Unsolved

This post is more than 5 years old

1708

June 18th, 2008 01:00

Trojan.Vundo Won't Go Away, Need Help!

I have what Norton called "Trojan.Vundo" I came here and found an old post from 2005 regarding the removal of this virus. The ID number for that post is id=20099 I followed the post and downloaded "virtmundobegone" which ran successfully and "FixVundo" which did not work, i got an error regarding the C ++ Library. I don't know what that means (obviously, or I wouldn't be here). Now, to make matters worse i can't post my Hijack-This Log because I'm limited by the number of characters allowed in the post. Please advise, thanks!

June 18th, 2008 01:00

Here is my Log:

 

 

 Logfile of HijackThis v1.99.1

Scan saved at 7:16:45 PM, on 6/17/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe

C:\WINDOWS\system32\HPConfig.exe

C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe

C:\WINDOWS\system32\PnkBstrA.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Viewpoint\Common\ViewpointService.exe

C:\WINDOWS\System32\wltrysvc.exe

C:\WINDOWS\System32\MsPMSPSv.exe

C:\WINDOWS\System32\bcmwltry.exe

C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Common Files\Symantec Shared\SecurityHistory\mcui32.exe

C:\WINDOWS\System32\msiexec.exe

C:\HJT\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8l.hpwis.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll

O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

O4 - HKLM\..\Run: [BM5844a3e0] Rundll32.exe "C:\WINDOWS\system32\txesogqu.dll",s

O4 - HKLM\..\Run: [5b77907c] rundll32.exe "C:\WINDOWS\system32\nybrsmgs.dll",b

O4 - Global Startup: Norton AntiVirus.lnk = C:\Program Files\Common Files\Symantec Shared\NMain.exe

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O11 - Options group: [INTERNATIONAL] International*

O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com

O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbcyahoo/TrueInstallSBC.exe

O20 - AppInit_DLLs:  

O21 - SSODL: ecgfb - {39d23dba-a362-4803-b26c-5f2cb46e669b} - C:\WINDOWS\System32\kfhrvq.dll (file missing)

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe

O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe

O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE

O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

 

4 Apprentice

 • 

20.5K Posts

June 18th, 2008 02:00


Welcome. Thank you for using Dell Community Forums.

Unfortunately, the tool that you ran is obsolete, so it is understandable that it did not help.

I am reviewing your log.
In the meantime, you can help me by doing the following:

* Have you have posted this issue on another forum? If so, please provide a link to the topic.

* If you are using any cracked software, please remove it.
Definition of cracked software:
http://en.wikipedia.org/wiki/Software_cracking

* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. If you have music files in those programs' folders that you want to save, please move those music files to another directory.
A list of P2P's is here: http://www.castlecops.com/t204179-P2P_programs_we_ask_that_you_remove_first.html


* If this computer belongs to someone else, do you have authority to apply the fixes we will use?

* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.

* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.

* During the course of our cleanup please do not do any online work or surfing until we have verified that your system is clean.

* We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.

* Your version of HijackThis is outdated. Please remove v. 1.99.1 HijackThis using Add/Remove Programs or use the uninstaller in the program.

Please download HJT Installer for version 2.02 from Here to your desktop.
If not available use this alternate link: Here
  • Click the Download button. When the Trend Micro HJT install box appears, double click on the HJTInstall.exe. Click on Install.
  • It will be installed by default here: C:\Program Files\Trend Micro\HijackThis.
  • A shortcut to the application will also be placed on your Desktop.
  • The program will open automatically after installation.
  • You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder. The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.
  • The first time you open HijackThis, check the Main Menu button at the bottom center. When the main menu appears check the box "Show this window when I start HijackThis".
  • Click on "Do a system scan and save logfile."
    When the log pops up in Notepad, copy and paste that file back here.
  • DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
  • Before closing HJT, please click on the AnalyzeThis button. "Analyze This" DOES NOT mean "Analyze My Log". You will need to post your log on the forum.
  • Close the web page that appears and then close the program


  • * If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.

    Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a HijackThis log at the top of this board to start a new forum topic.

4 Apprentice

 • 

20.5K Posts

June 19th, 2008 02:00

Thank you for updating that version.

Please download Malwarebytes' Anti-Malware from Here or Here
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
    • If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
    • On the Scanner tab:
      • Make sure the "Perform Quick Scan" option is selected.
      • Then click on the Scan button.
      • The next screen will ask you to select the drives to scan. Leave all the drives selected and click on the Start Scan button.
      • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
      • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
      • Click OK to close the message box and continue with the removal process.
      • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
      • Make sure that everything is checked, and click Remove Selected.
      • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. :(see Note below)
      • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
      • Copy and paste the contents of that report in your next reply and exit MBAM.
      • Please include a fresh HijackThis log as well.
        Notes:

        **If you encounter this message:"c:\program files\malwarebytes' Anti-Malware\mbamext.dll Unable to register the dll/ocx: RegSvr32 failed with exit code 0x5" Click on ignore mbamext.dll

        **If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

      June 19th, 2008 02:00

      thank you for your help and guidance, here is my Hijackthis log:

       

       

      Logfile of Trend Micro HijackThis v2.0.2

      Scan saved at 8:00:17 PM, on 6/18/2008

      Platform: Windows XP SP2 (WinNT 5.01.2600)

      MSIE: Internet Explorer v7.00 (7.00.6000.16640)

      Boot mode: Normal

       

      Running processes:

      C:\WINDOWS\System32\smss.exe

      C:\WINDOWS\system32\winlogon.exe

      C:\WINDOWS\system32\services.exe

      C:\WINDOWS\system32\lsass.exe

      C:\WINDOWS\system32\svchost.exe

      C:\WINDOWS\System32\svchost.exe

      C:\WINDOWS\Explorer.EXE

      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

      C:\WINDOWS\system32\spoolsv.exe

      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe

      C:\WINDOWS\system32\HPConfig.exe

      C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe

      C:\WINDOWS\system32\PnkBstrA.exe

      C:\WINDOWS\System32\svchost.exe

      C:\Program Files\Viewpoint\Common\ViewpointService.exe

      C:\WINDOWS\System32\wltrysvc.exe

      C:\WINDOWS\System32\MsPMSPSv.exe

      C:\WINDOWS\System32\bcmwltry.exe

      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

      C:\WINDOWS\System32\svchost.exe

      C:\WINDOWS\system32\rundll32.exe

      C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\knlwrap.exe

      C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\iKernel.exe

      C:\Program Files\Safari\Safari.exe

      C:\WINDOWS\system32\rundll32.exe

      C:\WINDOWS\system32\rundll32.exe

      C:\WINDOWS\System32\msiexec.exe

      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

       

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl

      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8l.hpwis.com/

      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll

      O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll

      O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"

      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

      O4 - HKLM\..\Run: [BM5844a3e0] Rundll32.exe "C:\WINDOWS\system32\ivcvnhev.dll",s

      O4 - HKLM\..\Run: [5b77907c] rundll32.exe "C:\WINDOWS\system32\nyawpojb.dll",b

      O4 - HKLM\..\Policies\Explorer\Run: [ishost.exe] ishost.exe

      O4 - HKLM\..\Policies\Explorer\Run: [kernel32.dll] C:\WINDOWS\System32\isnotify.exe

      O4 - Global Startup: Norton AntiVirus.lnk = C:\Program Files\Common Files\Symantec Shared\NMain.exe

      O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

      O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

      O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

      O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

      O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

      O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

      O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

      O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

      O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll

      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

      O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com

      O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab

      O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

      O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab

      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab

      O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

      O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbcyahoo/TrueInstallSBC.exe

      O20 - AppInit_DLLs:  

      O21 - SSODL: ecgfb - {39d23dba-a362-4803-b26c-5f2cb46e669b} - C:\WINDOWS\System32\kfhrvq.dll (file missing)

      O22 - SharedTaskScheduler: {39d23dba-a362-4803-b26c-5f2cb46e669b} - ecgfb - (no file)

      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe

      O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe

      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe

      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

      O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe

      O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe

      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE

      O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe

      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

      O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

      O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

       

      --

      End of file - 9366 bytes

       

      Please note: after i hit "analyze this" i got an error. the signature for the error is:

      AppName: hijackthis.exe AppVer: 2.0.0.2 ModName: jkkhbsjy.dll

      ModVer: 0.0.0.0 Offset: 00063433 

       

      Thank You! 

      June 19th, 2008 04:00

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:00:13 PM, on 6/18/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\WINDOWS\system32\HPConfig.exe
      C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\WINDOWS\System32\wltrysvc.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\WINDOWS\System32\bcmwltry.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Safari\Safari.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8l.hpwis.com/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: {f9273216-48c5-e5ba-1b94-d403e5eddba2} - {2abdde5e-304d-49b1-ab5e-5c846123729f} - C:\WINDOWS\system32\ctoitukl.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {8AB1A2CE-5535-4C44-AFF3-D75123938F19} - C:\WINDOWS\system32\efcAQKCR.dll (file missing)
      O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
      O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
      O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
      O4 - HKLM\..\Policies\Explorer\Run: [ishost.exe] ishost.exe
      O4 - HKLM\..\Policies\Explorer\Run: [kernel32.dll] C:\WINDOWS\System32\isnotify.exe
      O4 - Global Startup: Norton AntiVirus.lnk = C:\Program Files\Common Files\Symantec Shared\NMain.exe
      O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
      O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
      O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
      O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbcyahoo/TrueInstallSBC.exe
      O20 - AppInit_DLLs:  
      O21 - SSODL: ecgfb - {39d23dba-a362-4803-b26c-5f2cb46e669b} - C:\WINDOWS\System32\kfhrvq.dll (file missing)
      O22 - SharedTaskScheduler: {39d23dba-a362-4803-b26c-5f2cb46e669b} - ecgfb - (no file)
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
      O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
      O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
      O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

      --
      End of file - 9747 bytes

      June 19th, 2008 04:00

      Malwarebytes' Anti-Malware 1.17
      Database version: 869

      9:51:58 PM 6/18/2008
      mbam-log-6-18-2008 (21-51-58).txt

      Scan type: Quick Scan
      Objects scanned: 43588
      Time elapsed: 29 minute(s), 30 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 3
      Registry Keys Infected: 31
      Registry Values Infected: 3
      Registry Data Items Infected: 3
      Folders Infected: 1
      Files Infected: 26

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      C:\WINDOWS\system32\jkkHBSJy.dll (Trojan.Vundo) -> Unloaded module successfully.
      C:\WINDOWS\system32\nyawpojb.dll (Trojan.Vundo) -> Unloaded module successfully.
      C:\WINDOWS\system32\nybrsmgs.dll (Trojan.Vundo) -> Unloaded module successfully.

      Registry Keys Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22e0eaaa-8382-403f-bc82-d2292a2f6c5c} (Trojan.Vundo) -> Delete on reboot.
      HKEY_CLASSES_ROOT\CLSID\{22e0eaaa-8382-403f-bc82-d2292a2f6c5c} (Trojan.Vundo) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{02910a3c-5d77-4a3e-8a13-fdf81ac7fecd} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{0485b9a3-61d4-40a9-82ee-5b8b6bd51a58} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{29143580-a3e7-4afb-a8ef-b88f3b56c5a3} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{3eb2d5e5-ab7c-46db-950e-878cf812aa1c} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{5caeb087-af31-494d-842d-39cf1c7adade} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{5df8c005-6e2e-4bd6-a765-304a8e550ece} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{60659361-1c5f-4fa7-aeb0-f39df2547122} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{6a97a178-3e84-45af-8f28-982c22e9a49d} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{7d9351b3-4ebe-4f8f-981e-9af90ba99f54} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{7e22e1d0-5af8-4fb8-a635-bd31b3308c71} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{821a05ed-bb06-4444-a1e0-f0ab21ff626d} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{886bacae-e094-4bde-912e-99c3a3ddd122} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{8f290589-db12-447f-8f38-d24653ce9f13} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{bad16ee0-5134-4dc2-bd33-46a557c93d36} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{ec6671fe-7062-4f26-8383-4b887c4cb50b} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{fc8db863-22bc-4382-ac7a-96fabfd95bb8} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{8e9d2f33-4585-4404-aa57-15b2b03707f4} (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DFC (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DInf (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{4737d489-1fba-4fd6-88e5-01646b74d97e} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\5b77907c (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{487c9905-26a8-42c8-8033-c58ad3d2aec3} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM5844a3e0 (Trojan.Agent) -> Delete on reboot.

      Registry Data Items Infected:
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\jkkhbsjy -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\jkkhbsjy  -> Delete on reboot.
      HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

      Folders Infected:
      C:\Documents and Settings\Lana\Start Menu\Programs\VirusProtectPro (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.

      Files Infected:
      C:\WINDOWS\system32\jkkHBSJy.dll (Trojan.Vundo) -> Delete on reboot.
      C:\WINDOWS\system32\yJSBHkkj.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\yJSBHkkj.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\nyawpojb.dll (Trojan.Vundo) -> Delete on reboot.
      C:\WINDOWS\system32\bjopwayn.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\nybrsmgs.dll (Trojan.Vundo) -> Delete on reboot.
      C:\WINDOWS\system32\sgmsrbyn.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ssqPigFv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\vFgiPqss.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\vFgiPqss.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ukmbrlmn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\nmlrbmku.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\xwgdrveq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\qevrdgwx.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\xxyywwxV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\Vxwwyyxx.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\Vxwwyyxx.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ybddbwbm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\mbwbddby.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\khfEUnOh.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Lana\Local Settings\Temporary Internet Files\Content.IE5\UWLFIS1Z\kb456456[1] (Trojan.Vundo) -> Delete on reboot.
      C:\Documents and Settings\Lana\Start Menu\Programs\VirusProtectPro\Uninstall VirusProtectPro 3.4.lnk (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Lana\Start Menu\Programs\VirusProtectPro\VirusProtectPro 3.4 Website.lnk (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Lana\Start Menu\Programs\VirusProtectPro\VirusProtectPro 3.4.lnk (Rogue.VirusProtectPro) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ivcvnhev.dll (Trojan.Agent) -> Delete on reboot.
      C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
       
       
       
       
       

      4 Apprentice

       • 

      20.5K Posts

      June 19th, 2008 14:00

      MBAM did a good job, but we have more work to do. These things are rarely fixed with one shot.

      Please print these instructions and refer to them for downloading and running ComboFix:
      http://www.bleepingcomputer.com/combofix/how-to-use-combofix

      Please ensure you read this guide carefully and install the Recovery Console first.

      The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

      Once installed, you should see a blue screen prompt that says:

      The Recovery Console was successfully installed.

      Please continue as follows:
      1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      2. Click Yes to allow ComboFix to continue scanning for malware.

      When the tool is finished, it will produce a report for you.

      Please include the following reports for further review, and so we may continue cleaning the system:

      C:\ComboFix.txt
      New HijackThis log.


      Note: The above instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
      You should NOT use Combofix unless you have been instructed to do so by a Malware Removal Expert. It is intended by its creator to be used under the guidance and supervision of an expert, not for private use.







      June 26th, 2008 01:00

      .
      ------------------------ Other Running Processes ------------------------
      .
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\WINDOWS\system32\HPConfig.exe
      C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\system32\WLTRYSVC.EXE
      C:\WINDOWS\system32\MsPMSPSv.exe
      C:\WINDOWS\system32\BCMWLTRY.EXE
      C:\WINDOWS\system32\imapi.exe
      .
      **************************************************************************
      .
      Completion time: 2008-06-25 19:07:50 - machine was rebooted
      ComboFix-quarantined-files.txt  2008-06-26 02:07:30

      Pre-Run: 5,618,585,600 bytes free
      Post-Run: 6,623,825,920 bytes free

      WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
      C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

      266 --- E O F --- 2008-05-28 03:15:53

      June 26th, 2008 01:00

      .
      .
      *Note* empty entries & legit default entries are not shown 
      REGEDIT4

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2abdde5e-304d-49b1-ab5e-5c846123729f}]
      C:\WINDOWS\system32\ctoitukl.dll

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
      2008-05-08 20:56 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8AB1A2CE-5535-4C44-AFF3-D75123938F19}]
      C:\WINDOWS\system32\efcAQKCR.dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [ ]
      "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-25 18:47 51048]
      "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2008-02-06 23:49 718704]
      "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 00:56 158208]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
      "ecgfb"= {39d23dba-a362-4803-b26c-5f2cb46e669b} - C:\WINDOWS\System32\kfhrvq.dll [ ]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
      "AppInit_DLLs"= 

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "SENTINEL"= snti386.dll

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
      path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
      backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\5b77907c]
      C:\WINDOWS\system32\xwgdrveq.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
      --a------ 2008-04-23 02:08 483328 C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Version Cue CS2]
      --a------ 2005-04-04 18:58 856064 C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
      --a------ 2002-08-15 16:18 28672 C:\WINDOWS\system32\Ati2mdxx.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM5844a3e0]
      C:\WINDOWS\system32\biixirsn.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
      C:\WINDOWS\System32\bcmntray

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
      --a------ 2003-05-21 15:35 4608 C:\WINDOWS\system32\carpserv.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cpqset]
      C:\Program Files\HPQ\Default Settings\cpqset.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
      --a------ 2004-08-04 00:56 15360 C:\WINDOWS\system32\ctfmon.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Display Settings]
      C:\Program Files\HPQ\Notebook Utilities\hptasks.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
      --a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
      C:\WINDOWS\system32\dumprep 0 -k

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
      --a------ 2006-09-28 22:01 380928 C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
      --a------ 2004-10-13 09:24 1694208 C:\Program Files\Messenger\msmsgs.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QT4HPOT]
      C:\Program Files\HPQ\One-Touch\OneTouch.EXE

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
      --a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\QTTask.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
      C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
      C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
      --a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TV Now]
      C:\Program Files\HPQ\Notebook Utilities\TvNow.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
      --a------ 2006-03-30 16:45 313472 C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
      --a------ 2006-11-30 22:49 4662776 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
      --a------ 2006-07-21 17:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
      "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
      "C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
      "C:\\WINDOWS\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Yahoo!\\Messenger\\yserver.exe"=
      "C:\\Program Files\\uTorrent\\uTorrent.exe"=
      "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
      "C:\\Program Files\\iTunes\\iTunes.exe"=

      R0 sonyhcb;Sony Digital Imaging Base;C:\WINDOWS\system32\DRIVERS\sonyhcb.sys [2001-11-05 09:23]
      R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon []
      R2 Viewpoint Manager Service;Viewpoint Manager Service;"C:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 14:38]
      R3 CALIAUD;Conexant AMC 3D ENVIRONMENTAL AUDIO;C:\WINDOWS\system32\drivers\caliaud.sys [2002-11-05 08:04]
      R3 CALIHALA;CALIHALA;C:\WINDOWS\system32\drivers\calihal.sys [2002-11-05 08:04]
      R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\system32\DRIVERS\DP83815.SYS [2003-07-16 18:01]
      S2 Par1284;Par1284;C:\Program Files\FlexiSIGN-PRO 7.6v2\Program\Par1284.sys []
      S3 ALiIRDA;ALi Infrared Device Driver;C:\WINDOWS\system32\DRIVERS\aliirda.sys [2003-07-10 04:16]
      S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 21:32]
      S3 sonyhcs;Sony Digital Imaging Video;C:\WINDOWS\system32\DRIVERS\sonyhcs.sys [2001-11-05 09:23]

      .
      Contents of the 'Scheduled Tasks' folder
      "2008-06-08 01:47:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
      - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
      "2008-06-10 03:03:46 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Lana.job"
      - C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
      .
      **************************************************************************

      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-06-25 18:58:07
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ... 

      scanning hidden autostart entries ...

      scanning hidden files ... 

      scan completed successfully
      hidden files: 0

      **************************************************************************

      June 26th, 2008 01:00

      ComboFix 08-06-20.4 - Lana 2008-06-25 18:45:50.1 - NTFSx86
      Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.377 [GMT -7:00]
      Running from: C:\Documents and Settings\Lana\Desktop\ComboFix.exe
      Command switches used :: C:\Documents and Settings\Lana\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
       * Created a new restore point
      .

      (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\WINDOWS\BM5844a3e0.xml
      C:\WINDOWS\pskt.ini
      C:\WINDOWS\system32\apfkhxem.dll
      C:\WINDOWS\system32\aplixrfv.dll
      C:\WINDOWS\system32\biixirsn.dll
      C:\WINDOWS\system32\cifghibi.ini
      C:\WINDOWS\system32\components
      C:\WINDOWS\system32\copenbae.ini
      C:\WINDOWS\system32\eoqmexpr.ini
      C:\WINDOWS\system32\epgowlxe.dll
      C:\WINDOWS\system32\fnlfotoc.ini
      C:\WINDOWS\system32\ftglcipi.ini
      C:\WINDOWS\system32\gtstahar.dll
      C:\WINDOWS\system32\gvfqpaug.dll
      C:\WINDOWS\system32\hkyyumnc.dll
      C:\WINDOWS\system32\hmivlqhn.dll
      C:\WINDOWS\system32\ivcvnhev.dll
      C:\WINDOWS\system32\jkkHBSJy.dll
      C:\WINDOWS\system32\JQssDfhk.ini
      C:\WINDOWS\system32\JQssDfhk.ini2
      C:\WINDOWS\system32\kxkecvvj.dll
      C:\WINDOWS\system32\lkkwqlsx.ini
      C:\WINDOWS\system32\lyxnwvkt.dll
      C:\WINDOWS\system32\mcrh.tmp
      C:\WINDOWS\system32\ncvqwbag.ini
      C:\WINDOWS\system32\nyawpojb.dll
      C:\WINDOWS\system32\nybrsmgs.dll
      C:\WINDOWS\system32\oabtotbj.ini
      C:\WINDOWS\system32\pjcvsbsp.ini
      C:\WINDOWS\system32\pmykeiha.ini
      C:\WINDOWS\system32\RCKQAcfe.ini
      C:\WINDOWS\system32\RCKQAcfe.ini2
      C:\WINDOWS\system32\rqsxxkgw.dll
      C:\WINDOWS\system32\rsciiewf.ini
      C:\WINDOWS\system32\tppjlsvh.dll
      C:\WINDOWS\system32\txesogqu.dll
      C:\WINDOWS\system32\xhaqfgja.dll
      C:\WINDOWS\system32\yJSBHkkj.ini

      .
      (((((((((((((((((((((((((   Files Created from 2008-05-26 to 2008-06-26  )))))))))))))))))))))))))))))))
      .

      2008-06-18 21:12 . 2008-06-18 21:12 d-------- C:\Program Files\Malwarebytes' Anti-Malware
      2008-06-18 21:12 . 2008-06-18 21:12 d-------- C:\Documents and Settings\Lana\Application Data\Malwarebytes
      2008-06-18 21:12 . 2008-06-18 21:12 d----c--- C:\Documents and Settings\All Users\Application Data\Malwarebytes
      2008-06-18 21:12 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
      2008-06-18 21:12 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
      2008-06-18 19:58 . 2008-06-18 19:58 d-------- C:\Program Files\Trend Micro
      2008-06-17 19:15 . 2008-06-17 19:16 d----c--- C:\HJT
      2008-06-09 19:27 . 2008-06-09 19:27 47,968 --ah----- C:\WINDOWS\system32\mlfcache.dat
      2008-06-07 20:10 . 2008-06-13 19:51 54,156 --ah----- C:\WINDOWS\QTFont.qfn
      2008-06-07 20:10 . 2008-06-07 20:10 1,409 --a------ C:\WINDOWS\QTFont.for
      2008-06-07 19:08 . 2008-06-07 19:10 d-------- C:\Program Files\Safari
      2008-06-05 19:12 . 2008-06-05 19:28 d----c--- C:\Documents and Settings\All Users\Application Data\Lavasoft
      2008-06-05 19:09 . 2008-06-05 19:09 d-------- C:\Program Files\Common Files\Wise Installation Wizard
      2008-06-03 20:11 . 2008-06-03 20:11 d-------- C:\Program Files\uTorrent
      2008-06-03 20:11 . 2008-06-03 21:46 d-------- C:\Documents and Settings\Lana\Application Data\uTorrent

      .
      ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-06-12 00:18 --------- d-----w C:\Program Files\Common Files\Symantec Shared
      2008-06-08 17:56 --------- d-----w C:\Documents and Settings\Lana\Application Data\Apple Computer
      2008-06-08 03:06 --------- d-----w C:\Program Files\iTunes
      2008-06-08 03:05 --------- d-----w C:\Program Files\iPod
      2008-06-08 02:55 --------- d-----w C:\Program Files\QuickTime
      2008-06-06 02:21 --------- d-----w C:\Program Files\Lavasoft
      2008-06-06 02:17 --------- d-----w C:\Documents and Settings\Lana\Application Data\Lavasoft
      2008-06-05 03:00 --------- d-----w C:\Program Files\Apple Software Update
      2008-06-01 02:03 --------- d-----w C:\Documents and Settings\Lana\Application Data\AdobeUM
      2008-05-31 23:21 --------- d-----w C:\Program Files\Common Files\Adobe
      2008-05-09 04:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
      2008-05-09 04:08 --------- d-----w C:\Program Files\Norton AntiVirus
      2008-05-09 03:53 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
      2008-05-09 03:53 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
      2008-05-09 03:53 10,563 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
      2008-05-09 03:53 --------- d-----w C:\Program Files\Symantec
      2008-05-09 03:52 --------- d-----w C:\Program Files\Windows Sidebar
      2008-05-09 03:33 --------- d-----w C:\Documents and Settings\Lana\Application Data\Symantec
      2008-05-09 01:46 --------- d-----w C:\Program Files\Avanquest update
      2008-04-29 18:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
      2008-04-29 18:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
      2008-04-29 18:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
      2006-07-23 21:52 284 ----a-w C:\Documents and Settings\Lana\Application Data\ViewerApp.dat
      .

      (((((((((((((((((((((((((((((((((((((((((((((   AWF   ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      ----a-w           290,816 2002-08-15 01:29:38  C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe

      ----a-w           368,706 2002-09-11 05:26:26  C:\Program Files\BroadJump\Client Foundation\bak\CFD.exe

      ----a-w            65,536 2003-05-02 02:44:50  C:\Program Files\Common Files\Roxio Shared\System\bak\EngUtil.exe

      ----a-w            70,816 2003-11-10 21:30:02  C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe
      ----a-w            51,048 2008-01-26 01:47:22  C:\Program Files\Common Files\Symantec Shared\ccApp.exe

      ----a-w           155,896 2006-08-26 04:08:43  C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe

      ----a-w            49,152 2005-02-17 06:11:42  C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe

      ----a-w           184,412 2003-07-17 21:50:26  C:\Program Files\HPQ\Default Settings\bak\cpqset.exe

      ----a-w            45,056 2002-08-15 14:26:10  C:\Program Files\HPQ\Notebook Utilities\bak\hptasks.exe

      ----a-w           282,624 2003-01-30 18:34:08  C:\Program Files\HPQ\Notebook Utilities\bak\TvNow.exe

      ----a-w           102,400 2003-03-13 15:14:42  C:\Program Files\HPQ\One-Touch\bak\OneTouch.EXE

      ----a-w           278,528 2006-06-14 23:24:14  C:\Program Files\iTunes\bak\iTunesHelper.exe
      ----a-w           267,048 2008-03-30 17:36:40  C:\Program Files\iTunes\iTunesHelper.exe

      ----a-w           282,624 2006-07-15 03:42:10  C:\Program Files\QuickTime\bak\qttask.exe
      ----a-w           413,696 2008-03-29 06:37:20  C:\Program Files\QuickTime\QTTask.exe

      ----a-w           868,352 2003-07-19 01:23:22  C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\bak\DrgToDsc.exe

      ----a-w           380,928 2003-12-10 12:52:40  C:\Program Files\SBC Self Support Tool\SmartBridge\bak\MotiveSB.exe
      ----a-w           380,928 2006-09-29 05:01:26  C:\Program Files\SBC Self Support Tool\SmartBridge\MotiveSB.exe

      ----a-w           610,304 2003-05-22 22:06:00  C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe

      ----a-w           110,592 2003-05-22 21:10:00  C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe

      ----a-w            57,344 2003-07-11 21:51:16  C:\Program Files\Yahoo!\browser\bak\ybrwicon.exe
      ----a-w           129,536 2006-07-22 00:19:46  C:\Program Files\Yahoo!\browser\ybrwicon.exe

      .
      (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))

      June 26th, 2008 01:00

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 7:11:00 PM, on 6/25/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      C:\WINDOWS\system32\HPConfig.exe
      C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Viewpoint\Common\ViewpointService.exe
      C:\WINDOWS\System32\wltrysvc.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\WINDOWS\System32\bcmwltry.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\notepad.exe
      C:\Program Files\Safari\Safari.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\wuauclt.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us8l.hpwis.com/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: {f9273216-48c5-e5ba-1b94-d403e5eddba2} - {2abdde5e-304d-49b1-ab5e-5c846123729f} - C:\WINDOWS\system32\ctoitukl.dll (file missing)
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {8AB1A2CE-5535-4C44-AFF3-D75123938F19} - C:\WINDOWS\system32\efcAQKCR.dll (file missing)
      O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
      O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
      O4 - Global Startup: Norton AntiVirus.lnk = C:\Program Files\Common Files\Symantec Shared\NMain.exe
      O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://us8l.hpwis.com
      O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
      O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
      O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbcyahoo/TrueInstallSBC.exe
      O20 - AppInit_DLLs:  
      O21 - SSODL: ecgfb - {39d23dba-a362-4803-b26c-5f2cb46e669b} - C:\WINDOWS\System32\kfhrvq.dll (file missing)
      O22 - SharedTaskScheduler: {39d23dba-a362-4803-b26c-5f2cb46e669b} - ecgfb - (no file)
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
      O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
      O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
      O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

      --
      End of file - 9640 bytes

      4 Apprentice

       • 

      20.5K Posts

      June 27th, 2008 14:00

      You still have quite a mess there. You have a downloader trojan called Downloader.Agent.awf or Downloader.Agent.ayy. This trojan replaces legitimate files that are common on most computers with an infected file. It then moves the legitimate file to a "bak" or backup folder. Please follow the directions below to run FindAWF so we can identify the files that have been infected and the backups then restore them.

      Download FindAWF.exe from here or here, and save it to your desktop.
      • Double-click on the FindAWF.exe file to run it.
      • It will open a command prompt and ask you to "Press any key to continue".
      • You will be presented with a Menu.
      • 1. Press 1 then Enter to scan for bak folders
        2. Press 2 then Enter to restore files from bak folders
        3. Press 3 then Enter to remove bak folders
        4. Press 4 then Enter to reset domain zones
        5. Press E then Enter to EXIT
      • Press 1, then press Enter
      • It may take a few minutes to complete so be patient.
      • When it is complete, it will open a text file in notepad called AWF.txt.
      • Please copy and paste the contents of the AWF.txt file in your next reply.

      June 27th, 2008 23:00


        Find AWF report by noahdfear ©2006
                     Version 1.40

      The current date is: Fri 06/27/2008 
      The current time is: 13:46:33.90


        bak folders found
        ~~~~~~~~~~~


       Directory of C:\PROGRA~1\ITUNES\BAK

      06/14/2006  04:24 PM           278,528 iTunesHelper.exe
                     1 File(s)        278,528 bytes

       Directory of C:\PROGRA~1\MESSEN~1\BAK

                     0 File(s)              0 bytes

       Directory of C:\PROGRA~1\QUICKT~1\BAK

      07/14/2006  08:42 PM           282,624 qttask.exe
                     1 File(s)        282,624 bytes

       Directory of C:\WINDOWS\SYSTEM32\BAK

                     0 File(s)              0 bytes

       Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK

      08/14/2002  06:29 PM           290,816 atiptaxx.exe
                     1 File(s)        290,816 bytes

       Directory of C:\PROGRA~1\BROADJ~1\CLIENT~1\BAK

      09/10/2002  10:26 PM           368,706 CFD.exe
                     1 File(s)        368,706 bytes

       Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK

      11/10/2003  02:30 PM            70,816 ccApp.exe
                     1 File(s)         70,816 bytes

       Directory of C:\PROGRA~1\HP\HPSOFT~1\BAK

      02/16/2005  11:11 PM            49,152 HPWuSchd2.exe
                     1 File(s)         49,152 bytes

       Directory of C:\PROGRA~1\HPQ\DEFAUL~1\BAK

      07/17/2003  02:50 PM           184,412 cpqset.exe
                     1 File(s)        184,412 bytes

       Directory of C:\PROGRA~1\HPQ\NOTEBO~1\BAK

      08/15/2002  07:26 AM            45,056 hptasks.exe
      01/30/2003  11:34 AM           282,624 TvNow.exe
                     2 File(s)        327,680 bytes

       Directory of C:\PROGRA~1\HPQ\ONE-TO~1\BAK

      03/13/2003  08:14 AM           102,400 OneTouch.EXE
                     1 File(s)        102,400 bytes

       Directory of C:\PROGRA~1\SBCSEL~1\SMARTB~1\BAK

      12/10/2003  05:52 AM           380,928 MotiveSB.exe
                     1 File(s)        380,928 bytes

       Directory of C:\PROGRA~1\SYNAPT~1\SYNTP\BAK

      05/22/2003  03:06 PM           610,304 SynTPEnh.exe
      05/22/2003  02:10 PM           110,592 SynTPLpr.exe
                     2 File(s)        720,896 bytes

       Directory of C:\PROGRA~1\YAHOO!\BROWSER\BAK

      07/11/2003  02:51 PM            57,344 ybrwicon.exe
                     1 File(s)         57,344 bytes

       Directory of C:\PROGRA~1\COMMON~1\ROXIOS~1\SYSTEM\BAK

      05/01/2003  07:44 PM            65,536 EngUtil.exe
                     1 File(s)         65,536 bytes

       Directory of C:\PROGRA~1\GOOGLE\GOOGLE~1\10720~1.364\BAK

      08/25/2006  09:08 PM           155,896 GoogleToolbarNotifier.exe
                     1 File(s)        155,896 bytes

       Directory of C:\PROGRA~1\ROXIO\EASYCD~1\DRAGTO~1\BAK

      07/18/2003  06:23 PM           868,352 DrgToDsc.exe
                     1 File(s)        868,352 bytes


        Duplicate files of bak directory contents
        ~~~~~~~~~~~~~~~~~~~~~~~

          229952 Sep 12 2006 "C:\Program Files\iTunes\iTunesHelper.exe1159058286"
          116024 Jul  2 2007 "C:\Program Files\Apple Software Update\Packages\iTunesSetupAdmin.exe"
          278528 Jun 14 2006 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
          102400 Jun  7 2008 "C:\WINDOWS\Installer\{585776BC-4BD6-4BD2-A19A-1D6CB44A403B}\iTunesIco.exe"
        50009400 Aug 25 2007 "C:\Documents and Settings\Lana\Desktop\Desktop Stuff\iTunesSetup(2).exe"
           75048 Jun  7 2008 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.6.2.9\iTunesSetupAdmin.exe"
          413696 Mar 28 2008 "C:\Program Files\QuickTime\QTTask.exe"
          282624 Jul 14 2006 "C:\Program Files\QuickTime\bak\qttask.exe"
          290816 Aug 14 2002 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
          368706 Sep 10 2002 "C:\Program Files\BroadJump\Client Foundation\bak\CFD.exe"
           51048 Jan 25 2008 "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
           70816 Nov 10 2003 "C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe"
           49152 Feb 16 2005 "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
          184412 Jul 17 2003 "C:\SWSetup\Default\Cpqset.exe"
          184412 Jul 17 2003 "C:\Program Files\HPQ\Default Settings\bak\cpqset.exe"
           45056 Aug 15 2002 "C:\Program Files\HPQ\Notebook Utilities\bak\hptasks.exe"
          282624 Jan 30 2003 "C:\Program Files\HPQ\Notebook Utilities\bak\TvNow.exe"
          102400 Mar 13 2003 "C:\SWSetup\OneTouch\ONETOUCH.EXE"
          102400 Mar 13 2003 "C:\Program Files\HPQ\One-Touch\bak\OneTouch.EXE"
          380928 Sep 28 2006 "C:\Program Files\SBC Self Support Tool\SmartBridge\MotiveSB.exe"
          380928 Dec 10 2003 "C:\Program Files\SBC Self Support Tool\SmartBridge\bak\MotiveSB.exe"
          610304 May 22 2003 "C:\SWSetup\Touchpad\SynTPEnh.exe"
          610304 May 22 2003 "C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe"
          610304 May 22 2003 "C:\Program Files\Synaptics\SynTP\Media\SynTPEnh.exe"
          110592 May 22 2003 "C:\SWSetup\Touchpad\SynTPLpr.exe"
          110592 May 22 2003 "C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe"
          110592 May 22 2003 "C:\Program Files\Synaptics\SynTP\Media\SynTPLpr.exe"
          129536 Jul 21 2006 "C:\Program Files\Yahoo!\browser\ybrwicon.exe"
           57344 Jul 11 2003 "C:\Program Files\Yahoo!\browser\bak\ybrwicon.exe"
           65536 May  1 2003 "C:\Program Files\Common Files\Roxio Shared\System\bak\EngUtil.exe"
        13413048 Apr  8 2008 "C:\Documents and Settings\Lana\Desktop\Google_Earth_BZXV.exe"
           69632 Nov 13 2007 "C:\Program Files\Google\Google Earth\googleearth.exe"
           26694 Apr  8 2008 "C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe"
          837160 Oct 30 2006 "C:\Documents and Settings\Lana\Desktop\Desktop Stuff\JUNK N STUFF\GoogleToolbarInstaller.exe"
          155896 Aug 25 2006 "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe"
          868352 Jul 18 2003 "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\bak\DrgToDsc.exe"


        end of report

      June 27th, 2008 23:00

      I just wanted to say "thank you" for all the help you have given me so far. it is really great that you guys are willing to help people with these types of problems. :)

      4 Apprentice

       • 

      20.5K Posts

      June 28th, 2008 00:00

      You're welcome. This will take a while, but we'll do our best.

      Reboot into Safemode.
      Turn on the computer.
      Immediately begin tapping the F8 key.
      Use the arrow keys to highlight Safe Mode and press the Enter key.

      * Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

      "C:\Program Files\iTunes\bak\iTunesHelper.exe"
      "C:\Program Files\QuickTime\bak\qttask.exe"
      "C:\Program Files\BroadJump\Client Foundation\bak\CFD.exe"
      "C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe"
      "C:\Program Files\HP\HP Software Update\bak\HPWuSchd2.exe"
      "C:\Program Files\HPQ\Default Settings\bak\cpqset.exe"
      "C:\Program Files\HPQ\Notebook Utilities\bak\hptasks.exe"
      "C:\Program Files\HPQ\Notebook Utilities\bak\TvNow.exe"
      "C:\Program Files\HPQ\One-Touch\bak\OneTouch.EXE"
      "C:\Program Files\SBC Self Support Tool\SmartBridge\bak\MotiveSB.exe"
      "C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe"
      "C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe"
      "C:\Program Files\Yahoo!\browser\bak\ybrwicon.exe"
      "C:\Program Files\Common Files\Roxio Shared\System\bak\EngUtil.exe"
      "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe"
      "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\bak\DrgToDsc.exe"

      * Double-click on the FindAWF.exe file to run it.

      * It will open a command prompt and ask you to "Press any key to continue".
      * You will be presented with a Menu.

      1. Press 1 then Enter to scan for bak folders
      2. Press 2 then Enter to restore files from bak folders
      3. Press 3 then Enter to remove bak folders
      4. Press 4 then Enter to reset domain zones
      5. Press E then Enter to EXIT

      * Press 2, then press Enter.
      * Press any key to continue.
      * A Notepad document FindAWF.txt will appear with instructions to click below the line and paste the list of files to be restored.
      * Right click below this line and select Paste, to paste the list of files copied to the clipboard earlier. Save and close the document.
      * The program will proceed to move the legit files and will perform another scan for .bak folder
      * It may take a few minutes to complete so be patient.
      * When it is complete, it will open a text file in notepad called AWF.txt. Save/close that for now. You will need to post it in your next reply.

      Download ATF-Cleaner.
      http://www.atribune.org/ccount/click.php?id=1]
      Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
      If you use Firefox browser Click Firefox at
      the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please
      click No at the prompt.
      If you use Opera browser Click Opera at the
      top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please
      click No at the prompt.
      Click Exit on the Main menu to close the program.
      For Technical Support, double-click the e-mail address located
      at the bottom of each menu.

      * Please copy and paste the contents of the AWF.txt file in your next reply.

      No Events found!

      Top