Unsolved
This post is more than 5 years old
13 Posts
0
1992
July 6th, 2008 21:00
Both the Desktop And the Toolbar disappear
Just yesterday morning, my computer started going extra slow so i restarted the computer and now the desktop and toolbar completely disappears. I tried deleting programs just installed and doing restore points but, none of those worked. Here is my HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:02:20 PM, on 7/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM32\taskeng.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Users\owner\Program Files\DNA\btdna.exe
C:\Users\owner\Program Files\uTorrent\uTorrent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Auslogics\AusLogics BoostSpeed\DiskDefrag.exe
C:\WINDOWS\SYSTEM32\Taskmgr.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\helppane.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: (no name) - {056BF8C6-6895-4ECF-AA7A-BE6DB541810E} - C:\Windows\system32\byXNghiH.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\ljJBqooO.dll,#1
O4 - HKLM\..\Run: [Microsoft] pwkpmovo.exe
O4 - HKLM\..\Run: [Microsoft(1)] hnlrfayv.exe
O4 - HKLM\..\RunServices: [Microsoft] pwkpmovo.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\owner\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\owner\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\owner\AppData\Local\Temp\khfCrPiH.dll,#1
O4 - HKCU\..\Run: [RegDefRun] C:\Program Files\Auslogics\AusLogics BoostSpeed\reginfo.exe /r
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: vzTCPConfig - https://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200313887041
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203546833750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1213661161787&h=cefda793e7d44af90274ef084de6de44/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.shockwave.com/content/burgershop/sis/GoBitGamesPlayer_v4.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbl_device - - C:\Windows\system32\lxblcoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 11024 bytes
I would really appreciate the help!
Message Edited by Greenfire999 on 07-06-2008 05:04 PM
No Events found!


bamajim
10.4K Posts
0
July 7th, 2008 19:00
It will take a couple of runs at this to completely remove the infection, so please be patient.
1. Go HERE and download TempFix.
Save it to your Desktop (but do not run it yet)
2. Reboot into Safe Mode
This can be done by
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter
3. Rt Click TempFix.zip ->> Extract all ->> And extract it to your Desktop
Additional help on extracting zip files can be found HERE
Rt Click TempFix.vbe ->>Select Open Then Open to confirm.
As the program runs, it will appear that nothing is happening.
When the program is fnished it will produce a log for you C:\TempFix.txt
Copy and paste the contents of that log in your reply.
Note: if your root drive is something other thatn C:\ then the log will default to your designated root drive
4. Then reboot your PC into Normal Windows Mode->> Rerun Hijackthis and post a fresh Hiajckthis log.
As well as the C:\TempFix.txt log
"The world is what you make of it"
Greenfire999
13 Posts
0
July 8th, 2008 08:00
TempFix
Version 1.0
By bamajim @ bamajim.com
========================================
C:\Users\owner\AppData\Local\Temp\awTLdCrp.dll
C:\Users\owner\AppData\Local\Temp\awtrOghe.dll
C:\Users\owner\AppData\Local\Temp\bh_html.htm
C:\Users\owner\AppData\Local\Temp\JklUxyxx.ini
C:\Users\owner\AppData\Local\Temp\JklUxyxx.ini2
C:\Users\owner\AppData\Local\Temp\jusched.log
C:\Users\owner\AppData\Local\Temp\owner.bmp
C:\Users\owner\AppData\Local\Temp\pmnlkKbC.dll
C:\Users\owner\AppData\Local\Temp\ssqPhIxu.dll
C:\Users\owner\AppData\Local\Temp\swt-awt-win32-3346.dll
C:\Users\owner\AppData\Local\Temp\swt-win32-3346.dll
C:\Users\owner\AppData\Local\Temp\tmp00019a2c
C:\Users\owner\AppData\Local\Temp\tmp000240c6
C:\Users\owner\AppData\Local\Temp\uxIhPqss.ini
C:\Users\owner\AppData\Local\Temp\uxIhPqss.ini2
C:\Users\owner\AppData\Local\Temp\wmplog00.sqm
C:\Users\owner\AppData\Local\Temp\xxyxUlkJ.dll
C:\Users\owner\AppData\Local\Temp\~DF1205.tmp
C:\Users\owner\AppData\Local\Temp\~DF75E7.tmp
19 files deleted
and
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:30:17 AM, on 7/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Safe mode
Running processes:
C:\Windows\explorer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = >>> 'Full Speed' Enabled <<<
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D8CDED80-7413-4437-9404-2AAB6C865F2D} - C:\Windows\system32\byXNghiH.dll
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\PicLens.dll
O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Microsoft] pwkpmovo.exe
O4 - HKLM\..\Run: [Microsoft(1)] hnlrfayv.exe
O4 - HKLM\..\RunServices: [Microsoft] pwkpmovo.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\owner\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\owner\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: vzTCPConfig - https://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200313887041
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203546833750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1213661161787&h=cefda793e7d44af90274ef084de6de44/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.shockwave.com/content/burgershop/sis/GoBitGamesPlayer_v4.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbl_device - - C:\Windows\system32\lxblcoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10147 bytes
bamajim
10.4K Posts
0
July 8th, 2008 12:00
Good work. I have revised the TempFix tool to do more.
Please delete the current version of TempFix that you have, both the folder and the zip file.
And using the same link I provided in my previous post download the newer version
And rerun it the same as you did the first time and post the results of the C:\TempFix .txt log
This time I would like to see a fresh Hijackthis log run in Normal Windows mode.
"The world is what you make of it"
Greenfire999
13 Posts
0
July 8th, 2008 13:00
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:36:44 AM, on 7/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM32\taskeng.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Users\owner\Program Files\DNA\btdna.exe
C:\Users\owner\Program Files\uTorrent\uTorrent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wermgr.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = >>> 'Full Speed' Enabled <<<
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ReCycle Patch] "C:\Users\owner\AppData\Local\Temp\Rar$EX01.452\ReCyclePatch.exe" -s
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\owner\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\owner\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: vzTCPConfig - https://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200313887041
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203546833750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1213661161787&h=cefda793e7d44af90274ef084de6de44/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.shockwave.com/content/burgershop/sis/GoBitGamesPlayer_v4.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbl_device - - C:\Windows\system32\lxblcoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9603 bytes
Greenfire999
13 Posts
0
July 8th, 2008 13:00
6/21/2008 6:33:06 PM 155408 32 C:\Windows\System32\LMRT.dll
6/21/2008 6:33:06 PM 38160 32 C:\Windows\System32\LMRTREND.dll
7/5/2008 10:09:56 PM 839763 7 C:\Windows\System32\lnxchzmw.exe
6/29/2008 5:15:38 PM 839763 7 C:\Windows\System32\mausnrfg.exe
6/21/2008 6:32:45 PM 11776 32 C:\Windows\System32\mciqtz.drv
6/14/2008 2:36:09 AM 1244672 32 C:\Windows\System32\mcmde.dll
6/20/2008 4:58:57 PM 53248 32 C:\Windows\System32\mgxasio2.dll
6/20/2008 4:58:56 PM 27807 32 C:\Windows\System32\mgxcdr.txt
6/20/2008 4:53:26 PM 700416 0 C:\Windows\System32\mgxoschk.dll
7/6/2008 12:39:16 AM 653745 38 C:\Windows\System32\mnTuFeNn.ini
7/6/2008 12:39:17 AM 345 38 C:\Windows\System32\mnTuFeNn.ini2
6/14/2008 2:36:08 AM 68608 32 C:\Windows\System32\Mpeg2Data.ax
6/14/2008 2:36:07 AM 57856 32 C:\Windows\System32\MSDvbNP.ax
6/19/2008 3:50:05 PM 585728 32 C:\Windows\System32\msfeeds.dll
6/19/2008 3:50:17 PM 52224 32 C:\Windows\System32\msfeedsbs.dll
6/19/2008 3:50:08 PM 52736 32 C:\Windows\System32\msfeedssync.exe
6/19/2008 3:50:04 PM 45568 32 C:\Windows\System32\mshta.exe
6/19/2008 3:50:00 PM 5120000 32 C:\Windows\System32\mshtml.dll
6/19/2008 3:50:20 PM 1555456 32 C:\Windows\System32\mshtml.tlb
6/19/2008 3:50:18 PM 68608 32 C:\Windows\System32\mshtmled.dll
6/19/2008 3:50:21 PM 48128 32 C:\Windows\System32\mshtmler.dll
6/9/2008 5:31:42 PM 1050896 32 C:\Windows\System32\msjet35.dll
6/9/2008 5:31:43 PM 123664 32 C:\Windows\System32\msjint35.dll
6/9/2008 5:31:42 PM 24848 32 C:\Windows\System32\msjter35.dll
6/14/2008 2:36:08 AM 80896 32 C:\Windows\System32\MSNP.ax
6/19/2008 3:50:10 PM 193024 32 C:\Windows\System32\msrating.dll
7/2/2008 2:09:31 AM 372736 32 C:\Windows\System32\Mss32.dll
6/19/2008 3:50:05 PM 629248 32 C:\Windows\System32\mstime.dll
6/20/2008 4:58:57 PM 430080 32 C:\Windows\System32\MXRestore.exe
7/5/2008 12:27:30 AM 839763 7 C:\Windows\System32\nhfxzijk.exe
7/6/2008 1:23:05 AM 839763 7 C:\Windows\System32\nhyostol.exe
7/4/2008 10:20:25 AM 839763 7 C:\Windows\System32\niyfdihq.exe
7/3/2008 12:13:11 PM 839763 7 C:\Windows\System32\nlqanbbs.exe
7/6/2008 12:39:05 AM 318976 32 C:\Windows\System32\nNeFuTnm.dll
7/4/2008 6:51:39 PM 319488 32 C:\Windows\System32\nnnMGVpQ.dll
7/6/2008 12:11:12 AM 839763 7 C:\Windows\System32\nufzsvbf.exe
6/19/2008 3:50:09 PM 116224 32 C:\Windows\System32\occache.dll
7/4/2008 9:30:41 PM 839763 7 C:\Windows\System32\omdxmepo.exe
7/6/2008 12:19:11 AM 839763 7 C:\Windows\System32\omoeogjk.exe
7/5/2008 11:22:00 PM 839763 7 C:\Windows\System32\ovkgluxf.exe
7/4/2008 10:41:37 PM 839763 7 C:\Windows\System32\pdjfxriu.exe
6/19/2008 3:50:17 PM 20480 32 C:\Windows\System32\PDMSetup.exe
6/20/2008 4:24:56 PM 24576 32 C:\Windows\System32\pmNEUmMc.dll
6/20/2008 4:30:07 PM 24576 32 C:\Windows\System32\pmnmljiI.dll
6/19/2008 3:50:20 PM 44544 32 C:\Windows\System32\pngfilt.dll
7/4/2008 6:46:19 PM 839763 7 C:\Windows\System32\pqpkukdf.exe
6/14/2008 2:36:10 AM 292352 32 C:\Windows\System32\psisdecd.dll
6/14/2008 2:36:11 AM 218624 32 C:\Windows\System32\psisrndr.ax
7/6/2008 10:21:22 AM 839763 7 C:\Windows\System32\pwkpmovo.exe
6/21/2008 6:32:43 PM 194320 32 C:\Windows\System32\qcut.dll
7/5/2008 7:26:35 PM 318976 32 C:\Windows\System32\qoMgeCss.dll
7/4/2008 6:52:52 PM 653629 38 C:\Windows\System32\QpVGMnnn.ini
7/4/2008 6:52:56 PM 345 38 C:\Windows\System32\QpVGMnnn.ini2
6/10/2008 2:24:21 PM 1327104 32 C:\Windows\System32\quartz.dll
6/21/2008 6:32:45 PM 5672 32 C:\Windows\System32\quartz.vxd
7/6/2008 3:10:01 AM 839763 7 C:\Windows\System32\qwexznzd.exe
7/2/2008 9:57:31 PM 102400 0 C:\Windows\System32\RDrv2KInterface.dll
7/2/2008 9:57:30 PM 32768 0 C:\Windows\System32\RDrv9xInterface.dll
7/2/2008 9:57:30 PM 28672 0 C:\Windows\System32\RDrvInterface.dll
7/2/2008 9:57:30 PM 53248 0 C:\Windows\System32\RDrvNTInterface.dll
6/21/2008 4:38:15 PM 368640 32 C:\Windows\System32\ReWire.dll
6/21/2008 4:38:16 PM 233472 0 C:\Windows\System32\REX Shared Library.dll
7/5/2008 8:48:05 AM 839763 7 C:\Windows\System32\rjjqrlbt.exe
7/5/2008 4:03:05 AM 318976 32 C:\Windows\System32\rqRLecDS.dll
7/5/2008 11:47:22 PM 839763 7 C:\Windows\System32\rxwnlxlc.exe
7/4/2008 3:23:17 PM 839763 7 C:\Windows\System32\ryxknlts.exe
7/2/2008 3:45:28 AM 839763 7 C:\Windows\System32\sbexlbyg.exe
7/5/2008 4:03:20 AM 653745 38 C:\Windows\System32\SDceLRqr.ini
7/5/2008 4:03:31 AM 345 38 C:\Windows\System32\SDceLRqr.ini2
6/19/2008 3:50:17 PM 13824 32 C:\Windows\System32\SetDepNx.exe
6/19/2008 3:50:17 PM 13824 32 C:\Windows\System32\SetIEInstalledDate.exe
7/6/2008 3:00:02 AM 839763 7 C:\Windows\System32\sicvcjbv.exe
7/5/2008 6:06:26 PM 839763 7 C:\Windows\System32\sigjiyuq.exe
7/5/2008 7:26:49 PM 653745 38 C:\Windows\System32\ssCegMoq.ini
7/5/2008 7:26:53 PM 345 38 C:\Windows\System32\ssCegMoq.ini2
7/5/2008 8:53:20 AM 318976 32 C:\Windows\System32\sSmlJYSj.dll
6/20/2008 4:58:56 PM 32768 0 C:\Windows\System32\STRING32.dll
6/30/2008 3:55:25 PM 839763 7 C:\Windows\System32\tafohgaz.exe
6/19/2008 3:50:18 PM 66560 32 C:\Windows\System32\tdc.ocx
6/22/2008 5:56:31 PM 1408 32 C:\Windows\System32\TEST.log
6/21/2008 6:33:04 PM 140800 32 C:\Windows\System32\tm20dec.ax
6/20/2008 4:58:57 PM 24576 32 C:\Windows\System32\TTI32.dll
6/20/2008 4:58:57 PM 24576 32 C:\Windows\System32\TTIC32.dll
7/5/2008 12:14:48 AM 319488 32 C:\Windows\System32\tuvWMETJ.dll
7/4/2008 11:10:46 PM 839763 7 C:\Windows\System32\txwgmrar.exe
7/5/2008 1:32:14 AM 443 38 C:\Windows\System32\UFNopXbc.ini
7/5/2008 1:32:15 AM 345 38 C:\Windows\System32\UFNopXbc.ini2
6/30/2008 8:36:34 PM 839763 7 C:\Windows\System32\uijkxbrn.exe
6/21/2008 6:32:57 PM 63488 32 C:\Windows\System32\unam4ie.exe
7/5/2008 7:10:51 PM 839763 7 C:\Windows\System32\unpjyhxb.exe
7/2/2008 9:57:30 PM 36864 0 C:\Windows\System32\unVHDDrvExe.exe
6/19/2008 3:50:08 PM 105984 32 C:\Windows\System32\url.dll
6/19/2008 3:50:03 PM 1188352 32 C:\Windows\System32\urlmon.dll
7/6/2008 2:28:53 AM 319488 32 C:\Windows\System32\urqQjkkK.dll
7/4/2008 9:34:48 PM 653745 38 C:\Windows\System32\uuDcdccf.ini
7/4/2008 9:34:54 PM 345 38 C:\Windows\System32\uuDcdccf.ini2
7/5/2008 6:28:17 PM 839763 7 C:\Windows\System32\vhallcal.exe
6/21/2008 6:32:45 PM 10240 32 C:\Windows\System32\vidx16.dll
6/20/2008 11:40:04 PM 1294336 32 C:\Windows\System32\vorbis.acm
6/30/2008 12:09:54 AM 839763 7 C:\Windows\System32\vrbldejp.exe
6/21/2008 6:32:35 PM 2272 32 C:\Windows\System32\w95inf16.dll
6/21/2008 6:32:35 PM 4608 32 C:\Windows\System32\w95inf32.dll
6/19/2008 3:50:09 PM 233984 32 C:\Windows\System32\webcheck.dll
6/19/2008 3:50:09 PM 66560 32 C:\Windows\System32\wextract.exe
6/19/2008 3:50:09 PM 208384 32 C:\Windows\System32\WinFXDocObj.exe
6/19/2008 3:50:04 PM 830464 32 C:\Windows\System32\wininet.dll
6/10/2008 2:24:23 PM 14848 32 C:\Windows\System32\wshrm.dll
6/30/2008 8:47:24 PM 839763 7 C:\Windows\System32\xiecuyaw.exe
7/1/2008 1:22:59 AM 839763 7 C:\Windows\System32\xkpkiisx.exe
7/2/2008 5:31:56 AM 839763 7 C:\Windows\System32\xtoeifuw.exe
7/4/2008 10:25:14 AM 319488 32 C:\Windows\System32\yaywxYPJ.dll
6/30/2008 10:09:54 AM 839763 7 C:\Windows\System32\yenbzgtw.exe
7/1/2008 8:25:02 PM 839763 7 C:\Windows\System32\yghfufoq.exe
7/1/2008 11:28:55 PM 839763 7 C:\Windows\System32\ywmmfxhp.exe
7/4/2008 10:05:19 PM 839763 7 C:\Windows\System32\zgmvgrgy.exe
7/5/2008 6:16:45 PM 839763 7 C:\Windows\System32\zyyrsnvy.exe
========= Temp Files Deleted ========
13 Files deleted
Greenfire999
13 Posts
0
July 8th, 2008 13:00
Version 1.0.1
By bamajim @ bamajim.com
========================================
Report ran on --->>> 7/8/2008 7:09:30 AM
======== Files created in (System32) last 30 days ========
7/3/2008 12:39:22 PM 0 32 C:\Windows\System32\1f5c7e5e-.txt
6/30/2008 5:37:51 PM 839763 7 C:\Windows\System32\acxwbsuk.exe
6/19/2008 3:50:21 PM 69120 32 C:\Windows\System32\admparse.dll
6/19/2008 3:50:21 PM 126464 32 C:\Windows\System32\advpack.dll
7/5/2008 11:40:37 PM 839763 7 C:\Windows\System32\akzwxuov.exe
7/5/2008 5:55:56 PM 839763 7 C:\Windows\System32\aqkuqzdc.exe
6/19/2008 2:25:26 PM 88064 32 C:\Windows\System32\audiodg.exe
6/19/2008 2:25:26 PM 398848 32 C:\Windows\System32\AudioEng.dll
6/19/2008 2:25:26 PM 273408 32 C:\Windows\System32\AUDIOKSE.dll
6/19/2008 2:25:26 PM 115712 32 C:\Windows\System32\AudioSes.dll
6/19/2008 2:25:26 PM 310272 32 C:\Windows\System32\audiosrv.dll
7/5/2008 5:46:04 PM 839763 7 C:\Windows\System32\auvhtecf.exe
6/29/2008 6:13:01 PM 839763 7 C:\Windows\System32\bdfewdgr.exe
7/2/2008 9:59:39 PM 319488 32 C:\Windows\System32\byXNghiH.dll
7/5/2008 5:50:23 PM 318976 32 C:\Windows\System32\byXRkjgG.dll
7/5/2008 1:32:09 AM 318976 32 C:\Windows\System32\cbXpoNFU.dll
7/4/2008 10:47:12 PM 653745 38 C:\Windows\System32\cJSYFfhk.ini
7/4/2008 10:47:15 PM 345 38 C:\Windows\System32\cJSYFfhk.ini2
6/19/2008 3:50:18 PM 17920 32 C:\Windows\System32\corpol.dll
6/30/2008 7:04:39 PM 839763 7 C:\Windows\System32\cysmtwuw.exe
6/21/2008 6:32:44 PM 1088272 32 C:\Windows\System32\danim.dll
6/9/2008 5:31:38 PM 570128 32 C:\Windows\System32\dao350.dll
7/5/2008 8:34:59 PM 839763 7 C:\Windows\System32\dasdturh.exe
7/1/2008 10:25:58 AM 839763 7 C:\Windows\System32\ddwgqfkz.exe
6/20/2008 4:58:55 PM 487424 0 C:\Windows\System32\DLLAV32.dll
6/20/2008 4:58:55 PM 14182 32 C:\Windows\System32\DLLAV32.lib
6/20/2008 4:58:56 PM 114688 32 C:\Windows\System32\DLLCDA32.dll
6/20/2008 4:58:56 PM 61440 32 C:\Windows\System32\DLLCDF32.dll
6/20/2008 4:58:56 PM 94208 0 C:\Windows\System32\DLLCPY32.dll
6/20/2008 4:58:56 PM 163840 0 C:\Windows\System32\DLLDEV32.dll
6/20/2008 4:55:46 PM 120200 32 C:\Windows\System32\DLLDEV32i.dll
6/20/2008 4:58:56 PM 32768 32 C:\Windows\System32\DLLDIR32.dll
6/20/2008 4:58:56 PM 151552 0 C:\Windows\System32\DLLDRV32.dll
6/20/2008 4:58:56 PM 45056 32 C:\Windows\System32\DLLIMG32.dll
6/20/2008 4:58:56 PM 53248 0 C:\Windows\System32\DLLIO32.dll
6/20/2008 4:58:56 PM 32768 32 C:\Windows\System32\DLLISO32.dll
6/20/2008 4:58:56 PM 24576 32 C:\Windows\System32\DLLIX.dll
6/20/2008 4:58:56 PM 32768 32 C:\Windows\System32\DLLMSC32.dll
6/20/2008 4:58:56 PM 36864 0 C:\Windows\System32\DLLPNT32.dll
6/20/2008 4:58:56 PM 49152 32 C:\Windows\System32\DLLPRF32.dll
6/20/2008 4:58:56 PM 53248 32 C:\Windows\System32\DLLPRJ32.dll
6/20/2008 4:58:56 PM 65536 32 C:\Windows\System32\DLLPTL32.dll
6/20/2008 4:58:56 PM 40960 32 C:\Windows\System32\DLLRD32.dll
6/20/2008 4:58:56 PM 188416 0 C:\Windows\System32\DLLRES32.dll
6/20/2008 4:58:56 PM 57344 32 C:\Windows\System32\DLLTPO32.dll
7/5/2008 7:22:01 PM 839763 7 C:\Windows\System32\dmxttoci.exe
6/30/2008 7:20:07 PM 839763 7 C:\Windows\System32\doqblydu.exe
6/30/2008 6:05:34 PM 839763 7 C:\Windows\System32\dukwvmeg.exe
6/30/2008 5:45:20 PM 839763 7 C:\Windows\System32\dvbczwcg.exe
7/2/2008 9:57:25 PM 126976 32 C:\Windows\System32\DVC.dll
7/2/2008 9:57:26 PM 86016 32 C:\Windows\System32\Dversion.dll
6/19/2008 3:50:06 PM 345600 32 C:\Windows\System32\dxtmsft.dll
6/21/2008 6:33:02 PM 182032 32 C:\Windows\System32\dxtmsft3.dll
6/19/2008 3:50:06 PM 212992 32 C:\Windows\System32\dxtrans.dll
7/6/2008 12:49:53 AM 839763 7 C:\Windows\System32\dxzocgzt.exe
7/3/2008 9:12:21 PM 320000 32 C:\Windows\System32\efcApqPI.dll
7/4/2008 3:27:33 PM 319488 32 C:\Windows\System32\efcbYrRi.dll
6/14/2008 2:36:13 AM 428032 32 C:\Windows\System32\EncDec.dll
6/19/2008 2:25:23 PM 169984 32 C:\Windows\System32\EncDump.dll
6/30/2008 2:59:27 PM 6173 32 C:\Windows\System32\Entech.vxd
7/4/2008 9:34:36 PM 319488 32 C:\Windows\System32\fccdcDuu.dll
7/2/2008 9:57:25 PM 5120 32 C:\Windows\System32\Fsinst16.DLL
7/2/2008 9:57:25 PM 45056 32 C:\Windows\System32\Fsinst32.dll
6/30/2008 6:41:58 PM 839763 7 C:\Windows\System32\gdwjfjaj.exe
7/5/2008 5:50:38 PM 653745 38 C:\Windows\System32\GgjkRXyb.ini
7/5/2008 5:50:40 PM 345 38 C:\Windows\System32\GgjkRXyb.ini2
7/3/2008 12:18:05 PM 595 38 C:\Windows\System32\gOVwGfhk.ini
7/3/2008 12:18:26 PM 345 38 C:\Windows\System32\gOVwGfhk.ini2
6/29/2008 9:51:56 PM 839763 7 C:\Windows\System32\hcdwsmwi.exe
7/5/2008 10:45:57 PM 839763 7 C:\Windows\System32\helwwmhd.exe
7/2/2008 9:59:49 PM 646630 38 C:\Windows\System32\HihgNXyb.ini
7/2/2008 9:59:53 PM 646452 38 C:\Windows\System32\HihgNXyb.ini2
7/5/2008 7:33:36 PM 839763 7 C:\Windows\System32\hnlrfayv.exe
7/6/2008 1:06:23 AM 839763 7 C:\Windows\System32\hpczmssf.exe
6/19/2008 3:50:04 PM 385024 32 C:\Windows\System32\html.iec
6/20/2008 5:17:16 PM 85504 32 C:\Windows\System32\HtmlWH.dll
7/5/2008 9:06:08 PM 839763 7 C:\Windows\System32\iaflryia.exe
6/19/2008 3:50:22 PM 60928 32 C:\Windows\System32\icardie.dll
7/5/2008 3:58:42 AM 839763 7 C:\Windows\System32\idrgxuxs.exe
6/19/2008 3:50:08 PM 70656 32 C:\Windows\System32\ie4uinit.exe
6/19/2008 3:50:20 PM 119808 32 C:\Windows\System32\ieakeng.dll
6/19/2008 3:50:08 PM 224768 32 C:\Windows\System32\ieaksie.dll
6/19/2008 3:50:10 PM 149504 32 C:\Windows\System32\ieakui.dll
6/19/2008 3:50:04 PM 3670112 32 C:\Windows\System32\ieapfltr.dat
6/19/2008 3:50:22 PM 440832 32 C:\Windows\System32\ieapfltr.dll
6/19/2008 3:50:08 PM 349184 32 C:\Windows\System32\iedkcs32.dll
6/19/2008 3:50:05 PM 78336 32 C:\Windows\System32\ieencode.dll
6/19/2008 3:50:02 PM 8016384 32 C:\Windows\System32\ieframe.dll
6/19/2008 3:50:17 PM 184320 32 C:\Windows\System32\iepeers.dll
6/19/2008 3:50:21 PM 44032 32 C:\Windows\System32\iernonce.dll
6/19/2008 3:50:19 PM 268800 32 C:\Windows\System32\iertutil.dll
6/19/2008 3:50:17 PM 142848 32 C:\Windows\System32\IESetting.dll
6/19/2008 3:50:10 PM 69120 32 C:\Windows\System32\iesetup.dll
6/19/2008 3:50:21 PM 181248 32 C:\Windows\System32\ieui.dll
6/19/2008 3:50:09 PM 56413 32 C:\Windows\System32\ieuinit.inf
6/19/2008 3:50:17 PM 26624 32 C:\Windows\System32\ieUnatt.exe
6/19/2008 3:50:04 PM 168448 32 C:\Windows\System32\iexpress.exe
7/6/2008 2:24:19 AM 839763 7 C:\Windows\System32\iiozuprv.exe
6/19/2008 3:50:17 PM 36352 32 C:\Windows\System32\imgutil.dll
6/19/2008 3:50:03 PM 1547264 32 C:\Windows\System32\inetcpl.cpl
6/19/2008 3:50:16 PM 94208 32 C:\Windows\System32\inseng.dll
7/2/2008 9:57:30 PM 36864 0 C:\Windows\System32\inVHDDrvExe.exe
7/3/2008 9:12:32 PM 656835 38 C:\Windows\System32\IPqpAcfe.ini
7/3/2008 9:12:39 PM 345 38 C:\Windows\System32\IPqpAcfe.ini2
7/4/2008 3:27:39 PM 653745 38 C:\Windows\System32\iRrYbcfe.ini
7/4/2008 3:27:42 PM 345 38 C:\Windows\System32\iRrYbcfe.ini2
6/16/2008 5:09:42 PM 135168 32 C:\Windows\System32\java.exe
6/16/2008 5:09:42 PM 135168 32 C:\Windows\System32\javaw.exe
6/16/2008 5:09:42 PM 139264 32 C:\Windows\System32\javaws.exe
6/30/2008 10:52:45 PM 839763 7 C:\Windows\System32\jiukmfxr.exe
7/4/2008 10:25:24 AM 653981 38 C:\Windows\System32\JPYxwyay.ini
7/4/2008 10:25:28 AM 345 38 C:\Windows\System32\JPYxwyay.ini2
6/19/2008 3:50:06 PM 557056 32 C:\Windows\System32\jscript.dll
6/19/2008 3:50:19 PM 28672 32 C:\Windows\System32\jsproxy.dll
7/5/2008 8:53:28 AM 653745 38 C:\Windows\System32\jSYJlmSs.ini
7/5/2008 8:53:31 AM 345 38 C:\Windows\System32\jSYJlmSs.ini2
7/5/2008 12:14:52 AM 653745 38 C:\Windows\System32\JTEMWvut.ini
7/5/2008 12:14:54 AM 345 38 C:\Windows\System32\JTEMWvut.ini2
6/10/2008 4:40:52 PM 6283 32 C:\Windows\System32\jupdate-1.6.0_06-b02.log
7/3/2008 9:07:19 PM 839763 7 C:\Windows\System32\jwhulhhi.exe
7/4/2008 10:46:54 PM 319488 32 C:\Windows\System32\khfFYSJc.dll
7/3/2008 12:17:44 PM 320000 32 C:\Windows\System32\khfGwVOg.dll
7/6/2008 2:29:10 AM 653745 38 C:\Windows\System32\KkkjQqru.ini
7/6/2008 2:29:12 AM 345 38 C:\Windows\System32\KkkjQqru.ini2
7/6/2008 2:42:32 AM 839763 7 C:\Windows\System32\lbljjlnk.exe
6/19/2008 3:50:17 PM 41984 32 C:\Windows\System32\licmgr10.dll
bamajim
10.4K Posts
0
July 8th, 2008 15:00
That's quite an infection you have there
1. Please download the Killbox.
2) Rt Click->>Extract all->.Extract it to your Desktop
3) Double Click Killbox.exe to run it
4)Select " Delete on Reboot", and then select "All files".
5) Copy the file names below to the clipboard by highlighting them and pressing Control-C:
C:\Windows\System32\acxwbsuk.exe
C:\Windows\System32\akzwxuov.exe
C:\Windows\System32\aqkuqzdc.exe
C:\Windows\System32\auvhtecf.exe
C:\Windows\System32\bdfewdgr.exe
C:\Windows\System32\byXNghiH.dll
C:\Windows\System32\byXRkjgG.dll
C:\Windows\System32\cbXpoNFU.dll
C:\Windows\System32\cJSYFfhk.ini
C:\Windows\System32\cJSYFfhk.ini2
C:\Windows\System32\cysmtwuw.exe
C:\Windows\System32\dasdturh.exe
C:\Windows\System32\ddwgqfkz.exe
C:\Windows\System32\dmxttoci.exe
C:\Windows\System32\doqblydu.exe
C:\Windows\System32\dukwvmeg.exe
C:\Windows\System32\dvbczwcg.exe
C:\Windows\System32\dxzocgzt.exe
C:\Windows\System32\efcApqPI.dll
C:\Windows\System32\efcbYrRi.dll
C:\Windows\System32\fccdcDuu.dll
C:\Windows\System32\Fsinst16.DLL
C:\Windows\System32\Fsinst32.dll
C:\Windows\System32\gdwjfjaj.exe
C:\Windows\System32\GgjkRXyb.ini
C:\Windows\System32\GgjkRXyb.ini2
C:\Windows\System32\gOVwGfhk.ini
C:\Windows\System32\gOVwGfhk.ini2
C:\Windows\System32\hcdwsmwi.exe
C:\Windows\System32\helwwmhd.exe
C:\Windows\System32\HihgNXyb.ini
C:\Windows\System32\HihgNXyb.ini2
C:\Windows\System32\hnlrfayv.exe
C:\Windows\System32\hpczmssf.exe
C:\Windows\System32\iaflryia.exe
C:\Windows\System32\idrgxuxs.exe
C:\Windows\System32\iiozuprv.exe
C:\Windows\System32\IPqpAcfe.ini
C:\Windows\System32\IPqpAcfe.ini2
C:\Windows\System32\iRrYbcfe.ini
C:\Windows\System32\iRrYbcfe.ini2
C:\Windows\System32\jiukmfxr.exe
C:\Windows\System32\JPYxwyay.ini
C:\Windows\System32\JPYxwyay.ini2
C:\Windows\System32\jSYJlmSs.ini
C:\Windows\System32\jSYJlmSs.ini2
C:\Windows\System32\JTEMWvut.ini
C:\Windows\System32\JTEMWvut.ini2
C:\Windows\System32\jwhulhhi.exe
C:\Windows\System32\khfFYSJc.dll
C:\Windows\System32\khfGwVOg.dll
C:\Windows\System32\KkkjQqru.ini
C:\Windows\System32\KkkjQqru.ini2
C:\Windows\System32\lbljjlnk.exe
C:\Windows\System32\ljJBqooO.dll
C:\Windows\System32\lnxchzmw.exe
C:\Windows\System32\mausnrfg.exe
C:\Windows\System32\mnTuFeNn.ini
C:\Windows\System32\mnTuFeNn.ini2
C:\Windows\System32\nhfxzijk.exe
C:\Windows\System32\nhyostol.exe
C:\Windows\System32\niyfdihq.exe
C:\Windows\System32\nlqanbbs.exe
C:\Windows\System32\nNeFuTnm.dll
C:\Windows\System32\nnnMGVpQ.dll
C:\Windows\System32\nufzsvbf.exe
C:\Windows\System32\occache.dll
C:\Windows\System32\omdxmepo.exe
C:\Windows\System32\omoeogjk.exe
C:\Windows\System32\ovkgluxf.exe
C:\Windows\System32\pdjfxriu.exe
C:\Windows\System32\pmNEUmMc.dll
C:\Windows\System32\pmnmljiI.dll
C:\Windows\System32\pqpkukdf.exe
C:\Windows\System32\pwkpmovo.exe
C:\Windows\System32\qoMgeCss.dll
C:\Windows\System32\QpVGMnnn.ini
C:\Windows\System32\QpVGMnnn.ini2
C:\Windows\System32\qwexznzd.exe
C:\Windows\System32\rjjqrlbt.exe
C:\Windows\System32\rqRLecDS.dll
C:\Windows\System32\rxwnlxlc.exe
C:\Windows\System32\ryxknlts.exe
C:\Windows\System32\sbexlbyg.exe
C:\Windows\System32\SDceLRqr.ini
C:\Windows\System32\SDceLRqr.ini2
C:\Windows\System32\sicvcjbv.exe
C:\Windows\System32\sigjiyuq.exe
C:\Windows\System32\ssCegMoq.ini
C:\Windows\System32\ssCegMoq.ini2
C:\Windows\System32\sSmlJYSj.dll
C:\Windows\System32\tafohgaz.exe
C:\Windows\System32\tuvWMETJ.dll
C:\Windows\System32\txwgmrar.exe
C:\Windows\System32\UFNopXbc.ini
C:\Windows\System32\UFNopXbc.ini2
C:\Windows\System32\uijkxbrn.exe
C:\Windows\System32\unam4ie.exe
C:\Windows\System32\unpjyhxb.exe
C:\Windows\System32\urqQjkkK.dll
C:\Windows\System32\uuDcdccf.ini
C:\Windows\System32\uuDcdccf.ini2
C:\Windows\System32\vhallcal.exe
C:\Windows\System32\vrbldejp.exe
C:\Windows\System32\xiecuyaw.exe
C:\Windows\System32\xkpkiisx.exe
C:\Windows\System32\xtoeifuw.exe
C:\Windows\System32\yaywxYPJ.dll
C:\Windows\System32\yenbzgtw.exe
C:\Windows\System32\yghfufoq.exe
C:\Windows\System32\ywmmfxhp.exe
C:\Windows\System32\zgmvgrgy.exe
C:\Windows\System32\zyyrsnvy.exe
6) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
7) Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt.
Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log
"The world is what you make of it"
Greenfire999
13 Posts
0
July 8th, 2008 15:00
Scan saved at 10:00:33 AM, on 7/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal
Running processes:
C:\WINDOWS\SYSTEM32\taskeng.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Users\owner\Program Files\DNA\btdna.exe
C:\Users\owner\Program Files\uTorrent\uTorrent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Windows\helppane.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/browsers/redirect/?b=RRHSO_BLD1&CMP=OTC-RRHSO_BLD1HPRR&d=homerr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = >>> 'Full Speed' Enabled <<<
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\owner\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Users\owner\Program Files\uTorrent\uTorrent.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - (no file)
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: vzTCPConfig - https://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/MyFunCardsFWBInitialSetup1.0.1.0.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200313887041
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1203546833750
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1213661161787&h=cefda793e7d44af90274ef084de6de44/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {B516CA4E-A5BA-405C-AFCF-A97F08CC7429} (GoBit Games Player) - http://www.shockwave.com/content/burgershop/sis/GoBitGamesPlayer_v4.cab
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxbl_device - - C:\Windows\system32\lxblcoms.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 9603 bytes
bamajim
10.4K Posts
0
July 8th, 2008 19:00
Greenfire999
Did Killbox run without any problems?
Log looks good. How's your PC running now?
"The world is what you make of it"
Greenfire999
13 Posts
0
July 8th, 2008 21:00
bamajim
10.4K Posts
0
July 9th, 2008 00:00
Rerun Tempfix and let's see if there is something else there.
The log should be substantialy shorter
"The world is what you make of it"
Greenfire999
13 Posts
0
July 9th, 2008 02:00
TempFix
Version 1.0.1
By bamajim @ bamajim.com
========================================
Report ran on --->>> 7/8/2008 7:48:07 PM
======== Files created in (System32) last 30 days ========
7/3/2008 12:39:22 PM 0 32 C:\Windows\System32\1f5c7e5e-.txt
7/8/2008 4:44:33 PM 376832 32 C:\Windows\System32\actskin4.ocx
6/19/2008 3:50:21 PM 69120 32 C:\Windows\System32\admparse.dll
6/19/2008 3:50:21 PM 126464 32 C:\Windows\System32\advpack.dll
7/8/2008 11:54:41 AM 1269760 32 C:\Windows\System32\ASTAudioFile.dll
7/8/2008 11:54:40 AM 1200128 32 C:\Windows\System32\ASTAudioInformation.dll
7/8/2008 11:49:28 AM 1986560 32 C:\Windows\System32\AudFile.dll
6/19/2008 2:25:26 PM 88064 32 C:\Windows\System32\audiodg.exe
6/19/2008 2:25:26 PM 398848 32 C:\Windows\System32\AudioEng.dll
7/8/2008 11:49:28 AM 1212416 32 C:\Windows\System32\AudioInfos.dll
6/19/2008 2:25:26 PM 273408 32 C:\Windows\System32\AUDIOKSE.dll
6/19/2008 2:25:26 PM 115712 32 C:\Windows\System32\AudioSes.dll
6/19/2008 2:25:26 PM 310272 32 C:\Windows\System32\audiosrv.dll
7/8/2008 11:49:28 AM 458752 32 C:\Windows\System32\AudPlayer.dll
7/8/2008 11:16:31 AM 516096 32 C:\Windows\System32\CLVSD.ax
7/8/2008 11:49:24 AM 32768 32 C:\Windows\System32\CMDLGFR.DLL
6/19/2008 3:50:18 PM 17920 32 C:\Windows\System32\corpol.dll
6/21/2008 6:32:44 PM 1088272 32 C:\Windows\System32\danim.dll
6/9/2008 5:31:38 PM 570128 32 C:\Windows\System32\dao350.dll
7/8/2008 4:44:37 PM 40960 32 C:\Windows\System32\DGPNorm.ocx
6/20/2008 4:58:55 PM 487424 0 C:\Windows\System32\DLLAV32.dll
6/20/2008 4:58:55 PM 14182 32 C:\Windows\System32\DLLAV32.lib
6/20/2008 4:58:56 PM 114688 32 C:\Windows\System32\DLLCDA32.dll
6/20/2008 4:58:56 PM 61440 32 C:\Windows\System32\DLLCDF32.dll
6/20/2008 4:58:56 PM 94208 0 C:\Windows\System32\DLLCPY32.dll
6/20/2008 4:58:56 PM 163840 0 C:\Windows\System32\DLLDEV32.dll
6/20/2008 4:55:46 PM 120200 32 C:\Windows\System32\DLLDEV32i.dll
6/20/2008 4:58:56 PM 32768 32 C:\Windows\System32\DLLDIR32.dll
6/20/2008 4:58:56 PM 151552 0 C:\Windows\System32\DLLDRV32.dll
6/20/2008 4:58:56 PM 45056 32 C:\Windows\System32\DLLIMG32.dll
6/20/2008 4:58:56 PM 53248 0 C:\Windows\System32\DLLIO32.dll
6/20/2008 4:58:56 PM 32768 32 C:\Windows\System32\DLLISO32.dll
6/20/2008 4:58:56 PM 24576 32 C:\Windows\System32\DLLIX.dll
6/20/2008 4:58:56 PM 32768 32 C:\Windows\System32\DLLMSC32.dll
6/20/2008 4:58:56 PM 36864 0 C:\Windows\System32\DLLPNT32.dll
6/20/2008 4:58:56 PM 49152 32 C:\Windows\System32\DLLPRF32.dll
6/20/2008 4:58:56 PM 53248 32 C:\Windows\System32\DLLPRJ32.dll
6/20/2008 4:58:56 PM 65536 32 C:\Windows\System32\DLLPTL32.dll
6/20/2008 4:58:56 PM 40960 32 C:\Windows\System32\DLLRD32.dll
6/20/2008 4:58:56 PM 188416 0 C:\Windows\System32\DLLRES32.dll
6/20/2008 4:58:56 PM 57344 32 C:\Windows\System32\DLLTPO32.dll
7/2/2008 9:57:25 PM 126976 32 C:\Windows\System32\DVC.dll
7/2/2008 9:57:26 PM 86016 32 C:\Windows\System32\Dversion.dll
6/19/2008 3:50:06 PM 345600 32 C:\Windows\System32\dxtmsft.dll
6/21/2008 6:33:02 PM 182032 32 C:\Windows\System32\dxtmsft3.dll
6/19/2008 3:50:06 PM 212992 32 C:\Windows\System32\dxtrans.dll
6/14/2008 2:36:13 AM 428032 32 C:\Windows\System32\EncDec.dll
6/19/2008 2:25:23 PM 169984 32 C:\Windows\System32\EncDump.dll
6/30/2008 2:59:27 PM 6173 32 C:\Windows\System32\Entech.vxd
7/8/2008 4:44:37 PM 4188 32 C:\Windows\System32\faq.txt
7/8/2008 11:54:43 AM 992384 32 C:\Windows\System32\fpSpr30.ocx
6/19/2008 3:50:04 PM 385024 32 C:\Windows\System32\html.iec
6/20/2008 5:17:16 PM 85504 32 C:\Windows\System32\HtmlWH.dll
6/19/2008 3:50:22 PM 60928 32 C:\Windows\System32\icardie.dll
6/19/2008 3:50:08 PM 70656 32 C:\Windows\System32\ie4uinit.exe
6/19/2008 3:50:20 PM 119808 32 C:\Windows\System32\ieakeng.dll
6/19/2008 3:50:08 PM 224768 32 C:\Windows\System32\ieaksie.dll
6/19/2008 3:50:10 PM 149504 32 C:\Windows\System32\ieakui.dll
6/19/2008 3:50:04 PM 3670112 32 C:\Windows\System32\ieapfltr.dat
6/19/2008 3:50:22 PM 440832 32 C:\Windows\System32\ieapfltr.dll
6/19/2008 3:50:08 PM 349184 32 C:\Windows\System32\iedkcs32.dll
6/19/2008 3:50:05 PM 78336 32 C:\Windows\System32\ieencode.dll
6/19/2008 3:50:02 PM 8016384 32 C:\Windows\System32\ieframe.dll
6/19/2008 3:50:17 PM 184320 32 C:\Windows\System32\iepeers.dll
6/19/2008 3:50:21 PM 44032 32 C:\Windows\System32\iernonce.dll
6/19/2008 3:50:19 PM 268800 32 C:\Windows\System32\iertutil.dll
6/19/2008 3:50:17 PM 142848 32 C:\Windows\System32\IESetting.dll
6/19/2008 3:50:10 PM 69120 32 C:\Windows\System32\iesetup.dll
6/19/2008 3:50:21 PM 181248 32 C:\Windows\System32\ieui.dll
6/19/2008 3:50:09 PM 56413 32 C:\Windows\System32\ieuinit.inf
6/19/2008 3:50:17 PM 26624 32 C:\Windows\System32\ieUnatt.exe
6/19/2008 3:50:04 PM 168448 32 C:\Windows\System32\iexpress.exe
6/19/2008 3:50:17 PM 36352 32 C:\Windows\System32\imgutil.dll
6/19/2008 3:50:03 PM 1547264 32 C:\Windows\System32\inetcpl.cpl
7/8/2008 11:49:27 AM 15360 32 C:\Windows\System32\inetfr.DLL
6/19/2008 3:50:16 PM 94208 32 C:\Windows\System32\inseng.dll
7/2/2008 9:57:30 PM 36864 0 C:\Windows\System32\inVHDDrvExe.exe
6/16/2008 5:09:42 PM 135168 32 C:\Windows\System32\java.exe
6/16/2008 5:09:42 PM 135168 32 C:\Windows\System32\javaw.exe
6/16/2008 5:09:42 PM 139264 32 C:\Windows\System32\javaws.exe
6/19/2008 3:50:06 PM 557056 32 C:\Windows\System32\jscript.dll
6/19/2008 3:50:19 PM 28672 32 C:\Windows\System32\jsproxy.dll
6/10/2008 4:40:52 PM 6283 32 C:\Windows\System32\jupdate-1.6.0_06-b02.log
7/8/2008 11:49:24 AM 233472 32 C:\Windows\System32\lame_enc.dll
6/19/2008 3:50:17 PM 41984 32 C:\Windows\System32\licmgr10.dll
6/21/2008 6:33:06 PM 155408 32 C:\Windows\System32\LMRT.dll
6/21/2008 6:33:06 PM 38160 32 C:\Windows\System32\LMRTREND.dll
6/21/2008 6:32:45 PM 11776 32 C:\Windows\System32\mciqtz.drv
6/14/2008 2:36:09 AM 1244672 32 C:\Windows\System32\mcmde.dll
6/20/2008 4:58:57 PM 53248 32 C:\Windows\System32\mgxasio2.dll
6/20/2008 4:58:56 PM 27807 32 C:\Windows\System32\mgxcdr.txt
6/20/2008 4:53:26 PM 700416 0 C:\Windows\System32\mgxoschk.dll
6/14/2008 2:36:08 AM 68608 32 C:\Windows\System32\Mpeg2Data.ax
7/8/2008 11:49:25 AM 59904 32 C:\Windows\System32\Mscc2fr.dll
7/8/2008 11:49:25 AM 141312 32 C:\Windows\System32\MSCMCFR.DLL
6/14/2008 2:36:07 AM 57856 32 C:\Windows\System32\MSDvbNP.ax
6/19/2008 3:50:05 PM 585728 32 C:\Windows\System32\msfeeds.dll
6/19/2008 3:50:17 PM 52224 32 C:\Windows\System32\msfeedsbs.dll
6/19/2008 3:50:08 PM 52736 32 C:\Windows\System32\msfeedssync.exe
6/19/2008 3:50:04 PM 45568 32 C:\Windows\System32\mshta.exe
6/19/2008 3:50:00 PM 5120000 32 C:\Windows\System32\mshtml.dll
6/19/2008 3:50:20 PM 1555456 32 C:\Windows\System32\mshtml.tlb
6/19/2008 3:50:18 PM 68608 32 C:\Windows\System32\mshtmled.dll
6/19/2008 3:50:21 PM 48128 32 C:\Windows\System32\mshtmler.dll
7/8/2008 11:49:27 AM 115920 32 C:\Windows\System32\msinet.OCX
6/9/2008 5:31:42 PM 1050896 32 C:\Windows\System32\msjet35.dll
6/9/2008 5:31:43 PM 123664 32 C:\Windows\System32\msjint35.dll
6/9/2008 5:31:42 PM 24848 32 C:\Windows\System32\msjter35.dll
6/14/2008 2:36:08 AM 80896 32 C:\Windows\System32\MSNP.ax
6/19/2008 3:50:10 PM 193024 32 C:\Windows\System32\msrating.dll
7/2/2008 2:09:31 AM 372736 32 C:\Windows\System32\Mss32.dll
6/19/2008 3:50:05 PM 629248 32 C:\Windows\System32\mstime.dll
6/20/2008 4:58:57 PM 430080 32 C:\Windows\System32\MXRestore.exe
7/8/2008 4:44:41 PM 1703936 32 C:\Windows\System32\NCTAudioFile.dll
7/8/2008 4:44:42 PM 360448 32 C:\Windows\System32\NCTWMAFile.dll
7/8/2008 11:49:28 AM 116296 32 C:\Windows\System32\NCTWMAProfiles.prx
6/19/2008 3:50:09 PM 116224 32 C:\Windows\System32\occache.dll
6/19/2008 3:50:17 PM 20480 32 C:\Windows\System32\PDMSetup.exe
6/19/2008 3:50:20 PM 44544 32 C:\Windows\System32\pngfilt.dll
6/14/2008 2:36:10 AM 292352 32 C:\Windows\System32\psisdecd.dll
6/14/2008 2:36:11 AM 218624 32 C:\Windows\System32\psisrndr.ax
6/21/2008 6:32:43 PM 194320 32 C:\Windows\System32\qcut.dll
6/10/2008 2:24:21 PM 1327104 32 C:\Windows\System32\quartz.dll
6/21/2008 6:32:45 PM 5672 32 C:\Windows\System32\quartz.vxd
7/2/2008 9:57:31 PM 102400 0 C:\Windows\System32\RDrv2KInterface.dll
7/2/2008 9:57:30 PM 32768 0 C:\Windows\System32\RDrv9xInterface.dll
7/2/2008 9:57:30 PM 28672 0 C:\Windows\System32\RDrvInterface.dll
7/2/2008 9:57:30 PM 53248 0 C:\Windows\System32\RDrvNTInterface.dll
6/21/2008 4:38:15 PM 368640 32 C:\Windows\System32\ReWire.dll
6/21/2008 4:38:16 PM 233472 0 C:\Windows\System32\REX Shared Library.dll
6/19/2008 3:50:17 PM 13824 32 C:\Windows\System32\SetDepNx.exe
6/19/2008 3:50:17 PM 13824 32 C:\Windows\System32\SetIEInstalledDate.exe
6/20/2008 4:58:56 PM 32768 0 C:\Windows\System32\STRING32.dll
7/8/2008 11:49:26 AM 21504 32 C:\Windows\System32\TABCTFR.DLL
6/19/2008 3:50:18 PM 66560 32 C:\Windows\System32\tdc.ocx
7/8/2008 11:54:38 AM 278581 32 C:\Windows\System32\temp.000
7/8/2008 4:44:34 PM 73785 32 C:\Windows\System32\temp.001
7/8/2008 4:44:40 PM 1388544 32 C:\Windows\System32\temp.002
6/22/2008 5:56:31 PM 1408 32 C:\Windows\System32\TEST.log
6/21/2008 6:33:04 PM 140800 32 C:\Windows\System32\tm20dec.ax
6/20/2008 4:58:57 PM 24576 32 C:\Windows\System32\TTI32.dll
6/20/2008 4:58:57 PM 24576 32 C:\Windows\System32\TTIC32.dll
7/2/2008 9:57:30 PM 36864 0 C:\Windows\System32\unVHDDrvExe.exe
6/19/2008 3:50:08 PM 105984 32 C:\Windows\System32\url.dll
6/19/2008 3:50:03 PM 1188352 32 C:\Windows\System32\urlmon.dll
7/8/2008 11:49:27 AM 119568 32 C:\Windows\System32\VB6FR.DLL
6/21/2008 6:32:45 PM 10240 32 C:\Windows\System32\vidx16.dll
6/20/2008 11:40:04 PM 1294336 32 C:\Windows\System32\vorbis.acm
6/21/2008 6:32:35 PM 2272 32 C:\Windows\System32\w95inf16.dll
6/21/2008 6:32:35 PM 4608 32 C:\Windows\System32\w95inf32.dll
6/19/2008 3:50:09 PM 233984 32 C:\Windows\System32\webcheck.dll
6/19/2008 3:50:09 PM 66560 32 C:\Windows\System32\wextract.exe
6/19/2008 3:50:09 PM 208384 32 C:\Windows\System32\WinFXDocObj.exe
6/19/2008 3:50:04 PM 830464 32 C:\Windows\System32\wininet.dll
6/10/2008 2:24:23 PM 14848 32 C:\Windows\System32\wshrm.dll
7/8/2008 11:54:42 AM 1953792 32 C:\Windows\System32\~GLH0009.TMP
========= Temp Files Deleted ========
11 Files deleted
Greenfire999
13 Posts
0
July 9th, 2008 03:00
Greenfire999
13 Posts
0
July 9th, 2008 05:00
bamajim
10.4K Posts
0
July 9th, 2008 12:00
1. Rerun Killbox
2)Select " Delete on Reboot", and then select "All files".
3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:
C:\Windows\System32\~GLH0009.TMP
C:\Windows\System32\temp.000
4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
5) Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt.
2. You have a suspicious file I would Like to have a look at
Please go HERE
Put Your Name, and Dell HJT forum
and In the file to submit box, click Browse.
In the comments tell them that I asked you to upload the file
Then Select Send File.
"The world is what you make of it"