This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Removing Virtumonde

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:40:26 PM, on 12/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL

= http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

http://toolbar.aol.com/uninstall.html?base…=tb50-ie-holida

y&browser=ie&instd=27-11-2008
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName

=
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no

file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} -

C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: NRA - {CC0D77AF-731A-4C50-A69D-2BC36ED01A97} - C:\Program

Files\NRA\Toolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware

Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program

Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: Create Mobile Favorite -

{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -

C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… -

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7}

- C:\Program Files\Hewlett-Packard\Smart Web

Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select -

{700259D7-1666-479a-93B1-3250410481E8} - C:\Program

Files\Hewlett-Packard\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games

ActiveX Control) -

http://disney.go.com/pirates/online/testAc…gned/DisneyOnli

neGames.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)

-

http://www.update.microsoft.com/microsoftu…trols/en/x86/cl

ient/wuweb_site.cab?1209170590968
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)

-

http://www.update.microsoft.com/microsoftu…trols/en/x86/cl

ient/muweb_site.cab?1209170581578
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash

Object) -

http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} -

http://imikimi.com/download/imikimi_plugin_0.5.1.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) -

http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll
O23 - Service: Creative Service for CDROM Access - Creative Technology

Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown

owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner

- C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA

Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools -

C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools -

C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software,

Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

Here is the combo fix log

ComboFix 08-12-29.02 - Administrator 2008-12-30 15:00:55.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.571 [GMT -8:00]
Running from: F:\ComboFix.exe
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\temp\tn3
c:\windows\system32\a.exe
c:\windows\system32\akgajepj.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\bajuwuge.dll
c:\windows\system32\bgqtetil.ini
c:\windows\system32\cmtxga.dll
c:\windows\system32\domfpr.dll
c:\windows\system32\drivers\fad.sys
c:\windows\system32\dtsgiroi.dll
c:\windows\system32\duisorvk.ini
c:\windows\system32\egfNUvut.ini
c:\windows\system32\egfNUvut.ini2
c:\windows\system32\eqwpdwiw.dll
c:\windows\system32\fijeoa.dll
c:\windows\system32\gavuzeyi.dll
c:\windows\system32\gsfwfxyj.dll
c:\windows\system32\hpowiax3.dll
c:\windows\system32\iorigstd.ini
c:\windows\system32\jituwuwa.dll
c:\windows\system32\kgmbyy.dll
c:\windows\system32\kipnhg.dll
c:\windows\system32\llcqyb.dll
c:\windows\system32\lpoycr.dll
c:\windows\system32\mhqmkxud.dll
c:\windows\system32\miwajiho.dll
c:\windows\SYSTEM32\mlJDwULE.dll
c:\windows\system32\nnnkJDSm.dll
c:\windows\system32\ntbotibu.dll
c:\windows\system32\orumohuw.ini
c:\windows\system32\qadambhk.dll
c:\windows\system32\rapepute.dll
c:\windows\system32\rqBbdfii.ini
c:\windows\system32\rqBbdfii.ini2
c:\windows\system32\sfbipkgb.dll
c:\windows\system32\sosilore.dll
c:\windows\system32\TDSSmtvd.dat
c:\windows\system32\tojedela.dll
c:\windows\system32\tuhinibo.dll
c:\windows\system32\tuvUNfge.dll
c:\windows\system32\vDKmlnnn.ini
c:\windows\system32\vDKmlnnn.ini2
c:\windows\system32\vtULdBQI.dll
c:\windows\system32\vxljaf.dll
c:\windows\system32\wgkajfdo.dll
c:\windows\system32\wirulxaj.dll
c:\windows\system32\wrxkmwie.dll
c:\windows\system32\xacIkUtv.ini
c:\windows\system32\xacIkUtv.ini2
c:\windows\system32\xsqbop.dll
c:\windows\system32\xwwamtdw.ini
c:\windows\system32\xxywUOHW.dll
c:\windows\system32\xxyxUlIa.dll
c:\windows\system32\xyfcckta.ini
c:\windows\system32\yajosofo.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_TNIDRIVER
——-\Service_TnIDriver


((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-30 )))))))))))))))))))))))))))))))
.

2008-12-30 14:22 . 2008-12-30 14:22 d——– C:\VundoFix Backups
2008-12-30 13:05 . 2008-12-30 13:05 d——– c:\documents and settings\Rick\Application Data\Malwarebytes
2008-12-30 13:05 . 2008-12-30 13:05 72,192 –a—— c:\windows\system32\ddcCVLda.dll
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-30 11:05 . 2008-12-30 11:05 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Malwarebytes
2008-12-30 11:05 . 2008-12-03 19:54 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-30 11:05 . 2008-12-03 19:54 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-30 09:24 . 2008-12-30 09:24 d——– c:\program files\Trend Micro
2008-12-30 08:01 . 2008-12-30 08:01 d–hs—- c:\documents and settings\LocalService\PrivacIE
2008-12-30 00:21 . 2008-12-30 00:21 d——– c:\program files\CCleaner
2008-12-29 16:45 . 2008-12-29 16:45 d——– c:\documents and settings\Rick\Application Data\PC Tools
2008-12-29 16:45 . 2008-12-29 16:45 d——– c:\documents and settings\All Users\Application Data\PC Tools
2008-12-29 16:45 . 2008-07-28 12:29 160,792 –a—— c:\windows\system32\drivers\pctfw2.sys
2008-12-29 13:30 . 2008-12-29 13:30 d–hs—- c:\documents and settings\Julie\PrivacIE
2008-12-28 22:32 . 2008-04-13 16:12 82,432 –ah—t- c:\windows\system32\2d38355a.dll
2008-12-28 22:32 . 2008-04-13 16:12 82,432 –ah—t- c:\windows\system32\14270c4.dll
2008-12-28 22:20 . 2008-12-28 22:20 d–hs—- c:\documents and settings\Rick\PrivacIE
2008-12-28 22:12 . 2008-12-28 22:14 d–h-c— c:\windows\ie8
2008-12-28 21:15 . 2008-12-28 21:15 d——– c:\documents and settings\Rick\Application Data\HPAppData
2008-12-28 21:15 . 2008-12-28 21:15 d——– c:\documents and settings\All Users\Application Data\HPSSUPPLY
2008-12-28 21:12 . 2008-12-28 21:12 d——– c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-12-28 21:08 . 2008-12-28 21:20 141,188 –a—— c:\windows\hpoins14.dat
2008-12-28 21:08 . 2007-09-19 17:14 2,000 ——— c:\windows\hpomdl14.dat
2008-12-28 16:13 . 2008-12-28 16:13 d——– c:\documents and settings\All Users\Application Data\McAfee
2008-12-28 16:01 . 2008-12-30 15:07 d——– c:\program files\Spyware Doctor
2008-12-28 16:01 . 2008-08-25 12:36 81,288 –a—— c:\windows\system32\drivers\iksyssec.sys
2008-12-28 16:01 . 2008-08-25 12:36 66,952 –a—— c:\windows\system32\drivers\iksysflt.sys
2008-12-28 16:01 . 2008-08-25 12:36 40,840 –a—— c:\windows\system32\drivers\ikfilesec.sys
2008-12-28 16:01 . 2008-06-02 16:19 29,576 –a—— c:\windows\system32\drivers\kcom.sys
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\program files\Webroot
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\program files\Common Files\Webroot Shared
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\documents and settings\Julie\Application Data\Webroot
2008-12-28 15:54 . 2008-12-28 15:54 d——– c:\documents and settings\All Users\Application Data\Webroot
2008-12-28 15:54 . 2007-11-26 14:47 194,888 –a—— c:\windows\Unwash6.exe
2008-12-28 15:03 . 2008-04-13 11:39 14,592 –a—— c:\windows\system32\drivers\kbdhid.sys
2008-12-28 12:40 . 2008-12-28 16:01 d——– c:\documents and settings\Julie\Application Data\PC Tools
2008-12-24 16:41 . 2008-12-24 16:41 d——– c:\program files\2WIRE, Inc
2008-12-24 16:41 . 2006-08-24 13:44 477,696 –a—— c:\windows\system32\drivers\ZD1211BU.sys
2008-12-24 16:41 . 2004-01-14 11:25 81,920 –a—— c:\windows\system32\ZDPN50.DLL
2008-12-24 16:41 . 2005-03-18 15:35 31,744 –a—— c:\windows\system32\drivers\ZDPSp50a64.sys
2008-12-24 16:41 . 2005-06-08 18:44 29,184 –a—— c:\windows\system32\drivers\BRGSp50a64.sys
2008-12-24 16:41 . 2004-03-23 16:38 28,672 –a—— c:\windows\system32\InsDrvZD.dll
2008-12-24 16:41 . 2003-03-14 12:24 24,576 –a—— c:\windows\system32\ZyDelReg.exe
2008-12-24 16:41 . 2005-06-08 18:44 20,608 –a—— c:\windows\system32\drivers\BRGSp50.sys
2008-12-24 16:41 . 2004-10-25 13:40 17,664 –a—— c:\windows\system32\drivers\ZDPSp50.sys
2008-12-24 16:41 . 2004-01-14 11:30 17,151 –a—— c:\windows\system32\ZDPNDIS5.SYS
2008-12-24 16:41 . 2005-07-12 14:44 15,872 –a—— c:\windows\system32\InsDrvZD64.DLL
2008-12-24 15:29 . 2008-12-24 15:29 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Apple Computer
2008-12-23 14:55 . 2008-12-29 16:45 d——– c:\program files\Common Files\PC Tools
2008-12-23 14:55 . 2008-12-30 15:08 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-21 16:14 . 2008-12-22 17:33 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\Lavasoft
2008-12-20 16:16 . 2008-12-20 16:16 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH\Application Data\alot
2008-12-20 15:37 . 2008-12-30 13:02 d——– c:\documents and settings\Administrator.JULIE-D50TB0WUH
2008-12-20 14:56 . 2008-12-20 14:56 d——– c:\temp\REX81
2008-12-20 14:55 . 2008-12-30 10:51 d——– c:\windows\system32\cap2
2008-12-20 14:55 . 2008-12-20 14:56 d——– c:\windows\system32\ain
2008-12-20 14:55 . 2008-12-30 15:01 d——– C:\Temp
2008-12-17 21:04 . 2008-12-17 21:04 d——– c:\documents and settings\Julie\Application Data\Snapfish
2008-12-17 20:57 . 2008-12-17 20:57 d——– c:\documents and settings\Julie\Application Data\W Photo Studio
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\program files\Walgreens
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\documents and settings\Julie\Application Data\Walgreens
2008-12-17 20:56 . 2008-12-17 20:56 d——– c:\documents and settings\All Users\Application Data\Walgreens
2008-12-17 20:43 . 2008-12-17 20:56 d——– c:\documents and settings\Julie\Application Data\W Photo Studio Viewer
2008-12-11 10:44 . 2008-12-11 10:44 d——– c:\program files\DjToneXpress
2008-12-10 22:39 . 2007-03-17 08:11 303,104 -ra—— c:\windows\system32\hpovst10.dll
2008-12-10 22:24 . 2008-12-10 22:24 d——– c:\documents and settings\Rick\Application Data\HP
2008-12-07 13:43 . 2008-12-07 13:43 d——– C:\spoolerlogs
2008-12-06 08:42 . 2008-12-06 08:42 d——– c:\program files\NRA
2008-12-05 18:17 . 2008-12-30 00:31 d——– C:\Nexon
2008-12-05 18:17 . 2008-12-05 18:35 d——– c:\documents and settings\All Users\Application Data\NexonUS
2008-12-02 17:05 . 2008-12-02 17:05 d——– c:\documents and settings\Rick\Application Data\acccore
2008-12-01 21:59 . 2008-12-01 21:59 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-01 21:57 . 2008-12-01 21:57 d——– c:\program files\QuickTime
2008-11-27 02:16 . 2008-11-27 02:16 d——– c:\documents and settings\Julie\Application Data\HP
2008-11-23 22:45 . 2008-11-23 22:45 d——– c:\program files\MSXML 4.0
2008-11-23 21:14 . 2008-11-23 21:14 d——– c:\program files\MSECache
2008-11-23 00:39 . 2008-11-23 00:39 197,976 -ra—— c:\windows\cpnprt2.cid
2008-11-22 22:00 . 2008-11-22 22:00 d——– c:\documents and settings\All Users\Application Data\WEBREG
2008-11-22 21:56 . 2008-12-28 21:12 d——– c:\documents and settings\All Users\Application Data\HP
2008-11-22 21:55 . 2008-11-22 21:55 d——– c:\program files\Common Files\HP
2008-11-22 21:54 . 2008-12-28 21:15 d——– c:\program files\HP
2008-11-22 21:53 . 2008-11-22 21:53 d——– c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-11-22 21:52 . 2007-03-17 08:11 569,344 -ra—— c:\windows\system32\hpotscl3.dll
2008-11-22 21:52 . 2007-03-07 20:20 364,544 -ra—— c:\windows\system32\hppldcoi.dll
2008-11-22 21:52 . 2007-03-07 20:20 309,760 -ra—— c:\windows\system32\difxapi.dll
2008-11-22 21:52 . 2007-03-30 07:07 267,864 -ra—— c:\windows\system32\hpzids01.dll
2008-11-22 21:52 . 2007-03-28 14:01 117,760 –a—— c:\windows\system32\hpzll5ha.dll
2008-11-11 20:50 . 2008-09-04 09:15 1,106,944 —–c— c:\windows\system32\dllcache\msxml3.dll
2008-11-11 20:50 . 2008-10-24 03:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2008-11-08 21:26 . 2008-11-08 21:26 d——– c:\program files\Apple Software Update
2008-11-05 18:05 . 2008-11-05 18:05 d——– c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-11-04 10:30 . 2008-11-04 10:30 90,112 –a—— c:\windows\system32\QuickTimeVR.qtx
2008-11-04 10:30 . 2008-11-04 10:30 57,344 –a—— c:\windows\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 21:27 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-30 21:22 ——— d—–w c:\documents and settings\All Users\Application Data\PCPitstop
2008-12-30 08:24 ——— d—–w c:\documents and settings\Rick\Application Data\Lavasoft
2008-12-29 05:15 ——— d—–w c:\program files\Hewlett-Packard
2008-12-29 04:41 ——— d—–w c:\program files\Yahoo!
2008-12-29 04:04 ——— d—–w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-25 00:41 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-23 01:33 ——— d—–w c:\documents and settings\Administrator\Application Data\Lavasoft
2008-12-23 00:56 ——— d—–w c:\program files\Google
2008-12-23 00:52 ——— d—–w c:\program files\Common Files\Apple
2008-12-23 00:49 ——— d—–w c:\program files\Java
2008-12-22 00:12 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-12-20 23:41 ——— d—–w c:\program files\Common Files\AOL
2008-12-06 07:59 ——— d—–w c:\documents and settings\Rick\Application Data\EVEMon
2008-12-05 04:48 ——— d—–w c:\documents and settings\Julie\Application Data\Move Networks
2008-12-02 06:00 ——— d—–w c:\program files\iTunes
2008-12-02 05:59 ——— d—–w c:\program files\iPod
2008-11-26 00:37 29,704 —-a-w c:\documents and settings\Julie\Application Data\GDIPFONTCACHEV1.DAT
2008-11-01 16:07 ——— d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-06-02 06:10 186 —ha-w c:\documents and settings\Julie\Application Data\hpothb07.dat
2008-09-22 06:05 68,608 –sha-w c:\windows\system32\zerejuhu.dll
2008-05-21 12:37 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052120080522\index.dat
2008-08-03 15:15 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080320080804\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CC0D77AF-731A-4C50-A69D-2BC36ED01A97}"= "c:\program files\NRA\Toolbar.dll" [2008-12-06 1249280]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-08-25 1168264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\System32\ctmp3.acm
path=
backup=

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 8.lnk]
backup=c:\windows\pss\SnagIt 8.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-10-22 12:22 7700480 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\EVEMon\\EVEMon.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 pctfw2;pctfw2;\??\c:\windows\system32\drivers\pctfw2.sys [2008-12-29 160792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-28 356920]
S1 HPZius122;HPZius122;c:\windows\system32\drivers\HPZius122.sys []
S2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-09-26 566120]
S2 ioloSystemService;iolo System Service;c:\program files\iolo\common\lib\ioloServiceManager.exe [2008-09-26 566120]
S2 Viewpoint Manager Service;Viewpoint Manager Service; []
S2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-12-28 598856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2008-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2008-12-30 c:\windows\Tasks\drpjnsxc.job
- c:\windows\SYSTEM32\rundll32.exe [2008-04-13 16:12]

2008-12-18 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 13:21]

2008-12-30 c:\windows\Tasks\wpdvqbmu.job
- c:\windows\SYSTEM32\rundll32.exe [2008-04-13 16:12]
.
- - - - ORPHANS REMOVED - - - -

BHO-{ABA8CE4E-D190-4184-A252-10451F857EDD} - c:\windows\system32\tuvUNfge.dll
BHO-{AD884304-1F74-4CD1-928A-C128F6DA07FD} - c:\windows\system32\nnnlmKDv.dll
BHO-{ce51ca11-ba7d-4c49-8633-2061b30eee63} - c:\windows\system32\domfpr.dll


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = hxxp://toolbar.aol.com/uninstall.html?baseinvocationtype=tb50-ie-holiday&browser=ie&instd=27-11-2008
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

O16 -: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
c:\windows\Downloaded Program Files\imikimi_cab.inf
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-30 15:07:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(784)
c:\windows\System32\ctmp3.acm
.
———————— Other Running Processes ————————
.
c:\program files\Spyware Doctor\pctsSvc.exe
.
**************************************************************************
.
Completion time: 2008-12-30 15:10:42 - machine was rebooted [Administrator]
ComboFix-quarantined-files.txt 2008-12-30 23:10:40

Pre-Run: 44,107,530,240 bytes free
Post-Run: 43,981,017,088 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

299 — E O F — 2008-12-18 07:17:25
Hello Rickrides

Welcome to the Whatthetech Malware Removal Forum,

All advice given by anyone volunteering here, is taken at your own risk.
While best efforts are made to assist in removing infections safely, unexpected stuff can happen.


Sorry about the delay, but the amount of people posting with infected computers is through the roof and sometimes we can't get to logs as fast as we would like to. If you have not resolved your issue and still need assistance, post a HJT log please .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI