UNSOLVED

JIMMERW

updated

18 years ago

J

JIMMERW

21 Posts

0

2685

June 25th, 2008 21:00

userinit.exe - Application error

Hello, I recently had a major attack. My lower task bar and start button are gone. All my desktop icons are just gone and when I startup I get the following error.

 

 userinit.exe - Application Error

 The application failed to initialize properly (0xc0000005). Click on OK to terminate the application.

 

 I need to access my browser now by using ctrl/alt/delete, selecting new task, then browsing folders and files to get to my browser. I have run AdAware (Lavasoft) and Spybot, but the problem is still here. I tried Hijackthis and got the following log file.

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:25:16 PM, on 25/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thestar.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: (no name) - {144D91DD-D93C-4730-9F97-254982465CA6} - (no file)
O2 - BHO: (no name) - {21890061-4A03-416E-88B5-526EBD76FB56} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: (no name) - {66EA8EB2-F8B0-4ABE-9C06-87A7334CDD65} - (no file)
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: {62a86bb3-32fb-ac48-1c54-3f8acd957c38} - {83c759dc-a8f3-45c1-84ca-bf233bb68a26} - C:\WINDOWS\system32\ylsobfbc.dll
O2 - BHO: (no name) - {8A290466-39BD-419B-93DB-0E9599506654} - C:\WINDOWS\system32\vtUnoOFW.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [5cdf3c63] rundll32.exe "C:\WINDOWS\system32\ypjikeox.dll",b
O4 - HKLM\..\Run: [BM5fec0fff] Rundll32.exe "C:\WINDOWS\system32\rlximbya.dll",s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [SpybotDeletingA4050] command /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6095] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3830] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9466] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P10 /q C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\ECC9DWS8.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\617N0EG3.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\2BOLU1WL.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\PFT627~1\Reader\plug_ins\WEBBUY.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS9\Support\SymSC\SYMWMIIS.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS9\Support\Proxy.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Support\LUpdate\WLUEX.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Support\ccCommon\ccCommon.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Setup\Setup\SYMSHARE\CF.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NEEDFO~1\NEEDFO~1\GameData\SIMULA~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR~1\Content.IE5\GX2N81MB\HCTP_1~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR~1\Content.IE5\G9E7KPQN\KB7135~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR
O4 - HKCU\..\RunOnce: [SpybotDeletingB9540] command /c del "C:\WINDOWS\SYSTEM32\clwrqpii.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1720] cmd /c del "C:\WINDOWS\SYSTEM32\clwrqpii.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8926] command /c del "C:\WINDOWS\SYSTEM32\ivsoqrvv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8307] cmd /c del "C:\WINDOWS\SYSTEM32\ivsoqrvv.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB844] command /c del "C:\WINDOWS\SYSTEM32\anhppugd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3381] cmd /c del "C:\WINDOWS\SYSTEM32\anhppugd.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1920] command /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8065] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5114] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8098] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2825] command /c del "C:\WINDOWS\SYSTEM32\geBsrSLE.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD940] cmd /c del "C:\WINDOWS\SYSTEM32\geBsrSLE.dll_old"
O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [POSTRBT] C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe /REMEDIATE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD8514] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB8257] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old" (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD7869] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [POSTRBT] C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe /REMEDIATE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/bestfriends/miniclipGameLoader.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/198f28ea773f06d4e822/netzip/RdxIE601.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,11/mcgdmgr.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4356/mcfscan.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\msn.dll ylsobfbc.dll
O20 - Winlogon Notify: vtUnoOFW - C:\WINDOWS\SYSTEM32\vtUnoOFW.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 15259 bytes

 

 I am not a computer whiz, so I am hoping that there is someone here that can help me, in layman's terms, fix this problem.

 

Thank you very much,

 

Jimmer

  • bamajim

    10376 Posts

    457

    0

    Posted June 26th, 2008 00:00

    JIMMERW

    1. We Need to temporarily disable SpyBotS&D Tea timer so it doesn't interfere with our fix
    • 1) Run Spybot-S&D
      2) Go to the Mode menu, and make sure "Advanced Mode" is selected
      3) On the left hand side, choose Tools -> Resident
      4) Uncheck "Resident TeaTimer" and OK any prompts
      5) Restart your computer.





    2. Please download VundoFix.exe to your desktop.


    • Double-click VundoFix.exe to run it.
    • Click the Scan for Vundo button.
    • Once it's done scanning, click the Fix Vundo button.
    • You will receive a prompt asking if you want to remove the files, click YES
    • Once you click yes, your desktop will go blank as it starts removing Vundo.
    • When completed, it will prompt that it will reboot your computer, click OK.
    • Please post the contents of C:\vundofix.txt and a new HiJackThis log.

    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.











    Microsoft MVP Consumer-Security

     


    "The world is what you make of it"




  • JIMMERW

    21 Posts

    456

    0

    Posted June 26th, 2008 00:00

     Thank you. I will try it now. I'll let you know.
  • JIMMERW

    21 Posts

    456

    0

    Posted June 26th, 2008 01:00

     Ok, I ran the vundo fix, but still getting the userinit error and no bottom toolbar or desktop icons. Here are the logs.

     

    VundoFix V7.0.6
    
    Scan started at 9:55:33 PM 25/06/2008
    
    Listing files found while scanning....
    
    C:\Windows\SYSTEM32\abxqbtai.dll
    C:\Windows\SYSTEM32\buqiowax.dll
    C:\Windows\SYSTEM32\ccmwsivs.dll
    C:\Windows\SYSTEM32\epbwcwdu.dll
    C:\Windows\SYSTEM32\eyysveww.dll
    C:\Windows\SYSTEM32\fxrjdhbg.dll
    C:\Windows\SYSTEM32\gpauqotl.dll
    C:\Windows\SYSTEM32\hdfyqcnt.dll
    C:\Windows\SYSTEM32\innagpkm.dll
    C:\Windows\SYSTEM32\ixmqtgay.dll
    C:\Windows\SYSTEM32\jofpsfao.dll
    C:\Windows\SYSTEM32\jwdlkpgi.dll
    C:\Windows\SYSTEM32\kxumyjwb.dll
    C:\Windows\SYSTEM32\ljnpbbuv.dll
    C:\Windows\SYSTEM32\logvmgub.dll
    C:\Windows\SYSTEM32\ltoquapg.ini
    C:\Windows\SYSTEM32\mtquanng.dll
    C:\Windows\SYSTEM32\naskyddi.dll
    C:\Windows\SYSTEM32\njhuwjkw.dll
    C:\Windows\SYSTEM32\nqpagema.dll
    C:\Windows\SYSTEM32\odrxqstg.dll
    C:\Windows\SYSTEM32\oemykqqw.dll
    C:\Windows\SYSTEM32\oxgpdldc.dll
    C:\Windows\SYSTEM32\podnnbak.dll
    C:\Windows\SYSTEM32\qedglegy.dll
    C:\Windows\SYSTEM32\qvbmyavd.dll
    C:\Windows\SYSTEM32\rapwmyut.dll
    C:\Windows\SYSTEM32\rcyanrbq.dll
    C:\Windows\SYSTEM32\wwevsyye.ini
    
    Beginning removal...
    
     Attempting to delete C:\Windows\SYSTEM32\abxqbtai.dll
    C:\Windows\SYSTEM32\abxqbtai.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\buqiowax.dll
    C:\Windows\SYSTEM32\buqiowax.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\ccmwsivs.dll
    C:\Windows\SYSTEM32\ccmwsivs.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\epbwcwdu.dll
    C:\Windows\SYSTEM32\epbwcwdu.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\eyysveww.dll
    C:\Windows\SYSTEM32\eyysveww.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\fxrjdhbg.dll
    C:\Windows\SYSTEM32\fxrjdhbg.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\gpauqotl.dll
    C:\Windows\SYSTEM32\gpauqotl.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\hdfyqcnt.dll
    C:\Windows\SYSTEM32\hdfyqcnt.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\innagpkm.dll
    C:\Windows\SYSTEM32\innagpkm.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\ixmqtgay.dll
    C:\Windows\SYSTEM32\ixmqtgay.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\jofpsfao.dll
    C:\Windows\SYSTEM32\jofpsfao.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\jwdlkpgi.dll
    C:\Windows\SYSTEM32\jwdlkpgi.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\kxumyjwb.dll
    C:\Windows\SYSTEM32\kxumyjwb.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\ljnpbbuv.dll
    C:\Windows\SYSTEM32\ljnpbbuv.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\logvmgub.dll
    C:\Windows\SYSTEM32\logvmgub.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\ltoquapg.ini
    C:\Windows\SYSTEM32\ltoquapg.ini Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\mtquanng.dll
    C:\Windows\SYSTEM32\mtquanng.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\naskyddi.dll
    C:\Windows\SYSTEM32\naskyddi.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\njhuwjkw.dll
    C:\Windows\SYSTEM32\njhuwjkw.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\nqpagema.dll
    C:\Windows\SYSTEM32\nqpagema.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\odrxqstg.dll
    C:\Windows\SYSTEM32\odrxqstg.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\oemykqqw.dll
    C:\Windows\SYSTEM32\oemykqqw.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\oxgpdldc.dll
    C:\Windows\SYSTEM32\oxgpdldc.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\podnnbak.dll
    C:\Windows\SYSTEM32\podnnbak.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\qedglegy.dll
    C:\Windows\SYSTEM32\qedglegy.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\qvbmyavd.dll
    C:\Windows\SYSTEM32\qvbmyavd.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\rapwmyut.dll
    C:\Windows\SYSTEM32\rapwmyut.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\rcyanrbq.dll
    C:\Windows\SYSTEM32\rcyanrbq.dll Has been deleted!
    
     Attempting to delete C:\Windows\SYSTEM32\wwevsyye.ini
    C:\Windows\SYSTEM32\wwevsyye.ini Has been deleted!
    
    Performing Repairs to the registry.
    Done!
  • JIMMERW

    21 Posts

    456

    0

    Posted June 26th, 2008 01:00

    Here is the Hijackthis log.

     

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:26:30 PM, on 25/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\SiteAdvisor\6261\SAService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
    C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thestar.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
    O2 - BHO: (no name) - {144D91DD-D93C-4730-9F97-254982465CA6} - (no file)
    O2 - BHO: (no name) - {21890061-4A03-416E-88B5-526EBD76FB56} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: (no name) - {66EA8EB2-F8B0-4ABE-9C06-87A7334CDD65} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: {62a86bb3-32fb-ac48-1c54-3f8acd957c38} - {83c759dc-a8f3-45c1-84ca-bf233bb68a26} - C:\WINDOWS\system32\ylsobfbc.dll
    O2 - BHO: (no name) - {8A290466-39BD-419B-93DB-0E9599506654} - C:\WINDOWS\system32\vtUnoOFW.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [MMTray] MMTray.exe
    O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
    O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
    O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
    O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
    O4 - HKLM\..\Run: [5cdf3c63] rundll32.exe "C:\WINDOWS\system32\ypjikeox.dll",b
    O4 - HKLM\..\Run: [BM5fec0fff] Rundll32.exe "C:\WINDOWS\system32\rlximbya.dll",s
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4050] command /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6095] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3830] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9466] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
    O4 - HKCU\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P10 /q C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\ECC9DWS8.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\617N0EG3.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\2BOLU1WL.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\PFT627~1\Reader\plug_ins\WEBBUY.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS9\Support\SymSC\SYMWMIIS.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS9\Support\Proxy.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Support\LUpdate\WLUEX.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Support\ccCommon\ccCommon.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Setup\Setup\SYMSHARE\CF.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NEEDFO~1\NEEDFO~1\GameData\SIMULA~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR~1\Content.IE5\GX2N81MB\HCTP_1~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR~1\Content.IE5\G9E7KPQN\KB7135~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9540] command /c del "C:\WINDOWS\SYSTEM32\clwrqpii.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1720] cmd /c del "C:\WINDOWS\SYSTEM32\clwrqpii.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8926] command /c del "C:\WINDOWS\SYSTEM32\ivsoqrvv.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8307] cmd /c del "C:\WINDOWS\SYSTEM32\ivsoqrvv.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB844] command /c del "C:\WINDOWS\SYSTEM32\anhppugd.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3381] cmd /c del "C:\WINDOWS\SYSTEM32\anhppugd.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1920] command /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8065] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5114] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8098] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2825] command /c del "C:\WINDOWS\SYSTEM32\geBsrSLE.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD940] cmd /c del "C:\WINDOWS\SYSTEM32\geBsrSLE.dll_old"
    O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [POSTRBT] C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe /REMEDIATE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD8514] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB8257] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD7869] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [POSTRBT] C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe /REMEDIATE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/bestfriends/miniclipGameLoader.dll
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/198f28ea773f06d4e822/netzip/RdxIE601.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,11/mcgdmgr.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
    O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4356/mcfscan.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\msn.dll ylsobfbc.dll
    O20 - Winlogon Notify: vtUnoOFW - C:\WINDOWS\SYSTEM32\vtUnoOFW.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
    O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 15210 bytes

     Ok, those are the new logs. Thank you for the help. So what do I do next?

     

    JIMMER

  • bamajim

    10376 Posts

    456

    0

    Posted June 26th, 2008 11:00

    JIMMERW

    Better. We still have some work to do.
    We need to finish removing the infection, the we will focus on your desktop items.

    We are going to run Vundofix again, but change the instructions slightly.

    Open Notepad (Not Wordpad). Copy and paste the following into NotePad


    C:\WINDOWS\system32\ylsobfbc.dll
    C:\WINDOWS\system32\vtUnoOFW.dll
    C:\WINDOWS\system32\ypjikeox.dll
    C:\WINDOWS\system32\rlximbya.dll
    C:\WINDOWS\SYSTEM32\msktboty.dll_old
    C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old
    C:\WINDOWS\SYSTEM32\clwrqpii.dll_old
    C:\WINDOWS\SYSTEM32\ivsoqrvv.dll_old
    C:\WINDOWS\SYSTEM32\anhppugd.dll_old
    C:\WINDOWS\SYSTEM32\msktboty.dll_old
    C:\WINDOWS\SYSTEM32\geBsrSLE.dll_old
    C:\WINDOWS\SYSTEM32\vtUnoOFW.dll
    C:\WINDOWS\System32\msn.dll
    C:\WINDOWS\SYSTEM32\vtUnoOFW.dll

















    • Click File ->> Save As, and type in vundofix.vft (exactly as shown)
    • Under Save as type Select "All Files" and Save it to your Desktop
    • Double Click Vundofix.exe to run the program.
    • Next drag and drop the vundofix.vft file you made into the white window of Vundofix
    • The list of files should appear in the window
    • Right click in the open window and Select "Select all" (or manualy add check marks) in the boxes preceeeding the file names.
    • With the boxes all checked Select "Fix Vundo" Do Not Select "Scan for Vundo"
    • You will receive a prompt asking "Are you sure you want to remove these files?", click YES
    • Once you click yes, your desktop will go blank as it starts removing Vundo.
    • When completed, it will prompt that it will reboot your computer, click OK.
    • The vundofix.vtf file you made will be gone, this is normal.

    Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.

    Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting




















    Microsoft MVP Consumer-Security

     


    "The world is what you make of it"




  • JIMMERW

    21 Posts

    456

    0

    Posted June 26th, 2008 17:00

      Hi bamajim. Thanks for all the help so far. Here is the vundofix log.

     

    Beginning removal...
    
     Attempting to delete C:\WINDOWS\SYSTEM32\vtUnoOFW.dll
    C:\WINDOWS\SYSTEM32\vtUnoOFW.dll Could not be deleted.
    
     Attempting to delete C:\WINDOWS\SYSTEM32\vtUnoOFW.dll
    C:\WINDOWS\SYSTEM32\vtUnoOFW.dll Could not be deleted.
    
     Attempting to delete C:\WINDOWS\system32\vtUnoOFW.dll
    C:\WINDOWS\system32\vtUnoOFW.dll Could not be deleted.
    
     Attempting to delete C:\WINDOWS\system32\ylsobfbc.dll
    C:\WINDOWS\system32\ylsobfbc.dll Could not be deleted.
    
    Performing Repairs to the registry.
    Done!
     

     

     And here is the HJT log.

     

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:29:29 PM, on 26/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\SiteAdvisor\6261\SAService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
    C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.thestar.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
    O2 - BHO: (no name) - {144D91DD-D93C-4730-9F97-254982465CA6} - (no file)
    O2 - BHO: (no name) - {21890061-4A03-416E-88B5-526EBD76FB56} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
    O2 - BHO: (no name) - {66EA8EB2-F8B0-4ABE-9C06-87A7334CDD65} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
    O2 - BHO: {62a86bb3-32fb-ac48-1c54-3f8acd957c38} - {83c759dc-a8f3-45c1-84ca-bf233bb68a26} - C:\WINDOWS\system32\ylsobfbc.dll
    O2 - BHO: (no name) - {8A290466-39BD-419B-93DB-0E9599506654} - C:\WINDOWS\system32\vtUnoOFW.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [MMTray] MMTray.exe
    O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
    O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
    O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
    O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
    O4 - HKLM\..\Run: [5cdf3c63] rundll32.exe "C:\WINDOWS\system32\ypjikeox.dll",b
    O4 - HKLM\..\Run: [BM5fec0fff] Rundll32.exe "C:\WINDOWS\system32\rlximbya.dll",s
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4050] command /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6095] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3830] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC9466] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
    O4 - HKLM\..\RunOnce: [VundoFix] "C:\Documents and Settings\JAMES\Local Settings\Temporary Internet Files\Content.IE5\C94VWFON\vundofix.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
    O4 - HKCU\..\Run: [DelayShred] "C:\Program Files\McAfee\MSHR\ShrCL.EXE" /P10 /q C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\ECC9DWS8.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\617N0EG3.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.IE5\2BOLU1WL.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1\Content.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\TEMPOR~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\PFT627~1\Reader\plug_ins\WEBBUY.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS9\Support\SymSC\SYMWMIIS.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS9\Support\Proxy.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Support\LUpdate\WLUEX.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Support\ccCommon\ccCommon.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NIS150~1.60\Setup\Setup\SYMSHARE\CF.SH! C:\DOCUME~1\JAMES\LOCALS~1\Temp\NEEDFO~1\NEEDFO~1\GameData\SIMULA~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR~1\Content.IE5\GX2N81MB\HCTP_1~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR~1\Content.IE5\G9E7KPQN\KB7135~1.SH! C:\DOCUME~1\JAMES\LOCALS~1\TEMPOR
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9540] command /c del "C:\WINDOWS\SYSTEM32\clwrqpii.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD1720] cmd /c del "C:\WINDOWS\SYSTEM32\clwrqpii.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8926] command /c del "C:\WINDOWS\SYSTEM32\ivsoqrvv.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8307] cmd /c del "C:\WINDOWS\SYSTEM32\ivsoqrvv.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB844] command /c del "C:\WINDOWS\SYSTEM32\anhppugd.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3381] cmd /c del "C:\WINDOWS\SYSTEM32\anhppugd.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB1920] command /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8065] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB5114] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8098] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB2825] command /c del "C:\WINDOWS\SYSTEM32\geBsrSLE.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD940] cmd /c del "C:\WINDOWS\SYSTEM32\geBsrSLE.dll_old"
    O4 - HKUS\S-1-5-18\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [POSTRBT] C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe /REMEDIATE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD8514] cmd /c del "C:\WINDOWS\SYSTEM32\msktboty.dll_old" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB8257] command /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD7869] cmd /c del "C:\WINDOWS\SYSTEM32\xgrknpgr.dll_old" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [POSTRBT] C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe /REMEDIATE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/bestfriends/miniclipGameLoader.dll
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,64/mcinsctl.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/198f28ea773f06d4e822/netzip/RdxIE601.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,11/mcgdmgr.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
    O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadtech.net/cn1060/pcpowerscan.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4356/mcfscan.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\msn.dll ylsobfbc.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
    O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    --
    End of file - 15332 bytes

     So what's next? :)

     

    JIMMER

  • bamajim

    10376 Posts

    456

    0

    Posted June 26th, 2008 18:00

    JIMMERW

    We have some things in hiding.

    1. Go HERE and download File Lister.
    • Save it to your Desktop
      Rt Click ->> Extract all ->> And extract it to your Desktop
      Additional help on extracting zip files can be found HERE
      Open the File Lister Folder.
      Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
      As the program runs, it will appear that nothing is happening.
      When the program is fnished it will produce a log for you C:\Files.txt






    Copy and paste the contents of that log in your reply.













    Microsoft MVP Consumer-Security

     


    "The world is what you make of it"




  • JIMMERW

    21 Posts

    342

    0

    Posted June 26th, 2008 19:00

    Hi bamajim. Ok, here is the avenger log. I will post the HJT log in a new post to conserve posting space. BTW, my bottom toolbar and desktop icons have returned. :smileyhappy:

     

    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com
    
    Platform:  Windows XP
    
    *******************
    
    Script file opened successfully.
    Script file read successfully.
    
    Backups directory opened successfully at C:\Avenger
    
    *******************
    
    Beginning to process script file:
    
    Rootkit scan active.
    No rootkits found!
    
    File "C:\WINDOWS\SYSTEM32\aebbepen.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\bayeykdb.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\bdamigjw.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\bowfmvjh.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\cfwrmlcb.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\ctapvmwd.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\egvvursc.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\enrpgtyg.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\fkvxeaht.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\fvqnqoei.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\gdrvduan.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\gupvndjg.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\gvbufuwg.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\gvrvmcoy.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\hdkdkwta.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\hllwulyj.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\idulqgnc.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\irxtcber.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\jrcgcwhw.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\kgjmtdwh.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\lejrerjt.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\lgivwuds.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\lrysrrib.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\ltmgtfwo.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\mnvfraje.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\olqoqbye.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\ovqdbpbl.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\puxemwec.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\pwrpebwo.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\qeoswnip.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\qfcblkiu.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\qngjdrsn.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\qrsrqpgr.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\qtgjnrpp.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\ryiqxavk.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\sfyiakqo.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\tdtpakts.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\tjrerjel.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\tsqamcyu.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\ulcjtubj.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\umncjrju.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\undyucft.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\vcgmrdjx.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\vsdqlhly.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\wicecgud.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\wuoxlbte.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\xdxuxaib.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\xoekijpy.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\ylsobfbc.dll" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\ywwyilrg.ini" deleted successfully.
    File "C:\WINDOWS\SYSTEM32\yyaydlay.ini" deleted successfully.
    File "C:\WINDOWS\system32\vtUnoOFW.dll" deleted successfully.
    
    Error:  file "C:\WINDOWS\system32\ypjikeox.dll" not found!
    Deletion of file "C:\WINDOWS\system32\ypjikeox.dll" failed!
    Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
      --> the object does not exist
    
    
    Error:  file "C:\WINDOWS\system32\rlximbya.dll" not found!
    Deletion of file "C:\WINDOWS\system32\rlximbya.dll" failed!
    Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
      --> the object does not exist
    
    
    Completed script processing.
    
    *******************
    
    Finished!  Terminate.
  • JIMMERW

    21 Posts

    456

    0

    Posted June 26th, 2008 19:00

    Hello bamajim, the File Lister log is too big for 1, even 2 posts, so I have split it in 3. Here is part 1.

     

    +++++++++++++++++++++++++++++++++
    +
    + File Lister
    +
    + Version 1.0.2
    +
    +  By bamajim
    +
    +++++++++++++++++++++++++++++++++

    === Values under HKLM\~\Run ======

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
    "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\"  -osboot"
    "RemoteControl"="\"C:\\Program Files\\CyberLink DVD Solution\\PowerDVD\\PDVDServ.exe\""
    "InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
    "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
    "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
    "osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
    "Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
    "MMTray"="MMTray.exe"
    "MMTray2K"="MMTray2k.exe"
    "MMTrayLSI"="MMTrayLSI.exe"
    "nmctxth"="\"C:\\Program Files\\Common Files\\Pure Networks Shared\\Platform\\nmctxth.exe\""
    "nmapp"="\"C:\\Program Files\\Pure Networks\\Network Magic\\nmapp.exe\" -autorun -nosplash"
    "Sony Ericsson PC Suite"="\"C:\\Program Files\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "mcagent_exe"="C:\\Program Files\\McAfee.com\\Agent\\mcagent.exe /runkey"
    "SiteAdvisor"="\"C:\\Program Files\\SiteAdvisor\\6261\\SiteAdv.exe\""
    "5cdf3c63"="rundll32.exe \"C:\\WINDOWS\\system32\\ypjikeox.dll\",b"
    "BM5fec0fff"="Rundll32.exe \"C:\\WINDOWS\\system32\\rlximbya.dll\",s"
    "KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
      65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
    "Installed"="1"


    === Values under HKCU\~\Run ======

    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\" /tray"
    "DelayShred"="\"C:\\Program Files\\McAfee\\MSHR\\ShrCL.EXE\" /P10 /q C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\TEMPOR~1\\Content.IE5\\ECC9DWS8.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\TEMPOR~1\\Content.IE5\\617N0EG3.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\TEMPOR~1\\Content.IE5\\2BOLU1WL.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\TEMPOR~1\\Content.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\TEMPOR~1.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\PFT627~1\\Reader\\plug_ins\\WEBBUY.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\NIS9\\Support\\SymSC\\SYMWMIIS.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\NIS9\\Support\\Proxy.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\NIS150~1.60\\Support\\LUpdate\\WLUEX.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\NIS150~1.60\\Support\\ccCommon\\ccCommon.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\NIS150~1.60\\Setup\\Setup\\SYMSHARE\\CF.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\Temp\\NEEDFO~1\\NEEDFO~1\\GameData\\SIMULA~1.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\TEMPOR~1\\Content.IE5\\GX2N81MB\\HCTP_1~1.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\TEMPOR~1\\Content.IE5\\G9E7KPQN\\KB7135~1.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\TEMPOR~1\\Content.IE5\\SPAZODQR\\QUERY_~1.SH! C:\\DOCUME~1\\JAMES\\LOCALS~1\\TEMPOR~1\\Content.IE5\\255UJU1C\\KB5161~1.SH! C:\\DOCUME~1\\JAMES\\Cookies\\JA84D3~1.SH!"
    "Uniblue RegistryBooster 2"="C:\\Program Files\\Uniblue\\RegistryBooster 2\\RegistryBooster.exe /S"


    === Folders and Files from "%\" and "%\Windows" Created Last 30 Days ======

    25/06/2008 9:55:33 PM    5309232    C:\VundoFix Backups
    26/06/2008 3:58:09 PM    0    32    C:\Files.txt
    26/06/2008 2:15:56 PM    526    32    C:\vundofix.txt
    11/06/2008 6:38:21 PM    1409    32    C:\WINDOWS\QTFont.for
    11/06/2008 6:38:21 PM    54156    34    C:\WINDOWS\QTFont.qfn
    26/06/2008 1:52:20 PM    499    32    C:\WINDOWS\vundofix.vft
    28/05/2008 7:17:19 PM    2644181    38    C:\WINDOWS\SYSTEM32\aebbepen.ini
    14/06/2008 6:05:43 PM    1661002    38    C:\WINDOWS\SYSTEM32\bayeykdb.ini
    22/06/2008 6:34:26 PM    128512    32    C:\WINDOWS\SYSTEM32\bdamigjw.dll
    28/05/2008 6:46:18 PM    109568    32    C:\WINDOWS\SYSTEM32\bowfmvjh.dll
    27/05/2008 1:46:14 PM    1311927    38    C:\WINDOWS\SYSTEM32\cfwrmlcb.ini
    31/05/2008 12:53:21 PM    2438    38    C:\WINDOWS\SYSTEM32\ctapvmwd.ini
    30/05/2008 12:41:17 AM    106496    32    C:\WINDOWS\SYSTEM32\egvvursc.dll
    07/06/2008 9:12:00 AM    1554    38    C:\WINDOWS\SYSTEM32\enrpgtyg.ini
    21/06/2008 6:36:14 PM    130560    32    C:\WINDOWS\SYSTEM32\fkvxeaht.dll
    31/05/2008 12:52:27 AM    1838    38    C:\WINDOWS\SYSTEM32\fvqnqoei.ini
    11/06/2008 6:03:53 PM    3382    38    C:\WINDOWS\SYSTEM32\gdrvduan.ini
    31/05/2008 12:43:27 AM    109568    32    C:\WINDOWS\SYSTEM32\gupvndjg.dll
    28/05/2008 6:47:02 PM    112640    32    C:\WINDOWS\SYSTEM32\gvbufuwg.dll
    31/05/2008 12:41:18 PM    108544    32    C:\WINDOWS\SYSTEM32\gvrvmcoy.dll
    27/05/2008 1:55:37 PM    117760    32    C:\WINDOWS\SYSTEM32\hdkdkwta.dll
    20/06/2008 6:30:27 PM    1518626    38    C:\WINDOWS\SYSTEM32\hllwulyj.ini
    20/06/2008 6:27:36 PM    132608    32    C:\WINDOWS\SYSTEM32\idulqgnc.dll
    20/06/2008 6:27:25 PM    123392    32    C:\WINDOWS\SYSTEM32\irxtcber.dll
    21/06/2008 6:33:15 PM    1519348    38    C:\WINDOWS\SYSTEM32\jrcgcwhw.ini
    30/05/2008 12:42:17 AM    1426    38    C:\WINDOWS\SYSTEM32\kgjmtdwh.ini
    15/06/2008 6:27:35 PM    1657875    38    C:\WINDOWS\SYSTEM32\lejrerjt.ini
    08/06/2008 9:19:30 AM    2206    38    C:\WINDOWS\SYSTEM32\lgivwuds.ini
    16/06/2008 6:30:04 PM    1658227    38    C:\WINDOWS\SYSTEM32\lrysrrib.ini
    06/06/2008 2:52:32 PM    1074    38    C:\WINDOWS\SYSTEM32\ltmgtfwo.ini
    01/06/2008 1:02:30 PM    108544    32    C:\WINDOWS\SYSTEM32\mnvfraje.dll
    31/05/2008 12:49:28 AM    104448    32    C:\WINDOWS\SYSTEM32\olqoqbye.dll
    18/06/2008 6:30:34 PM    1566456    38    C:\WINDOWS\SYSTEM32\ovqdbpbl.ini
    02/06/2008 2:53:25 PM    4042    38    C:\WINDOWS\SYSTEM32\puxemwec.ini
    05/06/2008 2:51:10 PM    102400    32    C:\WINDOWS\SYSTEM32\pwrpebwo.dll
    04/06/2008 2:57:28 PM    104448    32    C:\WINDOWS\SYSTEM32\qeoswnip.dll
    10/06/2008 6:00:41 PM    3142    38    C:\WINDOWS\SYSTEM32\qfcblkiu.ini
    22/06/2008 6:28:33 PM    128512    32    C:\WINDOWS\SYSTEM32\qngjdrsn.dll
    30/05/2008 12:48:19 AM    111616    32    C:\WINDOWS\SYSTEM32\qrsrqpgr.dll
    04/06/2008 2:48:40 PM    106496    32    C:\WINDOWS\SYSTEM32\qtgjnrpp.dll
    21/06/2008 6:30:14 PM    128512    32    C:\WINDOWS\SYSTEM32\ryiqxavk.dll
    22/06/2008 6:31:27 PM    1519930    38    C:\WINDOWS\SYSTEM32\sfyiakqo.ini
    13/06/2008 2:45:48 PM    579464    32    C:\WINDOWS\SYSTEM32\SymNeti.dll
    13/06/2008 2:45:44 PM    207240    32    C:\WINDOWS\SYSTEM32\SymRedir.dll
    01/06/2008 12:41:30 PM    104448    32    C:\WINDOWS\SYSTEM32\tdtpakts.dll
    15/06/2008 6:27:34 PM    123392    0    C:\WINDOWS\SYSTEM32\tjrerjel.dll
    05/06/2008 3:00:10 PM    714    38    C:\WINDOWS\SYSTEM32\tsqamcyu.ini
    09/06/2008 6:03:58 PM    2730    38    C:\WINDOWS\SYSTEM32\ulcjtubj.ini
    31/05/2008 12:40:49 PM    104448    32    C:\WINDOWS\SYSTEM32\umncjrju.dll
    16/06/2008 6:26:59 PM    127488    32    C:\WINDOWS\SYSTEM32\undyucft.dll
    01/06/2008 12:59:31 PM    3210    38    C:\WINDOWS\SYSTEM32\vcgmrdjx.ini
    14/06/2008 6:02:39 PM    133632    32    C:\WINDOWS\SYSTEM32\vsdqlhly.dll
    17/06/2008 6:27:43 PM    1897103    38    C:\WINDOWS\SYSTEM32\wicecgud.ini
    17/06/2008 6:27:31 PM    124416    32    C:\WINDOWS\SYSTEM32\wuoxlbte.dll
    04/06/2008 2:48:48 PM    624    38    C:\WINDOWS\SYSTEM32\xdxuxaib.ini
    23/06/2008 6:31:32 PM    1588888    38    C:\WINDOWS\SYSTEM32\xoekijpy.ini
    23/06/2008 6:34:39 PM    137728    0    C:\WINDOWS\SYSTEM32\ylsobfbc.dll
    19/06/2008 6:35:17 PM    1508570    38    C:\WINDOWS\SYSTEM32\ywwyilrg.ini
    03/06/2008 3:04:16 PM    5030    38    C:\WINDOWS\SYSTEM32\yyaydlay.ini

    === Files under "\Administrator\Startup" Last 30 Days======

    28/05/2008 7:17:19 PM    2644181    38    C:\WINDOWS\SYSTEM32\aebbepen.ini
    14/06/2008 6:05:43 PM    1661002    38    C:\WINDOWS\SYSTEM32\bayeykdb.ini
    22/06/2008 6:34:26 PM    128512    32    C:\WINDOWS\SYSTEM32\bdamigjw.dll
    28/05/2008 6:46:18 PM    109568    32    C:\WINDOWS\SYSTEM32\bowfmvjh.dll
    27/05/2008 1:46:14 PM    1311927    38    C:\WINDOWS\SYSTEM32\cfwrmlcb.ini
    31/05/2008 12:53:21 PM    2438    38    C:\WINDOWS\SYSTEM32\ctapvmwd.ini
    30/05/2008 12:41:17 AM    106496    32    C:\WINDOWS\SYSTEM32\egvvursc.dll
    07/06/2008 9:12:00 AM    1554    38    C:\WINDOWS\SYSTEM32\enrpgtyg.ini
    21/06/2008 6:36:14 PM    130560    32    C:\WINDOWS\SYSTEM32\fkvxeaht.dll
    31/05/2008 12:52:27 AM    1838    38    C:\WINDOWS\SYSTEM32\fvqnqoei.ini
    11/06/2008 6:03:53 PM    3382    38    C:\WINDOWS\SYSTEM32\gdrvduan.ini
    31/05/2008 12:43:27 AM    109568    32    C:\WINDOWS\SYSTEM32\gupvndjg.dll
    28/05/2008 6:47:02 PM    112640    32    C:\WINDOWS\SYSTEM32\gvbufuwg.dll
    31/05/2008 12:41:18 PM    108544    32    C:\WINDOWS\SYSTEM32\gvrvmcoy.dll
    27/05/2008 1:55:37 PM    117760    32    C:\WINDOWS\SYSTEM32\hdkdkwta.dll
    20/06/2008 6:30:27 PM    1518626    38    C:\WINDOWS\SYSTEM32\hllwulyj.ini
    20/06/2008 6:27:36 PM    132608    32    C:\WINDOWS\SYSTEM32\idulqgnc.dll
    20/06/2008 6:27:25 PM    123392    32    C:\WINDOWS\SYSTEM32\irxtcber.dll
    21/06/2008 6:33:15 PM    1519348    38    C:\WINDOWS\SYSTEM32\jrcgcwhw.ini
    30/05/2008 12:42:17 AM    1426    38    C:\WINDOWS\SYSTEM32\kgjmtdwh.ini
    15/06/2008 6:27:35 PM    1657875    38    C:\WINDOWS\SYSTEM32\lejrerjt.ini
    08/06/2008 9:19:30 AM    2206    38    C:\WINDOWS\SYSTEM32\lgivwuds.ini
    16/06/2008 6:30:04 PM    1658227    38    C:\WINDOWS\SYSTEM32\lrysrrib.ini
    06/06/2008 2:52:32 PM    1074    38    C:\WINDOWS\SYSTEM32\ltmgtfwo.ini
    01/06/2008 1:02:30 PM    108544    32    C:\WINDOWS\SYSTEM32\mnvfraje.dll
    31/05/2008 12:49:28 AM    104448    32    C:\WINDOWS\SYSTEM32\olqoqbye.dll
    18/06/2008 6:30:34 PM    1566456    38    C:\WINDOWS\SYSTEM32\ovqdbpbl.ini
    02/06/2008 2:53:25 PM    4042    38    C:\WINDOWS\SYSTEM32\puxemwec.ini
    05/06/2008 2:51:10 PM    102400    32    C:\WINDOWS\SYSTEM32\pwrpebwo.dll
    04/06/2008 2:57:28 PM    104448    32    C:\WINDOWS\SYSTEM32\qeoswnip.dll
    10/06/2008 6:00:41 PM    3142    38    C:\WINDOWS\SYSTEM32\qfcblkiu.ini
    22/06/2008 6:28:33 PM    128512    32    C:\WINDOWS\SYSTEM32\qngjdrsn.dll
    30/05/2008 12:48:19 AM    111616    32    C:\WINDOWS\SYSTEM32\qrsrqpgr.dll
    04/06/2008 2:48:40 PM    106496    32    C:\WINDOWS\SYSTEM32\qtgjnrpp.dll
    21/06/2008 6:30:14 PM    128512    32    C:\WINDOWS\SYSTEM32\ryiqxavk.dll
    22/06/2008 6:31:27 PM    1519930    38    C:\WINDOWS\SYSTEM32\sfyiakqo.ini
    13/06/2008 2:45:48 PM    579464    32    C:\WINDOWS\SYSTEM32\SymNeti.dll
    13/06/2008 2:45:44 PM    207240    32    C:\WINDOWS\SYSTEM32\SymRedir.dll
    01/06/2008 12:41:30 PM    104448    32    C:\WINDOWS\SYSTEM32\tdtpakts.dll
    15/06/2008 6:27:34 PM    123392    0    C:\WINDOWS\SYSTEM32\tjrerjel.dll
    05/06/2008 3:00:10 PM    714    38    C:\WINDOWS\SYSTEM32\tsqamcyu.ini
    09/06/2008 6:03:58 PM    2730    38    C:\WINDOWS\SYSTEM32\ulcjtubj.ini
    31/05/2008 12:40:49 PM    104448    32    C:\WINDOWS\SYSTEM32\umncjrju.dll
    16/06/2008 6:26:59 PM    127488    32    C:\WINDOWS\SYSTEM32\undyucft.dll
    01/06/2008 12:59:31 PM    3210    38    C:\WINDOWS\SYSTEM32\vcgmrdjx.ini
    14/06/2008 6:02:39 PM    133632    32    C:\WINDOWS\SYSTEM32\vsdqlhly.dll
    17/06/2008 6:27:43 PM    1897103    38    C:\WINDOWS\SYSTEM32\wicecgud.ini
    17/06/2008 6:27:31 PM    124416    32    C:\WINDOWS\SYSTEM32\wuoxlbte.dll
    04/06/2008 2:48:48 PM    624    38    C:\WINDOWS\SYSTEM32\xdxuxaib.ini
    23/06/2008 6:31:32 PM    1588888    38    C:\WINDOWS\SYSTEM32\xoekijpy.ini
    23/06/2008 6:34:39 PM    137728    0    C:\WINDOWS\SYSTEM32\ylsobfbc.dll
    19/06/2008 6:35:17 PM    1508570    38    C:\WINDOWS\SYSTEM32\ywwyilrg.ini
    03/06/2008 3:04:16 PM    5030    38    C:\WINDOWS\SYSTEM32\yyaydlay.ini

    === Files under "\All Users\Startup" Last 30 Days======


    === Folders under "\Program Files" Last 30 Days======

    25/06/2008 6:24:27 PM    411622    C:\Program Files\Trend Micro
    25/06/2008 6:24:27 PM    411622    C:\Program Files\Trend Micro\HijackThis
    25/06/2008 6:53:06 PM    12848770    C:\Program Files\Uniblue
    25/06/2008 6:53:06 PM    12848770    C:\Program Files\Uniblue\RegistryBooster 2

  • bamajim

    10376 Posts

    342

    0

    Posted June 26th, 2008 19:00

    JIMMERW
    Do you have to read all of this???    Yep, affraid so.

    Let's change tools here.

    1. Please download The Avenger by Swandog46 to your Desktop.




    • Click on Avenger.zip to open the file
    • Extract avenger.exe to your desktop(How to extract (decompress) zipped or compressed files, help in the link here:)

    2. Copy all the text contained in the bold below to your Clipboard by highlighting it and pressing (Ctrl+C):

    Files to delete:
    C:\WINDOWS\SYSTEM32\aebbepen.ini
    C:\WINDOWS\SYSTEM32\bayeykdb.ini
    C:\WINDOWS\SYSTEM32\bdamigjw.dll
    C:\WINDOWS\SYSTEM32\bowfmvjh.dll
    C:\WINDOWS\SYSTEM32\cfwrmlcb.ini
    C:\WINDOWS\SYSTEM32\ctapvmwd.ini
    C:\WINDOWS\SYSTEM32\egvvursc.dll
    C:\WINDOWS\SYSTEM32\enrpgtyg.ini
    C:\WINDOWS\SYSTEM32\fkvxeaht.dll
    C:\WINDOWS\SYSTEM32\fvqnqoei.ini
    C:\WINDOWS\SYSTEM32\gdrvduan.ini
    C:\WINDOWS\SYSTEM32\gupvndjg.dll
    C:\WINDOWS\SYSTEM32\gvbufuwg.dll
    C:\WINDOWS\SYSTEM32\gvrvmcoy.dll
    C:\WINDOWS\SYSTEM32\hdkdkwta.dll
    C:\WINDOWS\SYSTEM32\hllwulyj.ini
    C:\WINDOWS\SYSTEM32\idulqgnc.dll
    C:\WINDOWS\SYSTEM32\irxtcber.dll
    C:\WINDOWS\SYSTEM32\jrcgcwhw.ini
    C:\WINDOWS\SYSTEM32\kgjmtdwh.ini
    C:\WINDOWS\SYSTEM32\lejrerjt.ini
    C:\WINDOWS\SYSTEM32\lgivwuds.ini
    C:\WINDOWS\SYSTEM32\lrysrrib.ini
    C:\WINDOWS\SYSTEM32\ltmgtfwo.ini
    C:\WINDOWS\SYSTEM32\mnvfraje.dll
    C:\WINDOWS\SYSTEM32\olqoqbye.dll
    C:\WINDOWS\SYSTEM32\ovqdbpbl.ini
    C:\WINDOWS\SYSTEM32\puxemwec.ini
    C:\WINDOWS\SYSTEM32\pwrpebwo.dll
    C:\WINDOWS\SYSTEM32\qeoswnip.dll
    C:\WINDOWS\SYSTEM32\qfcblkiu.ini
    C:\WINDOWS\SYSTEM32\qngjdrsn.dll
    C:\WINDOWS\SYSTEM32\qrsrqpgr.dll
    C:\WINDOWS\SYSTEM32\qtgjnrpp.dll
    C:\WINDOWS\SYSTEM32\ryiqxavk.dll
    C:\WINDOWS\SYSTEM32\sfyiakqo.ini
    C:\WINDOWS\SYSTEM32\tdtpakts.dll
    C:\WINDOWS\SYSTEM32\tjrerjel.dll
    C:\WINDOWS\SYSTEM32\tsqamcyu.ini
    C:\WINDOWS\SYSTEM32\ulcjtubj.ini
    C:\WINDOWS\SYSTEM32\umncjrju.dll
    C:\WINDOWS\SYSTEM32\undyucft.dll
    C:\WINDOWS\SYSTEM32\vcgmrdjx.ini
    C:\WINDOWS\SYSTEM32\vsdqlhly.dll
    C:\WINDOWS\SYSTEM32\wicecgud.ini
    C:\WINDOWS\SYSTEM32\wuoxlbte.dll
    C:\WINDOWS\SYSTEM32\xdxuxaib.ini
    C:\WINDOWS\SYSTEM32\xoekijpy.ini
    C:\WINDOWS\SYSTEM32\ylsobfbc.dll
    C:\WINDOWS\SYSTEM32\ywwyilrg.ini
    C:\WINDOWS\SYSTEM32\yyaydlay.ini
    C:\WINDOWS\system32\vtUnoOFW.dll
    C:\WINDOWS\system32\ypjikeox.dll
    C:\WINDOWS\system32\rlximbya.dll
























































    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

    3. Now, start The Avenger program by clicking on its icon on your desktop.
    • Select Load Script
    • Select Paste from Clipboard
    • The information should now appear in the Open window
    • Select Execute
    • Answer Yes When prompted "Are you sure you want to execute the current script?"

    4. The Avenger will automatically do the following:
    • It will Restart your computer.
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

    5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log














    Microsoft MVP Consumer-Security

     


    "The world is what you make of it"




    Message Edited by bamajim on 06-26-2008 03:40 PM