Unsolved

This post is more than 5 years old

13 Posts

1992

July 6th, 2008 21:00

Both the Desktop And the Toolbar disappear

Just yesterday morning, my computer started going extra slow so i restarted the computer and now the desktop and toolbar completely disappears. I tried deleting programs just installed and doing restore points but, none of those worked. Here is my HijackThis log:

 

 

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:02:20 PM, on 7/6/2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\taskeng.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Users\owner\Program Files\DNA\btdna.exe
C:\Users\owner\Program Files\uTorrent\uTorrent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Auslogics\AusLogics BoostSpeed\DiskDefrag.exe
C:\WINDOWS\SYSTEM32\Taskmgr.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\helppane.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: (no name) - {056BF8C6-6895-4ECF-AA7A-BE6DB541810E} - C:\Windows\system32\byXNghiH.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\ljJBqooO.dll,#1
O4 - HKLM\..\Run: [Microsoft] pwkpmovo.exe
O4 - HKLM\..\Run: [Microsoft(1)] hnlrfayv.exe
O4 - HKLM\..\RunServices: [Microsoft] pwkpmovo.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\owner\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\owner\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\owner\AppData\Local\Temp\khfCrPiH.dll,#1
O4 - HKCU\..\Run: [RegDefRun] C:\Program Files\Auslogics\AusLogics BoostSpeed\reginfo.exe /r
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: vzTCPConfig - https://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200313887041
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203546833750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1213661161787&h=cefda793e7d44af90274ef084de6de44/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.shockwave.com/content/burgershop/sis/GoBitGamesPlayer_v4.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbl_device -   - C:\Windows\system32\lxblcoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11024 bytes

I would really appreciate the help!

Message Edited by Greenfire999 on 07-06-2008 05:04 PM

10.4K Posts

July 7th, 2008 19:00

Greenfire999

It will take a couple of runs at this to completely remove the infection, so please be patient.

1. Go HERE and download TempFix.
Save it to your Desktop (but do not run it yet)

2. Reboot into Safe Mode
This can be done by
  • Restart your PC, and after it starts, but before you see the Windows Splash screen
    Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
    Use your arrow keys and select Safe Mode and then Enter


3. Rt Click TempFix.zip ->> Extract all ->> And extract it to your Desktop
Additional help on extracting zip files can be found HERE
  • Open the TempFix Folder.
    Rt Click TempFix.vbe ->>Select Open Then Open to confirm.
    As the program runs, it will appear that nothing is happening.
    When the program is fnished it will produce a log for you C:\TempFix.txt
    Copy and paste the contents of that log in your reply.
    Note: if your root drive is something other thatn C:\ then the log will default to your designated root drive





4. Then reboot your PC into Normal Windows Mode->> Rerun Hijackthis and post a fresh Hiajckthis log.
As well as the C:\TempFix.txt log

















Microsoft MVP Consumer-Security

 


"The world is what you make of it"




13 Posts

July 8th, 2008 08:00

TempFix

Version 1.0

By bamajim @ bamajim.com

========================================

C:\Users\owner\AppData\Local\Temp\awTLdCrp.dll
C:\Users\owner\AppData\Local\Temp\awtrOghe.dll
C:\Users\owner\AppData\Local\Temp\bh_html.htm
C:\Users\owner\AppData\Local\Temp\JklUxyxx.ini
C:\Users\owner\AppData\Local\Temp\JklUxyxx.ini2
C:\Users\owner\AppData\Local\Temp\jusched.log
C:\Users\owner\AppData\Local\Temp\owner.bmp
C:\Users\owner\AppData\Local\Temp\pmnlkKbC.dll
C:\Users\owner\AppData\Local\Temp\ssqPhIxu.dll
C:\Users\owner\AppData\Local\Temp\swt-awt-win32-3346.dll
C:\Users\owner\AppData\Local\Temp\swt-win32-3346.dll
C:\Users\owner\AppData\Local\Temp\tmp00019a2c
C:\Users\owner\AppData\Local\Temp\tmp000240c6
C:\Users\owner\AppData\Local\Temp\uxIhPqss.ini
C:\Users\owner\AppData\Local\Temp\uxIhPqss.ini2
C:\Users\owner\AppData\Local\Temp\wmplog00.sqm
C:\Users\owner\AppData\Local\Temp\xxyxUlkJ.dll
C:\Users\owner\AppData\Local\Temp\~DF1205.tmp
C:\Users\owner\AppData\Local\Temp\~DF75E7.tmp

19 files deleted
 

 

and

 

 Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:30:17 AM, on 7/8/2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Safe mode

Running processes:
C:\Windows\explorer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = >>> 'Full Speed' Enabled <<<
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D8CDED80-7413-4437-9404-2AAB6C865F2D} - C:\Windows\system32\byXNghiH.dll
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Microsoft] pwkpmovo.exe
O4 - HKLM\..\Run: [Microsoft(1)] hnlrfayv.exe
O4 - HKLM\..\RunServices: [Microsoft] pwkpmovo.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\owner\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\owner\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: vzTCPConfig - https://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200313887041
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203546833750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1213661161787&h=cefda793e7d44af90274ef084de6de44/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.shockwave.com/content/burgershop/sis/GoBitGamesPlayer_v4.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbl_device -   - C:\Windows\system32\lxblcoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10147 bytes

10.4K Posts

July 8th, 2008 12:00

Greenfire999

Good work. I have revised the TempFix tool to do more.

Please delete the current version of TempFix that you have, both the folder and the zip file.
And using the same link I provided in my previous post download the newer version

And rerun it the same as you did the first time and post the results of the C:\TempFix .txt log

This time I would like to see a fresh Hijackthis log run in Normal Windows mode.












Microsoft MVP Consumer-Security

 


"The world is what you make of it"




13 Posts

July 8th, 2008 13:00

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:36:44 AM, on 7/8/2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\taskeng.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Users\owner\Program Files\DNA\btdna.exe
C:\Users\owner\Program Files\uTorrent\uTorrent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wermgr.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = >>> 'Full Speed' Enabled <<<
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ReCycle Patch] "C:\Users\owner\AppData\Local\Temp\Rar$EX01.452\ReCyclePatch.exe" -s
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\owner\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\owner\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: vzTCPConfig - https://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200313887041
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203546833750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1213661161787&h=cefda793e7d44af90274ef084de6de44/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.shockwave.com/content/burgershop/sis/GoBitGamesPlayer_v4.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbl_device -   - C:\Windows\system32\lxblcoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9603 bytes

13 Posts

July 8th, 2008 13:00

7/6/2008 10:20:13 AM    24576    32    C:\Windows\System32\ljJBqooO.dll
6/21/2008 6:33:06 PM    155408    32    C:\Windows\System32\LMRT.dll
6/21/2008 6:33:06 PM    38160    32    C:\Windows\System32\LMRTREND.dll
7/5/2008 10:09:56 PM    839763    7    C:\Windows\System32\lnxchzmw.exe
6/29/2008 5:15:38 PM    839763    7    C:\Windows\System32\mausnrfg.exe
6/21/2008 6:32:45 PM    11776    32    C:\Windows\System32\mciqtz.drv
6/14/2008 2:36:09 AM    1244672    32    C:\Windows\System32\mcmde.dll
6/20/2008 4:58:57 PM    53248    32    C:\Windows\System32\mgxasio2.dll
6/20/2008 4:58:56 PM    27807    32    C:\Windows\System32\mgxcdr.txt
6/20/2008 4:53:26 PM    700416    0    C:\Windows\System32\mgxoschk.dll
7/6/2008 12:39:16 AM    653745    38    C:\Windows\System32\mnTuFeNn.ini
7/6/2008 12:39:17 AM    345    38    C:\Windows\System32\mnTuFeNn.ini2
6/14/2008 2:36:08 AM    68608    32    C:\Windows\System32\Mpeg2Data.ax
6/14/2008 2:36:07 AM    57856    32    C:\Windows\System32\MSDvbNP.ax
6/19/2008 3:50:05 PM    585728    32    C:\Windows\System32\msfeeds.dll
6/19/2008 3:50:17 PM    52224    32    C:\Windows\System32\msfeedsbs.dll
6/19/2008 3:50:08 PM    52736    32    C:\Windows\System32\msfeedssync.exe
6/19/2008 3:50:04 PM    45568    32    C:\Windows\System32\mshta.exe
6/19/2008 3:50:00 PM    5120000    32    C:\Windows\System32\mshtml.dll
6/19/2008 3:50:20 PM    1555456    32    C:\Windows\System32\mshtml.tlb
6/19/2008 3:50:18 PM    68608    32    C:\Windows\System32\mshtmled.dll
6/19/2008 3:50:21 PM    48128    32    C:\Windows\System32\mshtmler.dll
6/9/2008 5:31:42 PM    1050896    32    C:\Windows\System32\msjet35.dll
6/9/2008 5:31:43 PM    123664    32    C:\Windows\System32\msjint35.dll
6/9/2008 5:31:42 PM    24848    32    C:\Windows\System32\msjter35.dll
6/14/2008 2:36:08 AM    80896    32    C:\Windows\System32\MSNP.ax
6/19/2008 3:50:10 PM    193024    32    C:\Windows\System32\msrating.dll
7/2/2008 2:09:31 AM    372736    32    C:\Windows\System32\Mss32.dll
6/19/2008 3:50:05 PM    629248    32    C:\Windows\System32\mstime.dll
6/20/2008 4:58:57 PM    430080    32    C:\Windows\System32\MXRestore.exe
7/5/2008 12:27:30 AM    839763    7    C:\Windows\System32\nhfxzijk.exe
7/6/2008 1:23:05 AM    839763    7    C:\Windows\System32\nhyostol.exe
7/4/2008 10:20:25 AM    839763    7    C:\Windows\System32\niyfdihq.exe
7/3/2008 12:13:11 PM    839763    7    C:\Windows\System32\nlqanbbs.exe
7/6/2008 12:39:05 AM    318976    32    C:\Windows\System32\nNeFuTnm.dll
7/4/2008 6:51:39 PM    319488    32    C:\Windows\System32\nnnMGVpQ.dll
7/6/2008 12:11:12 AM    839763    7    C:\Windows\System32\nufzsvbf.exe
6/19/2008 3:50:09 PM    116224    32    C:\Windows\System32\occache.dll
7/4/2008 9:30:41 PM    839763    7    C:\Windows\System32\omdxmepo.exe
7/6/2008 12:19:11 AM    839763    7    C:\Windows\System32\omoeogjk.exe
7/5/2008 11:22:00 PM    839763    7    C:\Windows\System32\ovkgluxf.exe
7/4/2008 10:41:37 PM    839763    7    C:\Windows\System32\pdjfxriu.exe
6/19/2008 3:50:17 PM    20480    32    C:\Windows\System32\PDMSetup.exe
6/20/2008 4:24:56 PM    24576    32    C:\Windows\System32\pmNEUmMc.dll
6/20/2008 4:30:07 PM    24576    32    C:\Windows\System32\pmnmljiI.dll
6/19/2008 3:50:20 PM    44544    32    C:\Windows\System32\pngfilt.dll
7/4/2008 6:46:19 PM    839763    7    C:\Windows\System32\pqpkukdf.exe
6/14/2008 2:36:10 AM    292352    32    C:\Windows\System32\psisdecd.dll
6/14/2008 2:36:11 AM    218624    32    C:\Windows\System32\psisrndr.ax
7/6/2008 10:21:22 AM    839763    7    C:\Windows\System32\pwkpmovo.exe
6/21/2008 6:32:43 PM    194320    32    C:\Windows\System32\qcut.dll
7/5/2008 7:26:35 PM    318976    32    C:\Windows\System32\qoMgeCss.dll
7/4/2008 6:52:52 PM    653629    38    C:\Windows\System32\QpVGMnnn.ini
7/4/2008 6:52:56 PM    345    38    C:\Windows\System32\QpVGMnnn.ini2
6/10/2008 2:24:21 PM    1327104    32    C:\Windows\System32\quartz.dll
6/21/2008 6:32:45 PM    5672    32    C:\Windows\System32\quartz.vxd
7/6/2008 3:10:01 AM    839763    7    C:\Windows\System32\qwexznzd.exe
7/2/2008 9:57:31 PM    102400    0    C:\Windows\System32\RDrv2KInterface.dll
7/2/2008 9:57:30 PM    32768    0    C:\Windows\System32\RDrv9xInterface.dll
7/2/2008 9:57:30 PM    28672    0    C:\Windows\System32\RDrvInterface.dll
7/2/2008 9:57:30 PM    53248    0    C:\Windows\System32\RDrvNTInterface.dll
6/21/2008 4:38:15 PM    368640    32    C:\Windows\System32\ReWire.dll
6/21/2008 4:38:16 PM    233472    0    C:\Windows\System32\REX Shared Library.dll
7/5/2008 8:48:05 AM    839763    7    C:\Windows\System32\rjjqrlbt.exe
7/5/2008 4:03:05 AM    318976    32    C:\Windows\System32\rqRLecDS.dll
7/5/2008 11:47:22 PM    839763    7    C:\Windows\System32\rxwnlxlc.exe
7/4/2008 3:23:17 PM    839763    7    C:\Windows\System32\ryxknlts.exe
7/2/2008 3:45:28 AM    839763    7    C:\Windows\System32\sbexlbyg.exe
7/5/2008 4:03:20 AM    653745    38    C:\Windows\System32\SDceLRqr.ini
7/5/2008 4:03:31 AM    345    38    C:\Windows\System32\SDceLRqr.ini2
6/19/2008 3:50:17 PM    13824    32    C:\Windows\System32\SetDepNx.exe
6/19/2008 3:50:17 PM    13824    32    C:\Windows\System32\SetIEInstalledDate.exe
7/6/2008 3:00:02 AM    839763    7    C:\Windows\System32\sicvcjbv.exe
7/5/2008 6:06:26 PM    839763    7    C:\Windows\System32\sigjiyuq.exe
7/5/2008 7:26:49 PM    653745    38    C:\Windows\System32\ssCegMoq.ini
7/5/2008 7:26:53 PM    345    38    C:\Windows\System32\ssCegMoq.ini2
7/5/2008 8:53:20 AM    318976    32    C:\Windows\System32\sSmlJYSj.dll
6/20/2008 4:58:56 PM    32768    0    C:\Windows\System32\STRING32.dll
6/30/2008 3:55:25 PM    839763    7    C:\Windows\System32\tafohgaz.exe
6/19/2008 3:50:18 PM    66560    32    C:\Windows\System32\tdc.ocx
6/22/2008 5:56:31 PM    1408    32    C:\Windows\System32\TEST.log
6/21/2008 6:33:04 PM    140800    32    C:\Windows\System32\tm20dec.ax
6/20/2008 4:58:57 PM    24576    32    C:\Windows\System32\TTI32.dll
6/20/2008 4:58:57 PM    24576    32    C:\Windows\System32\TTIC32.dll
7/5/2008 12:14:48 AM    319488    32    C:\Windows\System32\tuvWMETJ.dll
7/4/2008 11:10:46 PM    839763    7    C:\Windows\System32\txwgmrar.exe
7/5/2008 1:32:14 AM    443    38    C:\Windows\System32\UFNopXbc.ini
7/5/2008 1:32:15 AM    345    38    C:\Windows\System32\UFNopXbc.ini2
6/30/2008 8:36:34 PM    839763    7    C:\Windows\System32\uijkxbrn.exe
6/21/2008 6:32:57 PM    63488    32    C:\Windows\System32\unam4ie.exe
7/5/2008 7:10:51 PM    839763    7    C:\Windows\System32\unpjyhxb.exe
7/2/2008 9:57:30 PM    36864    0    C:\Windows\System32\unVHDDrvExe.exe
6/19/2008 3:50:08 PM    105984    32    C:\Windows\System32\url.dll
6/19/2008 3:50:03 PM    1188352    32    C:\Windows\System32\urlmon.dll
7/6/2008 2:28:53 AM    319488    32    C:\Windows\System32\urqQjkkK.dll
7/4/2008 9:34:48 PM    653745    38    C:\Windows\System32\uuDcdccf.ini
7/4/2008 9:34:54 PM    345    38    C:\Windows\System32\uuDcdccf.ini2
7/5/2008 6:28:17 PM    839763    7    C:\Windows\System32\vhallcal.exe
6/21/2008 6:32:45 PM    10240    32    C:\Windows\System32\vidx16.dll
6/20/2008 11:40:04 PM    1294336    32    C:\Windows\System32\vorbis.acm
6/30/2008 12:09:54 AM    839763    7    C:\Windows\System32\vrbldejp.exe
6/21/2008 6:32:35 PM    2272    32    C:\Windows\System32\w95inf16.dll
6/21/2008 6:32:35 PM    4608    32    C:\Windows\System32\w95inf32.dll
6/19/2008 3:50:09 PM    233984    32    C:\Windows\System32\webcheck.dll
6/19/2008 3:50:09 PM    66560    32    C:\Windows\System32\wextract.exe
6/19/2008 3:50:09 PM    208384    32    C:\Windows\System32\WinFXDocObj.exe
6/19/2008 3:50:04 PM    830464    32    C:\Windows\System32\wininet.dll
6/10/2008 2:24:23 PM    14848    32    C:\Windows\System32\wshrm.dll
6/30/2008 8:47:24 PM    839763    7    C:\Windows\System32\xiecuyaw.exe
7/1/2008 1:22:59 AM    839763    7    C:\Windows\System32\xkpkiisx.exe
7/2/2008 5:31:56 AM    839763    7    C:\Windows\System32\xtoeifuw.exe
7/4/2008 10:25:14 AM    319488    32    C:\Windows\System32\yaywxYPJ.dll
6/30/2008 10:09:54 AM    839763    7    C:\Windows\System32\yenbzgtw.exe
7/1/2008 8:25:02 PM    839763    7    C:\Windows\System32\yghfufoq.exe
7/1/2008 11:28:55 PM    839763    7    C:\Windows\System32\ywmmfxhp.exe
7/4/2008 10:05:19 PM    839763    7    C:\Windows\System32\zgmvgrgy.exe
7/5/2008 6:16:45 PM    839763    7    C:\Windows\System32\zyyrsnvy.exe

 ========= Temp Files Deleted ========


13 Files deleted

13 Posts

July 8th, 2008 13:00

TempFix

Version 1.0.1

By bamajim @ bamajim.com

========================================


Report ran on --->>>  7/8/2008 7:09:30 AM


========  Files created in (System32) last 30 days  ========

7/3/2008 12:39:22 PM    0    32    C:\Windows\System32\1f5c7e5e-.txt
6/30/2008 5:37:51 PM    839763    7    C:\Windows\System32\acxwbsuk.exe
6/19/2008 3:50:21 PM    69120    32    C:\Windows\System32\admparse.dll
6/19/2008 3:50:21 PM    126464    32    C:\Windows\System32\advpack.dll
7/5/2008 11:40:37 PM    839763    7    C:\Windows\System32\akzwxuov.exe
7/5/2008 5:55:56 PM    839763    7    C:\Windows\System32\aqkuqzdc.exe
6/19/2008 2:25:26 PM    88064    32    C:\Windows\System32\audiodg.exe
6/19/2008 2:25:26 PM    398848    32    C:\Windows\System32\AudioEng.dll
6/19/2008 2:25:26 PM    273408    32    C:\Windows\System32\AUDIOKSE.dll
6/19/2008 2:25:26 PM    115712    32    C:\Windows\System32\AudioSes.dll
6/19/2008 2:25:26 PM    310272    32    C:\Windows\System32\audiosrv.dll
7/5/2008 5:46:04 PM    839763    7    C:\Windows\System32\auvhtecf.exe
6/29/2008 6:13:01 PM    839763    7    C:\Windows\System32\bdfewdgr.exe
7/2/2008 9:59:39 PM    319488    32    C:\Windows\System32\byXNghiH.dll
7/5/2008 5:50:23 PM    318976    32    C:\Windows\System32\byXRkjgG.dll
7/5/2008 1:32:09 AM    318976    32    C:\Windows\System32\cbXpoNFU.dll
7/4/2008 10:47:12 PM    653745    38    C:\Windows\System32\cJSYFfhk.ini
7/4/2008 10:47:15 PM    345    38    C:\Windows\System32\cJSYFfhk.ini2
6/19/2008 3:50:18 PM    17920    32    C:\Windows\System32\corpol.dll
6/30/2008 7:04:39 PM    839763    7    C:\Windows\System32\cysmtwuw.exe
6/21/2008 6:32:44 PM    1088272    32    C:\Windows\System32\danim.dll
6/9/2008 5:31:38 PM    570128    32    C:\Windows\System32\dao350.dll
7/5/2008 8:34:59 PM    839763    7    C:\Windows\System32\dasdturh.exe
7/1/2008 10:25:58 AM    839763    7    C:\Windows\System32\ddwgqfkz.exe
6/20/2008 4:58:55 PM    487424    0    C:\Windows\System32\DLLAV32.dll
6/20/2008 4:58:55 PM    14182    32    C:\Windows\System32\DLLAV32.lib
6/20/2008 4:58:56 PM    114688    32    C:\Windows\System32\DLLCDA32.dll
6/20/2008 4:58:56 PM    61440    32    C:\Windows\System32\DLLCDF32.dll
6/20/2008 4:58:56 PM    94208    0    C:\Windows\System32\DLLCPY32.dll
6/20/2008 4:58:56 PM    163840    0    C:\Windows\System32\DLLDEV32.dll
6/20/2008 4:55:46 PM    120200    32    C:\Windows\System32\DLLDEV32i.dll
6/20/2008 4:58:56 PM    32768    32    C:\Windows\System32\DLLDIR32.dll
6/20/2008 4:58:56 PM    151552    0    C:\Windows\System32\DLLDRV32.dll
6/20/2008 4:58:56 PM    45056    32    C:\Windows\System32\DLLIMG32.dll
6/20/2008 4:58:56 PM    53248    0    C:\Windows\System32\DLLIO32.dll
6/20/2008 4:58:56 PM    32768    32    C:\Windows\System32\DLLISO32.dll
6/20/2008 4:58:56 PM    24576    32    C:\Windows\System32\DLLIX.dll
6/20/2008 4:58:56 PM    32768    32    C:\Windows\System32\DLLMSC32.dll
6/20/2008 4:58:56 PM    36864    0    C:\Windows\System32\DLLPNT32.dll
6/20/2008 4:58:56 PM    49152    32    C:\Windows\System32\DLLPRF32.dll
6/20/2008 4:58:56 PM    53248    32    C:\Windows\System32\DLLPRJ32.dll
6/20/2008 4:58:56 PM    65536    32    C:\Windows\System32\DLLPTL32.dll
6/20/2008 4:58:56 PM    40960    32    C:\Windows\System32\DLLRD32.dll
6/20/2008 4:58:56 PM    188416    0    C:\Windows\System32\DLLRES32.dll
6/20/2008 4:58:56 PM    57344    32    C:\Windows\System32\DLLTPO32.dll
7/5/2008 7:22:01 PM    839763    7    C:\Windows\System32\dmxttoci.exe
6/30/2008 7:20:07 PM    839763    7    C:\Windows\System32\doqblydu.exe
6/30/2008 6:05:34 PM    839763    7    C:\Windows\System32\dukwvmeg.exe
6/30/2008 5:45:20 PM    839763    7    C:\Windows\System32\dvbczwcg.exe
7/2/2008 9:57:25 PM    126976    32    C:\Windows\System32\DVC.dll
7/2/2008 9:57:26 PM    86016    32    C:\Windows\System32\Dversion.dll
6/19/2008 3:50:06 PM    345600    32    C:\Windows\System32\dxtmsft.dll
6/21/2008 6:33:02 PM    182032    32    C:\Windows\System32\dxtmsft3.dll
6/19/2008 3:50:06 PM    212992    32    C:\Windows\System32\dxtrans.dll
7/6/2008 12:49:53 AM    839763    7    C:\Windows\System32\dxzocgzt.exe
7/3/2008 9:12:21 PM    320000    32    C:\Windows\System32\efcApqPI.dll
7/4/2008 3:27:33 PM    319488    32    C:\Windows\System32\efcbYrRi.dll
6/14/2008 2:36:13 AM    428032    32    C:\Windows\System32\EncDec.dll
6/19/2008 2:25:23 PM    169984    32    C:\Windows\System32\EncDump.dll
6/30/2008 2:59:27 PM    6173    32    C:\Windows\System32\Entech.vxd
7/4/2008 9:34:36 PM    319488    32    C:\Windows\System32\fccdcDuu.dll
7/2/2008 9:57:25 PM    5120    32    C:\Windows\System32\Fsinst16.DLL
7/2/2008 9:57:25 PM    45056    32    C:\Windows\System32\Fsinst32.dll
6/30/2008 6:41:58 PM    839763    7    C:\Windows\System32\gdwjfjaj.exe
7/5/2008 5:50:38 PM    653745    38    C:\Windows\System32\GgjkRXyb.ini
7/5/2008 5:50:40 PM    345    38    C:\Windows\System32\GgjkRXyb.ini2
7/3/2008 12:18:05 PM    595    38    C:\Windows\System32\gOVwGfhk.ini
7/3/2008 12:18:26 PM    345    38    C:\Windows\System32\gOVwGfhk.ini2
6/29/2008 9:51:56 PM    839763    7    C:\Windows\System32\hcdwsmwi.exe
7/5/2008 10:45:57 PM    839763    7    C:\Windows\System32\helwwmhd.exe
7/2/2008 9:59:49 PM    646630    38    C:\Windows\System32\HihgNXyb.ini
7/2/2008 9:59:53 PM    646452    38    C:\Windows\System32\HihgNXyb.ini2
7/5/2008 7:33:36 PM    839763    7    C:\Windows\System32\hnlrfayv.exe
7/6/2008 1:06:23 AM    839763    7    C:\Windows\System32\hpczmssf.exe
6/19/2008 3:50:04 PM    385024    32    C:\Windows\System32\html.iec
6/20/2008 5:17:16 PM    85504    32    C:\Windows\System32\HtmlWH.dll
7/5/2008 9:06:08 PM    839763    7    C:\Windows\System32\iaflryia.exe
6/19/2008 3:50:22 PM    60928    32    C:\Windows\System32\icardie.dll
7/5/2008 3:58:42 AM    839763    7    C:\Windows\System32\idrgxuxs.exe
6/19/2008 3:50:08 PM    70656    32    C:\Windows\System32\ie4uinit.exe
6/19/2008 3:50:20 PM    119808    32    C:\Windows\System32\ieakeng.dll
6/19/2008 3:50:08 PM    224768    32    C:\Windows\System32\ieaksie.dll
6/19/2008 3:50:10 PM    149504    32    C:\Windows\System32\ieakui.dll
6/19/2008 3:50:04 PM    3670112    32    C:\Windows\System32\ieapfltr.dat
6/19/2008 3:50:22 PM    440832    32    C:\Windows\System32\ieapfltr.dll
6/19/2008 3:50:08 PM    349184    32    C:\Windows\System32\iedkcs32.dll
6/19/2008 3:50:05 PM    78336    32    C:\Windows\System32\ieencode.dll
6/19/2008 3:50:02 PM    8016384    32    C:\Windows\System32\ieframe.dll
6/19/2008 3:50:17 PM    184320    32    C:\Windows\System32\iepeers.dll
6/19/2008 3:50:21 PM    44032    32    C:\Windows\System32\iernonce.dll
6/19/2008 3:50:19 PM    268800    32    C:\Windows\System32\iertutil.dll
6/19/2008 3:50:17 PM    142848    32    C:\Windows\System32\IESetting.dll
6/19/2008 3:50:10 PM    69120    32    C:\Windows\System32\iesetup.dll
6/19/2008 3:50:21 PM    181248    32    C:\Windows\System32\ieui.dll
6/19/2008 3:50:09 PM    56413    32    C:\Windows\System32\ieuinit.inf
6/19/2008 3:50:17 PM    26624    32    C:\Windows\System32\ieUnatt.exe
6/19/2008 3:50:04 PM    168448    32    C:\Windows\System32\iexpress.exe
7/6/2008 2:24:19 AM    839763    7    C:\Windows\System32\iiozuprv.exe
6/19/2008 3:50:17 PM    36352    32    C:\Windows\System32\imgutil.dll
6/19/2008 3:50:03 PM    1547264    32    C:\Windows\System32\inetcpl.cpl
6/19/2008 3:50:16 PM    94208    32    C:\Windows\System32\inseng.dll
7/2/2008 9:57:30 PM    36864    0    C:\Windows\System32\inVHDDrvExe.exe
7/3/2008 9:12:32 PM    656835    38    C:\Windows\System32\IPqpAcfe.ini
7/3/2008 9:12:39 PM    345    38    C:\Windows\System32\IPqpAcfe.ini2
7/4/2008 3:27:39 PM    653745    38    C:\Windows\System32\iRrYbcfe.ini
7/4/2008 3:27:42 PM    345    38    C:\Windows\System32\iRrYbcfe.ini2
6/16/2008 5:09:42 PM    135168    32    C:\Windows\System32\java.exe
6/16/2008 5:09:42 PM    135168    32    C:\Windows\System32\javaw.exe
6/16/2008 5:09:42 PM    139264    32    C:\Windows\System32\javaws.exe
6/30/2008 10:52:45 PM    839763    7    C:\Windows\System32\jiukmfxr.exe
7/4/2008 10:25:24 AM    653981    38    C:\Windows\System32\JPYxwyay.ini
7/4/2008 10:25:28 AM    345    38    C:\Windows\System32\JPYxwyay.ini2
6/19/2008 3:50:06 PM    557056    32    C:\Windows\System32\jscript.dll
6/19/2008 3:50:19 PM    28672    32    C:\Windows\System32\jsproxy.dll
7/5/2008 8:53:28 AM    653745    38    C:\Windows\System32\jSYJlmSs.ini
7/5/2008 8:53:31 AM    345    38    C:\Windows\System32\jSYJlmSs.ini2
7/5/2008 12:14:52 AM    653745    38    C:\Windows\System32\JTEMWvut.ini
7/5/2008 12:14:54 AM    345    38    C:\Windows\System32\JTEMWvut.ini2
6/10/2008 4:40:52 PM    6283    32    C:\Windows\System32\jupdate-1.6.0_06-b02.log
7/3/2008 9:07:19 PM    839763    7    C:\Windows\System32\jwhulhhi.exe
7/4/2008 10:46:54 PM    319488    32    C:\Windows\System32\khfFYSJc.dll
7/3/2008 12:17:44 PM    320000    32    C:\Windows\System32\khfGwVOg.dll
7/6/2008 2:29:10 AM    653745    38    C:\Windows\System32\KkkjQqru.ini
7/6/2008 2:29:12 AM    345    38    C:\Windows\System32\KkkjQqru.ini2
7/6/2008 2:42:32 AM    839763    7    C:\Windows\System32\lbljjlnk.exe
6/19/2008 3:50:17 PM    41984    32    C:\Windows\System32\licmgr10.dll

10.4K Posts

July 8th, 2008 15:00

Greenfire999

That's quite an infection you have there

Please note that on Vista you may be prompted to Rt Click the program and run as administrator.

1. Please download the Killbox.



  • 1)Save it to the desktop
    2) Rt Click->>Extract all->.Extract it to your Desktop
    3) Double Click Killbox.exe to run it
    4)Select " Delete on Reboot", and then select "All files".
    5) Copy the file names below to the clipboard by highlighting them and pressing Control-C:


    C:\Windows\System32\acxwbsuk.exe
    C:\Windows\System32\akzwxuov.exe
    C:\Windows\System32\aqkuqzdc.exe
    C:\Windows\System32\auvhtecf.exe
    C:\Windows\System32\bdfewdgr.exe
    C:\Windows\System32\byXNghiH.dll
    C:\Windows\System32\byXRkjgG.dll
    C:\Windows\System32\cbXpoNFU.dll
    C:\Windows\System32\cJSYFfhk.ini
    C:\Windows\System32\cJSYFfhk.ini2
    C:\Windows\System32\cysmtwuw.exe
    C:\Windows\System32\dasdturh.exe
    C:\Windows\System32\ddwgqfkz.exe
    C:\Windows\System32\dmxttoci.exe
    C:\Windows\System32\doqblydu.exe
    C:\Windows\System32\dukwvmeg.exe
    C:\Windows\System32\dvbczwcg.exe
    C:\Windows\System32\dxzocgzt.exe
    C:\Windows\System32\efcApqPI.dll
    C:\Windows\System32\efcbYrRi.dll
    C:\Windows\System32\fccdcDuu.dll
    C:\Windows\System32\Fsinst16.DLL
    C:\Windows\System32\Fsinst32.dll
    C:\Windows\System32\gdwjfjaj.exe
    C:\Windows\System32\GgjkRXyb.ini
    C:\Windows\System32\GgjkRXyb.ini2
    C:\Windows\System32\gOVwGfhk.ini
    C:\Windows\System32\gOVwGfhk.ini2
    C:\Windows\System32\hcdwsmwi.exe
    C:\Windows\System32\helwwmhd.exe
    C:\Windows\System32\HihgNXyb.ini
    C:\Windows\System32\HihgNXyb.ini2
    C:\Windows\System32\hnlrfayv.exe
    C:\Windows\System32\hpczmssf.exe
    C:\Windows\System32\iaflryia.exe
    C:\Windows\System32\idrgxuxs.exe
    C:\Windows\System32\iiozuprv.exe
    C:\Windows\System32\IPqpAcfe.ini
    C:\Windows\System32\IPqpAcfe.ini2
    C:\Windows\System32\iRrYbcfe.ini
    C:\Windows\System32\iRrYbcfe.ini2
    C:\Windows\System32\jiukmfxr.exe
    C:\Windows\System32\JPYxwyay.ini
    C:\Windows\System32\JPYxwyay.ini2
    C:\Windows\System32\jSYJlmSs.ini
    C:\Windows\System32\jSYJlmSs.ini2
    C:\Windows\System32\JTEMWvut.ini
    C:\Windows\System32\JTEMWvut.ini2
    C:\Windows\System32\jwhulhhi.exe
    C:\Windows\System32\khfFYSJc.dll
    C:\Windows\System32\khfGwVOg.dll
    C:\Windows\System32\KkkjQqru.ini
    C:\Windows\System32\KkkjQqru.ini2
    C:\Windows\System32\lbljjlnk.exe
    C:\Windows\System32\ljJBqooO.dll
    C:\Windows\System32\lnxchzmw.exe
    C:\Windows\System32\mausnrfg.exe
    C:\Windows\System32\mnTuFeNn.ini
    C:\Windows\System32\mnTuFeNn.ini2
    C:\Windows\System32\nhfxzijk.exe
    C:\Windows\System32\nhyostol.exe
    C:\Windows\System32\niyfdihq.exe
    C:\Windows\System32\nlqanbbs.exe
    C:\Windows\System32\nNeFuTnm.dll
    C:\Windows\System32\nnnMGVpQ.dll
    C:\Windows\System32\nufzsvbf.exe
    C:\Windows\System32\occache.dll
    C:\Windows\System32\omdxmepo.exe
    C:\Windows\System32\omoeogjk.exe
    C:\Windows\System32\ovkgluxf.exe
    C:\Windows\System32\pdjfxriu.exe
    C:\Windows\System32\pmNEUmMc.dll
    C:\Windows\System32\pmnmljiI.dll
    C:\Windows\System32\pqpkukdf.exe
    C:\Windows\System32\pwkpmovo.exe
    C:\Windows\System32\qoMgeCss.dll
    C:\Windows\System32\QpVGMnnn.ini
    C:\Windows\System32\QpVGMnnn.ini2
    C:\Windows\System32\qwexznzd.exe
    C:\Windows\System32\rjjqrlbt.exe
    C:\Windows\System32\rqRLecDS.dll
    C:\Windows\System32\rxwnlxlc.exe
    C:\Windows\System32\ryxknlts.exe
    C:\Windows\System32\sbexlbyg.exe
    C:\Windows\System32\SDceLRqr.ini
    C:\Windows\System32\SDceLRqr.ini2
    C:\Windows\System32\sicvcjbv.exe
    C:\Windows\System32\sigjiyuq.exe
    C:\Windows\System32\ssCegMoq.ini
    C:\Windows\System32\ssCegMoq.ini2
    C:\Windows\System32\sSmlJYSj.dll
    C:\Windows\System32\tafohgaz.exe
    C:\Windows\System32\tuvWMETJ.dll
    C:\Windows\System32\txwgmrar.exe
    C:\Windows\System32\UFNopXbc.ini
    C:\Windows\System32\UFNopXbc.ini2
    C:\Windows\System32\uijkxbrn.exe
    C:\Windows\System32\unam4ie.exe
    C:\Windows\System32\unpjyhxb.exe
    C:\Windows\System32\urqQjkkK.dll
    C:\Windows\System32\uuDcdccf.ini
    C:\Windows\System32\uuDcdccf.ini2
    C:\Windows\System32\vhallcal.exe
    C:\Windows\System32\vrbldejp.exe
    C:\Windows\System32\xiecuyaw.exe
    C:\Windows\System32\xkpkiisx.exe
    C:\Windows\System32\xtoeifuw.exe
    C:\Windows\System32\yaywxYPJ.dll
    C:\Windows\System32\yenbzgtw.exe
    C:\Windows\System32\yghfufoq.exe
    C:\Windows\System32\ywmmfxhp.exe
    C:\Windows\System32\zgmvgrgy.exe
    C:\Windows\System32\zyyrsnvy.exe


















































































































    6) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
    7) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.











Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log






Microsoft MVP Consumer-Security

 


"The world is what you make of it"




13 Posts

July 8th, 2008 15:00

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:00:33 AM, on 7/8/2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\WINDOWS\SYSTEM32\taskeng.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Users\owner\Program Files\DNA\btdna.exe
C:\Users\owner\Program Files\uTorrent\uTorrent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Windows\helppane.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = >>> 'Full Speed' Enabled <<<
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\owner\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\owner\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: vzTCPConfig - https://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200313887041
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203546833750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1213661161787&h=cefda793e7d44af90274ef084de6de44/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.shockwave.com/content/burgershop/sis/GoBitGamesPlayer_v4.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbl_device -   - C:\Windows\system32\lxblcoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9603 bytes
Message Edited by Greenfire999 on 07-08-2008 12:02 PM

10.4K Posts

July 8th, 2008 19:00

Greenfire999

 

Did Killbox run without any problems?

 

Log looks good. How's your PC running now?

 



 

Microsoft MVP Consumer-Security

 


"The world is what you make of it"


13 Posts

July 8th, 2008 21:00

Not that good. i cant open any documents or folders. If i do it 1 minute later after i used it, it turns off the toolbar and icons. Then comes on like 5 minutes later without the folder i just opened

10.4K Posts

July 9th, 2008 00:00

Greenfire999

Rerun Tempfix and let's see if there is something else there.

The log should be substantialy shorter







Microsoft MVP Consumer-Security

 


"The world is what you make of it"




13 Posts

July 9th, 2008 02:00

========================================
TempFix

Version 1.0.1

By bamajim @ bamajim.com

========================================


Report ran on --->>>  7/8/2008 7:48:07 PM


========  Files created in (System32) last 30 days  ========

7/3/2008 12:39:22 PM    0    32    C:\Windows\System32\1f5c7e5e-.txt
7/8/2008 4:44:33 PM    376832    32    C:\Windows\System32\actskin4.ocx
6/19/2008 3:50:21 PM    69120    32    C:\Windows\System32\admparse.dll
6/19/2008 3:50:21 PM    126464    32    C:\Windows\System32\advpack.dll
7/8/2008 11:54:41 AM    1269760    32    C:\Windows\System32\ASTAudioFile.dll
7/8/2008 11:54:40 AM    1200128    32    C:\Windows\System32\ASTAudioInformation.dll
7/8/2008 11:49:28 AM    1986560    32    C:\Windows\System32\AudFile.dll
6/19/2008 2:25:26 PM    88064    32    C:\Windows\System32\audiodg.exe
6/19/2008 2:25:26 PM    398848    32    C:\Windows\System32\AudioEng.dll
7/8/2008 11:49:28 AM    1212416    32    C:\Windows\System32\AudioInfos.dll
6/19/2008 2:25:26 PM    273408    32    C:\Windows\System32\AUDIOKSE.dll
6/19/2008 2:25:26 PM    115712    32    C:\Windows\System32\AudioSes.dll
6/19/2008 2:25:26 PM    310272    32    C:\Windows\System32\audiosrv.dll
7/8/2008 11:49:28 AM    458752    32    C:\Windows\System32\AudPlayer.dll
7/8/2008 11:16:31 AM    516096    32    C:\Windows\System32\CLVSD.ax
7/8/2008 11:49:24 AM    32768    32    C:\Windows\System32\CMDLGFR.DLL
6/19/2008 3:50:18 PM    17920    32    C:\Windows\System32\corpol.dll
6/21/2008 6:32:44 PM    1088272    32    C:\Windows\System32\danim.dll
6/9/2008 5:31:38 PM    570128    32    C:\Windows\System32\dao350.dll
7/8/2008 4:44:37 PM    40960    32    C:\Windows\System32\DGPNorm.ocx
6/20/2008 4:58:55 PM    487424    0    C:\Windows\System32\DLLAV32.dll
6/20/2008 4:58:55 PM    14182    32    C:\Windows\System32\DLLAV32.lib
6/20/2008 4:58:56 PM    114688    32    C:\Windows\System32\DLLCDA32.dll
6/20/2008 4:58:56 PM    61440    32    C:\Windows\System32\DLLCDF32.dll
6/20/2008 4:58:56 PM    94208    0    C:\Windows\System32\DLLCPY32.dll
6/20/2008 4:58:56 PM    163840    0    C:\Windows\System32\DLLDEV32.dll
6/20/2008 4:55:46 PM    120200    32    C:\Windows\System32\DLLDEV32i.dll
6/20/2008 4:58:56 PM    32768    32    C:\Windows\System32\DLLDIR32.dll
6/20/2008 4:58:56 PM    151552    0    C:\Windows\System32\DLLDRV32.dll
6/20/2008 4:58:56 PM    45056    32    C:\Windows\System32\DLLIMG32.dll
6/20/2008 4:58:56 PM    53248    0    C:\Windows\System32\DLLIO32.dll
6/20/2008 4:58:56 PM    32768    32    C:\Windows\System32\DLLISO32.dll
6/20/2008 4:58:56 PM    24576    32    C:\Windows\System32\DLLIX.dll
6/20/2008 4:58:56 PM    32768    32    C:\Windows\System32\DLLMSC32.dll
6/20/2008 4:58:56 PM    36864    0    C:\Windows\System32\DLLPNT32.dll
6/20/2008 4:58:56 PM    49152    32    C:\Windows\System32\DLLPRF32.dll
6/20/2008 4:58:56 PM    53248    32    C:\Windows\System32\DLLPRJ32.dll
6/20/2008 4:58:56 PM    65536    32    C:\Windows\System32\DLLPTL32.dll
6/20/2008 4:58:56 PM    40960    32    C:\Windows\System32\DLLRD32.dll
6/20/2008 4:58:56 PM    188416    0    C:\Windows\System32\DLLRES32.dll
6/20/2008 4:58:56 PM    57344    32    C:\Windows\System32\DLLTPO32.dll
7/2/2008 9:57:25 PM    126976    32    C:\Windows\System32\DVC.dll
7/2/2008 9:57:26 PM    86016    32    C:\Windows\System32\Dversion.dll
6/19/2008 3:50:06 PM    345600    32    C:\Windows\System32\dxtmsft.dll
6/21/2008 6:33:02 PM    182032    32    C:\Windows\System32\dxtmsft3.dll
6/19/2008 3:50:06 PM    212992    32    C:\Windows\System32\dxtrans.dll
6/14/2008 2:36:13 AM    428032    32    C:\Windows\System32\EncDec.dll
6/19/2008 2:25:23 PM    169984    32    C:\Windows\System32\EncDump.dll
6/30/2008 2:59:27 PM    6173    32    C:\Windows\System32\Entech.vxd
7/8/2008 4:44:37 PM    4188    32    C:\Windows\System32\faq.txt
7/8/2008 11:54:43 AM    992384    32    C:\Windows\System32\fpSpr30.ocx
6/19/2008 3:50:04 PM    385024    32    C:\Windows\System32\html.iec
6/20/2008 5:17:16 PM    85504    32    C:\Windows\System32\HtmlWH.dll
6/19/2008 3:50:22 PM    60928    32    C:\Windows\System32\icardie.dll
6/19/2008 3:50:08 PM    70656    32    C:\Windows\System32\ie4uinit.exe
6/19/2008 3:50:20 PM    119808    32    C:\Windows\System32\ieakeng.dll
6/19/2008 3:50:08 PM    224768    32    C:\Windows\System32\ieaksie.dll
6/19/2008 3:50:10 PM    149504    32    C:\Windows\System32\ieakui.dll
6/19/2008 3:50:04 PM    3670112    32    C:\Windows\System32\ieapfltr.dat
6/19/2008 3:50:22 PM    440832    32    C:\Windows\System32\ieapfltr.dll
6/19/2008 3:50:08 PM    349184    32    C:\Windows\System32\iedkcs32.dll
6/19/2008 3:50:05 PM    78336    32    C:\Windows\System32\ieencode.dll
6/19/2008 3:50:02 PM    8016384    32    C:\Windows\System32\ieframe.dll
6/19/2008 3:50:17 PM    184320    32    C:\Windows\System32\iepeers.dll
6/19/2008 3:50:21 PM    44032    32    C:\Windows\System32\iernonce.dll
6/19/2008 3:50:19 PM    268800    32    C:\Windows\System32\iertutil.dll
6/19/2008 3:50:17 PM    142848    32    C:\Windows\System32\IESetting.dll
6/19/2008 3:50:10 PM    69120    32    C:\Windows\System32\iesetup.dll
6/19/2008 3:50:21 PM    181248    32    C:\Windows\System32\ieui.dll
6/19/2008 3:50:09 PM    56413    32    C:\Windows\System32\ieuinit.inf
6/19/2008 3:50:17 PM    26624    32    C:\Windows\System32\ieUnatt.exe
6/19/2008 3:50:04 PM    168448    32    C:\Windows\System32\iexpress.exe
6/19/2008 3:50:17 PM    36352    32    C:\Windows\System32\imgutil.dll
6/19/2008 3:50:03 PM    1547264    32    C:\Windows\System32\inetcpl.cpl
7/8/2008 11:49:27 AM    15360    32    C:\Windows\System32\inetfr.DLL
6/19/2008 3:50:16 PM    94208    32    C:\Windows\System32\inseng.dll
7/2/2008 9:57:30 PM    36864    0    C:\Windows\System32\inVHDDrvExe.exe
6/16/2008 5:09:42 PM    135168    32    C:\Windows\System32\java.exe
6/16/2008 5:09:42 PM    135168    32    C:\Windows\System32\javaw.exe
6/16/2008 5:09:42 PM    139264    32    C:\Windows\System32\javaws.exe
6/19/2008 3:50:06 PM    557056    32    C:\Windows\System32\jscript.dll
6/19/2008 3:50:19 PM    28672    32    C:\Windows\System32\jsproxy.dll
6/10/2008 4:40:52 PM    6283    32    C:\Windows\System32\jupdate-1.6.0_06-b02.log
7/8/2008 11:49:24 AM    233472    32    C:\Windows\System32\lame_enc.dll
6/19/2008 3:50:17 PM    41984    32    C:\Windows\System32\licmgr10.dll
6/21/2008 6:33:06 PM    155408    32    C:\Windows\System32\LMRT.dll
6/21/2008 6:33:06 PM    38160    32    C:\Windows\System32\LMRTREND.dll
6/21/2008 6:32:45 PM    11776    32    C:\Windows\System32\mciqtz.drv
6/14/2008 2:36:09 AM    1244672    32    C:\Windows\System32\mcmde.dll
6/20/2008 4:58:57 PM    53248    32    C:\Windows\System32\mgxasio2.dll
6/20/2008 4:58:56 PM    27807    32    C:\Windows\System32\mgxcdr.txt
6/20/2008 4:53:26 PM    700416    0    C:\Windows\System32\mgxoschk.dll
6/14/2008 2:36:08 AM    68608    32    C:\Windows\System32\Mpeg2Data.ax
7/8/2008 11:49:25 AM    59904    32    C:\Windows\System32\Mscc2fr.dll
7/8/2008 11:49:25 AM    141312    32    C:\Windows\System32\MSCMCFR.DLL
6/14/2008 2:36:07 AM    57856    32    C:\Windows\System32\MSDvbNP.ax
6/19/2008 3:50:05 PM    585728    32    C:\Windows\System32\msfeeds.dll
6/19/2008 3:50:17 PM    52224    32    C:\Windows\System32\msfeedsbs.dll
6/19/2008 3:50:08 PM    52736    32    C:\Windows\System32\msfeedssync.exe
6/19/2008 3:50:04 PM    45568    32    C:\Windows\System32\mshta.exe
6/19/2008 3:50:00 PM    5120000    32    C:\Windows\System32\mshtml.dll
6/19/2008 3:50:20 PM    1555456    32    C:\Windows\System32\mshtml.tlb
6/19/2008 3:50:18 PM    68608    32    C:\Windows\System32\mshtmled.dll
6/19/2008 3:50:21 PM    48128    32    C:\Windows\System32\mshtmler.dll
7/8/2008 11:49:27 AM    115920    32    C:\Windows\System32\msinet.OCX
6/9/2008 5:31:42 PM    1050896    32    C:\Windows\System32\msjet35.dll
6/9/2008 5:31:43 PM    123664    32    C:\Windows\System32\msjint35.dll
6/9/2008 5:31:42 PM    24848    32    C:\Windows\System32\msjter35.dll
6/14/2008 2:36:08 AM    80896    32    C:\Windows\System32\MSNP.ax
6/19/2008 3:50:10 PM    193024    32    C:\Windows\System32\msrating.dll
7/2/2008 2:09:31 AM    372736    32    C:\Windows\System32\Mss32.dll
6/19/2008 3:50:05 PM    629248    32    C:\Windows\System32\mstime.dll
6/20/2008 4:58:57 PM    430080    32    C:\Windows\System32\MXRestore.exe
7/8/2008 4:44:41 PM    1703936    32    C:\Windows\System32\NCTAudioFile.dll
7/8/2008 4:44:42 PM    360448    32    C:\Windows\System32\NCTWMAFile.dll
7/8/2008 11:49:28 AM    116296    32    C:\Windows\System32\NCTWMAProfiles.prx
6/19/2008 3:50:09 PM    116224    32    C:\Windows\System32\occache.dll
6/19/2008 3:50:17 PM    20480    32    C:\Windows\System32\PDMSetup.exe
6/19/2008 3:50:20 PM    44544    32    C:\Windows\System32\pngfilt.dll
6/14/2008 2:36:10 AM    292352    32    C:\Windows\System32\psisdecd.dll
6/14/2008 2:36:11 AM    218624    32    C:\Windows\System32\psisrndr.ax
6/21/2008 6:32:43 PM    194320    32    C:\Windows\System32\qcut.dll
6/10/2008 2:24:21 PM    1327104    32    C:\Windows\System32\quartz.dll
6/21/2008 6:32:45 PM    5672    32    C:\Windows\System32\quartz.vxd
7/2/2008 9:57:31 PM    102400    0    C:\Windows\System32\RDrv2KInterface.dll
7/2/2008 9:57:30 PM    32768    0    C:\Windows\System32\RDrv9xInterface.dll
7/2/2008 9:57:30 PM    28672    0    C:\Windows\System32\RDrvInterface.dll
7/2/2008 9:57:30 PM    53248    0    C:\Windows\System32\RDrvNTInterface.dll
6/21/2008 4:38:15 PM    368640    32    C:\Windows\System32\ReWire.dll
6/21/2008 4:38:16 PM    233472    0    C:\Windows\System32\REX Shared Library.dll
6/19/2008 3:50:17 PM    13824    32    C:\Windows\System32\SetDepNx.exe
6/19/2008 3:50:17 PM    13824    32    C:\Windows\System32\SetIEInstalledDate.exe
6/20/2008 4:58:56 PM    32768    0    C:\Windows\System32\STRING32.dll
7/8/2008 11:49:26 AM    21504    32    C:\Windows\System32\TABCTFR.DLL
6/19/2008 3:50:18 PM    66560    32    C:\Windows\System32\tdc.ocx
7/8/2008 11:54:38 AM    278581    32    C:\Windows\System32\temp.000
7/8/2008 4:44:34 PM    73785    32    C:\Windows\System32\temp.001
7/8/2008 4:44:40 PM    1388544    32    C:\Windows\System32\temp.002
6/22/2008 5:56:31 PM    1408    32    C:\Windows\System32\TEST.log
6/21/2008 6:33:04 PM    140800    32    C:\Windows\System32\tm20dec.ax
6/20/2008 4:58:57 PM    24576    32    C:\Windows\System32\TTI32.dll
6/20/2008 4:58:57 PM    24576    32    C:\Windows\System32\TTIC32.dll
7/2/2008 9:57:30 PM    36864    0    C:\Windows\System32\unVHDDrvExe.exe
6/19/2008 3:50:08 PM    105984    32    C:\Windows\System32\url.dll
6/19/2008 3:50:03 PM    1188352    32    C:\Windows\System32\urlmon.dll
7/8/2008 11:49:27 AM    119568    32    C:\Windows\System32\VB6FR.DLL
6/21/2008 6:32:45 PM    10240    32    C:\Windows\System32\vidx16.dll
6/20/2008 11:40:04 PM    1294336    32    C:\Windows\System32\vorbis.acm
6/21/2008 6:32:35 PM    2272    32    C:\Windows\System32\w95inf16.dll
6/21/2008 6:32:35 PM    4608    32    C:\Windows\System32\w95inf32.dll
6/19/2008 3:50:09 PM    233984    32    C:\Windows\System32\webcheck.dll
6/19/2008 3:50:09 PM    66560    32    C:\Windows\System32\wextract.exe
6/19/2008 3:50:09 PM    208384    32    C:\Windows\System32\WinFXDocObj.exe
6/19/2008 3:50:04 PM    830464    32    C:\Windows\System32\wininet.dll
6/10/2008 2:24:23 PM    14848    32    C:\Windows\System32\wshrm.dll
7/8/2008 11:54:42 AM    1953792    32    C:\Windows\System32\~GLH0009.TMP

 ========= Temp Files Deleted ========


11 Files deleted

13 Posts

July 9th, 2008 03:00

Message Edited by Greenfire999 on 07-09-2008 01:24 AM

13 Posts

July 9th, 2008 05:00

Nevermind it did it again. It just disappeared just a few minutes ago.

10.4K Posts

July 9th, 2008 12:00

Greenfire999

1. Rerun Killbox
  • 1) Double Click Killbox.exe to run it
    2)Select " Delete on Reboot", and then select "All files".
    3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:



    C:\Windows\System32\~GLH0009.TMP
    C:\Windows\System32\temp.000





    4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
    5) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.









2. You have a suspicious file I would Like to have a look at

Please go HERE

Put Your Name, and Dell HJT forum

and In the file to submit box, click Browse.
  • C:\Windows\System32\fpSpr30.ocx

In the comments tell them that I asked you to upload the file
Then Select Send File.























Microsoft MVP Consumer-Security

 


"The world is what you make of it"



No Events found!

Top