . 2008-12-02 07:11 24,576 –a—— c:\windows\Dxajipidurayape.dll
2008-12-02 06:58 . 2008-12-02 06:58 34,816 –a—— c:\windows\system32\hgGywuUL.dll
2008-12-02 06:46 . 2008-12-02 06:46 32,768 –a—— c:\windows\system32\geBsspqQ.dll
2008-12-02 06:32 . 2008-12-02 06:32 32,768 –a—— c:\windows\system32\mlJDvsst.dll
2008-11-29 16:04 . 2008-11-29 16:04 d——– c:\program files\Micro Innovations
2008-11-29 16:04 . 2007-03-29 15:00 17,024 –a—— c:\windows\system32\drivers\KMWDFilter.SYS
2008-11-29 16:01 . 2008-04-14 05:41 21,504 –a—— c:\windows\system32\hidserv.dll
2008-11-29 16:01 . 2008-04-14 05:41 21,504 –a–c— c:\windows\system32\dllcache\hidserv.dll
2008-11-29 16:01 . 2008-04-14 00:09 14,592 –a—— c:\windows\system32\drivers\kbdhid.sys
2008-11-29 16:01 . 2008-04-14 00:09 14,592 –a–c— c:\windows\system32\dllcache\kbdhid.sys
2008-11-29 16:01 . 2001-08-17 13:48 12,160 –a—— c:\windows\system32\drivers\mouhid.sys
2008-11-29 16:01 . 2001-08-17 13:48 12,160 –a–c— c:\windows\system32\dllcache\mouhid.sys
2008-11-29 16:00 . 2008-04-14 00:15 10,368 –a—— c:\windows\system32\drivers\hidusb.sys
2008-11-29 16:00 . 2008-04-14 00:15 10,368 –a–c— c:\windows\system32\dllcache\hidusb.sys
2008-11-18 17:10 . 2008-12-02 12:09 54,156 –ah—– c:\windows\QTFont.qfn
2008-11-18 17:10 . 2008-11-18 17:10 1,409 –a—— c:\windows\QTFont.for
2008-11-12 02:46 . 2008-10-24 05:21 455,296 –a–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 02:41 . 2008-09-04 11:15 1,106,944 –a–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-10 08:56 . 2008-11-10 08:56 d——– c:\program files\Yahoo Lag Killer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-02 19:03 ——— d—–w c:\documents and settings\Owner\Application Data\foobar2000
2008-12-01 16:19 30,569 —-a-w C:\report.zip
2008-11-29 22:05 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-28 22:06 ——— d—–w c:\documents and settings\Owner\Application Data\Azureus
2008-11-28 19:01 ——— d—–w c:\program files\PokerStars
2008-11-28 04:20 ——— d—–w c:\documents and settings\Owner\Application Data\Audacity
2008-11-22 17:45 ——— d—–w c:\program files\DivX
2008-11-20 15:35 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-11-19 13:12 ——— d—–w c:\program files\Avant Browser
2008-11-09 19:49 ——— d—–w c:\program files\foobar2000
2008-11-06 17:47 ——— d—–w c:\documents and settings\Owner\Application Data\AdobeUM
2008-11-05 13:21 ——— d—–w c:\program files\Opera
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-16 20:13 202,776 —-a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 1,809,944 —-a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:12 561,688 —-a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 323,608 —-a-w c:\windows\system32\wucltui.dll
2008-10-16 20:09 92,696 —-a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 —-a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 43,544 -c–a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 -c–a-w c:\windows\system32\wups.dll
2008-10-16 20:06 268,648 —-a-w c:\windows\system32\mucltui.dll
2008-10-16 20:06 208,744 —-a-w c:\windows\system32\muweb.dll
2008-10-16 13:37 ——— d—–w c:\documents and settings\Owner\Application Data\vlc
2008-10-04 16:53 ——— d—–w c:\program files\Doras Carnival Adventure
2008-09-30 22:43 1,286,152 —-a-w c:\windows\system32\msxml4.dll
2008-09-25 15:06 185,920 -c–a-w c:\windows\system32\pnup1.dll
2008-09-25 15:05 348,160 —-a-w c:\windows\system32\msvcr71.dll
2008-09-19 21:55 200,704 -c–a-w c:\windows\system32\ssldivx.dll
2008-09-19 21:55 1,044,480 -c–a-w c:\windows\system32\libdivx.dll
2008-09-15 12:12 1,846,400 —-a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 -c–a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 —-a-w c:\windows\system32\msxml3.dll
2008-05-07 02:41 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050620080507\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E155B5F-DD8C-4BF9-A03F-2256AFE8E3D0}]
2008-12-03 13:50 302592 –a—— c:\windows\system32\khfCrRLd.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
2008-12-02 06:32 32768 –a—— c:\windows\system32\mlJDvsst.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2003-11-03 221184]
"Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2003-10-29 135168]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-25 185872]
"KMCONFIG"="c:\program files\Micro Innovations\Multimedia Keyboard Driver\StartAutorun.exe" [2007-03-06 212992]
"Eguwiroq"="c:\windows\Dxajipidurayape.dll" [2008-12-02 24576]
"Ydacecikot"="c:\windows\atajehuc.dll" [2008-12-02 142848]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 c:\windows\system32\narrator.exe]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2004-12-26 225280]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Yahoo Lag Killer.lnk - c:\program files\Yahoo Lag Killer\YahooLagKiller.exe [2008-11-10 221184]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= "c:\windows\system32\mlJDvsst.dll" [2008-12-02 32768]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJDvsst]
2008-12-02 06:32 32768 c:\windows\system32\mlJDvsst.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 c:\windows\system32\khfCrRLd

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=c:\windows\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a–c— 2006-01-12 14:40 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-09-25 09:03 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a–c— 2007-08-30 16:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Avant Browser\\avant.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Zone.com Deluxe Games\\Wheel of Fortune Deluxe\\Wheel of Fortune Deluxe.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Opera\\opera.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-05-02 97928]
R2 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-05-02 76040]
R3 FwHookDrv;FwHookDrv;\??\c:\program files\Yahoo Lag Killer\FwHookDrv.sys [2008-11-10 6060]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\DRIVERS\mr97310v.sys [2006-07-18 99840]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54671340-a80f-11dd-b924-000c76eb31cb}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL iexplore http://www.mgae.com/keylauncher/?code=3654402025325894
.
Contents of the 'Scheduled Tasks' folder

2008-11-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-12-03 c:\windows\Tasks\B932E7F0901D981C.job
- c:\docume~1\owner\applic~1\curbma~1\kind play file.exe []
.
- - - - ORPHANS REMOVED - - - -

BHO-{140BD8E3-C167-11D4-B4A3-080000180323} - (no file)
BHO-{CD5E91F8-E4A5-4074-9318-B4BBB7454952} - c:\windows\system32\pmnLfdCr.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKLM-Run-prunnet - c:\windows\system32\prunnet.exe
HKLM-Run-VTTimer - VTTimer.exe
MSConfigStartUp-mmtask - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
MSConfigStartUp-MMTray - c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
MSConfigStartUp-RealPlayer - c:\program files\Real\RealOne Player\realplay.exe
MSConfigStartUp-StormCodec_Helper - c:\program files\Ringz Studio\Storm Codec\StormSet.exe
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\zd25l0t3.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://yahoo.com
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npfd.dll
FF -: plugin - c:\program files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-03 13:42:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(560)
c:\windows\system32\mlJDvsst.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\program files\Micro Innovations\Multimedia Keyboard Driver\KMWDSrv.exe
c:\windows\system32\HPZipm12.exe
c:\progra~1\AVG\AVG8\avgemc.exe
c:\windows\system32\rundll32.exe
c:\program files\Micro Innovations\Multimedia Keyboard Driver\KMCONFIG.exe
c:\program files\Micro Innovations\Multimedia Keyboard Driver\KMProcess.exe
c:\windows\system32\rundll32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2008-12-03 13:56:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-03 19:56:15

Pre-Run: 2,861,326,336 bytes free
Post-Run: 2,998,693,888 bytes free

240 — E O F — 2008-11-12 09:36:39
Hello

Open notepad and copy/paste the text in the quotebox below into it:
http://forums.whatthetech.com/My_Desktop_gone_t97517.html#entry506239

Collect::
c:\windows\atajehuc.dll
C:\bflkwx.exe
c:\windows\Dxajipidurayape.dll
c:\windows\system32\hgGywuUL.dll
c:\windows\system32\geBsspqQ.dll
c:\windows\system32\mlJDvsst.dll

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{54671340-a80f-11dd-b924-000c76eb31cb}]


Suspect::
Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions to copy/paste/send the requested file.
THANKS MAN!!!!! :thumbup:
No other site responded back quick as u did & everything back to normal.
I'll come to this site first for anything else.
lol ever bored & need a webcam girl to watch on yahoo just let me know

This was the last Combofix.txt



ComboFix 08-12-02.02 - Owner 2008-12-03 15:23:32.2 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\Downloaded\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\Downloaded\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\bflkwx.exe
c:\windows\atajehuc.dll
c:\windows\Dxajipidurayape.dll
c:\windows\system32\dLRrCfhk.ini
c:\windows\system32\dLRrCfhk.ini2
c:\windows\system32\geBsspqQ.dll
c:\windows\system32\hgGywuUL.dll
c:\windows\system32\khfCrRLd.dll
c:\windows\system32\mlJDvsst.dll

.
((((((((((((((((((((((((( Files Created from 2008-11-03 to 2008-12-03 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 18:39 ——— d—–w c:\program files\Trend Micro
2008-12-01 16:19 30,569 —-a-w C:\report.zip
2008-11-29 22:05 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-29 22:04 4,710 —-a-r c:\windows\Installer\{F3851216-07F7-4D04-9820-660C889F4C33}\ARPPRODUCTICON.exe
2008-11-29 22:04 ——— d—–w c:\program files\Micro Innovations
2008-11-28 19:01 ——— d—–w c:\program files\PokerStars
2008-11-22 17:45 ——— d—–w c:\program files\DivX
2008-11-20 15:35 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-11-19 13:12 ——— d—–w c:\program files\Avant Browser
2008-11-12 09:22 794,624 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
2008-11-12 09:22 409,600 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
2008-11-12 09:22 4,096 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
2008-11-12 09:22 286,720 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
2008-11-12 09:22 27,136 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
2008-11-12 09:22 249,856 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
2008-11-12 09:22 23,040 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
2008-11-12 09:22 135,168 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
2008-11-12 09:22 12,288 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
2008-11-12 09:22 11,264 —-a-r c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
2008-11-12 09:06 32,768 —-a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
2008-11-10 14:56 ——— d—–w c:\program files\Yahoo Lag Killer
2008-11-09 19:49 ——— d—–w c:\program files\foobar2000
2008-11-06 17:47 25,214 —-a-r c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A70000000000}\SC_Reader.exe
2008-11-05 13:21 ——— d—–w c:\program files\Opera
2008-10-24 11:41 455,936 —-a-w c:\windows\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys
2008-10-24 11:21 455,296 ——w c:\windows\Driver Cache\i386\mrxsmb.sys
2008-10-15 16:25 339,456 —-a-w c:\windows\$hf_mig$\KB958644\SP3QFE\netapi32.dll
2008-10-04 16:53 ——— d—–w c:\program files\Doras Carnival Adventure
2008-10-03 17:26 6,068,224 —-a-w c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\ieframe.dll
2008-09-15 12:25 1,846,912 —-a-w c:\windows\$hf_mig$\KB954211\SP3QFE\win32k.sys
2008-09-10 01:10 1,379,840 -c–a-w c:\windows\$hf_mig$\KB954459\SP3QFE\msxml6.dll
2008-09-08 11:37 333,824 —-a-w c:\windows\$hf_mig$\KB957095\SP3QFE\srv.sys
2008-09-04 17:12 1,106,944 —-a-w c:\windows\$hf_mig$\KB955069\SP3QFE\msxml3.dll
2008-05-07 02:41 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008050620080507\index.dat
.
\user32.dll … is infected !!
577,024 2005-03-02 18:09:30 c:\windows\$hf_mig$\KB890859\SP2GDR\user32.dll
577,024 2005-03-02 18:19:56 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
577,536 2007-03-08 15:36:28 c:\windows\$NtServicePackUninstall$\user32.dll
577,024 2004-08-04 07:56:46 c:\windows\$NtServicePackUninstall$\user32.dll.000
265,649 2003-08-16 01:53:46 c:\windows\I386\USER32.DL_
578,560 2008-04-14 10:42:10 c:\windows\ServicePackFiles\i386\user32.dll
578,560 2008-04-14 10:42:10 c:\windows\system32\user32.dll


((((((((((((((((((((((((((((( snapshot@2008-12-03_13.53.58.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-03 21:18:46 389,120 —-a-w c:\windows\system32\CF9593.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-08-20 118784]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2003-11-03 221184]
"Sunkist2k"="c:\program files\Multimedia Card Reader\shwicon2k.exe" [2003-10-29 135168]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-08-20 155648]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-11-27 1261336]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-10 385024]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-25 185872]
"KMCONFIG"="c:\program files\Micro Innovations\Multimedia Keyboard Driver\StartAutorun.exe" [2007-03-06 212992]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 c:\windows\system32\narrator.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\\WINDOWS\\system32\\userinit.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= c:\windows\system32\l3codeca.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=c:\windows\pss\Compaq Connections.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=c:\windows\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a–c— 2006-01-12 14:40 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-09-25 09:03 185872 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a–c— 2007-08-30 16:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001


*Newly Created Service* - FWHOOKDRV
.
- - - - ORPHANS REMOVED - - - -

BHO-{1E155B5F-DD8C-4BF9-A03F-2256AFE8E3D0} - c:\windows\system32\khfCrRLd.dll
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKLM-Run-Eguwiroq - c:\windows\Dxajipidurayape.dll
HKLM-Run-Ydacecikot - c:\windows\atajehuc.dll
Notify-mlJDvsst - mlJDvsst.dll



**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-03 16:05:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\smss.exe
c:\windows\system32\csrss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\AVG\AVG8\avgwdsvc.exe
c:\program files\Micro Innovations\Multimedia Keyboard Driver\KMWDSrv.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\svchost.exe
c:\windows\system32\CF9593.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgemc.exe
c:\windows\system32\alg.exe
c:\program files\Micro Innovations\Multimedia Keyboard Driver\KMCONFIG.exe
c:\program files\Yahoo Lag Killer\YahooLagKiller.exe
c:\program files\Micro Innovations\Multimedia Keyboard Driver\KMProcess.exe
.
**************************************************************************
.
Completion time: 2008-12-03 16:16:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-03 22:15:44
ComboFix2.txt 2008-12-03 19:56:29

Pre-Run: 2,989,633,536 bytes free
Post-Run: 2,976,387,072 bytes free

172 — E O F — 2008-11-12 09:36:39
Will you let the people at TechGuy.org and any other forums you posted at that I am helping you, just so they don't reply as it will be a waste of their time

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::

Folder::
FCopy::
c:\windows\$NtServicePackUninstall$\user32.dll | c:\windows\system32\user32.dll

FileLook::
c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
C:\report.zip

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.





Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI