Unsolved

This post is more than 5 years old

23 Posts

1926

February 1st, 2007 10:00

Cannot run Adware!!!

I've been attempting to run my Lavasoft Adware to clean up my system, and everytime I try, I receive a pop-up very briefly, then my screen goes blue with some message in white...at the end of the message, it says "Your system has been shut down" So, I can't even run adware. I hope you can help me with the information on my log. Thank you...
 
Logfile of HijackThis v1.99.1
Scan saved at 3:44:48 AM, on 2/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe
C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\FREECELL.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\WINDOWS\system32\tmp9E.tmp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7a480f9a-4094-44c0-9d07-642ff03c8239} - C:\WINDOWS\system32\CIADACM.dll
O2 - BHO: (no name) - {CA943B69-FBA9-FF7A-FE36-FAEA1BBF7AC2} - C:\WINDOWS\system32\ntpz.dll
O2 - BHO: (no name) - {CB943B19-FBDC-FC7C-FE4A-8DEA1CBA7AC7} - C:\WINDOWS\system32\ntpz.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRA~1\QUICKT~1\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [SDR6_Check] "C:\Program Files\Common Files\DriveCleaner 2006 Free\udcsdr.exe"
O4 - HKLM\..\Run: [PAS_Check] "C:\Program Files\Common Files\DriveCleaner 2006 Free\udcpas.exe"
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\yaawwx.dll",setvm
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/download/scanner/en-us/wlscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163310797015
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O20 - Winlogon Notify: abqmshuh - C:\WINDOWS\SYSTEM32\abqmshuh.dll
O20 - Winlogon Notify: CIADACM - C:\WINDOWS\SYSTEM32\CIADACM.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
 

23 Posts

March 10th, 2007 01:00

Also, I was unable to download WinPFind...This is what the page gave me when I clicked on the link:
 

  Blogs    Chat    Help    RSS    
Welcome Guest (Log In | Create Account) New Member? Join for free.

  BleepingComputer.com
Welcome Guest
You have to log in before you can post to this site

Username

Password

Remember Me?

Search
Search:

Search at:
Message BoardsGoogleYahooBarnes & NobleAmazonEbayShopping.com
Advanced Search



Page Not Found / Error!
404 ERROR: Page Not Found!

The requested page http://www.bleepingcomputer.com/files/oldtimer/WinPFind.zip could not be found on this server.

23 Posts

March 10th, 2007 01:00

Here's my log from the L2MFix I ran...
 
L2mfix 032106
Creating Account.
The command completed successfully.
Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
 Granting SeDebugPrivilege to L2MFIX   ... successful
 
Running From:
C:\WINDOWS\system32
 
Killing Processes!
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 528 'smss.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 776 'winlogon.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 200 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Error, Cannot find a process with an image name of rundll32.exe
Restoring Sedebugprivilege:
 Granting SeDebugPrivilege to Administrators   ... successful
 
Scanning First Pass. Please Wait!
 
First Pass Completed
 
Second Pass Scanning
 
Second pass Completed!
 
 
 
Restoring Windows Update Certificates.:
 
The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\abqmshuh]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"Logon"="StartProcessAtWinLogon"
"Logoff"="StopProcessAtWinLogoff"
"DLLName"="abqmshuh.dll"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
  6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
@=""
"DLLName"="igfxdev.dll"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001
"Unlock"="WinlogonUnlockEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000000
"SafeMode"=dword:00000001
"MaxWait"=dword:ffffffff
"DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\
  6c,00,6c,00,00,00
"InstallNotifyShown"=dword:00000001
"Event"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings]
"Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\
  00,00,3f,26,f1,a1,b2,3d,9d,42,90,68,9d,25,15,b5,62,06,04,00,00,00,04,00,00,\
  00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,65,c2,59,8a,a0,9f,61,57,\
  f7,4d,90,3f,fe,ee,7f,67,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,98,\
  0b,58,bd,f3,89,46,f0,6a,76,b7,b0,82,a9,ed,89,08,06,00,00,28,42,d1,71,10,5e,\
  65,73,48,a1,94,a5,d0,48,44,f0,1b,dd,10,f8,3b,53,2a,70,85,f0,13,83,36,36,c4,\
  e4,e3,42,3a,e2,34,52,98,ac,ea,e4,1a,0e,26,67,78,1c,e1,bc,62,75,df,23,eb,35,\
  af,e5,11,0e,39,16,a5,35,04,d0,17,cd,a4,3e,de,40,48,85,4d,1d,cf,54,69,c3,02,\
  f1,6b,32,2b,81,68,b4,2d,39,13,5e,52,41,ad,75,d6,a5,51,25,8c,d6,b5,ae,17,bf,\
  56,88,1e,fb,60,4b,0d,1e,87,2d,83,55,85,ed,08,fb,f9,53,25,2b,05,de,44,8a,2c,\
  57,3f,39,1d,45,d4,9b,12,41,b2,cd,61,92,e4,5c,5e,9a,02,54,a9,7b,75,3b,99,7d,\
  19,e9,86,80,4e,c0,4e,f2,7e,b9,f0,67,20,35,00,44,a2,e6,a7,9b,6a,aa,f0,09,4e,\
  f4,fe,d5,7e,66,10,12,67,20,9e,fd,ba,a3,0a,68,b4,02,c4,83,bf,9a,fe,c6,c1,69,\
  88,8e,86,3c,9d,ba,c2,b5,3e,68,12,0a,7e,81,db,0c,c3,f6,55,9b,35,32,cc,4c,36,\
  fe,06,dc,07,e3,b7,ed,a9,a3,36,5d,42,00,f6,b8,70,85,a5,a9,bb,33,71,31,4b,3e,\
  c6,7c,db,91,5b,73,37,f1,2e,3e,63,db,40,e8,af,61,dd,76,2a,f6,37,30,84,23,79,\
  e6,69,9e,07,d7,eb,76,e7,13,96,72,65,58,dd,67,78,bd,60,d6,70,36,10,89,37,e1,\
  95,6f,5d,68,08,c1,92,0a,4c,5c,17,58,c4,5d,c5,6e,d7,5e,9e,72,ca,8d,00,d9,ae,\
  26,10,fe,ea,d2,1d,01,ff,53,b2,dd,bd,9d,f7,17,8a,d4,ba,7e,9d,d1,71,c4,55,92,\
  4c,3b,de,82,de,8d,a8,fe,23,cf,40,cc,34,66,73,a9,7f,46,3f,ed,fc,6a,45,e9,99,\
  1f,bb,22,d2,68,64,b3,94,e8,0e,ba,06,dc,43,6a,83,cf,11,f7,75,72,b0,ff,f8,9f,\
  4a,5b,5d,94,ec,9d,79,45,ac,8c,cb,5d,9a,3f,61,ba,e9,3b,05,40,e2,24,eb,f0,13,\
  b5,8c,33,ba,b1,f5,3f,b9,11,04,cd,db,fe,f1,61,3b,2a,9a,94,52,43,5c,39,8d,5d,\
  17,05,c8,a6,2c,39,9b,ec,9a,ce,bb,d6,2a,07,8b,fe,de,41,34,5e,7c,28,44,01,64,\
  d9,1d,8f,93,ed,50,f0,b6,9a,0c,1b,20,87,28,79,f6,8d,0e,5e,3f,3d,2e,f9,ff,09,\
  d6,8f,bd,ee,ba,e7,f2,96,b8,92,95,c6,01,48,59,ee,7e,f4,fa,d2,a5,71,26,41,c0,\
  c9,c8,05,dc,cb,41,c9,19,a0,51,0b,d5,a6,3f,6b,55,a0,a1,35,d0,e3,99,85,38,c9,\
  eb,04,e2,c7,c9,8b,18,ba,98,3c,4b,58,ef,2c,ac,82,61,93,26,a8,1a,1d,1d,b3,32,\
  4f,28,2f,34,84,b6,75,84,e6,48,bb,8a,c9,1b,ef,bf,cc,cf,fe,ed,9d,3b,0b,e3,75,\
  68,38,df,fa,b9,be,6f,23,49,53,50,99,cf,c9,2d,ef,2a,e6,1e,a1,11,ec,5d,ed,bf,\
  b6,56,ea,4c,07,6b,1c,5a,c3,97,7f,cd,71,cb,87,b3,f6,61,2e,88,59,30,f4,f1,fd,\
  54,b9,ba,11,47,e9,a8,90,bd,37,81,76,c4,1b,f5,8b,62,dd,85,9d,ab,08,04,a4,c7,\
  64,9c,29,60,2a,a6,9d,24,5e,33,fb,bc,db,4c,26,e7,04,9a,ff,00,02,39,05,77,76,\
  86,fb,62,44,86,70,59,2c,47,3e,0e,36,60,39,3f,cd,8f,3b,18,e5,3c,05,88,96,42,\
  9a,e4,49,74,d4,ac,1a,90,d9,19,12,9f,5d,6f,e4,ae,1e,4b,d8,da,25,e6,1a,36,b0,\
  e9,8e,40,4c,e0,a0,57,50,35,78,aa,9a,de,ba,d8,2b,14,44,e7,e4,19,aa,e5,d8,c3,\
  a2,ee,2f,c5,d4,5f,44,62,71,0c,05,74,72,d0,ea,75,20,e0,81,58,24,46,da,f8,79,\
  33,27,8f,f0,95,d0,01,2d,4d,9e,5a,e4,e6,53,0f,9c,5e,4d,52,b3,44,9a,7e,44,24,\
  a8,7e,7d,6f,10,a5,c8,83,f8,8b,13,12,00,8c,61,dc,f7,fb,e5,07,39,bc,fa,95,48,\
  17,66,fb,aa,71,70,45,65,c1,9e,bb,fb,c3,2a,bf,59,bd,4c,c2,9b,36,6b,2e,e9,2f,\
  be,04,52,f1,b3,e0,82,f9,af,e1,dc,f2,9a,8e,d8,0b,a4,d8,db,41,0d,07,01,3d,0f,\
  df,04,63,52,01,38,40,33,8d,10,8d,9c,2f,d9,9e,f5,21,0f,48,72,f0,94,4d,f5,1d,\
  b4,de,38,0c,a1,a1,93,8e,14,f1,dd,87,bf,fe,74,7e,f6,d9,f3,1e,f6,28,53,e2,5e,\
  a8,1a,cb,fd,25,27,b8,87,54,e6,8e,32,c7,54,23,6e,bc,f1,84,bb,68,fe,f7,bf,af,\
  34,69,9b,02,e1,3a,ac,41,29,e7,e3,d2,6f,e2,9f,f4,14,00,0f,05,56,ac,8e,81,13,\
  f1,b2,45,74,fa,31,ce,42,b3,65,3c,1c,82,12,d1,f3,db,41,7f,69,44,a5,0c,69,fa,\
  97,65,e5,0e,fa,e8,9f,2f,d1,47,82,a3,81,b4,6a,c2,fa,cf,12,83,c4,c0,fb,7f,c0,\
  b8,cb,b9,3c,d8,96,95,d3,f2,b5,26,22,0e,8b,d7,d5,79,27,9d,6a,80,46,4b,e7,82,\
  98,12,80,9a,55,20,57,37,2d,3b,38,f4,b8,c8,f9,59,7a,f4,9d,d6,3d,e4,50,39,0d,\
  36,76,ab,48,8d,99,05,91,c3,80,b7,29,a3,c2,1c,7b,1d,2b,7c,4f,f9,1d,d0,1b,d2,\
  50,a8,80,15,13,61,ed,f0,c3,0b,14,7f,f2,9c,76,6c,60,4b,8b,20,0e,3a,35,69,7a,\
  02,54,cf,64,74,d2,8d,57,9e,2f,10,12,91,2d,9d,54,ba,f9,c1,cb,5d,89,0c,96,ab,\
  e6,b8,f6,b6,f0,da,be,9b,a7,f1,84,aa,a9,44,25,50,b5,04,73,55,e5,27,eb,7e,6d,\
  47,5b,a6,13,bc,c6,b5,ba,85,30,67,a4,7b,c9,06,2d,48,9f,55,a1,54,1c,78,a1,37,\
  9d,31,72,99,94,d0,e5,b9,8e,fe,e1,ca,d5,72,81,3f,4f,8e,31,fb,30,53,12,ed,79,\
  2f,22,fb,64,11,d9,6b,a6,af,b9,83,7b,c6,1f,c4,1d,44,e4,50,4c,f4,d2,82,90,51,\
  31,bc,e7,c3,3f,14,f7,46,ef,07,27,c5,99,71,60,87,61,50,b2,63,db,48,1d,5a,fc,\
  7e,10,65,0b,6f,ac,01,5f,ad,b3,da,d9,90,94,17,6a,51,bc,64,2f,c2,1a,27,25,ff,\
  c1,a1,d9,b8,ba,a8,4e,82,13,7e,4a,57,30,89,9f,71,46,ae,41,e0,12,7d,ff,71,03,\
  f5,b4,cf,60,52,7a,ee,b7,c1,48,86,d6,fc,7c,dc,03,1a,a9,2c,91,a5,03,85,77,79,\
  c5,65,e3,c5,09,87,73,b0,4c,2a,23,22,e4,24,b4,bc,33,f4,c5,e7,40,25,dd,83,fa,\
  2c,83,bd,f0,e4,00,41,a8,80,70,de,83,db,d6,be,04,45,f2,ec,9b,39,ab,62,e1,24,\
  98,ad,9b,97,1b,fc,5e,01,79,3b,4d,cb,84,22,77,32,63,e9,37,cb,16,de,b4,22,17,\
  43,ce,1d,53,6c,db,cf,c9,73,96,c7,5f,81,bd,c4,77,1c,e9,e4,e8,fc,e8,4d,18,14,\
  34,00,0c,c2,cc,11,3e,a8,e9,31,5c,b0,f9,e6,9d,5b,4c,eb,41,db,4a,ca,5c,23,56,\
  00,58,63,22,af,c8,9b,bf,01,d3,3a,07,69,c9,43,6e,11,d6,62,f1,9d,7d,b7,09,ae,\
  d4,4b,44,3b,d7,1f,23,3d,6e,ec,f4,7c,6a,14,00,00,00,43,b6,36,06,7b,df,a6,b3,\
  af,df,f2,a6,5e,fc,66,00,a5,e3,a0,56
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
 
The following are the files found:
****************************************************************************
 
Registry Entries that were Deleted:
Please verify that the listing looks ok. 
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
****************************************************************************
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
 zip warning: name not matched: dlls\*.*
zip error: Nothing to do! (backup.zip)
  adding: backregs/notibac.reg (164 bytes security) (deflated 79%)
  adding: backregs/shell.reg (164 bytes security) (deflated 73%)

23 Posts

March 10th, 2007 01:00

Hello Ron,
I know it's been a while since I've responded. I apologize for the long delay in time. I have not been well and was also out of town. Hopefully, we can pick up where we left off. Thank you again for your time. -K
 
Here is the last junk.text notepad file you requested...
 
Volume in drive C has no label.
 Volume Serial Number is 8419-F8F7
 Directory of C:\WINDOWS\SYSTEM32\DLLCACHE
03/24/2003  04:52 PM            20,540 admin.dll
03/24/2003  04:52 PM            16,439 admin.exe
02/14/2006  04:22 PM           142,464 aec.sys
10/12/2006  06:02 AM            42,496 agentdp2.dll
10/12/2006  06:02 AM            57,344 agentdpv.dll
10/12/2006  03:09 AM           256,512 agentsvr.exe
08/04/2004  03:00 AM            19,456 agt0404.dll
08/04/2004  03:00 AM            19,456 agt0411.dll
08/04/2004  03:00 AM            19,456 agt0412.dll
08/04/2004  03:00 AM            19,456 agt0804.dll
10/04/2006  06:06 AM           217,118 apphelp.sdb
10/04/2006  06:06 AM           764,868 apph_sp.sdb
10/18/2006  09:47 PM             7,168 asferror.dll
08/03/2004  08:59 PM            95,360 atapi.sys
03/24/2003  04:52 PM            20,540 author.dll
03/24/2003  04:52 PM            16,439 author.exe
 Directory of C:\WINDOWS\SYSTEM32\DLLCACHE
              16 File(s)      1,735,112 bytes
               0 Dir(s)  61,249,294,336 bytes free

2 Intern

 • 

5.9K Posts

March 12th, 2007 13:00

Sorry about that.
 
It seems there is a new version.
 
 
The log is very large so email it to me directly as an attachment.
 
rkinner
AT
gmail
DOT
com
AT=@
DOT=.
Subject: PhamsEvie
 
Ron
 
 

2 Intern

 • 

5.9K Posts

March 12th, 2007 17:00

Let's try avenger again.  I think I found the problem.
 
*************************************
 
Files to delete:
c:\windows\system32\mtuninst.exe
c:\windows\system32\msclock32.dll
c:\windows\system32\oins.exe 
c:\windows\system32\abqmshuh.dll
%UserDocuments%\tropicalus.jpg
Registry values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify | abqmshuh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet | Control_RunDLL
 
*****************************************  
 
Post the avenger log and a new HJT log and then make a new winpfind3u and send me the log.
 
Ron

23 Posts

March 13th, 2007 23:00

Hi Ron...
 
Avenger:
 
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\sfpwqfpo
*******************
Script file located at: \??\C:\WINDOWS\cdbicqxj.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
 
File c:\windows\system32\mtuninst.exe not found!
Deletion of file c:\windows\system32\mtuninst.exe failed!
Could not process line:
c:\windows\system32\mtuninst.exe
Status: 0xc0000034
File c:\windows\system32\msclock32.dll deleted successfully.
File c:\windows\system32\oins.exe deleted successfully.
File c:\windows\system32\abqmshuh.dll deleted successfully.

Could not open file %UserDocuments%\tropicalus.jpg for deletion
Deletion of file %UserDocuments%\tropicalus.jpg failed!
Could not process line:
%UserDocuments%\tropicalus.jpg
Status: 0xc000003a
 
Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify|abqmshuh
Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify|abqmshuh failed!
Status: 0xc0000034
 
Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet|Control_RunDLL
Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet|Control_RunDLL failed!
Status: 0xc000000d

Completed script processing.
*******************
Finished!  Terminate.
 
______________________________________
HJT:
 
Logfile of HijackThis v1.99.1
Scan saved at 4:57:20 PM, on 3/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Kara Evengeline Earl\Desktop\Phams.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/download/scanner/en-us/wlscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163310797015
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O20 - Winlogon Notify: abqmshuh - C:\WINDOWS\SYSTEM32\abqmshuh.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
 
 

2 Intern

 • 

5.9K Posts

March 14th, 2007 11:00

Getting rid of the msclock.dll cloaking file revealed a hidden service:  tu^pbcab.sys.
Let's try avenger again. 
 
*************************************
 
drivers to unload:
tu^pbcab.sys
Files to delete:
C:\windows\system32\drivers\tu^pbcab.sys
c:\windows\mtuninst.exe
c:\windows\system32\abqmshuh.dll
Registry values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify | abqmshuh
 
***************************************** 
 
I think this time avenger should reboot your system twice.  Post the avenger log and a new HJT log and then make a new winpfind3u and send me the log.
 
Ron

23 Posts

March 14th, 2007 21:00

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\afktbstu
*******************
Script file located at: \??\C:\Program Files\cpofehwr.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
 
Registry key \Registry\Machine\System\CurrentControlSet\Services\tu^pbcab.sys not found!
Unload of driver tu^pbcab.sys failed!
Could not process line:
tu^pbcab.sys
Status: 0xc0000034
File C:\windows\system32\drivers\tu^pbcab.sys deleted successfully.
File c:\windows\mtuninst.exe deleted successfully.
File c:\windows\system32\abqmshuh.dll deleted successfully.

Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify|abqmshuh
Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify|abqmshuh failed!
Status: 0xc0000034

Completed script processing.
*******************
Finished!  Terminate.
 
____________________________________________
 
Logfile of HijackThis v1.99.1
Scan saved at 3:36:35 PM, on 3/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/download/scanner/en-us/wlscbase3401.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163310797015
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O20 - Winlogon Notify: abqmshuh - C:\WINDOWS\SYSTEM32\abqmshuh.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe

2 Intern

 • 

5.9K Posts

March 15th, 2007 11:00

Did you upload the file to the two sites like I asked you to do back on page 2?  I'm going to ask them for help if this next idea doesn't work but they won't be able to help if they don't have a sample of abqmshuh.dll.
 
 
Boot into Safe Mode (restart and when you see the maker's logo appear start tapping F8 slowly until you get the safe mode menu) and select Command Prompt.  Then type:
 
cd \windows\system32\drivers
 
attrib -a -r -h -s tu^pbcab.sys
 
del /a tu^pbcab.sys
 
mkdir tu^pbcab.sys
 
cd \windows\system32
 
attrib -a -r -h -s abqmshuh.dll
 
del /a abqmshuh.dll
 
mkdir abqmshuh.dll
 
Then Ctrl + Alt +Del and select shutdown and restart.

1. Go to http://www.ewido.net/en/download/ and Download AVG Anti-Spyware
(30 day free trial version) Save it to Your Desktop
 
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menu

Under "Your computers Security"
Click change status on Resident shield to inactive
Click Update now (next to last update)
After the update loads
Under Automatic updates Uncheck download and install updates automatically(recommended)
(you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tab
Under How to act? Set default action for detected malwareTo Quarantine
Under how to scan All boxes should be checked
Under Possibly unwanted software All boxes should be checked
Under reports Select Automatically generate report after every scan
Uncheck Only if threats were found
Under what to scan Scan every file should be highlighted
Exit AVG(But do not run it yet)
 
2. Reboot into Safe Mode
This can be done by
Restart your PC, and after it starts, but before you see the Windows Splash screen
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter.
 
3. Run AVG Anti-Spyware
Click scanner
Select Complete system scan
Once the scan finishes
Select Apply all actions (The items found will be quarantined)
Click save report as (Another window will open)
Save it to your desktop
(By default It will be saved in the AVG folder as)
C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
Exit AVG
 
4. Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
Double click the report-scan txt. you saved to your desktop
It will open in Notepad
Copy and paste that report as a reply to this thread
Your reply should include
a fresh hijackthis log
your report_scan.txt from AVG
You may have to post the results in more than one reply or just send them to me directly.
 
Ron
 
 
 
 

23 Posts

April 9th, 2007 21:00

Hi Ron,
 
Yes I did upload the file to those two sites from page 2. I also "
Boot into Safe Mode (restart and when you see the maker's logo appear start tapping F8 slowly until you get the safe mode menu) and select Command Prompt.  Then type:
 
cd \windows\system32\drivers"
However, after I typed "attrib -a -r -h -s tu^pbcab.sys" It gave me a "File not found - tupbcab.sys" message
 
 
That is where I've stopped so far. Also, I was wondering...with this virus on my computer, do you think it would be safe to do my taxes from this computer? I have TAXCUT cd/program that I would like to use to do them, but I don't want to mess up anything we're doing.
 
Kara

2 Intern

 • 

5.9K Posts

April 10th, 2007 11:00

Doing your taxes on the PC won't hurt what we are doing but there is some danger of the malware reporting back to its master.  I'd leave out your social security number, do your taxes and print them out then add the SSN by hand.  (If the program insists on a SSN then put in a dummy then white it out and put in the correct one after you print.)
 
Since you have reported the file to Dave you might download the newest version of VundoFix and see if it can now get rid of the file.  When you last ran it it was 6.3.5 and it's now up to 6.3.19.
 
The fact that attrib can't find a file is actually good.  That means the file is gone so we should have no problem replacing it with a directory of the same name.  Go ahead and finish the instructions.  If the del can't find the file that's OK.  The main concern is if the mkdir command fails.  That means that even tho we tried to delete the file the file is still there.
 
Also let's run winpfind3u
 
 
Post the log in your next reply.
 
Ron
 
 
 
 
 
 
 
 
 
No Events found!

Top