This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Several aspects of windows not running

49 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. I was wondering if you guys can help me. My machine is progressively getting worse. It started off with a lot of pop-ups and popups for Windows Antivirus 09. Now internet explorer almost constantly opens new pages on its own that can not be displayed in addition to all of the antivirus 09 popups. I am no longer able to run Windows updates on my machine and my firewall has been disable and will not allow me to enable it. I am not able to run housecall on my machine and when I try to run disk cleanup nothing happens. I have run Spybot, registery booster 2, Spyeraser, Defender, and Speedup my pc. At one time they found problems but they no longer do. I am also constantly receiving pop-ups stating that programs want to change my registery which I deny the change when I see it. I also get an MMC error when trying to run defrag and occasionally error messages stating that files can not be found. HELP!! I ran Hijack this and below is my log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:22:07 PM, on 1/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {e221f306-3905-48f1-87c9-bd2a08a2816f} - C:\WINDOWS\system32\bonigezi.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\sotugulu.dll",s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [CPM8b8494a1] Rundll32.exe "c:\windows\system32\sekelumo.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe -s
O4 - HKUS\S-1-5-19\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\sotugulu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\sotugulu.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/bingame/pacz/default/pandaonline.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/bingame/rtlw/default/R…bGameLoader.cab
O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v42/jigsaw/jigsaw.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v47/blockwerx/blockwerx.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinner.com/games/v40/freecell/freecell.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147439234046
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.arcadetown.com/swf/luxor/mjolauncher.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {9D8D7672-93FF-417E-9024-C16AD141C50C} (Haunted Control) - http://www.worldwinner.com/games/v48/haunted/haunted.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} - http://www.worldwinner.com/games/v41/tilecity/tilecity.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\jahasike.dll c:\windows\system32\sekelumo.dll
O20 - Winlogon Notify: winzbb32 - winzbb32.dll (file missing)
O20 - Winlogon Notify: __c0074A88 - C:\WINDOWS\
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sekelumo.dll
O22 - SharedTaskScheduler: awash - {e3623691-f85d-48d8-8e4d-abe79077f841} - (no file)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sekelumo.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - http://www.xlectric.com/wolf/wcouple02_195x225.jpg

–
End of file - 10603 bytes


Any help that you can provide would be very much appreciated.

Tinytears
Hi tinytears, welcome to the forum.

Please be advised, as I'm still in training, all my replies will have to be approved by a teacher or expert before I can post them. This may cause some delays, but I will do my best to keep them as short as possible.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
I will post back soon with additional instructions.


Thanks
Hi tinytears,

What are you using for an antivirus program?

We have to disable a program that may interfer with cleaning your computer. Please disable Windows Defender
  • Click Start , click Programs , click Windows Defender or launch from the system tray icon.
  • Click on Tools & Settings , click Options.
  • Under Real-time protection options, uncheck the "Real-time protection" check box.
  • Click Save.
  • Go to Start, Control Panel , Security , Windows Defender, at the bottom of the Window Defenders page uncheck under Administrator Options "use Windows Defender" and then Save.
    (When we are done, you can re-enable Defender using the same steps but this time place a check next to "Turn on real-time protection" check box.)

Next, open Hijackthis, run a system scan only , check mark the following lines, if present

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: (no name) - {e221f306-3905-48f1-87c9-bd2a08a2816f} - C:\WINDOWS\system32\bonigezi.dll
O4 - HKLM\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\sotugulu.dll",s
O4 - HKLM\..\Run: [CPM8b8494a1] Rundll32.exe "c:\windows\system32\sekelumo.dll",a
O4 - HKUS\S-1-5-19\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\sotugulu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\sotugulu.dll",s (User 'NETWORK SERVICE')
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\jahasike.dll c:\windows\system32\sekelumo.dll
O20 - Winlogon Notify: winzbb32 - winzbb32.dll (file missing)
http://spywarefiles.prevx.com/RRHDIA016266…NZBB32.DLL.html
O20 - Winlogon Notify: __c0074A88 - C:\WINDOWS\
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sekelumo.dll
O22 - SharedTaskScheduler: awash - {e3623691-f85d-48d8-8e4d-abe79077f841} - (no file)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sekelumo.dll


Close all other windows/browsers and click fix checked. Close Hijackthis.

Next, Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.

Next, Please download Malwarebytes Anti-Malware and save it to your desktop.please double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Launch Malwarebytes' Anti-Malware, uncheck Update Malwarebytes' Anti-Malware, if checked, then click Finish.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Next, Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

Please post the MBAM log, the GMER log and a new HJT (hijackthis) log in your next reply. Please answer my question regarding your antvirus program.

Thanks
Thank you so much for your help!! I really appreciate it. I had been running AVG as my antivirus until it stopped running correctly. Then I was using Mcaffe until the trial ran out and then I am not sure what exactly was being used. I know poor answer and I should be much more cautious about my system.

I started following your suggestions and wanted to touch base as I had a couple of questions. When I went to security control panel, security, the only thing I saw was the security center. When I clicked on that I did not see anything that listed Defender so I was not able to complete that step. I continued with your directions and when I got to the next spot where you suggested I that run hijackthis and check the certain items I did not click a couple of items because the name was different and I was afraid I would mess something up. The items I did not check were as follows:

O2 - BHO: (no name) - {e221f306-3905-48f1-87c9-bd2a08a2816f} - C:\WINDOWS\system32\bonigezi.dll
O4 - HKLM\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\sotugulu.dll",s
O4 - HKLM\..\Run: [CPM8b8494a1] Rundll32.exe "c:\windows\system32\sekelumo.dll",a
O4 - HKUS\S-1-5-20\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\sotugulu.dll",s (User 'NETWORK SERVICE')
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sekelumo.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sekelumo.dll

Mine were listed as follows (I bolded the word that was different):
O2 - BHO: (no name) - {e221f306-3905-48f1-87c9-bd2a08a2816f} - C:\WINDOWS\system32\tivekovu.dll
O4 - HKLM\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\bozuhui.dll",s
O4 - HKLM\..\Run: [CPM8b8494a1] Rundll32.exe "c:\windows\system32\gobotuni.dll",a
O4 - HKUS\S-1-5-20\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\bozuhuwii.dll",s (User 'NETWORK SERVICE')
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gobotuni.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\gobotuni.dll

I am currently running Malwarebytes Anti-Malaware on the machine but wanted to check to make sure everything is ok since it has been running since about 9am this morning and it is currently 7:24pm and has been listing Windows Defenders as the section it is scanning for several hours now. Is that ok? Should I uninstall Defender?

Please advise and thank you again for your help.

Tinytears
Hi Tinytears,

Window Defender seems to be causing problems. Did you follow all the instructions for disabling Windows Defender before running MBAM? If you did, then uninstall Windows Defender, then scan with MBAM. Also check in Security Center for an anti virus program.

Thanks
Sorry it took so long. I was wrong in my last message when I refered to Malwarebytes. I forgot I was running GMER. I was using a different computer as I did not want to mess with this one as it was running the software. The scan was finished this morning when I woke up. Please see the previous message from me for the comments in regards to my antivirus and a couple of questions I had for you. Here are the new logs. Sorry if I seem like :pullhair: and :wacko: it has been the longest week ever. As the logs were so long I had to post them in seperate replies. The MBAM log is: Malwarebytes' Anti-Malware 1.32 Database version: 1616 Windows 5.1.2600 Service Pack 3 1/10/2009 9:29:57 AM mbam-log-2009-01-10 (09-29-57).txt Scan type: Quick Scan Objects scanned: 59745 Time elapsed: 6 minute(s), 15 second(s) Memory Processes Infected: 0 Memory Modules Infected: 6 Registry Keys Infected: 23 Registry Values Infected: 7 Registry Data Items Infected: 5 Folders Infected: 22 Files Infected: 107 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\wizisili.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\nekajiyu.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\bozuhuwi.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\tivekova.dll (Trojan.Vundo.H) -> Delete on reboot. c:\WINDOWS\system32\gobotuni.dll (Trojan.Vundo.H) -> Delete on reboot. c:\WINDOWS\system32\sekelumo.dll (Trojan.Vundo) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e221f306-3905-48f1-87c9-bd2a08a2816f} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{e221f306-3905-48f1-87c9-bd2a08a2816f} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{e221f306-3905-48f1-87c9-bd2a08a2816f} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{3b7aaeb1-9f3d-4491-9c06-c7165ca8d058} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4e7bd74f-2b8d-469e-defa-eb76b1d5fa7d} (Adware.BetterInternet) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{10e42047-deb9-4535-a118-b3f6ec39b807} (Adware.ISTBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{42f2c9ba-614f-47c0-b3e3-ecfd34eed658} (Adware.ISTBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227d9c-0efe-4f8a-aa55-30386a3f5686} (Adware.ISTBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba4271e-5c1e-48e2-b432-d8bf420dd31d} (Rogue.DeusCleaner) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3b7aaeb1-9f3d-4491-9c06-c7165ca8d058} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b5141620-c2b2-4d95-9f0f-134d99c87ab0} (Rogue.WinAntivirus) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\88b7a73d (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm8b8494a1 (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\kubafomufi (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\rhc3qkj0eeb5 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\nekajiyu.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\nekajiyu.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\nekajiyu.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\gobotuni.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\gobotuni.dll -> Delete on reboot. Folders Infected: C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\rhc3qkj0eeb5\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5 (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\Application Data\rhc3qkj0eeb5\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\bizapiku.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ukipazib.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bizokefa.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\afekozib.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\degejiba.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\abijeged.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\feyavezi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\izevayef.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\furihepi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ipehiruf.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\gayumeri.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\iremuyag.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hukolihi.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ihilokuh.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\jatuveru.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\urevutaj.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\kimejiru.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\urijemik.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lakabemu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\umebakal.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lesuzeka.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\akezusel.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lobiwaja.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ajawibol.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lusazilu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ulizasul.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mewufogu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ugofuwem.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pufuniso.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\osinufup.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ramobugu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ugubomar.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\runimogo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ogominur.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vekajifa.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\afijakev.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vigoyusu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\usuyogiv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vimogiva.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\avigomiv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vuzofafu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ufafozuv.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wanulago.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ogalunaw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wepozara.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\arazopew.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wizisili.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\ilisiziw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wupefifo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ofifepuw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yuziwoho.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ohowizuy.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\zukidudu.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ududikuz.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. c:\WINDOWS\system32\gobotuni.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\bozuhuwi.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\tivekova.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\nekajiyu.dll (Trojan.Vundo.H) -> Delete on reboot. c:\WINDOWS\system32\sekelumo.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\bemijuwi.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bidiyije.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bigupavi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bonigezi.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\bupodaze.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\darokizi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\dorigome.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\duhavevo.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\duzileru.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\gahagaja.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\hatasefa.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\jahasike.dll.tmp (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\jezosehi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\jobugute.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\juyimuri.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\kanuvopi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\kuzinugi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lokonofe.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mevegupe.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\monelare.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nefuheli.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nohisoye.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nufifini.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pomosini.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ratofoze.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ripojopo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\romupogo.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sehajiwi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sobazofe.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sotugulu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tahadevo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tajelavo.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\toduzosi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tupihegu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vegejeme.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\votinote.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wimesabi.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wotadupa.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yavupofa.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yawugedu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yikibaho.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yokuyive.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\zebizino.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\zutokewa.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\Sonny\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\My Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully. C:\Documents and Settings\Jenni\My Documents\My Documents.url (Trojan.Zlob) -> Quarantined and deleted successfully.
I am not sure how to send you the GMER log as it is to long for a message and evidently to large to attach. Here is the HJT log.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:33:33 AM, on 1/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe -s
O4 - HKUS\S-1-5-20\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\bozuhuwi.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/bingame/pacz/default/pandaonline.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/bingame/rtlw/default/R…bGameLoader.cab
O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v42/jigsaw/jigsaw.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v47/blockwerx/blockwerx.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinner.com/games/v40/freecell/freecell.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147439234046
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.arcadetown.com/swf/luxor/mjolauncher.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {9D8D7672-93FF-417E-9024-C16AD141C50C} (Haunted Control) - http://www.worldwinner.com/games/v48/haunted/haunted.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} - http://www.worldwinner.com/games/v41/tilecity/tilecity.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O20 - AppInit_DLLs: ,
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - http://www.xlectric.com/wolf/wcouple02_195x225.jpg

–
End of file - 8834 bytes


THANK YOU SOOOOO MUCH!!!!!!

Tinytears
Hi Tinytears,

Can you zip it, then attach it?

To attach a file, do the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Thanks
Hi Tinytears,

MBAM did a good job, but there's still a bit left.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post the combofix log and a new HJT (hijackthis) log in your next reply.

Thanks
The combofix log is:

ComboFix 09-01-10.03 - Jenni 2009-01-11 12:34:46.1 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: Norton Internet Worm Protection *disabled*
.
ADS - WINDOWS: deleted 48 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Jenni\Application Data\SCURIT~1
c:\program files\icroso~1
c:\program files\icroso~1\?icrosoft\
c:\windows\IE4 Error Log.txt
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\amayotes.ini
c:\windows\system32\fijahuka.dll
c:\windows\system32\godisida.dll
c:\windows\system32\imutokam.ini
c:\windows\system32\jopowoti.dll
c:\windows\system32\jukazudu.dll
c:\windows\system32\kakenere.dll
c:\windows\system32\loyayono.dll
c:\windows\system32\mamapome.dll
c:\windows\system32\msrdo20.dll
c:\windows\system32\nigavimi.dll
c:\windows\system32\nopuyeba.dll
c:\windows\system32\okofopiy.ini
c:\windows\system32\olejuzew.ini
c:\windows\system32\pefupupu.dll
c:\windows\system32\rdocurs.dll
c:\windows\system32\stera.log
c:\windows\system32\tupopazo.dll
c:\windows\system32\wnstssv.exe
c:\windows\system32\woduluju.dll
c:\windows\system32\yolefode.dll
c:\windows\system32\yutepuwa.dll
c:\windows\system32\yutozazu.dll
c:\windows\system32\zumidiba.dll
C:\xcrashdump.dat
D:\Autorun.inf
G:\Autorun.inf

—– BITS: Possible infected sites —–

hxxp://77.74.48.105
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FOPN
——-\Legacy_VSPF
——-\Legacy_VSPF_HK
——-\Service_sysrest.sys


((((((((((((((((((((((((( Files Created from 2008-12-11 to 2009-01-11 )))))))))))))))))))))))))))))))
.

2009-01-10 09:35 . 2009-01-10 09:36 250 –a—— c:\windows\gmer.ini
2009-01-10 09:20 . 2009-01-10 09:20 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-10 09:20 . 2009-01-10 09:20 d——– c:\documents and settings\Jenni\Application Data\Malwarebytes
2009-01-10 09:20 . 2009-01-10 09:20 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-10 09:20 . 2009-01-04 18:39 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-10 09:20 . 2009-01-04 18:39 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-06 19:08 . 2009-01-06 19:09 d——– c:\program files\ERUNT
2009-01-06 06:15 . 2009-01-06 06:15 d——– c:\program files\Trend Micro
2009-01-05 19:56 . 2009-01-05 20:31 d——– c:\documents and settings\Jenni\.housecall6.6
2009-01-05 18:31 . 2009-01-05 18:31 d——– c:\program files\iPod
2009-01-05 18:30 . 2009-01-05 18:31 d——– c:\program files\iTunes
2009-01-05 18:30 . 2009-01-05 18:31 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-30 20:13 . 2008-12-30 20:13 2,098 —hs—- c:\windows\system32\vefilima.dll
2008-12-30 20:13 . 2008-12-30 20:13 2,098 —hs—- c:\windows\system32\gidogiso.dll
2008-12-30 17:41 . 2008-12-30 17:41 d——– c:\program files\Bonjour
2008-12-30 17:36 . 2009-01-04 21:38 d——– c:\program files\QuickTime
2008-12-23 07:17 . 2008-12-23 07:17 2,098 —hs—- c:\windows\system32\yenojuje.exe
2008-12-22 13:15 . 2008-12-22 13:15 2,098 —hs—- c:\windows\system32\wovohudi.exe
2008-12-21 02:32 . 2008-12-21 02:32 2,098 —hs—- c:\windows\system32\wokunuti.exe
2008-12-20 19:54 . 2008-12-28 14:58 443 –a—— c:\windows\wininit.ini
2008-12-18 07:20 . 2008-12-18 07:20 d——– c:\windows\system32\scripting
2008-12-18 07:20 . 2008-12-18 07:20 d——– c:\windows\system32\en
2008-12-18 07:20 . 2008-12-18 07:20 d——– c:\windows\l2schemas
2008-12-16 19:49 . 2008-12-16 19:49 d——– c:\program files\Windows Defender
2008-12-16 11:16 . 2008-12-16 11:16 2,098 —hs—- c:\windows\system32\hitaheja.dll
2008-12-11 19:55 . 2008-12-11 19:55 d——– c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-12-11 19:55 . 2008-12-11 19:55 d——– c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-12-11 19:44 . 2008-12-11 19:44 d——– c:\documents and settings\Jenni\Application Data\Viewpoint

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 00:57 102,664 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-01-03 17:49 ——— d—–w c:\program files\Microsoft Money
2009-01-03 17:29 ——— d—–w c:\program files\Microsoft Money 2006
2008-12-30 23:28 ——— d—–w c:\program files\Common Files\Apple
2008-12-30 22:28 ——— d—–w c:\program files\Safari
2008-12-26 04:46 ——— d—–w c:\documents and settings\Jenni\Application Data\Apple Computer
2008-12-21 20:31 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-21 20:30 ——— d-s—w c:\documents and settings\All Users\Application Data\Memeo
2008-12-21 20:26 ——— d—–w c:\documents and settings\Sonny\Application Data\InstallShield
2008-12-21 20:25 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-20 19:21 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-20 19:21 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-18 11:16 ——— d—–w c:\program files\Lavasoft
2008-12-06 20:24 ——— d—–w c:\documents and settings\Sonny\Application Data\U3
2008-12-03 16:15 ——— d—–w c:\documents and settings\Sonny\Application Data\Azureus
2008-12-03 05:07 ——— d—–w c:\program files\Vuze
2008-11-23 01:10 ——— d—–w c:\documents and settings\All Users\Application Data\PBGsavesDirectory
2008-11-17 02:31 ——— d—–w c:\program files\UNO Undercover
2006-06-29 01:40 774,144 —-a-w c:\program files\RngInterstitial.dll
1601-01-01 00:12 90,112 –sha-w c:\windows\system32\gekujoni.dll
2008-09-27 17:08 47,104 –sha-w c:\windows\system32\keveyate.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-10-31 2259904]
"Uniblue SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe" [2007-04-25 8828448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= ,

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^.protected]
backup=c:\windows\pss\.protectedCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Jenni^Start Menu^Programs^Startup^.protected]
backup=c:\windows\pss\.protectedStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Sonny^Start Menu^Programs^Startup^Memeo AutoBackup Launcher.lnk]
backup=c:\windows\pss\Memeo AutoBackup Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Sonny^Start Menu^Programs^Startup^Memeo AutoSync Launcher.lnk]
backup=c:\windows\pss\Memeo AutoSync Launcher.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FastTVSync
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Qjqgvlt
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rwor
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Defender
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiVirusPro2006

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
–a—— 2008-09-01 09:30 2321600 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
–a—— 2008-10-31 11:12 2259904 c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
–a—— 2006-09-28 15:21 57344 g:\clonecd\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a—— 2003-04-07 02:19 155648 c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfotoNow USB Detection]
–a—— 2002-11-05 09:32 77824 c:\progra~1\Ofoto\OfotoNow\OFUSBS.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
–a—— 2007-02-20 20:18 366400 c:\program files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicFocus]
–a—— 2003-04-16 20:16 1220608 c:\program files\Sonic Focus\SFIGUI\SFIGUI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-07-07 09:42 2156368 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-02-22 03:25 144784 c:\program files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]
–a—— 2007-04-25 16:27 8828448 c:\program files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpyEraser]
–a—— 2008-01-08 09:14 1260296 c:\program files\Uniblue\SpyEraser\SpyEraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
–a—— 2006-11-03 19:20 866584 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2005-08-19 18:34 3084288 c:\progra~1\Yahoo!\MESSEN~1\YPager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\QuickTime\\QTTask.exe"=

R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2004-10-11 32640]
R4 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-02-16 36368]
R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 w600bus;Sony Ericsson W600 driver (WDM);c:\windows\system32\DRIVERS\w600bus.sys –> c:\windows\system32\DRIVERS\w600bus.sys [?]
S3 w600mdfl;Sony Ericsson W600 USB WMC Modem Filter;c:\windows\system32\DRIVERS\w600mdfl.sys –> c:\windows\system32\DRIVERS\w600mdfl.sys [?]
S3 w600mdm;Sony Ericsson W600 USB WMC Modem Drivers;c:\windows\system32\DRIVERS\w600mdm.sys –> c:\windows\system32\DRIVERS\w600mdm.sys [?]
S3 w600mgmt;Sony Ericsson W600 USB WMC Device Management Drivers;c:\windows\system32\DRIVERS\w600mgmt.sys –> c:\windows\system32\DRIVERS\w600mgmt.sys [?]
S3 w600obex;Sony Ericsson W600 USB WMC OBEX Interface Drivers;c:\windows\system32\DRIVERS\w600obex.sys –> c:\windows\system32\DRIVERS\w600obex.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - g:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5397ba71-961b-11dd-a29a-000cf199848e}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-01-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-01-11 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

2009-01-05 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe [2007-04-25 16:27]

2008-01-21 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe [2007-04-25 16:27]

2008-10-25 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2008-01-08 09:14]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-kubafomufi - c:\windows\system32\kibepina.dll
MSConfigStartUp-PP5300usb - c:\paprport\FBDirect.exe
MSConfigStartUp-363edd41 - (no file)
MSConfigStartUp-brastk - brastk.exe
MSConfigStartUp-go34RkdEU - psbtok.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-11 13:23:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\WRLogonNTF.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Executive Software\Diskeeper\DkService.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-11 13:33:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-11 18:31:48

Pre-Run: 5,737,332,736 bytes free
Post-Run: 5,667,725,312 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

270 — E O F — 2008-12-19 01:31:44



The new HJT log is:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:40:44 PM, on 1/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe -s
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/bingame/pacz/default/pandaonline.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/bingame/rtlw/default/R…bGameLoader.cab
O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v42/jigsaw/jigsaw.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v47/blockwerx/blockwerx.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinner.com/games/v40/freecell/freecell.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147439234046
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.arcadetown.com/swf/luxor/mjolauncher.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {9D8D7672-93FF-417E-9024-C16AD141C50C} (Haunted Control) - http://www.worldwinner.com/games/v48/haunted/haunted.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} - http://www.worldwinner.com/games/v41/tilecity/tilecity.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O20 - AppInit_DLLs: ,
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - http://www.xlectric.com/wolf/wcouple02_195x225.jpg

–
End of file - 9207 bytes


Thanks,

Tinytears
Hi Tinytears,

A little more to go.

Please do not use any P2P program while we are cleaning this machine.

The combofix log shows Spybot's Teatimer may be active. If it is it could interfere. Please check to see if it is disabled.

this is a two step process.
First step:
  • Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)
  • If you have the new version 1.5, Click once on Resident Protection, then Right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • If you have Version 1.4, Click on Exit Spybot S&D Resident
Second step, For Either Version :
  • Open Spybot S&D
  • Click Mode, choose Advanced Mode
  • Go To the bottom of the Vertical Panel on the Left, Click Tools
  • then, also in left panel, click Resident shows a red/white shield.
  • If your firewall raises a question, say OK
  • In the Resident protection status frame, Uncheck the box labelled Resident "Tea-Timer"(Protection of over-all system settings) active
  • OK any prompts.
  • Use File, Exit to terminate Spybot
  • Reboot your machine fully for the changes to take effect.

I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

Http://www.virustotal.com

copy and paste the following into the upload a file box (one at a time if more than one file is listed)

c:\windows\system32\wovohudi.exe
c:\windows\system32\wokunuti.exe
c:\windows\SYSTEM32\hitaheja.dll


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.

Next, open Hijackthis, run a system scan only , check mark the following lines, if present
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O20 - AppInit_DLLs: ,


Close all other browsers/windows and click fix checked.

Still in HJT, click Main Menu
  • click Open the misc tool section
  • click Open Unistall manager
  • click Save list
  • save it a convenient location such as your desktop, click save
  • please post it in your next reply.
Click Main menu again
  • click
  • click open ADS spy
  • click scan
  • click save log
  • Please post this log in your next reply

We will be using Combofix again.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

http://forums.whatthetech.com/Several_aspects_windows_not_running_t98724.html&gopid=517614

KillAll::

Collect::[4]
c:\windows\system32\wovohudi.exe 
c:\windows\system32\wokunuti.exe
c:\windows\SYSTEM32\hitaheja.dll
c:\windows\system32\yenojuje.exe
c:\windows\system32\gekujoni.dll 
c:\windows\system32\keveyate.dll 

File::
c:\windows\system32\vefilima.dll
c:\windows\system32\gidogiso.dll

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Qjqgvlt]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ultimate Defender]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAntiVirusPro2006]

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browsers/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note** When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
  • A browser will open.
  • Simply follow the instructions on the page that opens to copy/paste/send the requested file.
Please save the log in a convenient place such as your desktop so you can post it when you have completed the rest.

Please download a free anti-virus software (for personal use), from one these excellent vendors

avast! 4 Home Edition
-Anti-virus program for Windows.
-The home edition is freeware for noncommercial user
Antivir PersonalEditionClassic
-Free anti-virus software for Windows.
-Detects and removes more than 50,000 viruses. Free support

Please include in your next reply
  • Combofix log
  • uninstall list
  • ADS log
  • HJT log
Thanks
I had a tough time getting combofix to run when I drag the notepad item onto it but I finally got it to run this evening. Here is the latest logs: Virustotal response for c:\windows\system32\wovohudi.exe results: File has already been analysed: MD5: e819c12f8c3ab79445c63d8faa90d6b7 First received: - Date: 01.11.2009 00:32:39 (CET) [+1D] Results: 0/38 Permalink: analisis/fa18fc9c0bc75850fbdecf5d20b8cc6b File wovohudi.exe received on 01.12.2009 01:42:51 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/38 (0%) Loading server information… Your file is queued in position: 4. Estimated start time is between 62 and 88 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.0.0.73 2009.01.11 - AhnLab-V3 2009.1.10.0 2009.01.11 - AntiVir 7.9.0.54 2009.01.11 - Authentium 5.1.0.4 2009.01.10 - Avast 4.8.1281.0 2009.01.11 - AVG 8.0.0.229 2009.01.11 - BitDefender 7.2 2009.01.12 - CAT-QuickHeal 10.00 2009.01.09 - ClamAV 0.94.1 2009.01.12 - Comodo 915 2009.01.11 - DrWeb 4.44.0.09170 2009.01.11 - eSafe 7.0.17.0 2009.01.11 - eTrust-Vet 31.6.6301 2009.01.10 - F-Prot 4.4.4.56 2009.01.11 - F-Secure 8.0.14470.0 2009.01.12 - Fortinet 3.117.0.0 2009.01.11 - GData 19 2009.01.12 - Ikarus T3.1.1.45.0 2009.01.12 - K7AntiVirus 7.10.584 2009.01.09 - Kaspersky 7.0.0.125 2009.01.12 - McAfee 5492 2009.01.11 - McAfee+Artemis 5492 2009.01.11 - Microsoft 1.4205 2009.01.11 - NOD32 3757 2009.01.11 - Norman 5.99.02 2009.01.09 - Panda 9.4.3.3 2009.01.11 - PCTools 4.4.2.0 2009.01.11 - Prevx1 V2 2009.01.12 - Rising 21.11.62.00 2009.01.11 - SecureWeb-Gateway 6.7.6 2009.01.11 - Sophos 4.37.0 2009.01.11 - Sunbelt 3.2.1831.2 2009.01.09 - Symantec 10 2009.01.12 - TheHacker [removed].218 2009.01.11 - TrendMicro 8.700.0.1004 2009.01.11 - VBA32 3.12.8.10 2009.01.10 - ViRobot 2009.1.10.1553 2009.01.10 - VirusBuster 4.5.11.0 2009.01.11 - Additional information File size: 2098 bytes MD5…: e819c12f8c3ab79445c63d8faa90d6b7 SHA1..: 5ed2e96cf3a866f9ab4b59f6979e6fa8f10fd493 SHA256: ca313a44fc110ec9e99fc1c3c7a4829f0c849873a0a3c5e6d1f033f1241f9cfe SHA512: 4433032b67f1ac5f13cc98629428bbc04784df8117716f1ae1fd68c961231d45 10eb0476a06db6bc4325d47af3a722f7c64af25990d199b96c16b519c043b82b ssdeep: 48:qSYZScvPFZ23XApANzgHzdWNgO/y0/4qzQn5:IfbcEHRtWyc4F PEiD..: - TrID..: File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) PEInfo: - CWSandbox info: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=e819c12f8c3ab79445c63d8faa90d6b7 ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware. Results for c:\windows\system32\wokunuti.exe results: File has already been analysed: MD5: e819c12f8c3ab79445c63d8faa90d6b7 First received: - Date: 01.12.2009 01:46:59 (CET) [<1D] Results: 0/38 Permalink: analisis/cb9070c15299a42c650ebbb34a5c70a8 File wokunuti.exe received on 01.12.2009 01:47:47 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/38 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 38 and 55 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.0.0.73 2009.01.11 - AhnLab-V3 2009.1.10.0 2009.01.11 - AntiVir 7.9.0.54 2009.01.11 - Authentium 5.1.0.4 2009.01.10 - Avast 4.8.1281.0 2009.01.11 - AVG 8.0.0.229 2009.01.11 - BitDefender 7.2 2009.01.12 - CAT-QuickHeal 10.00 2009.01.09 - ClamAV 0.94.1 2009.01.12 - Comodo 915 2009.01.11 - DrWeb 4.44.0.09170 2009.01.11 - eSafe 7.0.17.0 2009.01.11 - eTrust-Vet 31.6.6301 2009.01.10 - F-Prot 4.4.4.56 2009.01.11 - F-Secure 8.0.14470.0 2009.01.12 - Fortinet 3.117.0.0 2009.01.11 - GData 19 2009.01.12 - Ikarus T3.1.1.45.0 2009.01.12 - K7AntiVirus 7.10.584 2009.01.09 - Kaspersky 7.0.0.125 2009.01.12 - McAfee 5492 2009.01.11 - McAfee+Artemis 5492 2009.01.11 - Microsoft 1.4205 2009.01.11 - NOD32 3757 2009.01.11 - Norman 5.99.02 2009.01.09 - Panda 9.4.3.3 2009.01.11 - PCTools 4.4.2.0 2009.01.11 - Prevx1 V2 2009.01.12 - Rising 21.11.62.00 2009.01.11 - SecureWeb-Gateway 6.7.6 2009.01.11 - Sophos 4.37.0 2009.01.11 - Sunbelt 3.2.1831.2 2009.01.09 - Symantec 10 2009.01.12 - TheHacker [removed].218 2009.01.11 - TrendMicro 8.700.0.1004 2009.01.11 - VBA32 3.12.8.10 2009.01.10 - ViRobot 2009.1.10.1553 2009.01.10 - VirusBuster 4.5.11.0 2009.01.11 - Additional information File size: 2098 bytes MD5…: e819c12f8c3ab79445c63d8faa90d6b7 SHA1..: 5ed2e96cf3a866f9ab4b59f6979e6fa8f10fd493 SHA256: ca313a44fc110ec9e99fc1c3c7a4829f0c849873a0a3c5e6d1f033f1241f9cfe SHA512: 4433032b67f1ac5f13cc98629428bbc04784df8117716f1ae1fd68c961231d45 10eb0476a06db6bc4325d47af3a722f7c64af25990d199b96c16b519c043b82b ssdeep: 48:qSYZScvPFZ23XApANzgHzdWNgO/y0/4qzQn5:IfbcEHRtWyc4F PEiD..: - TrID..: File type identification HyperText Markup Language with DOCTYPE (80.6%) HyperText Markup Language (19.3%) PEInfo: - CWSandbox info: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=e819c12f8c3ab79445c63d8faa90d6b7 ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware. Results for C:\windows\system32\hitaheja.dll results: File has already been analysed: MD5: e819c12f8c3ab79445c63d8faa90d6b7 First received: - Date: 01.12.2009 01:50:21 (CET) [<1D] Results: 0/38 Permalink: analisis/6cf290c5a2cff22203c063519b3a4a51 File hitaheja.dll_ received on 01.12.2009 01:51:25 (CET) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/38 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 38 and 55 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.0.0.73 2009.01.11 - AhnLab-V3 2009.1.10.0 2009.01.11 - AntiVir 7.9.0.54 2009.01.11 - Authentium 5.1.0.4 2009.01.10 - Avast 4.8.1281.0 2009.01.11 - AVG 8.0.0.229 2009.01.11 - BitDefender 7.2 2009.01.12 - CAT-QuickHeal 10.00 2009.01.09 - ClamAV 0.94.1 2009.01.12 - Comodo 915 2009.01.11 - DrWeb 4.44.0.09170 2009.01.11 - eSafe 7.0.17.0 2009.01.11 - eTrust-Vet 31.6.6301 2009.01.10 - F-Prot 4.4.4.56 2009.01.11 - F-Secure 8.0.14470.0 2009.01.12 - Fortinet 3.117.0.0 2009.01.11 - GData 19 2009.01.12 - Ikarus T3.1.1.45.0 2009.01.12 - K7AntiVirus 7.10.584 2009.01.09 - Kaspersky 7.0.0.125 2009.01.12 - McAfee 5492 2009.01.11 - McAfee+Artemis 5492 2009.01.11 - Microsoft 1.4205 2009.01.11 - NOD32 3757 2009.01.11 - Norman 5.99.02 2009.01.09 - Panda 9.4.3.3 2009.01.11 - PCTools 4.4.2.0 2009.01.11 - Prevx1 V2 2009.01.12 - Rising 21.11.62.00 2009.01.11 - SecureWeb-Gateway 6.7.6 2009.01.11 - Sophos 4.37.0 2009.01.11 - Sunbelt 3.2.1831.2 2009.01.09 - Symantec 10 2009.01.12 - TheHacker [removed].218 2009.01.11 - TrendMicro 8.700.0.1004 2009.01.11 - VBA32 3.12.8.10 2009.01.10 - ViRobot 2009.1.10.1553 2009.01.10 - VirusBuster 4.5.11.0 2009.01.11 - Additional information File size: 2098 bytes MD5…: e819c12f8c3ab79445c63d8faa90d6b7 SHA1..: 5ed2e96cf3a866f9ab4b59f6979e6fa8f10fd493 SHA256: ca313a44fc110ec9e99fc1c3c7a4829f0c849873a0a3c5e6d1f033f1241f9cfe SHA512: 4433032b67f1ac5f13cc98629428bbc04784df8117716f1ae1fd68c961231d45 10eb0476a06db6bc4325d47af3a722f7c64af25990d199b96c16b519c043b82b ssdeep: 48:qSYZScvPFZ23XApANzgHzdWNgO/y0/4qzQn5:IfbcEHRtWyc4F PEiD..: - TrID..: File type identification file seems to be plain text/ASCII (0.0%) PEInfo: - CWSandbox info: http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=e819c12f8c3ab79445c63d8faa90d6b7 ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
I ran ADS but no log was created so I do not have a log for you for that one. Below please find (if they all fit on one message) the logs for Combofix, Unistall, and HJT. Thanks.


COMBOFIX LOG:

ComboFix 09-01-10.03 - Jenni 2009-01-12 18:26:11.3 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jenni\Desktop\CFScript.txt
FW: Norton Internet Worm Protection *disabled*

FILE ::
c:\windows\system32\gidogiso.dll
c:\windows\system32\vefilima.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\gekujoni.dll
c:\windows\system32\gidogiso.dll
c:\windows\SYSTEM32\hitaheja.dll
c:\windows\system32\keveyate.dll
c:\windows\system32\vefilima.dll
c:\windows\system32\wokunuti.exe
c:\windows\system32\wovohudi.exe
c:\windows\system32\yenojuje.exe

.
((((((((((((((((((((((((( Files Created from 2008-12-12 to 2009-01-12 )))))))))))))))))))))))))))))))
.

2009-01-10 09:35 . 2009-01-10 09:36 250 –a—— c:\windows\gmer.ini
2009-01-10 09:20 . 2009-01-10 09:20 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-10 09:20 . 2009-01-10 09:20 d——– c:\documents and settings\Jenni\Application Data\Malwarebytes
2009-01-10 09:20 . 2009-01-10 09:20 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-10 09:20 . 2009-01-04 18:39 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-10 09:20 . 2009-01-04 18:39 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-06 19:08 . 2009-01-06 19:09 d——– c:\program files\ERUNT
2009-01-06 06:15 . 2009-01-06 06:15 d——– c:\program files\Trend Micro
2009-01-05 19:56 . 2009-01-05 20:31 d——– c:\documents and settings\Jenni\.housecall6.6
2009-01-05 18:31 . 2009-01-05 18:31 d——– c:\program files\iPod
2009-01-05 18:30 . 2009-01-05 18:31 d——– c:\program files\iTunes
2009-01-05 18:30 . 2009-01-05 18:31 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-30 17:41 . 2008-12-30 17:41 d——– c:\program files\Bonjour
2008-12-30 17:36 . 2009-01-04 21:38 d——– c:\program files\QuickTime
2008-12-20 19:54 . 2008-12-28 14:58 443 –a—— c:\windows\wininit.ini
2008-12-18 07:20 . 2008-12-18 07:20 d——– c:\windows\system32\scripting
2008-12-18 07:20 . 2008-12-18 07:20 d——– c:\windows\system32\en
2008-12-18 07:20 . 2008-12-18 07:20 d——– c:\windows\l2schemas
2008-12-16 19:49 . 2008-12-16 19:49 d——– c:\program files\Windows Defender

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 00:57 102,664 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-01-03 17:49 ——— d—–w c:\program files\Microsoft Money
2009-01-03 17:29 ——— d—–w c:\program files\Microsoft Money 2006
2008-12-30 23:28 ——— d—–w c:\program files\Common Files\Apple
2008-12-30 22:28 ——— d—–w c:\program files\Safari
2008-12-26 04:46 ——— d—–w c:\documents and settings\Jenni\Application Data\Apple Computer
2008-12-21 20:31 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-21 20:30 ——— d-s—w c:\documents and settings\All Users\Application Data\Memeo
2008-12-21 20:26 ——— d—–w c:\documents and settings\Sonny\Application Data\InstallShield
2008-12-21 20:25 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-20 19:21 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-20 19:21 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-18 11:16 ——— d—–w c:\program files\Lavasoft
2008-12-12 00:55 ——— d—–w c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2008-12-12 00:55 ——— d—–w c:\program files\File Scanner Library (Spybot - Search & Destroy)
2008-12-12 00:44 ——— d—–w c:\documents and settings\Jenni\Application Data\Viewpoint
2008-12-06 20:24 ——— d—–w c:\documents and settings\Sonny\Application Data\U3
2008-12-03 16:15 ——— d—–w c:\documents and settings\Sonny\Application Data\Azureus
2008-12-03 05:07 ——— d—–w c:\program files\Vuze
2008-11-23 01:10 ——— d—–w c:\documents and settings\All Users\Application Data\PBGsavesDirectory
2008-11-17 02:31 ——— d—–w c:\program files\UNO Undercover
2006-06-29 01:40 774,144 —-a-w c:\program files\RngInterstitial.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-11_13.27.40.46 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-10-31 2259904]
"Uniblue SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe" [2007-04-25 8828448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"kubafomufi"="c:\windows\system32\bozuhuwi.dll" [BU]
"88b7a73d"="c:\windows\system32\wizisili.dll" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^.protected]
backup=c:\windows\pss\.protectedCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Jenni^Start Menu^Programs^Startup^.protected]
backup=c:\windows\pss\.protectedStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Sonny^Start Menu^Programs^Startup^Memeo AutoBackup Launcher.lnk]
backup=c:\windows\pss\Memeo AutoBackup Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Sonny^Start Menu^Programs^Startup^Memeo AutoSync Launcher.lnk]
backup=c:\windows\pss\Memeo AutoSync Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
–a—— 2008-09-01 09:30 2321600 c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
–a—— 2008-10-31 11:12 2259904 c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
–a—— 2006-09-28 15:21 57344 g:\clonecd\CloneCDTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a—— 2003-04-07 02:19 155648 c:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OfotoNow USB Detection]
–a—— 2002-11-05 09:32 77824 c:\progra~1\Ofoto\OfotoNow\OFUSBS.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
–a—— 2007-02-20 20:18 366400 c:\program files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SonicFocus]
–a—— 2003-04-16 20:16 1220608 c:\program files\Sonic Focus\SFIGUI\SFIGUI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-07-07 09:42 2156368 c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2008-02-22 03:25 144784 c:\program files\Java\jre1.6.0_05\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]
–a—— 2007-04-25 16:27 8828448 c:\program files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpyEraser]
–a—— 2008-01-08 09:14 1260296 c:\program files\Uniblue\SpyEraser\SpyEraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
–a—— 2006-11-03 19:20 866584 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2005-08-19 18:34 3084288 c:\progra~1\Yahoo!\MESSEN~1\YPager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\QuickTime\\QTTask.exe"=

R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2004-10-11 32640]
R4 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-02-16 36368]
R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 w600bus;Sony Ericsson W600 driver (WDM);c:\windows\system32\DRIVERS\w600bus.sys –> c:\windows\system32\DRIVERS\w600bus.sys [?]
S3 w600mdfl;Sony Ericsson W600 USB WMC Modem Filter;c:\windows\system32\DRIVERS\w600mdfl.sys –> c:\windows\system32\DRIVERS\w600mdfl.sys [?]
S3 w600mdm;Sony Ericsson W600 USB WMC Modem Drivers;c:\windows\system32\DRIVERS\w600mdm.sys –> c:\windows\system32\DRIVERS\w600mdm.sys [?]
S3 w600mgmt;Sony Ericsson W600 USB WMC Device Management Drivers;c:\windows\system32\DRIVERS\w600mgmt.sys –> c:\windows\system32\DRIVERS\w600mgmt.sys [?]
S3 w600obex;Sony Ericsson W600 USB WMC OBEX Interface Drivers;c:\windows\system32\DRIVERS\w600obex.sys –> c:\windows\system32\DRIVERS\w600obex.sys [?]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - g:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5397ba71-961b-11dd-a29a-000cf199848e}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-01-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-01-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

2009-01-05 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe [2007-04-25 16:27]

2008-01-21 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe [2007-04-25 16:27]

2008-10-25 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe [2008-01-08 09:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm

O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

O16 -: Microsoft XML Parser for Java - c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-12 18:33:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\WRLogonNTF.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Executive Software\Diskeeper\DkService.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Symantec\LiveUpdate\AUPDATE.EXE
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
.
**************************************************************************
.
Completion time: 2009-01-12 18:42:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-12 23:41:22
ComboFix2.txt 2009-01-12 01:20:23
ComboFix3.txt 2009-01-11 18:33:14

Pre-Run: 5,422,809,088 bytes free
Post-Run: 5,410,562,048 bytes free

217 — E O F — 2009-01-12 00:50:04




UNINSTALL LIST LOG


Adobe Flash Player ActiveX
Adobe Reader 8
AnyDVD
Apple Mobile Device Support
Apple Software Update
AVI DivX MPEG to DVD Converter & Burner 4.0
Azada
Betty's Beer Bar
Bonjour
Cake Mania
Cake Mania 2
Cake Mania 3
CD Wave Editor version 1.96.1
Check Identical Files 3
CloneCD
CloneDVD2
CloneDVDmobile
Concentration
Cooking Dash
dBpowerAMP CD Writer
dBpoweramp FLAC Codec
Diner Dash 2
Direct Show Ogg Vorbis Filter (remove only)
Disc2Phone
Diskeeper Professional Edition
DivX 4.12 Codec
DVD Creator3
DVDFab Platinum 2.9.6.0
ERUNT 1.1j
Farm Frenzy 2
Final Draft 7
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
Interpol The Trail Of Dr Chaos
InterVideo DVDCopy 3
iTunes
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
LiveUpdate 3.0 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Lottso Deluxe
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Money 2006
Microsoft Office Professional Edition 2003
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
MobileMe Control Panel
MSN Toolbar
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
OfotoNow
Picasa 2
PowerDVD
QuickTime
Safari
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB960714)
Sonic Focus
SopCast 3.0.3
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
Symantec KB-DocID:2003093015493306
Trillian
TVAnts 1.0
TVUPlayer [removed]
Uniblue RegistryBooster 2
Uniblue SpeedUpMyPC
Uniblue SpyEraser
Uniblue System Tweaker
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
VideoLAN VLC media player 0.8.6c
Viewpoint Manager (Remove Only)
Viewpoint Media Player
WD Diagnostics
Windows Defender
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
Xilisoft DVD Creator
Xilisoft DVD to iPod Converter 5
Xvid 1.1.3 final uninstall
Yahoo! Messenger
Yahoo! Toolbar

HJT LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:53:11 PM, on 1/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [kubafomufi] Rundll32.exe "C:\WINDOWS\system32\bozuhuwi.dll",s
O4 - HKLM\..\Run: [88b7a73d] rundll32.exe "C:\WINDOWS\system32\wizisili.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [Uniblue SpeedUpMyPC] C:\Program Files\Uniblue\SpeedUpMyPC\SpeedUpMyPC.exe -s
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/bingame/pacz/default/pandaonline.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/bingame/rtlw/default/R…bGameLoader.cab
O16 - DPF: {41D1977F-4161-4720-800F-EA4903983A38} (Jigsaw Genius Control) - http://www.worldwinner.com/games/v42/jigsaw/jigsaw.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} - http://zone.msn.com/bingame/rock/default/popcaploader1.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase8300.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v47/blockwerx/blockwerx.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinner.com/games/v40/freecell/freecell.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147439234046
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.arcadetown.com/swf/luxor/mjolauncher.cab
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v44/sol/sol.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {9D8D7672-93FF-417E-9024-C16AD141C50C} (Haunted Control) - http://www.worldwinner.com/games/v48/haunted/haunted.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v61/swapit/swapit.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a…asyInstallX.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} - http://www.worldwinner.com/games/v41/tilecity/tilecity.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/gold/default/gf.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/bingame/hsol/default/SCEWebLauncher.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O24 - Desktop Component 0: (no name) - http://www.xlectric.com/wolf/wcouple02_195x225.jpg

–
End of file - 8851 bytes


Thanks again

Tinytears
Hi Tinytears,

If HJT doesn't find an ADS, then there won't be a log. You really have to get an antivirus program installed or the infection is going to keep coming back. Some all ready has. You can reinstall AVG if you wish.

AVG

Azureus and Vuze
You have or at one time had Azureus and Vuze, P2P/file sharing programs installed on your computer. P2P applications like them are the largest source of malware we see. You'll be doing yourself a favor by removing them.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/1605005…cles/art053.htm
http://www.internetworldstats.com/articles/art053.htm

Please go to add/remove programs anduninstall Azureus and Vuze , if present until we get this system cleaned.

If you must use this type of program, a list of clean and infected P2P programs can be found at http://malwareremoval.com/p2pindex.php

As you can see Vuze is in the list of Unsafe programs

The risks of using a P2P program are stated in this http://aresgalaxy.sourceforge.net/p2prisks.htmSourceforge website and http://www.informationweek.com/security/sh…ext=Information Week article

Back to the malware.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do not copy the word Code

    :Processes
    explorer.exe
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    kubafomufi"=-
    "88b7a73d"=-
    
    :Files
    c:\windows\system32\bozuhuwi.dll
    c:\windows\system32\wizisili.dll
    
    :Commands
    [Purity]
    [EmptyTemp]
    [Start Explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Let's look deeper. Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.

And we'll also take care of the old vulnerable java you have installed.

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

Please post back with the OTMOVEIT3 log, the Rooter log and a new HJT log.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI