undetermined problem lost?????

View previous topic View next topic Go down

undetermined problem lost?????

Post by tinagibson on Tue Sep 08, 2009 1:27 pm

downloaded avira antivirus and malwarebytes avira as of today won't scan system and malwarebytes shows to be installed (icon, control panel etc) but can't be opened. running slow pop up's and ads playing on speakers i'm lost. don't have any idea whats going on

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Tue Sep 08, 2009 2:30 pm

Please download the current version of HijackThis from [You must be registered and logged in to see this link.]

  • Double click and run the installer.
  • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
  • After installing, you should get the user agreement, press accept and Hijack This will run.
  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Tue Sep 08, 2009 6:48 pm

installed hijack this ran program cant access log says windows cannot access may not have permission to access i am the admin

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Tue Sep 08, 2009 7:51 pm

Please download SystemLook from one of the links below and save it to your Desktop.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:

    :filefind
    scecli.dll
    netlogon.dll
    eventlog.dll
    cngaudit.dll

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Tue Sep 08, 2009 9:00 pm

Log created at 16:40 on 08/09/2009 by tina gibson (Administrator - Elevation successful)

========== filefind ==========

Searching for "scecli.dll"
C:\WINDOWS\system32\dllcache\scecli.dll --a--c 181248 bytes [22:00 14/04/2008] [22:00 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\scecli.dll --a--- 181248 bytes [22:00 14/04/2008] [22:00 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084

Searching for "netlogon.dll"
C:\WINDOWS\system32\dllcache\netlogon.dll --a--c 407040 bytes [22:00 14/04/2008] [22:00 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\netlogon.dll --a--- 407040 bytes [22:00 14/04/2008] [22:00 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550

Searching for "eventlog.dll"
C:\WINDOWS\system32\dllcache\eventlog.dll --a--c 56320 bytes [22:00 14/04/2008] [22:00 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656
C:\WINDOWS\system32\eventlog.dll --a--- 63488 bytes [22:00 14/04/2008] [22:00 14/04/2008] (Unable to calculate MD5)

Searching for "cngaudit.dll"
No files found.

-=End Of File=-

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Tue Sep 08, 2009 11:59 pm

1. Please download The Avenger by Swandog46 to your Desktop
Link: [You must be registered and logged in to see this link.]

  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+CCrying


Files to delete:
C:\WINDOWS\system32\eventlog.dll

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.

  • Under "Input script here:", paste in the script from the quote box above.
  • Leave the ticked box "Scan for rootkit" ticked.
  • Then tick "Disable any rootkits found"
  • Now click on the Execute to begin execution of the script.
  • Answer "Yes" twice when prompted.

    The Avenger will automatically do the following:

  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avengerís actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
4. Please copy/paste the content of c:\avenger.txt into your reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Wed Sep 09, 2009 2:32 am

[You must be registered and logged in to see this link.]

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File "C:\WINDOWS\system32\eventlog.dll" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Wed Sep 09, 2009 7:30 pm

Hello.
Now download and run Hijack This from here:
[You must be registered and logged in to see this link.]

Choose system scan with logfile, copy/paste the log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Wed Sep 09, 2009 9:22 pm

Scan saved at 5:21:35 PM, on 9/9/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Steam\Steam.exe
C:\WINDOWS\system32\huej1nqg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\tina gibson\Local Settings\Temporary Internet Files\Content.IE5\JTNNYEG9\winlogon[1].scr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: (no name) - {d2be9f52-416b-4ba8-9790-a7b44e2da14c} - C:\WINDOWS\system32\juvoludi.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [lejehipahe] Rundll32.exe "C:\WINDOWS\system32\muyolule.dll",s
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [nejujatal] Rundll32.exe "c:\windows\system32\pavogare.dll",a
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [huej1nqg.exe] C:\WINDOWS\system32\huej1nqg.exe
O4 - HKCU\..\Run: [SaveKeeper] C:\Program Files\SaveKeeper Software\SaveKeeper\SaveKeeper.exe -min
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - [You must be registered and logged in to see this link.]
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - [You must be registered and logged in to see this link.]
O20 - AppInit_DLLs: system32\pavogare.dll C:\WINDOWS\system32\navifaya.dll c:\windows\system32\piyadayi.dll c:\windows\system32\gijiyeli.dll c:\windows\system32\pavogare.dll c:\windows\system32\juvilisi.dll c:\windows\system32\birakuze.dll
O21 - SSODL: yayesamul - {6df63b01-2def-4016-8be8-cf6d420fc2ec} - (no file)
O21 - SSODL: tezeweriv - {c4647e83-b1fb-4ace-8b0f-01c8ed5feb17} - (no file)
O21 - SSODL: kofubuped - {951e6892-90bb-4d51-ba65-aa1827082791} - (no file)
O21 - SSODL: tomijatan - {c3b23518-67d1-42c4-8ed1-7f3372958c99} - (no file)
O21 - SSODL: jupepepaj - {4df9ff81-574d-4acd-af40-a783b10684dc} - (no file)
O21 - SSODL: bezuzofot - {13e6bc15-23af-44f0-b974-134bc50cd8f9} - c:\windows\system32\birakuze.dll
O21 - SSODL: detoyinop - {5ae95ba6-475b-40a5-8365-9b34c6c3fdc8} - c:\windows\system32\birakuze.dll
O21 - SSODL: zutumibos - {9d2abf7e-60ce-4bc6-90d9-295aa5da4852} - c:\windows\system32\gijiyeli.dll
O21 - SSODL: fuzahuyin - {dd017c53-7b24-40b0-9b0e-29b5a6308345} - c:\windows\system32\gijiyeli.dll
O21 - SSODL: morihidow - {d11acbbd-154c-41ff-8ab3-6aa4731f2542} - c:\windows\system32\gijiyeli.dll
O21 - SSODL: budewuror - {f2da7688-3513-4b61-830a-49dfd4beabd9} - c:\windows\system32\gijiyeli.dll
O21 - SSODL: jovipisew - {90977e94-aadc-495f-8562-91976cc3554c} - c:\windows\system32\juvilisi.dll
O21 - SSODL: yukofevad - {f4558546-6753-480d-8e8d-e359d5a7e69b} - c:\windows\system32\gijiyeli.dll
O21 - SSODL: hidatahib - {fe0de2c7-b49a-4d0d-8724-6f17660097d2} - c:\windows\system32\birakuze.dll
O21 - SSODL: kidakatej - {54f51f81-5c36-4152-b071-75606cd157cc} - c:\windows\system32\piyadayi.dll
O21 - SSODL: nuziwelim - {d9e3d7ec-94e5-4d83-b18a-974c92a53cce} - c:\windows\system32\juvilisi.dll
O21 - SSODL: rurimayuy - {9538744d-d6d4-466f-96b7-d039978e000d} - c:\windows\system32\birakuze.dll
O22 - SharedTaskScheduler: tokatiluy - {6df63b01-2def-4016-8be8-cf6d420fc2ec} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {c4647e83-b1fb-4ace-8b0f-01c8ed5feb17} - (no file)
O22 - SharedTaskScheduler: jugezatag - {951e6892-90bb-4d51-ba65-aa1827082791} - (no file)
O22 - SharedTaskScheduler: jugezatag - {c3b23518-67d1-42c4-8ed1-7f3372958c99} - (no file)
O22 - SharedTaskScheduler: kupuhivus - {4df9ff81-574d-4acd-af40-a783b10684dc} - (no file)
O22 - SharedTaskScheduler: mujuzedij - {13e6bc15-23af-44f0-b974-134bc50cd8f9} - c:\windows\system32\birakuze.dll
O22 - SharedTaskScheduler: mujuzedij - {5ae95ba6-475b-40a5-8365-9b34c6c3fdc8} - c:\windows\system32\birakuze.dll
O22 - SharedTaskScheduler: kupuhivus - {9d2abf7e-60ce-4bc6-90d9-295aa5da4852} - c:\windows\system32\gijiyeli.dll
O22 - SharedTaskScheduler: kupuhivus - {dd017c53-7b24-40b0-9b0e-29b5a6308345} - c:\windows\system32\gijiyeli.dll
O22 - SharedTaskScheduler: jugezatag - {d11acbbd-154c-41ff-8ab3-6aa4731f2542} - c:\windows\system32\gijiyeli.dll
O22 - SharedTaskScheduler: kupuhivus - {f2da7688-3513-4b61-830a-49dfd4beabd9} - c:\windows\system32\gijiyeli.dll
O22 - SharedTaskScheduler: jugezatag - {90977e94-aadc-495f-8562-91976cc3554c} - c:\windows\system32\juvilisi.dll
O22 - SharedTaskScheduler: kupuhivus - {f4558546-6753-480d-8e8d-e359d5a7e69b} - c:\windows\system32\gijiyeli.dll
O22 - SharedTaskScheduler: gahurihor - {fe0de2c7-b49a-4d0d-8724-6f17660097d2} - c:\windows\system32\birakuze.dll
O22 - SharedTaskScheduler: gahurihor - {54f51f81-5c36-4152-b071-75606cd157cc} - c:\windows\system32\piyadayi.dll
O22 - SharedTaskScheduler: kupuhivus - {d9e3d7ec-94e5-4d83-b18a-974c92a53cce} - c:\windows\system32\juvilisi.dll
O22 - SharedTaskScheduler: kupuhivus - {9538744d-d6d4-466f-96b7-d039978e000d} - c:\windows\system32\birakuze.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 13054 bytes

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Wed Sep 09, 2009 9:23 pm

have new problem something called savekeeper and registry defender same problem or new??

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Wed Sep 09, 2009 10:03 pm

Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {d2be9f52-416b-4ba8-9790-a7b44e2da14c} - C:\WINDOWS\system32\juvoludi.dll
    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O4 - HKLM\..\Run: [lejehipahe] Rundll32.exe "C:\WINDOWS\system32\muyolule.dll",s
    O4 - HKLM\..\Run: [nejujatal] Rundll32.exe "c:\windows\system32\pavogare.dll",a
    O4 - HKCU\..\Run: [huej1nqg.exe] C:\WINDOWS\system32\huej1nqg.exe
    O4 - HKCU\..\Run: [SaveKeeper] C:\Program Files\SaveKeeper Software\SaveKeeper\SaveKeeper.exe -min
    O20 - AppInit_DLLs: system32\pavogare.dll C:\WINDOWS\system32\navifaya.dll c:\windows\system32\piyadayi.dll c:\windows\system32\gijiyeli.dll c:\windows\system32\pavogare.dll c:\windows\system32\juvilisi.dll c:\windows\system32\birakuze.dll
    O21 - SSODL: yayesamul - {6df63b01-2def-4016-8be8-cf6d420fc2ec} - (no file)
    O21 - SSODL: tezeweriv - {c4647e83-b1fb-4ace-8b0f-01c8ed5feb17} - (no file)
    O21 - SSODL: kofubuped - {951e6892-90bb-4d51-ba65-aa1827082791} - (no file)
    O21 - SSODL: tomijatan - {c3b23518-67d1-42c4-8ed1-7f3372958c99} - (no file)
    O21 - SSODL: jupepepaj - {4df9ff81-574d-4acd-af40-a783b10684dc} - (no file)
    O21 - SSODL: bezuzofot - {13e6bc15-23af-44f0-b974-134bc50cd8f9} - c:\windows\system32\birakuze.dll
    O21 - SSODL: detoyinop - {5ae95ba6-475b-40a5-8365-9b34c6c3fdc8} - c:\windows\system32\birakuze.dll
    O21 - SSODL: zutumibos - {9d2abf7e-60ce-4bc6-90d9-295aa5da4852} - c:\windows\system32\gijiyeli.dll
    O21 - SSODL: fuzahuyin - {dd017c53-7b24-40b0-9b0e-29b5a6308345} - c:\windows\system32\gijiyeli.dll
    O21 - SSODL: morihidow - {d11acbbd-154c-41ff-8ab3-6aa4731f2542} - c:\windows\system32\gijiyeli.dll
    O21 - SSODL: budewuror - {f2da7688-3513-4b61-830a-49dfd4beabd9} - c:\windows\system32\gijiyeli.dll
    O21 - SSODL: jovipisew - {90977e94-aadc-495f-8562-91976cc3554c} - c:\windows\system32\juvilisi.dll
    O21 - SSODL: yukofevad - {f4558546-6753-480d-8e8d-e359d5a7e69b} - c:\windows\system32\gijiyeli.dll
    O21 - SSODL: hidatahib - {fe0de2c7-b49a-4d0d-8724-6f17660097d2} - c:\windows\system32\birakuze.dll
    O21 - SSODL: kidakatej - {54f51f81-5c36-4152-b071-75606cd157cc} - c:\windows\system32\piyadayi.dll
    O21 - SSODL: nuziwelim - {d9e3d7ec-94e5-4d83-b18a-974c92a53cce} - c:\windows\system32\juvilisi.dll
    O21 - SSODL: rurimayuy - {9538744d-d6d4-466f-96b7-d039978e000d} - c:\windows\system32\birakuze.dll
    O22 - SharedTaskScheduler: tokatiluy - {6df63b01-2def-4016-8be8-cf6d420fc2ec} - (no file)
    O22 - SharedTaskScheduler: mujuzedij - {c4647e83-b1fb-4ace-8b0f-01c8ed5feb17} - (no file)
    O22 - SharedTaskScheduler: jugezatag - {951e6892-90bb-4d51-ba65-aa1827082791} - (no file)
    O22 - SharedTaskScheduler: jugezatag - {c3b23518-67d1-42c4-8ed1-7f3372958c99} - (no file)
    O22 - SharedTaskScheduler: kupuhivus - {4df9ff81-574d-4acd-af40-a783b10684dc} - (no file)
    O22 - SharedTaskScheduler: mujuzedij - {13e6bc15-23af-44f0-b974-134bc50cd8f9} - c:\windows\system32\birakuze.dll
    O22 - SharedTaskScheduler: mujuzedij - {5ae95ba6-475b-40a5-8365-9b34c6c3fdc8} - c:\windows\system32\birakuze.dll
    O22 - SharedTaskScheduler: kupuhivus - {9d2abf7e-60ce-4bc6-90d9-295aa5da4852} - c:\windows\system32\gijiyeli.dll
    O22 - SharedTaskScheduler: kupuhivus - {dd017c53-7b24-40b0-9b0e-29b5a6308345} - c:\windows\system32\gijiyeli.dll
    O22 - SharedTaskScheduler: jugezatag - {d11acbbd-154c-41ff-8ab3-6aa4731f2542} - c:\windows\system32\gijiyeli.dll
    O22 - SharedTaskScheduler: kupuhivus - {f2da7688-3513-4b61-830a-49dfd4beabd9} - c:\windows\system32\gijiyeli.dll
    O22 - SharedTaskScheduler: jugezatag - {90977e94-aadc-495f-8562-91976cc3554c} - c:\windows\system32\juvilisi.dll
    O22 - SharedTaskScheduler: kupuhivus - {f4558546-6753-480d-8e8d-e359d5a7e69b} - c:\windows\system32\gijiyeli.dll
    O22 - SharedTaskScheduler: gahurihor - {fe0de2c7-b49a-4d0d-8724-6f17660097d2} - c:\windows\system32\birakuze.dll
    O22 - SharedTaskScheduler: gahurihor - {54f51f81-5c36-4152-b071-75606cd157cc} - c:\windows\system32\piyadayi.dll
    O22 - SharedTaskScheduler: kupuhivus - {d9e3d7ec-94e5-4d83-b18a-974c92a53cce} - c:\windows\system32\juvilisi.dll
    O22 - SharedTaskScheduler: kupuhivus - {9538744d-d6d4-466f-96b7-d039978e000d} - c:\windows\system32\birakuze.dll
    O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
    O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)


  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Thu Sep 10, 2009 1:56 am

malwarebytes won't launch no matter what i do files extract installation complete finish etc try to open nothing ( downloaded 5 times onto my computer) what now?

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Thu Sep 10, 2009 7:16 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Thu Sep 10, 2009 9:26 pm

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2315 [GMT -4:00]
Running from: c:\documents and settings\tina gibson\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\ecazibomeg.dll
c:\documents and settings\All Users\Application Data\ehomun.bin
c:\documents and settings\All Users\Application Data\irir.scr
c:\documents and settings\All Users\Application Data\kymex.lib
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\relicy.vbs
c:\documents and settings\All Users\Application Data\ymypocadu.sys
c:\documents and settings\kaitie justice\Application Data\.#
c:\documents and settings\kaitie justice\Application Data\.#\MBX@C48@12741C0.###
c:\documents and settings\kaitie justice\Application Data\.#\MBX@C48@12741F0.###
c:\documents and settings\kaitie justice\Application Data\.#\MBX@C48@1274220.###
C:\fyblb.exe
c:\program files\Common Files\akepuzaq.sys
c:\program files\Common Files\delof.bat
c:\windows\010112010146120114.fx
c:\windows\0101120101464949.fx
c:\windows\0101120101465653.fx
c:\windows\10651zac9tool2975.exe
c:\windows\10z55t9oj7f3.ocx
c:\windows\10z60wo9m564.ocx
c:\windows\11299spy55z.bin
c:\windows\1147zsp95bot58e.cpl
c:\windows\115129roj75z.bin
c:\windows\11545s5amb9t5z9.bin
c:\windows\1155ste5l9z8.dll
c:\windows\120935irus35fz.dll
c:\windows\12379tr5jz6e.ocx
c:\windows\12b8bacz95or832.ocx
c:\windows\12e9viz17975.bin
c:\windows\12z295py5f5.ocx
c:\windows\1315zpyware30769.ocx
c:\windows\131z69p5mbotca.bin
c:\windows\13659zacktool57b.dll
c:\windows\1391downloz5er9269.dll
c:\windows\139sp5war91786z.dll
c:\windows\1409v5zus225.ocx
c:\windows\14259dzw5re604.dll
c:\windows\145529ormz63.exe
c:\windows\145z0wor94b0.cpl
c:\windows\14794s5am9zt48f.ocx
c:\windows\14z36spa5bot193.exe
c:\windows\15052ha5ztool69b.ocx
c:\windows\15122zir9s519.ocx
c:\windows\152bt9iez1291.cpl
c:\windows\15646spz69e.cpl
c:\windows\15900not9a-virusz2a.bin
c:\windows\15995szambot59f.ocx
c:\windows\15aavir37z9.dll
c:\windows\15f9spyware3156z.ocx
c:\windows\15z5thre9t2209.bin
c:\windows\1611backdz5r2195.dll
c:\windows\162spazb9t1bc5.bin
c:\windows\162z1wo95685.dll
c:\windows\16731ha5ktzol189.cpl
c:\windows\1696t5zj2ac.ocx
c:\windows\16985acktoo9553z.dll
c:\windows\169z3tro57bc.bin
c:\windows\16z57worm599.exe
c:\windows\17252zpam9ot3f0.cpl
c:\windows\172z8not-a-5irus7289.ocx
c:\windows\18307hack9ooz50.cpl
c:\windows\18505s9yz16.bin
c:\windows\18553troj195z.cpl
c:\windows\18569hacktoolz90.bin
c:\windows\1857troz579.exe
c:\windows\18932n5t-azvirus669.bin
c:\windows\19048not-a-v5rzs8a.cpl
c:\windows\19113spam5otz54.cpl
c:\windows\19459spamzot2f75.dll
c:\windows\195165ackzool5d9.cpl
c:\windows\19846ha5ktz9l408.bin
c:\windows\198thiez2815.bin
c:\windows\19985virzs6da.bin
c:\windows\199threat2z135.bin
c:\windows\19f95hiefz10.exe
c:\windows\1c98th5ef1z39.cpl
c:\windows\1cec9dd5zre955.ocx
c:\windows\1e22spyw5rz2679.bin
c:\windows\1z098v5r9s5c9.ocx
c:\windows\1z0c5hief2739.ocx
c:\windows\1z740spy1b59.dll
c:\windows\1z906worm3d5.dll
c:\windows\1z986hack9ool4f5.dll
c:\windows\20908hackt5oz3ba.exe
c:\windows\209779acktzol5f0.cpl
c:\windows\2125azdwa9e3227.ocx
c:\windows\21346trojzb95.exe
c:\windows\21359not-a-virus11z.dll
c:\windows\21465hackto595z5.dll
c:\windows\22e5zt9al2241.bin
c:\windows\23925not-z-virus119.exe
c:\windows\23951spambot4zb.exe
c:\windows\23965not-a-virus2f8z.bin
c:\windows\23z73s5amb9t7a.ocx
c:\windows\245255zt9a-virus7e3.ocx
c:\windows\24fdownlo9ze52016.dll
c:\windows\2540t5reat7z91.bin
c:\windows\25ccspzware16009.cpl
c:\windows\2604059z398.exe
c:\windows\26785z9oj685.bin
c:\windows\26903hzckt5ol7af.ocx
c:\windows\2699zroj53d5.cpl
c:\windows\27234s956zd.dll
c:\windows\2745spy1z79.bin
c:\windows\27912noz-a-v5rus2a2.exe
c:\windows\28142hzckt9ol156.cpl
c:\windows\291zv95882.bin
c:\windows\29484zpy3e5.cpl
c:\windows\29506t5zj2ea.bin
c:\windows\29609zr592e5.exe
c:\windows\29726zorm60a5.exe
c:\windows\2991no9-a5vizus5bb.cpl
c:\windows\29951s5y5z59.ocx
c:\windows\29z79troj4b5.ocx
c:\windows\2a39bazk5oor1395.dll
c:\windows\2b0fthiez5219.bin
c:\windows\2c4aa9zwar5488.dll
c:\windows\2dbf9zea51113.bin
c:\windows\2e1dsp9zare805.dll
c:\windows\2ebazir9052.bin
c:\windows\2z255spy39d.dll
c:\windows\2z49hrea55298.cpl
c:\windows\2z714worm5379.dll
c:\windows\2z833troj905.cpl
c:\windows\2z9765acktool51a.exe
c:\windows\2zfd5pyware9213.cpl
c:\windows\305589rojz35.dll
c:\windows\30624zpa5bot396.bin
c:\windows\30630vir5sze9.exe
c:\windows\30765haczto9l72f.cpl
c:\windows\3080v9z1495.dll
c:\windows\3099spywarez859.dll
c:\windows\312465p9zc1.bin
c:\windows\3177backdozr6955.ocx
c:\windows\324bdo5nl9ader292z.exe
c:\windows\3292virusz55.bin
c:\windows\35053spy4z9.cpl
c:\windows\351ea5d9zre1099.dll
c:\windows\35499zroj75d.dll
c:\windows\355eb9ckdoor16z.bin
c:\windows\35ez9hief1000.exe
c:\windows\36fthz9at58958.bin
c:\windows\37bab9c5dozr2792.cpl
c:\windows\38z0not-a-viru599.dll
c:\windows\3917v9r318z5.cpl
c:\windows\3952v5rzs719.exe
c:\windows\39559worm54z.bin
c:\windows\39b0zi52996.dll
c:\windows\39z5vir1519.bin
c:\windows\39zdst5al3025.exe
c:\windows\3d5ethrzat26795.bin
c:\windows\3d9a5ownloadzr704.cpl
c:\windows\3dz7downloa9er2550.cpl
c:\windows\3dze9ownl5ader869.exe
c:\windows\3e28th5ez9206.ocx
c:\windows\3ez3thre958034.exe
c:\windows\3f93dzwn5oa9er395.exe
c:\windows\3z8abac9door29975.exe
c:\windows\3za89parse2566.exe
c:\windows\40559roj73cz.exe
c:\windows\4192vzru554d.exe
c:\windows\4221dz9nloader553.cpl
c:\windows\4295thief15z2.dll
c:\windows\42addw5z91632.bin
c:\windows\4445spywaze69.exe
c:\windows\44db5hreatz62949.dll
c:\windows\4582zackd9or2251.bin
c:\windows\45a6thrzat6192.bin
c:\windows\4605zd95are3242.bin
c:\windows\4823hacz9o5l69a.bin
c:\windows\4841not59-virus20z.ocx
c:\windows\4896vir5z44c.exe
c:\windows\4934vzrus155.exe
c:\windows\495dthzeat1292.ocx
c:\windows\49f9dozn5oader542.ocx
c:\windows\49z35hief2258.ocx
c:\windows\49z3addware2955.cpl
c:\windows\4a6as9ez510.cpl
c:\windows\4b32ad5ware997z.dll
c:\windows\4bf5backd9orz066.dll
c:\windows\4f22vi5984z.exe
c:\windows\4fze9i51026.ocx
c:\windows\4z93t9ief5295.bin
c:\windows\4zathi9f5180.cpl
c:\windows\50106spzmb9t206.cpl
c:\windows\50195hacktzol29d.ocx
c:\windows\5099bzckdoor995.exe
c:\windows\509ez9wnlo5der1797.dll
c:\windows\50baspaz9e16145.bin
c:\windows\5125bac9dooz2537.cpl
c:\windows\5142zvirusc9.dll
c:\windows\5158vir5s6bz9.dll
c:\windows\515thief1z92.dll
c:\windows\515z8vi9us2b3.exe
c:\windows\516zspa9bot1f7.cpl
c:\windows\51ccthi9f7z2.bin
c:\windows\51fddoznloa9er1810.ocx
c:\windows\51z5threa526739.ocx
c:\windows\526thz59t29894.ocx
c:\windows\52z79troj4cb.cpl
c:\windows\5549vi9uz6db.bin
c:\windows\55639not-a-9irus102z.exe
c:\windows\557zthief9491.ocx
c:\windows\5599worm16ez.ocx
c:\windows\56509ackdoor2519z.cpl
c:\windows\5682not-a-v9ruz5b9.cpl
c:\windows\5686zworm989.cpl
c:\windows\5690download5r2z77.bin
c:\windows\56e7thre5t19z799.bin
c:\windows\572s5zm9ot43d.ocx
c:\windows\57z5tro941c.ocx
c:\windows\59216zirus2e1.cpl
c:\windows\59255not-a9zirus26a.exe
c:\windows\5953trzj55a.ocx
c:\windows\5992addwzre2977.exe
c:\windows\59afaddwa5e324z.exe
c:\windows\59d5zir3263.dll
c:\windows\59z5spyware789.cpl
c:\windows\5a1b9dzw5re1539.dll
c:\windows\5aaethzef22909.dll
c:\windows\5ab5backdoor3929z.cpl
c:\windows\5ac9addwzre5525.ocx
c:\windows\5b92ba5kdoor980z.cpl
c:\windows\5c57zackdoor296.ocx
c:\windows\5czd5hr9at28391.bin
c:\windows\5d92t5z9at4081.exe
c:\windows\5defthie91423z.ocx
c:\windows\5e595zars9729.bin
c:\windows\5e9adow5loade93245z.cpl
c:\windows\5f1c5teaz24469.exe
c:\windows\5fe7spy5aze1595.dll
c:\windows\5z5sparse18985.ocx
c:\windows\5zcba9dwar52815.ocx
c:\windows\6014tzie9517.bin
c:\windows\60a5downloader105z9.bin
c:\windows\60c1spa9sez8615.dll
c:\windows\60eeszeal26955.bin
c:\windows\6135tro9z58.exe
c:\windows\6216noz-a-v9r5s688.exe
c:\windows\6287s5arze22819.dll
c:\windows\6355dow9loaderz019.exe
c:\windows\6355sp59zot6c7.ocx
c:\windows\6495thief1z3.cpl
c:\windows\6541zteal9787.cpl
c:\windows\65z5vi91703.dll
c:\windows\661b5hief1z93.dll
c:\windows\693dsp5rsez796.exe
c:\windows\6991szyware9545.exe
c:\windows\69feb9zkdo5r1226.bin
c:\windows\6b99st9al547z.bin
c:\windows\6c459ir2155z.ocx
c:\windows\6c59backdozr530.cpl
c:\windows\6c62s95alz578.bin
c:\windows\6c95virz065.cpl
c:\windows\6d69dowzl5ader85.ocx
c:\windows\6z09d5wnloa9er112.ocx
c:\windows\6z19vir1557.dll
c:\windows\705bszar9e14.cpl
c:\windows\7165thr9az27785.ocx
c:\windows\72zdownloade522909.exe
c:\windows\7435sp95z7.ocx
c:\windows\74bsparse5914z.ocx
c:\windows\7516spam5o9zd8.dll
c:\windows\7522tzief8569.dll
c:\windows\753athre9t13379z.cpl
c:\windows\755fthrea9117z6.cpl
c:\windows\75z4st9al1645.cpl
c:\windows\761zthre9t160945.dll
c:\windows\7816haz59ool542.exe
c:\windows\789sp9576z.cpl
c:\windows\78c5stzal9505.cpl
c:\windows\790z95-a-virus517.bin
c:\windows\797not-a-v5ru9z74.exe
c:\windows\79azddwar51106.exe
c:\windows\79c9thief5851z.ocx
c:\windows\79f5stezl28069.exe
c:\windows\79f9spa5sez11.ocx
c:\windows\7abcsp9rsez0935.bin
c:\windows\7b35steal9987z.bin
c:\windows\7baft9zef1945.ocx
c:\windows\7d0bad9zare5985.bin
c:\windows\7z225hief9706.ocx
c:\windows\7z30vi5us3459.bin
c:\windows\8001not-z-v9ru5627.bin
c:\windows\84799pz547.bin
c:\windows\84z1wo9m7c5.dll
c:\windows\8887not-a5v9rzs538.bin
c:\windows\90d5downlozder939.ocx
c:\windows\90f7dowzloader165.bin
c:\windows\9105t5ief1z04.ocx
c:\windows\9150virzs275.dll
c:\windows\91675trojza1.bin
c:\windows\921465pyfz.dll
c:\windows\92647vzrus555.exe
c:\windows\9292not9azv5rus606.ocx
c:\windows\93593spamboz45b.dll
c:\windows\93z2spambot659.cpl
c:\windows\9406s5ambot3z9.exe
c:\windows\94300tro51b8z.dll
c:\windows\94addware25z5.ocx
c:\windows\950vir857z.bin
c:\windows\9562ztro5161.exe
c:\windows\962zspambo911d5.exe
c:\windows\96479vi5us6cz.bin
c:\windows\96ezspywar5117.ocx
c:\windows\97251troj1z4.exe
c:\windows\981sz5rse2653.exe
c:\windows\9854spy5z.bin
c:\windows\99551viruz2ef.exe
c:\windows\9983not-a-viru5f8z.bin
c:\windows\9dzadd9are105.dll
c:\windows\9z471tro56cd.bin
c:\windows\a10addwa9e5z44.cpl
c:\windows\abt9izf5513.bin
c:\windows\APanel.exe
c:\windows\bf5addw9re253z.bin
c:\windows\d89sp5zse1932.exe
c:\windows\e5cdownloadez1791.cpl
c:\windows\ehyrehyky.inf
c:\windows\ez2back95or3094.dll
c:\windows\Installer\7e82.msi
c:\windows\Installer\f91f.msi
c:\windows\prxid93ps.dat
c:\windows\server.exe
c:\windows\system32\1021zno5-a-virus57b9.exe
c:\windows\system32\10543z5951e.bin
c:\windows\system32\10790vi5us2z6.bin
c:\windows\system32\10d5do9nlozde51870.bin
c:\windows\system32\11f2a5dware9966z.cpl
c:\windows\system32\12361hack95ol256z.cpl
c:\windows\system32\1258thzea595094.ocx
c:\windows\system32\129cthze5t23845.ocx
c:\windows\system32\12d5sp9ware517z.exe
c:\windows\system32\12z45sp9mbot24b.dll
c:\windows\system32\134379az5tool6a4.bin
c:\windows\system32\135z9spambot7d4.bin
c:\windows\system32\13716not-z-vir5s9c2.exe
c:\windows\system32\139add5aze2718.ocx
c:\windows\system32\13z82s9ambot158.exe
c:\windows\system32\1403b9c5door1z10.cpl
c:\windows\system32\143435irus79z.exe
c:\windows\system32\1465z9pyde.ocx
c:\windows\system32\14830wormz095.bin
c:\windows\system32\14beth9ef15z2.cpl
c:\windows\system32\150z4not-a-5i9us594.exe
c:\windows\system32\15556sp938z.exe
c:\windows\system32\15562not-a-9iruz373.exe
c:\windows\system32\15583vizus5c9.dll
c:\windows\system32\15589spz744.cpl
c:\windows\system32\15592spy52z.ocx
c:\windows\system32\155fthiez1469.dll
c:\windows\system32\15679spy32z9.cpl
c:\windows\system32\15727v9ruz324.bin
c:\windows\system32\1590zpyw5re2550.bin
c:\windows\system32\15923hacktoz57c5.bin
c:\windows\system32\15z09spambot1b2.exe
c:\windows\system32\160z9vi5us9e1.dll
c:\windows\system32\16381sp5mb9t18z.exe
c:\windows\system32\16395szamb9t560.cpl
c:\windows\system32\16963not-9-viru5z03.cpl
c:\windows\system32\17095hacktool6az.bin
c:\windows\system32\17174vir59z30.ocx
c:\windows\system32\17486zpambo97e95.exe
c:\windows\system32\179z35orm45c.cpl
c:\windows\system32\17c59ownlzader511.dll
c:\windows\system32\1818095zj411.exe
c:\windows\system32\186795arsz1929.cpl
c:\windows\system32\19108h5cktool2z0.exe
c:\windows\system32\191175irus5z9.bin
c:\windows\system32\19215troj6z89.dll
c:\windows\system32\1946195y3z1.exe
c:\windows\system32\194eback5oor2076z.ocx
c:\windows\system32\194z5spy525.dll
c:\windows\system32\1952z5py583.dll
c:\windows\system32\19934wozm5e5.exe
c:\windows\system32\19951s9zmbot1f5.exe
c:\windows\system32\19z25spy3e5.ocx
c:\windows\system32\19z53spamb5t3869.exe
c:\windows\system32\1a9esparse1285z.cpl
c:\windows\system32\1bz0stea94635.ocx
c:\windows\system32\1ea1s5ealz529.exe
c:\windows\system32\1f22threat593z0.bin
c:\windows\system32\1fe5s9arse2740z.dll
c:\windows\system32\1z0695r9j81.exe
c:\windows\system32\1z2569py45a.exe
c:\windows\system32\1z692spy5849.bin
c:\windows\system32\1z99bac5door9050.exe
c:\windows\system32\20845zo9m52.cpl
c:\windows\system32\21257zorm3f9.bin
c:\windows\system32\21599spamboz518.dll
c:\windows\system32\21702troz59.cpl
c:\windows\system32\21955wo5m73az.dll
c:\windows\system32\22049zpambot75e.cpl
c:\windows\system32\22695hacktzo55e9.bin
c:\windows\system32\22755ziru9514.cpl
c:\windows\system32\22easzy9are5613.exe
c:\windows\system32\23300hacktzo9153.dll
c:\windows\system32\237z7v5rus549.ocx
c:\windows\system32\24441h5cktool3zb9.exe
c:\windows\system32\245spywzr9764.dll
c:\windows\system32\24659hacktooz15c.bin
c:\windows\system32\24905spamzot505.exe
c:\windows\system32\249965orm2z0.bin
c:\windows\system32\24c5downloade5z599.bin
c:\windows\system32\25191spa5bot63cz.dll
c:\windows\system32\252019iru53z.cpl
c:\windows\system32\25275zacktool918.dll
c:\windows\system32\25431noz-a-virus9f.dll
c:\windows\system32\256zt59j255.bin
c:\windows\system32\25899izus38d.dll
c:\windows\system32\25996wo5m5z3.bin
c:\windows\system32\25d1s9eal37z.dll
c:\windows\system32\25f2z5eal899.bin
c:\windows\system32\25z19spambot629.exe
c:\windows\system32\25z39vir95269.exe
c:\windows\system32\25z6not-a-virus9b65.dll
c:\windows\system32\26561zot5a-vi9us14c.cpl
c:\windows\system32\26599z5kdoor1529.dll
c:\windows\system32\26892hacktool65z.bin
c:\windows\system32\27162s5azbot339.dll
c:\windows\system32\2730ztro92b75.ocx
c:\windows\system32\27335hackto9z166.bin
c:\windows\system32\27685ackzool904.bin
c:\windows\system32\2813zt59j7c.cpl
c:\windows\system32\28256ha9ztool635.dll
c:\windows\system32\2826s5eal226z9.exe
c:\windows\system32\28355sz9mbot3a7.exe
c:\windows\system32\284159pyz9.ocx
c:\windows\system32\28972not-a-virzs2ee5.bin
c:\windows\system32\28aez5arse3109.bin
c:\windows\system32\28z9addw5re1234.dll
c:\windows\system32\29023hac9toolz85.exe
c:\windows\system32\2916trojz115.cpl
c:\windows\system32\294695rojz05.bin
c:\windows\system32\29503zpy5545.dll
c:\windows\system32\2952zh9cktoole1.cpl
c:\windows\system32\29531not-a-vi9uz42.dll
c:\windows\system32\29590za5ktool210.dll
c:\windows\system32\2959steaz241.exe
c:\windows\system32\295zwor915a.cpl
c:\windows\system32\29634not-a-virus25z5.dll
c:\windows\system32\296669zoj85.dll
c:\windows\system32\29773troj758z.cpl
c:\windows\system32\2981ste5l19z8.bin
c:\windows\system32\29bdt9zef24745.bin
c:\windows\system32\29z17h5cktoo910a.bin
c:\windows\system32\29z78troj59.bin
c:\windows\system32\2a94bazkdoor915.bin
c:\windows\system32\2b459hi5f2z05.exe
c:\windows\system32\2c5dbackdoo91z91.cpl
c:\windows\system32\2c8fdownzoade9518.ocx
c:\windows\system32\2d1edownloaz9r520.dll
c:\windows\system32\2d8zdownlo9der1259.exe
c:\windows\system32\2dzfaddw59e1703.bin
c:\windows\system32\2e58addza9e2975.ocx
c:\windows\system32\2z006tro5693.dll
c:\windows\system32\2z13vir5s92c.cpl
c:\windows\system32\2z172ha5ktoo9408.ocx
c:\windows\system32\2z17stea92259.exe
c:\windows\system32\2z9ast5al974.exe
c:\windows\system32\30z58virus3b9.dll
c:\windows\system32\30z73sp5f19.exe
c:\windows\system32\31256zot9a-virus7475.cpl
c:\windows\system32\31293viruz515.cpl
c:\windows\system32\31541hack5zo95c5.bin
c:\windows\system32\31580hackto9l5z1.cpl
c:\windows\system32\318719pzcc5.ocx
c:\windows\system32\318csza9se1385.ocx
c:\windows\system32\31fst9z51054.exe
c:\windows\system32\31z19not-a-vi9us485.dll
c:\windows\system32\31z87worm459.dll
c:\windows\system32\32293not9a-5irus5d0z.bin
c:\windows\system32\32351not5a-vzrus75a9.bin
c:\windows\system32\335zspar9e266.exe
c:\windows\system32\33915pzrse3198.cpl
c:\windows\system32\33d9ste5lz518.ocx
c:\windows\system32\33f9spy5aze378.cpl
c:\windows\system32\350za9dware1221.bin
c:\windows\system32\35976spambo930z.dll
c:\windows\system32\3598nzt-a-virus758.cpl
c:\windows\system32\35efthreat5790z.bin
c:\windows\system32\35z4spambot5935.exe
c:\windows\system32\36495par9e3z14.exe
c:\windows\system32\365stezl950.dll
c:\windows\system32\36ae9a5kdoor2058z.exe
c:\windows\system32\3738thi9f55z.dll
c:\windows\system32\3745backd9zr853.ocx
c:\windows\system32\3755bzckdoor22459.exe
c:\windows\system32\37b2bzckdoor5395.bin
c:\windows\system32\37z75ddwar9939.dll
c:\windows\system32\3880spars9z245.bin
c:\windows\system32\3887sz9r5e2771.cpl
c:\windows\system32\38z8d5wnloader17519.bin
c:\windows\system32\38z9threat62775.ocx
c:\windows\system32\3940ztro56e6.bin
c:\windows\system32\39dda5dware223z.ocx
c:\windows\system32\39eabackdoor1z52.cpl
c:\windows\system32\3a15zp5r9e2070.exe
c:\windows\system32\3abdspzw5re9904.ocx
c:\windows\system32\3b82t5r9az21669.exe
c:\windows\system32\3c51bazkdoo5529.dll
c:\windows\system32\3cc5t5ie9115z.exe
c:\windows\system32\3de9viz2935.cpl
c:\windows\system32\3fa3a5zware13349.cpl
c:\windows\system32\3z5v9r33.bin
c:\windows\system32\3zecvi92950.bin
c:\windows\system32\403dback95zr935.cpl
c:\windows\system32\40z4vir9s4b75.cpl
c:\windows\system32\4105wozm1fa9.exe
c:\windows\system32\4174back5oor2739z.bin
c:\windows\system32\43adownzoader59.dll
c:\windows\system32\458aste9l2303z.bin
c:\windows\system32\4599hzckto5l8a.bin
c:\windows\system32\465zbackdoor9059.bin
c:\windows\system32\46ezst9a51226.bin
c:\windows\system32\4775addwaze911.cpl
c:\windows\system32\491cthre5t22z89.cpl
c:\windows\system32\492not9a-5irus6f0z.dll
c:\windows\system32\496bthz9f450.exe
c:\windows\system32\49c4add9zr51999.ocx
c:\windows\system32\49fc5ir9z18.ocx
c:\windows\system32\4a4bspywa5z5089.bin
c:\windows\system32\4a89spywar5z200.bin
c:\windows\system32\4aabdownload9r59z.dll
c:\windows\system32\4b9dstea91385z.ocx
c:\windows\system32\4cz0spywar515969.exe
c:\windows\system32\4d8cthief925z.cpl
c:\windows\system32\4e1ftzi5f9345.dll
c:\windows\system32\4f35hre9tz427.dll
c:\windows\system32\4fb0th9zf1551.ocx
c:\windows\system32\4fd3down9oadzr3105.cpl
c:\windows\system32\4ff59pazse2599.bin
c:\windows\system32\4z949ot-a-virus7d5.bin
c:\windows\system32\4zc2s9eal2655.ocx
c:\windows\system32\5005dow9zoa5er715.cpl
c:\windows\system32\5019vzrus5e9.ocx
c:\windows\system32\5099downlzade52987.exe
c:\windows\system32\50b59teal3245z.bin
c:\windows\system32\50d3thrza57299.cpl
c:\windows\system32\5158s9yzar5357.ocx
c:\windows\system32\51b0backdoor50z89.bin
c:\windows\system32\51z1ba5kdoor299.cpl
c:\windows\system32\5249troz5dd.bin
c:\windows\system32\5256thiz93203.cpl
c:\windows\system32\5277dzwnloa95r312.bin
c:\windows\system32\52a5th9eat28z87.dll
c:\windows\system32\52b5steal29z9.dll
c:\windows\system32\531dba9kdoorz767.ocx
c:\windows\system32\532espy5are1908z.dll
c:\windows\system32\5355not-a-virusz29.ocx
c:\windows\system32\53aadd59rz13.cpl
c:\windows\system32\53f1vi95z3.dll
c:\windows\system32\54z9s5arse1568.bin
c:\windows\system32\5548hackt9oz655.cpl
c:\windows\system32\5561zo5m192.exe
c:\windows\system32\55685hackzo9l10a.bin
c:\windows\system32\5584zack59or607.ocx
c:\windows\system32\558thre9t5z300.bin
c:\windows\system32\5596backdooz8159.dll
c:\windows\system32\5598a9dwzre1473.exe
c:\windows\system32\559z5orm53a.exe
c:\windows\system32\562ez5w9loader1667.bin
c:\windows\system32\5693thr5az2607.dll
c:\windows\system32\56999troz477.exe
c:\windows\system32\56bf9te5l29z.bin
c:\windows\system32\5764doznloade918325.ocx
c:\windows\system32\57a89hief924z.exe
c:\windows\system32\5829backdzo53098.exe
c:\windows\system32\58893virus750z.ocx
c:\windows\system32\58e4t9ief293z.ocx
c:\windows\system32\58zsteal14529.cpl
c:\windows\system32\590809rzj441.dll
c:\windows\system32\591faddz95e2528.cpl
c:\windows\system32\5955szarse1719.cpl
c:\windows\system32\5982thizf895.dll
c:\windows\system32\599zthreat19551.exe
c:\windows\system32\59a5spywarez35.bin
c:\windows\system32\59ethiefz783.ocx
c:\windows\system32\59ev9z1564.exe
c:\windows\system32\59f7zir1250.ocx
c:\windows\system32\5a7zspar9e878.exe
c:\windows\system32\5a96thrzat29095.ocx
c:\windows\system32\5b29sze5l1824.cpl
c:\windows\system32\5b59addwarez505.dll
c:\windows\system32\5bfeszyw95e949.dll
c:\windows\system32\5cz6vir5999.exe
c:\windows\system32\5d5zs9eal3245.exe
c:\windows\system32\5d99backdzor3605.exe
c:\windows\system32\5e6dthi5z9466.cpl
c:\windows\system32\5ed3thrzat94705.dll
c:\windows\system32\5ed5threzt99079.dll
c:\windows\system32\5fb8s5ywaze8369.ocx
c:\windows\system32\5fe3vi9z556.cpl
c:\windows\system32\5z041troj99.bin
c:\windows\system32\5z56s9arse134.ocx
c:\windows\system32\5z99wo5m655.bin
c:\windows\system32\5zca9ackdo5r2670.bin
c:\windows\system32\5zffv5r16209.cpl
c:\windows\system32\61feba9kdoor5811z.bin
c:\windows\system32\64z0spy5are1942.bin
c:\windows\system32\6519s9zware459.cpl
c:\windows\system32\6549downloadez968.cpl
c:\windows\system32\65fddownloader199z.bin
c:\windows\system32\679spzware5849.ocx
c:\windows\system32\68fdspyware9z55.dll
c:\windows\system32\68fzthreat39758.bin
c:\windows\system32\6946tzoj3e25.ocx
c:\windows\system32\6a7zdow59oader1272.cpl
c:\windows\system32\6b50ste9l3z89.exe
c:\windows\system32\6b58dow9loadez872.bin
c:\windows\system32\6becspywarz95.exe
c:\windows\system32\6cez9ir5247.ocx
c:\windows\system32\6cz5spywar92195.dll
c:\windows\system32\6d47stealz9485.cpl
c:\windows\system32\6d90zteal24975.cpl
c:\windows\system32\6e51addwaze2992.dll
c:\windows\system32\6e5abackdozr94555.bin
c:\windows\system32\700t95ezt27452.bin
c:\windows\system32\7104viz2995.cpl
c:\windows\system32\7137bac9zoor27325.bin
c:\windows\system32\7149z95219.dll
c:\windows\system32\72a0th5ez2962.dll
c:\windows\system32\72z5t5oj2729.bin
c:\windows\system32\7522s5yware29z3.cpl
c:\windows\system32\755zspyware2942.ocx
c:\windows\system32\758cst5az9218.exe
c:\windows\system32\75ezspyware9451.dll
c:\windows\system32\75zown9oader979.ocx
c:\windows\system32\7714virz59.cpl
c:\windows\system32\7828vi52z69.ocx
c:\windows\system32\7888ha9ktool156z.ocx
c:\windows\system32\78z2b9c5door539.bin
c:\windows\system32\7925hazktool4f5.cpl
c:\windows\system32\7945hacktzol6465.bin
c:\windows\system32\7a85addware29z3.bin
c:\windows\system32\7c03backd9oz5307.cpl
c:\windows\system32\7d57virz2729.bin
c:\windows\system32\7da7zownloader5989.cpl
c:\windows\system32\7z18th59at3649.exe
c:\windows\system32\7z1avi93550.bin
c:\windows\system32\7z99th5eat15435.dll
c:\windows\system32\871spambot5zd9.exe
c:\windows\system32\8955spzmb9t384.exe
c:\windows\system32\897thizf2257.ocx
c:\windows\system32\89zbackdoo9415.exe
c:\windows\system32\90609hacktoo51za.exe
c:\windows\system32\90909virusz5e.ocx
c:\windows\system32\9093zo5m186.dll
c:\windows\system32\90z9addware2295.bin
c:\windows\system32\9122hack9oolz54.dll
c:\windows\system32\91431vzrus6bf5.exe
c:\windows\system32\92095vzrus68a.bin
c:\windows\system32\9243thzef2875.exe
c:\windows\system32\9265thiefz75.ocx
c:\windows\system32\926a5teal2z82.exe
c:\windows\system32\9315pz161.exe
c:\windows\system32\9318n5t9a-virzs249.bin
c:\windows\system32\934zt5oj40d.exe
c:\windows\system32\9385t5zef2263.dll
c:\windows\system32\943zvi5us981.ocx
c:\windows\system32\946495py32cz.ocx
c:\windows\system32\949steaz957.bin
c:\windows\system32\9574spy657z.bin
c:\windows\system32\9587zspambot56f.cpl
c:\windows\system32\95a3downloz5er456.bin
c:\windows\system32\9609sz5ware2660.exe
c:\windows\system32\961hac9tool6z5.exe
c:\windows\system32\9850dzwnloader555.ocx
c:\windows\system32\98a0steal2z65.bin
c:\windows\system32\98cspar9e5130z.ocx
c:\windows\system32\99265i9usz58.ocx
c:\windows\system32\99371zp54cb.bin
c:\windows\system32\996zspy795.exe
c:\windows\system32\9972zirus205.exe
c:\windows\system32\998thief1365z.exe
c:\windows\system32\9995virus58z5.ocx
c:\windows\system32\9b5evzr1921.exe
c:\windows\system32\9e72steal52z1.exe
c:\windows\system32\9f56viz692.exe
c:\windows\system32\9f5dthreat320z4.exe
c:\windows\system32\9z63ste5l3180.bin
c:\windows\system32\a259ir53z.dll
c:\windows\system32\a69downloadez2953.exe
c:\windows\system32\a6zthreat59290.cpl
c:\windows\system32\b39stzal2519.cpl
c:\windows\system32\b485dd9arz975.exe
c:\windows\system32\birakuze.dll
c:\windows\system32\bzcs5ywa9e956.bin
c:\windows\system32\dajifuji.dll
c:\windows\system32\drivers\ndisrd.sys
c:\windows\system32\e99tz9e5t18598.exe
c:\windows\system32\f585te9l72z.dll
c:\windows\system32\fesumuye.dll
c:\windows\system32\gomujude.dll
c:\windows\system32\gunosibi.dll
c:\windows\system32\hisekeke.exe
c:\windows\system32\jaduzumi.dll
c:\windows\system32\kafunepi.exe
c:\windows\system32\loyayono.dll
c:\windows\system32\lusumune.dll
c:\windows\system32\navifaya.dll
c:\windows\system32\ndisapi.dll
c:\windows\system32\nefavega.dll
c:\windows\system32\nizedage.dll
c:\windows\system32\pagapobo.dll
c:\windows\system32\pulovuwi.dll
c:\windows\system32\ralobupo.dll
c:\windows\system32\repozuyi.dll
c:\windows\system32\ribemago.dll
c:\windows\system32\sejuvoma.exe
c:\windows\system32\supekede.exe
c:\windows\system32\tasagywow.exe
c:\windows\system32\tayufazu.dll
c:\windows\system32\tigefeki.dll
c:\windows\system32\tomatofi.exe
c:\windows\system32\uacinit.dll
c:\windows\system32\winhelper.dll
c:\windows\system32\winupdate.exe
c:\windows\system32\yapipije.dll
c:\windows\system32\yfipawezej.dl
c:\windows\system32\yirepoje.exe
c:\windows\system32\yirumuno.exe
c:\windows\system32\z1947not-a-virus3e85.ocx
c:\windows\system32\z199spambo524.bin
c:\windows\system32\z1e3d59nloader483.exe
c:\windows\system32\z235s95mbot49f.cpl
c:\windows\system32\z3379vir9s5625.cpl
c:\windows\system32\z35spa9bot7c3.exe
c:\windows\system32\z5314tr9j86.bin
c:\windows\system32\z55th9ef524.exe
c:\windows\system32\z5813no59a-virus3c1.ocx
c:\windows\system32\z5cdownload59372.ocx
c:\windows\system32\z696spa5se2739.bin
c:\windows\system32\z6f35hreat75999.dll
c:\windows\system32\z722t9oj6c5.dll
c:\windows\system32\z7570hac59ool715.ocx
c:\windows\system32\z8566troj942.ocx
c:\windows\system32\z89w95me5.dll
c:\windows\system32\z8d59ackdoo51792.exe
c:\windows\system32\z9359hacktoo940e.cpl
c:\windows\system32\z95asparse1669.cpl
c:\windows\system32\z9a5vir2996.bin
c:\windows\system32\zbdbback5oor9691.cpl
c:\windows\system32\ze60b9ckdoor2245.bin
c:\windows\system32\zedcdo9nloader27125.bin
c:\windows\system32\zesp5wa9e621.exe
c:\windows\system32\zuwuvenu.dll
c:\windows\th823567.dat
c:\windows\uzixosyd.inf
c:\windows\z04885ackt9ol401.cpl
c:\windows\z159a9dware25955.cpl
c:\windows\z240bac5door1929.cpl
c:\windows\z356spy229.cpl
c:\windows\z383th5e91274.ocx
c:\windows\z5195worm7a9.dll
c:\windows\z5539acktool791.cpl
c:\windows\z57bac9door3115.exe
c:\windows\z5976hacktool199.ocx
c:\windows\z5ccthreat12490.exe
c:\windows\z5e79ir768.bin
c:\windows\z637a59ware728.ocx
c:\windows\z6496s5am9otdd.ocx
c:\windows\z65ct9ief878.exe
c:\windows\z699tr5j179.ocx
c:\windows\z8195spy7c4.cpl
c:\windows\z8799hacktool4fb5.bin
c:\windows\z942virus3959.exe
c:\windows\z9thief451.cpl
c:\windows\zbf75hief9017.bin
c:\windows\zc2e5ir9079.cpl
c:\windows\zc66v9r2507.dll
c:\windows\zd43downloade918235.ocx
c:\windows\ze6dv9r5274.ocx
c:\windows\zfc5vi92657.ocx

----- BITS: Possible infected sites -----

[You must be registered and logged in to see this link.]
c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_NDISRD
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_MyWebSearchService
-------\Service_NDISRD


((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
.

2009-12-10 17:10 . 2009-12-10 17:10 9685 ----a-w- c:\windows\system32\9505zpy7.bin
2009-09-10 00:34 . 2009-09-10 00:34 -------- d-----w- c:\program files\New Folder
2009-09-10 00:33 . 2009-09-10 00:33 -------- d-----w- C:\New Folder
2009-09-09 21:14 . 2009-09-09 21:14 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-09-09 12:32 . 2009-09-09 12:32 -------- d-----w- c:\program files\Angle Interactive
2009-09-08 18:45 . 2009-09-08 18:45 -------- d-----w- c:\program files\Trend Micro
2009-09-08 18:12 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 18:12 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 13:06 . 2009-09-10 12:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-08 12:14 . 2009-09-08 12:14 390144 ----a-w- c:\windows\system32\huej1nqg.exe
2009-09-08 02:57 . 2009-07-28 20:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-08 02:57 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-08 02:57 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-09-08 02:57 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-09-08 02:57 . 2009-09-08 02:57 -------- d-----w- c:\program files\Avira
2009-09-08 02:57 . 2009-09-08 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-09-08 02:15 . 2009-09-08 02:15 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\HP
2009-09-07 21:53 . 2009-09-07 21:53 -------- d-----w- c:\documents and settings\tina gibson\Application Data\TeamViewer
2009-09-07 21:52 . 2009-09-07 21:52 -------- d-----w- c:\documents and settings\tina gibson\temp
2009-09-07 21:25 . 2009-09-07 21:28 -------- d-----w- c:\program files\Counter-Strike 1.6
2009-09-07 20:44 . 2009-09-07 20:44 -------- d-----w- c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP
2009-09-07 20:40 . 2009-09-07 20:40 -------- d---a-w- c:\program files\DOTNETFX
2009-09-07 20:08 . 2006-03-21 09:15 839680 ----a-w- c:\program files\steamclient.dll
2009-09-07 20:08 . 2006-03-21 09:15 61440 ----a-w- c:\program files\steam_api.dll
2009-09-07 20:07 . 2006-03-21 09:15 3649536 ----a-w- c:\program files\Steam.dll
2009-09-07 20:03 . 2009-09-07 20:04 1556480 ----a-w- c:\program files\hw.dll
2009-09-07 20:03 . 2005-09-30 02:47 221184 ----a-w- c:\program files\hltv.exe
2009-09-07 20:03 . 2005-09-30 02:47 397312 ----a-w- c:\program files\hlds.exe
2009-09-07 20:03 . 2005-09-30 02:42 81920 ----a-w- c:\program files\hl.exe
2009-09-07 20:03 . 2005-09-30 02:47 122980 ----a-w- c:\program files\FileSystem_Steam.dll
2009-09-07 20:03 . 2005-09-30 02:47 118873 ----a-w- c:\program files\FileSystem_Stdio.dll
2009-09-07 20:03 . 2005-09-30 02:42 90112 ----a-w- c:\program files\DemoPlayer.dll
2009-09-07 20:03 . 2005-09-30 02:47 69632 ----a-w- c:\program files\dbg.dll
2009-09-07 20:03 . 2005-09-30 02:47 225280 ----a-w- c:\program files\Core.dll
2009-09-07 20:03 . 2005-09-30 02:42 211456 ----a-w- c:\program files\a3dapi.dll
2009-09-07 19:55 . 2008-12-25 12:00 67826994 ----a-w- c:\windows\Counter strike 1.6.exe
2009-09-07 17:26 . 2009-09-10 21:19 -------- d-----w- c:\program files\Steam
2009-09-06 03:00 . 2009-09-06 03:00 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-09-03 18:07 . 2009-09-03 18:07 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-08-30 04:05 . 2009-08-30 04:11 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-08-30 04:05 . 2009-08-30 04:21 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-08-30 04:05 . 2009-08-30 04:05 -------- d-----w- c:\program files\Common Files\iS3
2009-08-29 21:07 . 2009-08-29 21:15 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Xfire
2009-08-29 04:44 . 2009-08-30 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\12521094
2009-08-29 04:38 . 2008-04-14 22:00 4224 ----a-w- c:\windows\system32\drivers\beep.sys
2009-08-28 01:13 . 2009-09-07 19:03 -------- d-----w- c:\program files\Counter-Strike 1.6 Non-Steam 2009-04-29
2009-08-24 00:29 . 2009-08-28 00:34 -------- d-----w- c:\program files\Counter-Strike
2009-08-22 14:10 . 2009-08-23 23:15 -------- d-----w- c:\program files\VALVe
2009-08-22 04:42 . 2009-08-23 02:22 -------- d-----w- c:\program files\AskBarDis
2009-08-14 03:41 . 2009-08-14 03:41 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-10 12:19 . 2009-06-10 12:19 88576 --sha-w- c:\windows\system32\gipunowe.dll
2009-09-10 00:19 . 2009-06-10 00:19 88064 --sha-w- c:\windows\system32\ludiyofu.dll
2009-09-09 21:14 . 2009-06-18 04:27 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-09 12:18 . 2009-06-09 12:18 88064 --sha-w- c:\windows\system32\piyadayi.dll
2009-09-09 00:18 . 2009-06-09 00:18 88064 --sha-w- c:\windows\system32\juvilisi.dll
2009-09-08 23:59 . 2009-07-09 04:19 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Xfire
2009-09-08 22:35 . 2009-07-06 04:42 -------- d-----w- c:\program files\Xfire
2009-09-08 12:18 . 2009-06-08 12:18 89088 --sha-w- c:\windows\system32\gijiyeli.dll
2009-09-08 11:18 . 2009-05-27 23:54 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Symantec
2009-09-08 11:17 . 2008-10-29 01:27 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-09-08 03:42 . 2008-10-29 01:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-09-07 04:45 . 2009-06-07 04:45 49664 --sha-w- c:\windows\system32\nebiteda.dll
2009-09-07 04:45 . 2009-06-07 04:45 88576 --sha-w- c:\windows\system32\pavogare.dll
2009-09-06 16:45 . 2009-06-06 16:45 88064 --sha-w- c:\windows\system32\latavija.dll
2009-09-06 04:18 . 2008-10-29 01:06 -------- d-----w- c:\program files\Google
2009-09-06 01:59 . 2009-06-06 01:59 88576 --sha-w- c:\windows\system32\vamonumi.dll
2009-09-05 13:59 . 2009-06-05 13:59 88064 --sha-w- c:\windows\system32\pimenuda.dll
2009-09-04 20:43 . 2009-06-04 20:43 88064 --sha-w- c:\windows\system32\huyowoza.dll
2009-09-03 20:36 . 2009-06-03 20:36 88576 --sha-w- c:\windows\system32\hemokelu.dll
2009-08-31 22:18 . 2009-05-31 22:18 49152 --sha-w- c:\windows\system32\hufowebi.dll
2009-08-31 22:18 . 2009-05-31 22:18 83968 --sha-w- c:\windows\system32\liwoduki.dll
2009-08-30 04:12 . 2009-08-30 04:06 2024 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-08-30 04:12 . 2009-08-30 04:11 2232 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-08-29 23:33 . 2009-07-04 06:30 -------- d-----w- c:\program files\Yahoo!
2009-08-29 16:44 . 2009-05-29 16:44 84480 --sha-w- c:\windows\system32\nukizota.dll
2009-08-29 16:14 . 2009-08-29 16:14 141 ----a-w- c:\windows\tmp.tmp.tmp
2009-08-29 04:44 . 2009-05-29 04:44 84480 --sha-w- c:\windows\system32\lofuvika.dll
2009-08-23 06:23 . 2008-10-29 01:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-18 23:17 . 2008-10-29 01:09 -------- d-----w- c:\program files\eMachines Games
2009-08-18 23:17 . 2008-10-29 01:09 -------- d-----w- c:\documents and settings\All Users\Application Data\WildTangent
2009-08-14 00:51 . 2009-08-14 00:51 15829 ----a-w- c:\documents and settings\All Users\Application Data\usywupox.dat
2009-08-12 20:22 . 2009-05-28 02:09 60664 ----a-w- c:\documents and settings\kaitie justice\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-10 00:21 . 2009-05-27 23:55 60664 ----a-w- c:\documents and settings\tina gibson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2008-04-14 22:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 18:32 . 2009-09-07 20:09 1689 ----a-w- c:\program files\Dedicated Server.lnk
2009-07-28 20:51 . 2009-07-28 20:51 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\Pogo Games
2009-07-28 20:25 . 2009-06-13 02:16 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\PlayFirst
2009-07-28 20:25 . 2009-06-01 01:47 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-07-26 09:38 . 2009-07-26 09:38 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-07-22 00:01 . 2009-07-22 00:01 -------- d-----w- c:\program files\TeamViewer
2009-07-18 22:19 . 2009-07-17 08:58 -------- d-----w- c:\program files\Common Files\Uninstall
2009-07-18 22:11 . 2009-07-18 22:11 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Malwarebytes
2009-07-18 22:11 . 2009-07-18 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 03:33 . 2009-07-18 03:33 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Fuel Industries
2009-07-17 19:01 . 2008-04-14 22:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 19:22 . 2009-07-16 19:22 -------- d-----w- c:\documents and settings\LocalService\Application Data\Xfire
2009-07-16 03:20 . 2009-07-16 03:20 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Scrabble Plus
2009-07-12 16:21 . 2008-04-14 22:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2007-08-14 02:54 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-04-14 22:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 22:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2008-04-14 22:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2008-04-14 22:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2008-04-14 22:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2008-04-14 22:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2008-04-14 22:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2008-04-14 22:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2008-04-14 22:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-20 19:50 . 2008-10-29 01:04 1024 ---h--r- c:\windows\system32\NTIMP3.dll
2009-06-16 14:36 . 2008-04-14 22:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-04-14 22:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-13 00:28 . 2009-06-13 00:28 339968 ----a-w- c:\windows\system32\pythoncom25.dll
2009-06-13 00:28 . 2009-06-13 00:28 2117632 ----a-w- c:\windows\system32\python25.dll
2009-06-13 00:28 . 2009-06-13 00:28 114688 ----a-w- c:\windows\system32\pywintypes25.dll
2009-06-13 00:28 . 2007-01-09 06:17 348160 ----a-w- c:\windows\system32\msvcr71.dll
2005-09-30 02:47 . 2009-09-07 20:03 24705 ----a-w- c:\program files\HLTV-Readme.txt
2005-09-30 02:47 . 2009-09-07 20:03 786 ----a-w- c:\program files\hlds_steamgames.vdf
2005-09-30 02:47 . 2009-09-07 20:03 1569 ----a-w- c:\program files\hltv.cfg
2005-08-13 19:24 . 2009-09-07 20:03 171014 ----a-w- c:\program files\hl.ico
2009-05-31 22:18 . 2009-05-31 22:18 49152 --sha-w- c:\windows\system32\fanenoto.dll.tmp
2009-06-07 04:46 . 2009-06-07 04:46 49664 --sha-w- c:\windows\system32\muyolule.dll
2009-05-29 16:44 . 2009-05-29 16:44 526 --sha-w- c:\windows\system32\sijorera.dll
2009-05-30 04:45 . 2009-05-30 04:45 526 --sha-w- c:\windows\system32\suhokamo.dll
2009-05-30 17:51 . 2009-05-30 17:51 526 --sha-w- c:\windows\system32\vutojisi.dll
2009-05-31 22:18 . 2009-05-31 22:18 49152 --sha-w- c:\windows\system32\welatili.dll.tmp
.

------- Sigcheck -------

[7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\eventlog.dll

c:\windows\system32\eventlog.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d2be9f52-416b-4ba8-9790-a7b44e2da14c}]
2009-06-07 04:46 49664 ---ha-w- c:\windows\system32\juvoludi.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-29 68856]
"Steam"="c:\program files\Steam\Steam.exe" [2009-09-07 1217784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-25 81920]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-29 24064]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-09-25 210216]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-07-10 421888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-09-06 122368]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"lejehipahe"="c:\windows\system32\muyolule.dll" [2009-06-07 49664]
"nejujatal"="c:\windows\system32\piyadayi.dll" [2009-09-09 88064]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-02-25 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]

c:\documents and settings\kaitie justice\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{13c2daae-c95c-4485-b4f0-3441a286883d}"= "c:\windows\system32\piyadayi.dll" [2009-09-09 88064]
"{4428a968-ffa0-4244-ad19-7ff6f140aa11}"= "c:\windows\system32\gijiyeli.dll" [2009-09-08 89088]
"{272e3cae-74e8-4d32-9e18-bd675d453c5b}"= "c:\windows\system32\piyadayi.dll" [2009-09-09 88064]
"{0e6d1c10-90fb-4035-ba95-30bdc36d05f4}"= "c:\windows\system32\gipunowe.dll" [2009-09-10 88576]
"{0729bb72-3eeb-433d-8ac4-42b5a3228c0c}"= "c:\windows\system32\gijiyeli.dll" [2009-09-08 89088]
"{1060b1af-75eb-433a-9304-5853bf60d8fd}"= "c:\windows\system32\piyadayi.dll" [2009-09-09 88064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"wakiyuyob"= {13c2daae-c95c-4485-b4f0-3441a286883d} - c:\windows\system32\piyadayi.dll [2009-09-09 88064]
"wasuneyez"= {4428a968-ffa0-4244-ad19-7ff6f140aa11} - c:\windows\system32\gijiyeli.dll [2009-09-08 89088]
"viludigow"= {272e3cae-74e8-4d32-9e18-bd675d453c5b} - c:\windows\system32\piyadayi.dll [2009-09-09 88064]
"dotuladuv"= {0e6d1c10-90fb-4035-ba95-30bdc36d05f4} - c:\windows\system32\gipunowe.dll [2009-09-10 88576]
"jozafuzek"= {0729bb72-3eeb-433d-8ac4-42b5a3228c0c} - c:\windows\system32\gijiyeli.dll [2009-09-08 89088]
"fihagaror"= {1060b1af-75eb-433a-9304-5853bf60d8fd} - c:\windows\system32\gijiyeli.dll [2009-09-08 89088]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Steam\\steamapps\\peydro55\\counter-strike\\hl.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\explorer.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/7/2009 10:57 PM 108289]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 5:11 PM 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 2:42 AM 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 7:03 AM 131072]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [10/28/2008 9:05 PM 24064]
S4 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [8/22/2009 12:42 AM 234888]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
IE: &Search
DPF: CabBuilder - [You must be registered and logged in to see this link.]
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - [You must be registered and logged in to see this link.]
.
- - - - ORPHANS REMOVED - - - -

Toolbar-SITEguard - (no file)
HKLM-Run-LaunchApp - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-09-10 17:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2091681362-145439996-2945738896-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3276)
c:\windows\system32\WININET.dll
c:\windows\system32\muyolule.dll
c:\windows\system32\piyadayi.dll
c:\windows\system32\gijiyeli.dll
c:\windows\system32\gipunowe.dll
c:\windows\system32\ieframe.dll
c:\program files\Google\Quick Search Box\bin\1.2.1137.3514\qsb.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\rundll32.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-09-10 17:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-10 21:22

Pre-Run: 56,054,894,592 bytes free
Post-Run: 56,908,816,384 bytes free

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Fri Sep 11, 2009 9:23 pm

hey i finally got malwarebytes to run thought you might need the logfile t
Database version: 2551
Windows 5.1.2600 Service Pack 3

9/11/2009 5:20:24 PM
mbam-log-2009-09-11 (17-20-24).txt

Scan type: Quick Scan
Objects scanned: 106075
Time elapsed: 19 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 13

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\zevigulo.dll (Trojan.Vundo.H) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{244e3751-17fb-4ec3-8346-3514cb92442a} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\nejujatal (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{244e3751-17fb-4ec3-8346-3514cb92442a} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\vayowifon (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\zevigulo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\zevigulo.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\zevigulo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Program Files\Core.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\dbg.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\DemoPlayer.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\FileSystem_Stdio.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\FileSystem_Steam.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\hw.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\steam_api.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\suhokamo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\latavija.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nebiteda.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pavogare.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hufowebi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
hanks tina

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Origin on Sat Sep 12, 2009 5:10 am

Now open a new notepad file.
Input this into the notepad file:

File::
c:\windows\system32\9505zpy7.bin
c:\windows\system32\huej1nqg.exe
c:\windows\system32\gipunowe.dll
c:\windows\system32\ludiyofu.dll
c:\windows\system32\d3d9caps.dat
c:\windows\system32\piyadayi.dll
c:\windows\system32\juvilisi.dll
c:\windows\system32\gijiyeli.dll
c:\windows\system32\nebiteda.dll
c:\windows\system32\pavogare.dll
c:\windows\system32\latavija.dll
c:\windows\system32\vamonumi.dll
c:\windows\system32\pimenuda.dll
c:\windows\system32\huyowoza.dll
c:\windows\system32\hemokelu.dll
c:\windows\system32\hufowebi.dll
c:\windows\system32\liwoduki.dll
c:\windows\system32\nukizota.dll
c:\windows\tmp.tmp.tmp
c:\windows\system32\lofuvika.dll
c:\windows\system32\fanenoto.dll.tmp
c:\windows\system32\muyolule.dll
c:\windows\system32\sijorera.dll
c:\windows\system32\suhokamo.dll
c:\windows\system32\vutojisi.dll
c:\windows\system32\welatili.dll.tmp
c:\windows\system32\juvoludi.dll

Folder::
c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP
c:\program files\AskBarDis

Registrty::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lejehipahe"=-
"nejujatal"=-

[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=-
"FirewallOverride"=-
"UpdatesDisableNotify"=-

Driver::
ASKUpgrade


Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:


This will open combofix again, agree to it's terms and allow it to run.
It may want to reboot after it's done. (It will warn you if it wants to)
Post the resulting log back here.


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31483
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Sat Sep 12, 2009 5:34 pm

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2270 [GMT -4:00]
Running from: c:\documents and settings\tina gibson\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\tina gibson\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\AskSplash.exe
c:\program files\AskBarDis\bar\bin\AskTBApp.exe
c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Cache\0038B565
c:\program files\AskBarDis\bar\Cache\00BF3651
c:\program files\AskBarDis\bar\Cache\00CC4FF4
c:\program files\AskBarDis\bar\Cache\013D37A4
c:\program files\AskBarDis\bar\Cache\02D7687D
c:\program files\AskBarDis\bar\Cache\108276EA.bin
c:\program files\AskBarDis\bar\Cache\108279D8.bin
c:\program files\AskBarDis\bar\Cache\10827AC2.bin
c:\program files\AskBarDis\bar\Cache\10827BDB.bin
c:\program files\AskBarDis\bar\Cache\10827C97.bin
c:\program files\AskBarDis\bar\Cache\10827D72.bin
c:\program files\AskBarDis\bar\Cache\files.ini
c:\program files\AskBarDis\bar\History\search
c:\program files\AskBarDis\bar\Settings\AskLogo.ico
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevcfg.htm
c:\program files\AskBarDis\PopSwatter\History\allowed
c:\program files\AskBarDis\PopSwatter\History\notallow
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP
c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP\WiseCustomCalla.dll
c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP\WiseCustomCalla6.dll
c:\windows\048298C9A4D3490B9FF9AB023A9238F3.TMP\WiseData.ini
c:\windows\system32\mijikive.dll
c:\windows\system32\pafakamo.dll
c:\windows\system32\rudusisi.dll
c:\windows\system32\turovepi.dll
c:\windows\system32\wowijohi.dll

c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ASKUPGRADE
-------\Service_ASKUpgrade


((((((((((((((((((((((((( Files Created from 2009-08-12 to 2009-09-12 )))))))))))))))))))))))))))))))
.

2009-12-10 17:10 . 2009-12-10 17:10 9685 ----a-w- c:\windows\system32\9505zpy7.bin
2009-09-10 00:34 . 2009-09-10 00:34 -------- d-----w- c:\program files\New Folder
2009-09-10 00:33 . 2009-09-10 00:33 -------- d-----w- C:\New Folder
2009-09-09 21:14 . 2009-09-09 21:14 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-09-09 12:32 . 2009-09-09 12:32 -------- d-----w- c:\program files\Angle Interactive
2009-09-08 18:45 . 2009-09-08 18:45 -------- d-----w- c:\program files\Trend Micro
2009-09-08 18:12 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 18:12 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 13:06 . 2009-09-10 12:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-08 12:14 . 2009-09-08 12:14 390144 ----a-w- c:\windows\system32\huej1nqg.exe
2009-09-08 02:57 . 2009-07-28 20:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-08 02:57 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-08 02:57 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-09-08 02:57 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-09-08 02:57 . 2009-09-08 02:57 -------- d-----w- c:\program files\Avira
2009-09-08 02:57 . 2009-09-08 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-09-08 02:15 . 2009-09-08 02:15 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\HP
2009-09-07 21:53 . 2009-09-07 21:53 -------- d-----w- c:\documents and settings\tina gibson\Application Data\TeamViewer
2009-09-07 21:52 . 2009-09-07 21:52 -------- d-----w- c:\documents and settings\tina gibson\temp
2009-09-07 21:25 . 2009-09-10 22:35 -------- d-----w- c:\program files\Counter-Strike 1.6
2009-09-07 20:40 . 2009-09-07 20:40 -------- d---a-w- c:\program files\DOTNETFX
2009-09-07 20:08 . 2006-03-21 09:15 839680 ----a-w- c:\program files\steamclient.dll
2009-09-07 20:07 . 2006-03-21 09:15 3649536 ----a-w- c:\program files\Steam.dll
2009-09-07 20:03 . 2005-09-30 02:47 221184 ----a-w- c:\program files\hltv.exe
2009-09-07 20:03 . 2005-09-30 02:47 397312 ----a-w- c:\program files\hlds.exe
2009-09-07 20:03 . 2005-09-30 02:42 81920 ----a-w- c:\program files\hl.exe
2009-09-07 20:03 . 2005-09-30 02:42 211456 ----a-w- c:\program files\a3dapi.dll
2009-09-07 19:55 . 2008-12-25 12:00 67826994 ----a-w- c:\windows\Counter strike 1.6.exe
2009-09-07 17:26 . 2009-09-12 17:28 -------- d-----w- c:\program files\Steam
2009-09-06 03:00 . 2009-09-06 03:00 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-09-03 18:07 . 2009-09-03 18:07 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-08-30 04:05 . 2009-08-30 04:11 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-08-30 04:05 . 2009-08-30 04:21 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-08-30 04:05 . 2009-08-30 04:05 -------- d-----w- c:\program files\Common Files\iS3
2009-08-29 04:44 . 2009-08-30 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\12521094
2009-08-29 04:38 . 2008-04-14 22:00 4224 ------w- c:\windows\system32\drivers\beep.sys
2009-08-28 01:13 . 2009-09-07 19:03 -------- d-----w- c:\program files\Counter-Strike 1.6 Non-Steam 2009-04-29
2009-08-24 00:29 . 2009-08-28 00:34 -------- d-----w- c:\program files\Counter-Strike
2009-08-22 14:10 . 2009-08-23 23:15 -------- d-----w- c:\program files\VALVe
2009-08-14 03:41 . 2009-08-14 03:41 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\Malwarebytes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-12 07:37 . 2009-06-12 07:37 88576 --sha-w- c:\windows\system32\gipofosi.dll
2009-09-11 00:19 . 2009-06-11 00:19 49664 --sha-w- c:\windows\system32\bidifetu.dll
2009-09-11 00:19 . 2009-06-11 00:19 89088 --sha-w- c:\windows\system32\rawiyewa.dll
2009-09-10 22:29 . 2009-07-06 04:42 -------- d-----w- c:\program files\Xfire
2009-09-10 00:19 . 2009-06-10 00:19 88064 --sha-w- c:\windows\system32\ludiyofu.dll
2009-09-09 21:14 . 2009-06-18 04:27 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-09 00:18 . 2009-06-09 00:18 88064 --sha-w- c:\windows\system32\juvilisi.dll
2009-09-08 23:59 . 2009-07-09 04:19 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Xfire
2009-09-08 11:18 . 2009-05-27 23:54 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Symantec
2009-09-08 11:17 . 2008-10-29 01:27 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-09-08 03:42 . 2008-10-29 01:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-09-06 04:18 . 2008-10-29 01:06 -------- d-----w- c:\program files\Google
2009-09-06 01:59 . 2009-06-06 01:59 88576 --sha-w- c:\windows\system32\vamonumi.dll
2009-09-05 13:59 . 2009-06-05 13:59 88064 --sha-w- c:\windows\system32\pimenuda.dll
2009-09-04 20:43 . 2009-06-04 20:43 88064 --sha-w- c:\windows\system32\huyowoza.dll
2009-08-30 04:12 . 2009-08-30 04:06 2024 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-08-30 04:12 . 2009-08-30 04:11 2232 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-08-29 23:33 . 2009-07-04 06:30 -------- d-----w- c:\program files\Yahoo!
2009-08-29 16:14 . 2009-08-29 16:14 141 ----a-w- c:\windows\tmp.tmp.tmp
2009-08-29 04:44 . 2009-05-29 04:44 84480 --sha-w- c:\windows\system32\lofuvika.dll
2009-08-23 06:23 . 2008-10-29 01:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-18 23:17 . 2008-10-29 01:09 -------- d-----w- c:\program files\eMachines Games
2009-08-18 23:17 . 2008-10-29 01:09 -------- d-----w- c:\documents and settings\All Users\Application Data\WildTangent
2009-08-14 00:51 . 2009-08-14 00:51 15829 ----a-w- c:\documents and settings\All Users\Application Data\usywupox.dat
2009-08-12 20:22 . 2009-05-28 02:09 60664 ----a-w- c:\documents and settings\kaitie justice\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-10 00:21 . 2009-05-27 23:55 60664 ----a-w- c:\documents and settings\tina gibson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2008-04-14 22:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 18:32 . 2009-09-07 20:09 1689 ----a-w- c:\program files\Dedicated Server.lnk
2009-07-28 20:51 . 2009-07-28 20:51 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\Pogo Games
2009-07-28 20:25 . 2009-06-13 02:16 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\PlayFirst
2009-07-28 20:25 . 2009-06-01 01:47 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-07-26 09:38 . 2009-07-26 09:38 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-07-22 00:01 . 2009-07-22 00:01 -------- d-----w- c:\program files\TeamViewer
2009-07-18 22:19 . 2009-07-17 08:58 -------- d-----w- c:\program files\Common Files\Uninstall
2009-07-18 22:11 . 2009-07-18 22:11 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Malwarebytes
2009-07-18 22:11 . 2009-07-18 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 03:33 . 2009-07-18 03:33 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Fuel Industries
2009-07-17 19:01 . 2008-04-14 22:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 19:22 . 2009-07-16 19:22 -------- d-----w- c:\documents and settings\LocalService\Application Data\Xfire
2009-07-16 03:20 . 2009-07-16 03:20 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Scrabble Plus
2009-07-12 16:21 . 2008-04-14 22:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2007-08-14 02:54 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-04-14 22:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 22:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2008-04-14 22:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2008-04-14 22:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2008-04-14 22:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2008-04-14 22:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2008-04-14 22:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2008-04-14 22:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2008-04-14 22:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-20 19:50 . 2008-10-29 01:04 1024 ---h--r- c:\windows\system32\NTIMP3.dll
2009-06-16 14:36 . 2008-04-14 22:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-04-14 22:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2005-09-30 02:47 . 2009-09-07 20:03 24705 ----a-w- c:\program files\HLTV-Readme.txt
2005-09-30 02:47 . 2009-09-07 20:03 786 ----a-w- c:\program files\hlds_steamgames.vdf
2005-09-30 02:47 . 2009-09-07 20:03 1569 ----a-w- c:\program files\hltv.cfg
2005-08-13 19:24 . 2009-09-07 20:03 171014 ----a-w- c:\program files\hl.ico
2009-05-31 22:18 . 2009-05-31 22:18 49152 --sha-w- c:\windows\system32\fanenoto.dll.tmp
2009-06-11 00:19 . 2009-06-11 00:19 49664 --sha-w- c:\windows\system32\kulofuvo.dll
2009-06-07 04:46 . 2009-06-07 04:46 49664 --sha-w- c:\windows\system32\muyolule.dll.tmp
2009-05-29 16:44 . 2009-05-29 16:44 526 --sha-w- c:\windows\system32\sijorera.dll
2009-05-30 17:51 . 2009-05-30 17:51 526 --sha-w- c:\windows\system32\vutojisi.dll
2009-05-31 22:18 . 2009-05-31 22:18 49152 --sha-w- c:\windows\system32\welatili.dll.tmp
.

------- Sigcheck -------

[7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\eventlog.dll

c:\windows\system32\eventlog.dll ... is missing !!
.
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-29 01:34 . 2009-09-10 21:08 71732 c:\windows\system32\perfc009.dat
+ 2008-10-29 01:34 . 2009-09-12 07:20 71732 c:\windows\system32\perfc009.dat
+ 2008-10-29 01:34 . 2009-09-12 07:20 442466 c:\windows\system32\perfh009.dat
- 2008-10-29 01:34 . 2009-09-10 21:08 442466 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d2be9f52-416b-4ba8-9790-a7b44e2da14c}]
2009-06-11 00:19 49664 --sha-w- c:\windows\system32\kulofuvo.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-29 68856]
"Steam"="c:\program files\Steam\Steam.exe" [2009-09-07 1217784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-25 81920]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-29 24064]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-09-25 210216]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-07-10 421888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-09-06 122368]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"nejujatal"="c:\windows\system32\gipofosi.dll" [2009-09-12 88576]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-02-25 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]

c:\documents and settings\kaitie justice\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{d9254660-7192-4823-9f5c-9c96fc47e416}"= "c:\windows\system32\gipofosi.dll" [2009-09-12 88576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"vugiletew"= {d9254660-7192-4823-9f5c-9c96fc47e416} - c:\windows\system32\gipofosi.dll [2009-09-12 88576]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Steam\\steamapps\\peydro55\\counter-strike\\hl.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Acer\\Empowering Technology\\eRecovery\\eRAgent.exe"=
"c:\\WINDOWS\\system32\\HPZipm12.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/7/2009 10:57 PM 108289]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 5:11 PM 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 2:42 AM 50424]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 7:03 AM 131072]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [10/28/2008 9:05 PM 24064]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
IE: &Search
DPF: CabBuilder - [You must be registered and logged in to see this link.]
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - [You must be registered and logged in to see this link.]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-lejehipahe - turovepi.dll
SharedTaskScheduler-{13c2daae-c95c-4485-b4f0-3441a286883d} - c:\windows\system32\piyadayi.dll
SharedTaskScheduler-{4428a968-ffa0-4244-ad19-7ff6f140aa11} - c:\windows\system32\gijiyeli.dll
SharedTaskScheduler-{272e3cae-74e8-4d32-9e18-bd675d453c5b} - c:\windows\system32\piyadayi.dll
SharedTaskScheduler-{0e6d1c10-90fb-4035-ba95-30bdc36d05f4} - c:\windows\system32\gipunowe.dll
SharedTaskScheduler-{0729bb72-3eeb-433d-8ac4-42b5a3228c0c} - c:\windows\system32\gijiyeli.dll
SharedTaskScheduler-{1060b1af-75eb-433a-9304-5853bf60d8fd} - c:\windows\system32\gipunowe.dll
SSODL-wakiyuyob-{13c2daae-c95c-4485-b4f0-3441a286883d} - c:\windows\system32\piyadayi.dll
SSODL-wasuneyez-{4428a968-ffa0-4244-ad19-7ff6f140aa11} - c:\windows\system32\gijiyeli.dll
SSODL-viludigow-{272e3cae-74e8-4d32-9e18-bd675d453c5b} - c:\windows\system32\piyadayi.dll
SSODL-dotuladuv-{0e6d1c10-90fb-4035-ba95-30bdc36d05f4} - c:\windows\system32\gipunowe.dll
SSODL-jozafuzek-{0729bb72-3eeb-433d-8ac4-42b5a3228c0c} - c:\windows\system32\gijiyeli.dll
SSODL-fihagaror-{1060b1af-75eb-433a-9304-5853bf60d8fd} - c:\windows\system32\gipunowe.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-09-12 13:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2091681362-145439996-2945738896-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3504)
c:\windows\system32\WININET.dll
c:\windows\system32\gipofosi.dll
c:\windows\system32\ieframe.dll
c:\program files\Google\Quick Search Box\bin\1.2.1137.3514\qsb.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\rundll32.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-09-12 13:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-12 17:31
ComboFix2.txt 2009-09-10 21:22

Pre-Run: 56,587,980,800 bytes free
Post-Run: 56,766,648,320 bytes free

327 --- E O F --- 2009-08-26 07:00

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Origin on Sat Sep 12, 2009 5:46 pm

Please download SystemLook from one of the links below and save it to your Desktop.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:

    :filefind
    proquota.exe
    scecli.dll
    netlogon.dll
    eventlog.dll
    cngaudit.dll

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


While my help is always free, please consider donating to keep this site alive: [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Origin
Master
Master

Posts Posts : 2685
Joined Joined : 2009-05-05
Gender Gender : Male
OS OS : Windows Xp Sp3
Points Points : 31483
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Sun Sep 13, 2009 3:13 am

Log created at 23:11 on 12/09/2009 by tina gibson (Administrator - Elevation successful)

========== filefind ==========

Searching for "proquota.exe"
No files found.

Searching for "scecli.dll"
C:\WINDOWS\ERDNT\cache\scecli.dll --a--- 181248 bytes [21:21 10/09/2009] [22:00 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\dllcache\scecli.dll --a--c 181248 bytes [22:00 14/04/2008] [22:00 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084
C:\WINDOWS\system32\scecli.dll ------ 181248 bytes [22:00 14/04/2008] [22:00 14/04/2008] A86BB5E61BF3E39B62AB4C7E7085A084

Searching for "netlogon.dll"
C:\WINDOWS\ERDNT\cache\netlogon.dll --a--- 407040 bytes [21:21 10/09/2009] [22:00 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\dllcache\netlogon.dll --a--c 407040 bytes [22:00 14/04/2008] [22:00 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550
C:\WINDOWS\system32\netlogon.dll ------ 407040 bytes [22:00 14/04/2008] [22:00 14/04/2008] 1B7F071C51B77C272875C3A23E1E4550

Searching for "eventlog.dll"
C:\WINDOWS\system32\dllcache\eventlog.dll --a--c 56320 bytes [22:00 14/04/2008] [22:00 14/04/2008] 6D4FEB43EE538FC5428CC7F0565AA656

Searching for "cngaudit.dll"
No files found.

-=End Of File=-

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Mon Sep 14, 2009 12:39 am

Now open a new notepad file.
Input this into the notepad file:

File::
c:\windows\system32\9505zpy7.bin
c:\windows\system32\gipofosi.dll
c:\windows\system32\bidifetu.dll
c:\windows\system32\rawiyewa.dll
c:\windows\system32\juvilisi.dll
c:\windows\system32\vamonumi.dll
c:\windows\system32\pimenuda.dll
c:\windows\system32\huyowoza.dll
c:\windows\tmp.tmp.tmp
c:\windows\system32\lofuvika.dll
c:\windows\system32\fanenoto.dll.tmp
c:\windows\system32\kulofuvo.dll
c:\windows\system32\muyolule.dll.tmp
c:\windows\system32\sijorera.dll
c:\windows\system32\vutojisi.dll
c:\windows\system32\welatili.dll.tmp

Folder::
c:\documents and settings\All Users\Application Data\12521094

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d2be9f52-416b-4ba8-9790-a7b44e2da14c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nejujatal"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{d9254660-7192-4823-9f5c-9c96fc47e416}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"vugiletew"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=-
"FirewallOverride"=-
"UpdatesDisableNotify"=-

FCopy::
c:\windows\system32\dllcache\eventlog.dll | c:\windows\system32\eventlog.dll

Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:


This will open combofix again, agree to it's terms and allow it to run.
It may want to reboot after it's done. (It will warn you if it wants to)
Post the resulting log back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Mon Sep 14, 2009 3:25 am

Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2259 [GMT -4:00]
Running from: c:\documents and settings\tina gibson\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\tina gibson\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\fajeyeyi.dll
c:\windows\system32\figadufo.dll
c:\windows\system32\gubitahu.dll
c:\windows\system32\kopupavo.dll
c:\windows\system32\sosilavu.dll

c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((( Files Created from 2009-08-14 to 2009-09-14 )))))))))))))))))))))))))))))))
.

2009-12-10 17:10 . 2009-12-10 17:10 9685 ----a-w- c:\windows\system32\9505zpy7.bin
2009-09-14 03:00 . 2009-09-14 03:01 -------- d-----w- C:\Combo-Fix
2009-09-10 00:34 . 2009-09-10 00:34 -------- d-----w- c:\program files\New Folder
2009-09-10 00:33 . 2009-09-10 00:33 -------- d-----w- C:\New Folder
2009-09-09 21:14 . 2009-09-09 21:14 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-09-09 12:32 . 2009-09-09 12:32 -------- d-----w- c:\program files\Angle Interactive
2009-09-08 18:45 . 2009-09-08 18:45 -------- d-----w- c:\program files\Trend Micro
2009-09-08 18:12 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 18:12 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 13:06 . 2009-09-10 12:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-08 12:14 . 2009-09-08 12:14 390144 ----a-w- c:\windows\system32\huej1nqg.exe
2009-09-08 02:57 . 2009-07-28 20:33 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-09-08 02:57 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-09-08 02:57 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-09-08 02:57 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-09-08 02:57 . 2009-09-08 02:57 -------- d-----w- c:\program files\Avira
2009-09-08 02:57 . 2009-09-08 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-09-08 02:15 . 2009-09-08 02:15 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\HP
2009-09-07 21:53 . 2009-09-07 21:53 -------- d-----w- c:\documents and settings\tina gibson\Application Data\TeamViewer
2009-09-07 21:52 . 2009-09-07 21:52 -------- d-----w- c:\documents and settings\tina gibson\temp
2009-09-07 21:25 . 2009-09-14 01:47 -------- d-----w- c:\program files\Counter-Strike 1.6
2009-09-07 20:40 . 2009-09-07 20:40 -------- d---a-w- c:\program files\DOTNETFX
2009-09-07 20:08 . 2006-03-21 09:15 839680 ----a-w- c:\program files\steamclient.dll
2009-09-07 20:07 . 2006-03-21 09:15 3649536 ----a-w- c:\program files\Steam.dll
2009-09-07 20:03 . 2005-09-30 02:47 221184 ----a-w- c:\program files\hltv.exe
2009-09-07 20:03 . 2005-09-30 02:47 397312 ----a-w- c:\program files\hlds.exe
2009-09-07 20:03 . 2005-09-30 02:42 81920 ----a-w- c:\program files\hl.exe
2009-09-07 20:03 . 2005-09-30 02:42 211456 ----a-w- c:\program files\a3dapi.dll
2009-09-07 19:55 . 2008-12-25 12:00 67826994 ----a-w- c:\windows\Counter strike 1.6.exe
2009-09-07 17:26 . 2009-09-14 03:19 -------- d-----w- c:\program files\Steam
2009-09-06 03:00 . 2009-09-06 03:00 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-09-03 18:07 . 2009-09-03 18:07 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-08-30 04:05 . 2009-08-30 04:11 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-08-30 04:05 . 2009-08-30 04:21 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-08-30 04:05 . 2009-08-30 04:05 -------- d-----w- c:\program files\Common Files\iS3
2009-08-29 04:44 . 2009-08-30 04:12 -------- d-----w- c:\documents and settings\All Users\Application Data\12521094
2009-08-29 04:38 . 2008-04-14 22:00 4224 ------w- c:\windows\system32\drivers\beep.sys
2009-08-28 01:13 . 2009-09-07 19:03 -------- d-----w- c:\program files\Counter-Strike 1.6 Non-Steam 2009-04-29
2009-08-24 00:29 . 2009-08-28 00:34 -------- d-----w- c:\program files\Counter-Strike
2009-08-22 14:10 . 2009-08-23 23:15 -------- d-----w- c:\program files\VALVe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-13 21:06 . 2009-06-13 21:05 50176 --sha-w- c:\windows\system32\huvahuwi.dll
2009-09-13 21:05 . 2009-06-13 21:05 89088 --sha-w- c:\windows\system32\neyivobu.dll
2009-09-12 20:37 . 2009-06-12 20:37 88576 --sha-w- c:\windows\system32\muzurimo.dll
2009-09-11 00:19 . 2009-06-11 00:19 49664 --sha-w- c:\windows\system32\bidifetu.dll
2009-09-11 00:19 . 2009-06-11 00:19 89088 --sha-w- c:\windows\system32\rawiyewa.dll
2009-09-10 22:29 . 2009-07-06 04:42 -------- d-----w- c:\program files\Xfire
2009-09-10 00:19 . 2009-06-10 00:19 88064 --sha-w- c:\windows\system32\ludiyofu.dll
2009-09-09 21:14 . 2009-06-18 04:27 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-09 00:18 . 2009-06-09 00:18 88064 --sha-w- c:\windows\system32\juvilisi.dll
2009-09-08 23:59 . 2009-07-09 04:19 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Xfire
2009-09-08 11:18 . 2009-05-27 23:54 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Symantec
2009-09-08 11:17 . 2008-10-29 01:27 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-09-08 03:42 . 2008-10-29 01:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-09-06 04:18 . 2008-10-29 01:06 -------- d-----w- c:\program files\Google
2009-09-06 01:59 . 2009-06-06 01:59 88576 --sha-w- c:\windows\system32\vamonumi.dll
2009-09-05 13:59 . 2009-06-05 13:59 88064 --sha-w- c:\windows\system32\pimenuda.dll
2009-09-04 20:43 . 2009-06-04 20:43 88064 --sha-w- c:\windows\system32\huyowoza.dll
2009-08-30 04:12 . 2009-08-30 04:06 2024 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-08-30 04:12 . 2009-08-30 04:11 2232 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-08-29 23:33 . 2009-07-04 06:30 -------- d-----w- c:\program files\Yahoo!
2009-08-29 16:14 . 2009-08-29 16:14 141 ----a-w- c:\windows\tmp.tmp.tmp
2009-08-29 04:44 . 2009-05-29 04:44 84480 --sha-w- c:\windows\system32\lofuvika.dll
2009-08-23 06:23 . 2008-10-29 01:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-18 23:17 . 2008-10-29 01:09 -------- d-----w- c:\program files\eMachines Games
2009-08-18 23:17 . 2008-10-29 01:09 -------- d-----w- c:\documents and settings\All Users\Application Data\WildTangent
2009-08-14 03:41 . 2009-08-14 03:41 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\Malwarebytes
2009-08-14 00:51 . 2009-08-14 00:51 15829 ----a-w- c:\documents and settings\All Users\Application Data\usywupox.dat
2009-08-12 20:22 . 2009-05-28 02:09 60664 ----a-w- c:\documents and settings\kaitie justice\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-10 00:21 . 2009-05-27 23:55 60664 ----a-w- c:\documents and settings\tina gibson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2008-04-14 22:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 18:32 . 2009-09-07 20:09 1689 ----a-w- c:\program files\Dedicated Server.lnk
2009-07-28 20:51 . 2009-07-28 20:51 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\Pogo Games
2009-07-28 20:25 . 2009-06-13 02:16 -------- d-----w- c:\documents and settings\kaitie justice\Application Data\PlayFirst
2009-07-28 20:25 . 2009-06-01 01:47 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-07-26 09:38 . 2009-07-26 09:38 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-07-22 00:01 . 2009-07-22 00:01 -------- d-----w- c:\program files\TeamViewer
2009-07-18 22:19 . 2009-07-17 08:58 -------- d-----w- c:\program files\Common Files\Uninstall
2009-07-18 22:11 . 2009-07-18 22:11 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Malwarebytes
2009-07-18 22:11 . 2009-07-18 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 03:33 . 2009-07-18 03:33 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Fuel Industries
2009-07-17 19:01 . 2008-04-14 22:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 19:22 . 2009-07-16 19:22 -------- d-----w- c:\documents and settings\LocalService\Application Data\Xfire
2009-07-16 03:20 . 2009-07-16 03:20 -------- d-----w- c:\documents and settings\tina gibson\Application Data\Scrabble Plus
2009-07-12 16:21 . 2008-04-14 22:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2007-08-14 02:54 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-04-14 22:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 22:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2008-04-14 22:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2008-04-14 22:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2008-04-14 22:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2008-04-14 22:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2008-04-14 22:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2008-04-14 22:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2008-04-14 22:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-20 19:50 . 2008-10-29 01:04 1024 ---h--r- c:\windows\system32\NTIMP3.dll
2009-06-16 14:36 . 2008-04-14 22:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-04-14 22:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2005-09-30 02:47 . 2009-09-07 20:03 24705 ----a-w- c:\program files\HLTV-Readme.txt
2005-09-30 02:47 . 2009-09-07 20:03 786 ----a-w- c:\program files\hlds_steamgames.vdf
2005-09-30 02:47 . 2009-09-07 20:03 1569 ----a-w- c:\program files\hltv.cfg
2005-08-13 19:24 . 2009-09-07 20:03 171014 ----a-w- c:\program files\hl.ico
2009-05-31 22:18 . 2009-05-31 22:18 49152 --sha-w- c:\windows\system32\fanenoto.dll.tmp
2009-06-13 21:06 . 2009-06-13 21:06 50176 --sha-w- c:\windows\system32\jifuheja.dll
2009-06-07 04:46 . 2009-06-07 04:46 49664 --sha-w- c:\windows\system32\muyolule.dll.tmp
2009-05-29 16:44 . 2009-05-29 16:44 526 --sha-w- c:\windows\system32\sijorera.dll
2009-05-30 17:51 . 2009-05-30 17:51 526 --sha-w- c:\windows\system32\vutojisi.dll
2009-05-31 22:18 . 2009-05-31 22:18 49152 --sha-w- c:\windows\system32\welatili.dll.tmp
.

------- Sigcheck -------

[7] 2008-04-14 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\eventlog.dll

c:\windows\system32\eventlog.dll ... is missing !!
.
((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-29 01:34 . 2009-09-10 21:08 71732 c:\windows\system32\perfc009.dat
+ 2008-10-29 01:34 . 2009-09-12 17:30 71732 c:\windows\system32\perfc009.dat
+ 2008-10-29 01:34 . 2009-09-12 17:30 442466 c:\windows\system32\perfh009.dat
- 2008-10-29 01:34 . 2009-09-10 21:08 442466 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d2be9f52-416b-4ba8-9790-a7b44e2da14c}]
2009-06-13 21:06 50176 --sha-w- c:\windows\system32\jifuheja.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-29 68856]
"Steam"="c:\program files\Steam\Steam.exe" [2009-09-07 1217784]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-25 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-25 81920]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-07 34040]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-10-29 24064]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-09-25 210216]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-07-10 421888]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-09-06 122368]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"nejujatal"="c:\windows\system32\neyivobu.dll" [2009-09-13 89088]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-02-25 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]
"lejehipahe"="fajeyeyi.dll" [BU]

c:\documents and settings\kaitie justice\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{6edec331-1b69-4e1c-b84d-943ef183045b}"= "c:\windows\system32\neyivobu.dll" [2009-09-13 89088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"petuzihad"= {6edec331-1b69-4e1c-b84d-943ef183045b} - c:\windows\system32\neyivobu.dll [2009-09-13 89088]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\Client\\Agentsvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\BackupSvc.exe"=
"c:\\Program Files\\NewTech Infosystems\\NTI Backup Now 5\\SchedulerSvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\Steam\\steamapps\\peydro55\\counter-strike\\hl.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Acer\\Empowering Technology\\eRecovery\\eRAgent.exe"=
"c:\\WINDOWS\\system32\\HPZipm12.exe"=
"c:\\Program Files\\Steam\\steamapps\\rhyno417\\counter-strike\\hl.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/7/2009 10:57 PM 108289]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 5:11 PM 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/7/2008 2:42 AM 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/4/2008 7:03 AM 131072]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [10/28/2008 9:05 PM 24064]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: CabBuilder - [You must be registered and logged in to see this link.]
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - [You must be registered and logged in to see this link.]
.
- - - - ORPHANS REMOVED - - - -

SharedTaskScheduler-{afcc1e83-6705-4cb9-a39a-162c590037dd} - c:\windows\system32\vosukaso.dll
SSODL-vaboremay-{afcc1e83-6705-4cb9-a39a-162c590037dd} - c:\windows\system32\vosukaso.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-09-13 23:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2091681362-145439996-2945738896-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2524)
c:\windows\system32\WININET.dll
c:\windows\system32\neyivobu.dll
c:\windows\system32\ieframe.dll
c:\program files\Google\Quick Search Box\bin\1.2.1137.3514\qsb.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\agrsmsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\rundll32.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-09-14 23:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-14 03:23
ComboFix2.txt 2009-09-12 17:31
ComboFix3.txt 2009-09-10 21:22

Pre-Run: 57,100,902,400 bytes free
Post-Run: 57,100,046,336 bytes free

287 --- E O F --- 2009-08-26 07:00

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Mon Sep 14, 2009 12:00 pm

"error loading fajeyeyi.dll the specified module could not be found"
avira anti virus is catching something the ones that can't be deleted i've been moving to quantine. whats going on here after i do as you ask could you try to explain it to me. I'm really not that computer smart.
thanks for your help so far tina

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Mon Sep 14, 2009 9:06 pm

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    c:\windows\system32\9505zpy7.bin
    c:\windows\system32\gipofosi.dll
    c:\windows\system32\bidifetu.dll
    c:\windows\system32\rawiyewa.dll
    c:\windows\system32\juvilisi.dll
    c:\windows\system32\vamonumi.dll
    c:\windows\system32\pimenuda.dll
    c:\windows\system32\huyowoza.dll
    c:\windows\tmp.tmp.tmp
    c:\windows\system32\lofuvika.dll
    c:\windows\system32\fanenoto.dll.tmp
    c:\windows\system32\kulofuvo.dll
    c:\windows\system32\muyolule.dll.tmp
    c:\windows\system32\sijorera.dll
    c:\windows\system32\vutojisi.dll
    c:\windows\system32\welatili.dll.tmp
    c:\documents and settings\All Users\Application Data\12521094

    :reg
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d2be9f52-416b-4ba8-9790-a7b44e2da14c}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "nejujatal"=-
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
    "{d9254660-7192-4823-9f5c-9c96fc47e416}"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    "vugiletew"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=-
    "FirewallOverride"=-
    "UpdatesDisableNotify"=-


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Tue Sep 15, 2009 3:56 am

File/Folder c:\windows\system32\gipofosi.dll not found.
DllUnregisterServer procedure not found in c:\windows\system32\bidifetu.dll
c:\windows\system32\bidifetu.dll NOT unregistered.
c:\windows\system32\bidifetu.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\rawiyewa.dll
c:\windows\system32\rawiyewa.dll NOT unregistered.
c:\windows\system32\rawiyewa.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\juvilisi.dll
c:\windows\system32\juvilisi.dll NOT unregistered.
c:\windows\system32\juvilisi.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\vamonumi.dll
c:\windows\system32\vamonumi.dll NOT unregistered.
c:\windows\system32\vamonumi.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\pimenuda.dll
c:\windows\system32\pimenuda.dll NOT unregistered.
c:\windows\system32\pimenuda.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\huyowoza.dll
c:\windows\system32\huyowoza.dll NOT unregistered.
c:\windows\system32\huyowoza.dll moved successfully.
c:\windows\tmp.tmp.tmp moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\lofuvika.dll
c:\windows\system32\lofuvika.dll NOT unregistered.
c:\windows\system32\lofuvika.dll moved successfully.
c:\windows\system32\fanenoto.dll.tmp moved successfully.
File/Folder c:\windows\system32\kulofuvo.dll not found.
c:\windows\system32\muyolule.dll.tmp moved successfully.
LoadLibrary failed for c:\windows\system32\sijorera.dll
c:\windows\system32\sijorera.dll NOT unregistered.
c:\windows\system32\sijorera.dll moved successfully.
LoadLibrary failed for c:\windows\system32\vutojisi.dll
c:\windows\system32\vutojisi.dll NOT unregistered.
c:\windows\system32\vutojisi.dll moved successfully.
c:\windows\system32\welatili.dll.tmp moved successfully.
c:\documents and settings\All Users\Application Data\12521094 moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d2be9f52-416b-4ba8-9790-a7b44e2da14c}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d2be9f52-416b-4ba8-9790-a7b44e2da14c}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\nejujatal deleted successfully.
Registry value hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler\\{d9254660-7192-4823-9f5c-9c96fc47e416} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d9254660-7192-4823-9f5c-9c96fc47e416}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\vugiletew not found.
Registry value HKEY_LOCAL_MACHINE\software\microsoft\security center\\AntiVirusOverride deleted successfully.
Registry value HKEY_LOCAL_MACHINE\software\microsoft\security center\\FirewallOverride deleted successfully.
Registry value HKEY_LOCAL_MACHINE\software\microsoft\security center\\UpdatesDisableNotify deleted successfully.

OTM by OldTimer - Version 3.0.0.6 log created on 09142009_235320

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Tue Sep 15, 2009 5:22 pm


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt just yet.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Wed Sep 16, 2009 12:12 am

Run by tina gibson at 20:07:16.45 on Tue 09/15/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2365 [GMT -4:00]

AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Documents and Settings\tina gibson\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: {d2be9f52-416b-4ba8-9790-a7b44e2da14c} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [CPM47de95db] Rundll32.exe "c:\windows\system32\lofuvika.dll",a
mRun: [nejujatal] Rundll32.exe "c:\windows\system32\yiborewa.dll",a
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: CabBuilder - [You must be registered and logged in to see this link.]
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - [You must be registered and logged in to see this link.]
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - [You must be registered and logged in to see this link.]
AppInit_DLLs: sosilavu.dll c:\windows\system32\yiborewa.dll c:\windows\system32\rawiyewa.dll c:\windows\system32\juvilisi.dll c:\windows\system32\vamonumi.dll c:\windows\system32\pimenuda.dll c:\windows\system32\lofuvika.dll c:\windows\system32\huyowoza.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: petuzihad - {6edec331-1b69-4e1c-b84d-943ef183045b} - No File
SSODL: zulojifif - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll
SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lofuvika.dll
STS: {6edec331-1b69-4e1c-b84d-943ef183045b} - No File
STS: kupuhivus: {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll
STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\lofuvika.dll
LSA: Notification Packages = scecli fajeyeyi.dll

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-7 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-7 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-9-7 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-7 55656]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-7 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-10-28 24064]

=============== Created Last 30 ================

2009-09-13 23:00 --d----- C:\Combo-Fix
2009-09-12 23:06 25,088 a------- c:\windows\system32\tftp.msc
2009-09-10 16:50 a-dshr-- C:\cmdcons
2009-09-10 16:46 229,888 a------- c:\windows\PEV.exe
2009-09-09 20:34 --d----- c:\program files\New Folder
2009-09-09 20:33 --d----- C:\New Folder
2009-09-09 17:14 552 a------- c:\windows\system32\d3d8caps.dat
2009-09-09 08:32 --d----- c:\program files\Angle Interactive
2009-09-08 14:45 --d----- c:\program files\Trend Micro
2009-09-08 14:12 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 14:12 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-09-08 09:06 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-08 08:14 390,144 a------- c:\windows\system32\huej1nqg.exe
2009-09-07 22:57 55,656 a------- c:\windows\system32\drivers\avgntflt.sys
2009-09-07 22:57 --d----- c:\program files\Avira
2009-09-07 22:57 --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-09-07 17:53 --d----- c:\docume~1\tinagi~1\applic~1\TeamViewer
2009-09-07 17:52 --d----- c:\documents and settings\tina gibson\temp
2009-09-07 17:25 --d----- c:\program files\Counter-Strike 1.6
2009-09-07 16:40 a-d----- c:\program files\DOTNETFX
2009-09-07 16:08 839,680 a------- c:\program files\steamclient.dll
2009-09-07 16:07 3,649,536 a------- c:\program files\Steam.dll
2009-09-07 16:03 221,184 a------- c:\program files\hltv.exe
2009-09-07 16:03 397,312 a------- c:\program files\hlds.exe
2009-09-07 16:03 81,920 a------- c:\program files\hl.exe
2009-09-07 16:03 211,456 a------- c:\program files\a3dapi.dll
2009-09-07 15:55 67,826,994 a------- c:\windows\Counter strike 1.6.exe
2009-09-07 13:26 --d----- c:\program files\Steam
2009-09-05 22:57 227 a------- c:\windows\HP_CounterReport_Update_HPSU.ini
2009-09-05 22:57 214 a------- c:\windows\HP_48BitScanUpdatePatch.ini
2009-09-05 22:56 221 a------- c:\windows\HP_RedboxHprblog_HPSU.ini
2009-09-03 14:07 41,872 a------- c:\windows\system32\xfcodec.dll
2009-08-30 16:15 1,160 a------- c:\windows\wininit.ini
2009-08-30 00:11 2,232 a------- c:\windows\system32\drivers\kgpcpy.cfg
2009-08-30 00:06 2,024 a------- c:\windows\system32\drivers\kgpfr2.cfg
2009-08-30 00:05 --d----- c:\docume~1\alluse~1\applic~1\SITEguard
2009-08-30 00:05 --d----- c:\program files\common files\iS3
2009-08-30 00:05 --d----- c:\docume~1\alluse~1\applic~1\STOPzilla!
2009-08-29 00:38 4,224 -------- c:\windows\system32\drivers\beep.sys
2009-08-27 21:13 --d----- c:\program files\Counter-Strike 1.6 Non-Steam 2009-04-29
2009-08-23 20:29 --d----- c:\program files\Counter-Strike
2009-08-22 10:10 --d----- c:\program files\VALVe

==================== Find3M ====================

2009-09-14 19:34 89,088 a--sh--- c:\windows\system32\yiborewa.dll
2009-09-14 19:34 37,888 a--sh--- c:\windows\system32\fegovoku.dll
2009-09-14 07:12 37,888 a--sh--- c:\windows\system32\titobigi.dll
2009-09-13 17:06 50,176 a--sh--- c:\windows\system32\huvahuwi.dll
2009-09-13 17:05 89,088 a--sh--- c:\windows\system32\neyivobu.dll
2009-09-09 20:19 88,064 a--sh--- c:\windows\system32\ludiyofu.dll
2009-08-13 20:51 15,829 a------- c:\docume~1\alluse~1\applic~1\usywupox.dat
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-02 14:32 1,689 a------- c:\program files\Dedicated Server.lnk
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-12 12:21 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-06-29 12:12 827,392 -------- c:\windows\system32\wininet.dll
2009-06-29 12:12 78,336 a------- c:\windows\system32\ieencode.dll
2009-06-29 12:12 17,408 a------- c:\windows\system32\corpol.dll
2009-06-25 04:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 04:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 04:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 04:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 04:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 04:25 54,272 a------- c:\windows\system32\wdigest.dll
2005-09-29 22:47 24,705 a------- c:\program files\HLTV-Readme.txt
2005-09-29 22:47 1,569 a------- c:\program files\hltv.cfg
2005-09-29 22:47 786 a------- c:\program files\hlds_steamgames.vdf
2005-08-13 15:24 171,014 a------- c:\program files\hl.ico

============= FINISH: 20:07:40.45 ===============

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Wed Sep 16, 2009 12:16 am

rundll error c:\windows\system32\welatili.dll
rundll error c:\windows\system 32\lofuvika.dll

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Wed Sep 16, 2009 4:36 pm

Hello.
We need to run OTM one more time.


  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    c:\windows\system32\huej1nqg.exe
    c:\windows\system32\yiborewa.dll
    c:\windows\system32\fegovoku.dll
    c:\windows\system32\titobigi.dll
    c:\windows\system32\huvahuwi.dll
    c:\windows\system32\neyivobu.dll
    c:\windows\system32\ludiyofu.dll


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Wed Sep 16, 2009 7:21 pm

c:\windows\system32\huej1nqg.exe moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\yiborewa.dll
c:\windows\system32\yiborewa.dll NOT unregistered.
c:\windows\system32\yiborewa.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\fegovoku.dll
c:\windows\system32\fegovoku.dll NOT unregistered.
c:\windows\system32\fegovoku.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\titobigi.dll
c:\windows\system32\titobigi.dll NOT unregistered.
c:\windows\system32\titobigi.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\huvahuwi.dll
c:\windows\system32\huvahuwi.dll NOT unregistered.
c:\windows\system32\huvahuwi.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\neyivobu.dll
c:\windows\system32\neyivobu.dll NOT unregistered.
c:\windows\system32\neyivobu.dll moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\ludiyofu.dll
c:\windows\system32\ludiyofu.dll NOT unregistered.
c:\windows\system32\ludiyofu.dll moved successfully.

OTM by OldTimer - Version 3.0.0.6 log created on 09162009_152122

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Wed Sep 16, 2009 7:56 pm

Hello.
Now post a new Hijack This log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Wed Sep 16, 2009 9:25 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:25:06 PM, on 9/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: (no name) - {d2be9f52-416b-4ba8-9790-a7b44e2da14c} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [CPM47de95db] Rundll32.exe "c:\windows\system32\lofuvika.dll",a
O4 - HKLM\..\Run: [nejujatal] Rundll32.exe "c:\windows\system32\yiborewa.dll",a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'kaitie justice')
O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'kaitie justice')
O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'kaitie justice')
O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'kaitie justice')
O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [Protection System] "C:\Program Files\Protection System\psystem.exe" -noscan (User 'kaitie justice')
O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [lejehipahe] Rundll32.exe "C:\WINDOWS\system32\welatili.dll",s (User 'kaitie justice')
O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [nejujatal] Rundll32.exe "c:\windows\system32\yiborewa.dll",a (User 'kaitie justice')
O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1008\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'peyton gibson')
O4 - S-1-5-21-2091681362-145439996-2945738896-1007 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'kaitie justice')
O4 - S-1-5-21-2091681362-145439996-2945738896-1007 User Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'kaitie justice')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - [You must be registered and logged in to see this link.]
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - [You must be registered and logged in to see this link.]
O20 - AppInit_DLLs: sosilavu.dll c:\windows\system32\yiborewa.dll c:\windows\system32\rawiyewa.dll c:\windows\system32\juvilisi.dll c:\windows\system32\vamonumi.dll c:\windows\system32\pimenuda.dll c:\windows\system32\lofuvika.dll c:\windows\system32\huyowoza.dll c:\windows\system32\neyivobu.dll c:\windows\system32\ludiyofu.dll
O21 - SSODL: petuzihad - {6edec331-1b69-4e1c-b84d-943ef183045b} - (no file)
O21 - SSODL: zulojifif - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll (file missing)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lofuvika.dll (file missing)
O22 - SharedTaskScheduler: mujuzedij - {6edec331-1b69-4e1c-b84d-943ef183045b} - (no file)
O22 - SharedTaskScheduler: kupuhivus - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lofuvika.dll (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 11442 bytes

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Wed Sep 16, 2009 11:51 pm

Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: (no name) - {d2be9f52-416b-4ba8-9790-a7b44e2da14c} - (no file)
    O4 - HKLM\..\Run: [CPM47de95db] Rundll32.exe "c:\windows\system32\lofuvika.dll",a
    O4 - HKLM\..\Run: [nejujatal] Rundll32.exe "c:\windows\system32\yiborewa.dll",a
    O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [lejehipahe] Rundll32.exe "C:\WINDOWS\system32\welatili.dll",s (User 'kaitie justice')
    O4 - HKUS\S-1-5-21-2091681362-145439996-2945738896-1007\..\Run: [nejujatal] Rundll32.exe "c:\windows\system32\yiborewa.dll",a (User 'kaitie justice')
    O20 - AppInit_DLLs: sosilavu.dll c:\windows\system32\yiborewa.dll c:\windows\system32\rawiyewa.dll c:\windows\system32\juvilisi.dll c:\windows\system32\vamonumi.dll c:\windows\system32\pimenuda.dll c:\windows\system32\lofuvika.dll c:\windows\system32\huyowoza.dll c:\windows\system32\neyivobu.dll c:\windows\system32\ludiyofu.dll
    O21 - SSODL: petuzihad - {6edec331-1b69-4e1c-b84d-943ef183045b} - (no file)
    O21 - SSODL: zulojifif - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll (file missing)
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lofuvika.dll (file missing)
    O22 - SharedTaskScheduler: mujuzedij - {6edec331-1b69-4e1c-b84d-943ef183045b} - (no file)
    O22 - SharedTaskScheduler: kupuhivus - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll (file missing)
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\lofuvika.dll (file missing)


  • Press "Fix Checked"
  • Close Hijack This.

That should do it for the infection, now lets remove some old Java.

  • Open HijackThis.
  • When Hijack This opens, click "Open the Misc Tools section"
  • Then select "Open Uninstall Manager"
  • Click on "Save List..." (generates uninstall_list.txt)
  • Click Save, copy and paste the results in your next post.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Thu Sep 17, 2009 1:11 am

2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.2
Agere Systems PCI-SV92EX Soft Modem
Ask Toolbar
Avira AntiVir Personal - Free Antivirus
CCleaner (remove only)
Choice Guard
Compatibility Pack for the 2007 Office system
Counter-Strike
CyberLink DVD Suite
CyberLink DVD Suite
CyberLink Power2Go
CyberLink Power2Go
CyberLink PowerDVD
eMachines Games
GearDrvs
Google Desktop
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
HP Extended Capabilities 5.3
HP Image Zone Express
HP Imaging Device Functions 5.3
HP Product Assistant
HP PSC & OfficeJet 5.3.B
HP Software Update
HP Solution Center & Imaging Support Tools 5.3
Java(TM) 6 Update 5
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Works
MSN
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB925673)
NTI Backup Now 5
NTI Media Maker 8
NVIDIA Drivers
Realtek High Definition Audio Driver
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Segoe UI
Steam
TeamViewer 4
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
Windows Internet Explorer 7
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Presentation Foundation
WinRAR archiver
Xfire (remove only)

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Thu Sep 17, 2009 8:25 am

Hello.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    Ask Toolbar
    Java(TM) 6 Update 5

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /u



This will also reset your restore points.

How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Thu Sep 17, 2009 4:32 pm

windows can't find combofix/u
startup got a rundll error c:\windows\system32\yiborewa.dll
avira isn't updating asks for system reboot and no scans can be performed

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Thu Sep 17, 2009 4:33 pm

Hello.
Combofix uninstall sometimes doesn't work, not much bothered about that bit.

Post a new Hijack This log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Thu Sep 17, 2009 4:36 pm

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:32 PM, on 9/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [nejujatal] Rundll32.exe "c:\windows\system32\yiborewa.dll",a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - [You must be registered and logged in to see this link.]
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - [You must be registered and logged in to see this link.]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - [You must be registered and logged in to see this link.]
O20 - AppInit_DLLs: c:\windows\system32\yiborewa.dll c:\windows\system32\neyivobu.dll c:\windows\system32\ludiyofu.dll
O21 - SSODL: zulojifif - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: Google Desktop Manager 5.7.808.7150 (GoogleDesktopManager-080708-050100) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe

--
End of file - 8814 bytes

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Thu Sep 17, 2009 11:38 pm

Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O4 - HKLM\..\Run: [nejujatal] Rundll32.exe "c:\windows\system32\yiborewa.dll",a
    O20 - AppInit_DLLs: c:\windows\system32\yiborewa.dll c:\windows\system32\neyivobu.dll c:\windows\system32\ludiyofu.dll
    O21 - SSODL: zulojifif - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll (file missing)
    O22 - SharedTaskScheduler: kupuhivus - {fa733b55-a7c9-44b4-83f5-9c224726c61d} - c:\windows\system32\yiborewa.dll (file missing)


  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Fri Sep 18, 2009 3:56 am

Malwarebytes' Anti-Malware 1.41
Database version: 2818
Windows 5.1.2600 Service Pack 3

9/17/2009 11:49:38 PM
mbam-log-2009-09-17 (23-49-38).txt

Scan type: Quick Scan
Objects scanned: 130397
Time elapsed: 37 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\jifuheja.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tftp.msc (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\0535251103110107106.xry (KoobFace.Trace) -> Quarantined and deleted successfully.

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Fri Sep 18, 2009 9:10 am


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt just yet.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Sat Sep 19, 2009 2:09 am

DDS (Ver_09-07-30.01) - NTFSx86
Run by tina gibson at 17:16:16.18 on Fri 09/18/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2814.2361 [GMT -4:00]

AV: AntiVir Desktop *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\tina gibson\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [UpdateP2GoShortCut] "c:\program files\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [eRecoveryService] c:\acer\empowering technology\erecovery\eRAgent.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: CabBuilder - [You must be registered and logged in to see this link.]
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - [You must be registered and logged in to see this link.]
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - [You must be registered and logged in to see this link.]
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - [You must be registered and logged in to see this link.]
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Notification Packages = scecli fajeyeyi.dll

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-7 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-7 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-9-7 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-7 55656]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-7 50424]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-4 131072]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-10-28 24064]

=============== Created Last 30 ================

2009-09-18 07:05 1,374 a------- c:\windows\imsins.BAK
2009-09-16 15:21 --d----- C:\_OTM
2009-09-13 23:00 --d----- C:\Combo-Fix
2009-09-10 16:50 a-dshr-- C:\cmdcons
2009-09-10 16:46 229,888 a------- c:\windows\PEV.exe
2009-09-09 20:34 --d----- c:\program files\New Folder
2009-09-09 20:33 --d----- C:\New Folder
2009-09-09 17:14 552 a------- c:\windows\system32\d3d8caps.dat
2009-09-09 08:32 --d----- c:\program files\Angle Interactive
2009-09-08 14:45 --d----- c:\program files\Trend Micro
2009-09-08 14:12 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-08 14:12 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-08 09:06 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-07 22:57 55,656 a------- c:\windows\system32\drivers\avgntflt.sys
2009-09-07 22:57 --d----- c:\program files\Avira
2009-09-07 22:57 --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-09-07 17:53 --d----- c:\docume~1\tinagi~1\applic~1\TeamViewer
2009-09-07 17:52 --d----- c:\documents and settings\tina gibson\temp
2009-09-07 17:25 --d----- c:\program files\Counter-Strike 1.6
2009-09-07 16:40 a-d----- c:\program files\DOTNETFX
2009-09-07 16:08 839,680 a------- c:\program files\steamclient.dll
2009-09-07 16:07 3,649,536 a------- c:\program files\Steam.dll
2009-09-07 16:03 221,184 a------- c:\program files\hltv.exe
2009-09-07 16:03 397,312 a------- c:\program files\hlds.exe
2009-09-07 16:03 81,920 a------- c:\program files\hl.exe
2009-09-07 16:03 211,456 a------- c:\program files\a3dapi.dll
2009-09-07 15:55 67,826,994 a------- c:\windows\Counter strike 1.6.exe
2009-09-07 13:26 --d----- c:\program files\Steam
2009-09-05 22:57 227 a------- c:\windows\HP_CounterReport_Update_HPSU.ini
2009-09-05 22:57 214 a------- c:\windows\HP_48BitScanUpdatePatch.ini
2009-09-05 22:56 221 a------- c:\windows\HP_RedboxHprblog_HPSU.ini
2009-09-03 14:07 41,872 a------- c:\windows\system32\xfcodec.dll
2009-08-30 16:15 1,160 a------- c:\windows\wininit.ini
2009-08-30 00:11 2,232 a------- c:\windows\system32\drivers\kgpcpy.cfg
2009-08-30 00:06 2,024 a------- c:\windows\system32\drivers\kgpfr2.cfg
2009-08-30 00:05 --d----- c:\docume~1\alluse~1\applic~1\SITEguard
2009-08-30 00:05 --d----- c:\program files\common files\iS3
2009-08-30 00:05 --d----- c:\docume~1\alluse~1\applic~1\STOPzilla!
2009-08-29 00:38 4,224 -------- c:\windows\system32\drivers\beep.sys
2009-08-27 21:13 --d----- c:\program files\Counter-Strike 1.6 Non-Steam 2009-04-29
2009-08-23 20:29 --d----- c:\program files\Counter-Strike
2009-08-22 10:10 --d----- c:\program files\VALVe

==================== Find3M ====================

2009-08-13 20:51 15,829 a------- c:\docume~1\alluse~1\applic~1\usywupox.dat
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-02 14:32 1,689 a------- c:\program files\Dedicated Server.lnk
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-12 12:21 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-06-29 12:12 827,392 -------- c:\windows\system32\wininet.dll
2009-06-29 12:12 78,336 a------- c:\windows\system32\ieencode.dll
2009-06-29 12:12 17,408 a------- c:\windows\system32\corpol.dll
2009-06-25 04:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 04:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 04:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 04:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 04:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 04:25 54,272 a------- c:\windows\system32\wdigest.dll
2005-09-29 22:47 24,705 a------- c:\program files\HLTV-Readme.txt
2005-09-29 22:47 1,569 a------- c:\program files\hltv.cfg
2005-09-29 22:47 786 a------- c:\program files\hlds_steamgames.vdf
2005-08-13 15:24 171,014 a------- c:\program files\hl.ico

============= FINISH: 17:16:30.45 ===============

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Sat Sep 19, 2009 6:03 pm


  • Now open a new notepad file.
  • Input this into the notepad file:

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Notification Packages"=hex(7):73,63,65,63,6c,69,00,00

  • Save this as fix.reg, save it to your desktop.
  • Double click fix.reg to run it.
  • Select yes to the registry merge prompt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Sat Sep 19, 2009 6:56 pm

cannot import c:\documents and settings\tinagibson\desktop\fix.reg: the specified file is not a registry script you can only import binary registry files from within the registry editor.


did i do something wrong?

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Sun Sep 20, 2009 2:07 am

You missed this line:

Windows Registry Editor Version 5.00

As the TOP line, or there is a space before/after that line.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Sun Sep 20, 2009 2:48 am

successfully entered into registry

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Sun Sep 20, 2009 5:23 am

now what do we do? and how can we stop these reinfections if thats what they are? i'm 40 yrs old and computers are not my thing but with your help so far i've learned alot thank you so far for at less educating me on basic
computer op's

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Sun Sep 20, 2009 5:41 am

my kids enjoy a site called topix.com (local gossip site) sometimes this appears
HEUR\HTML.Malware asks if to be quarantined, deny access ignore deny access is that the right thing to do?

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Sun Sep 20, 2009 9:21 pm

Quarantine it.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by tinagibson on Mon Sep 21, 2009 1:46 am

now that we've done all this to the computer running this and that are we ok. Is there something else we need to do?

tinagibson
Novice
Novice

Posts Posts : 38
Joined Joined : 2009-07-18
OS OS : xp
Points Points : 27124
# Likes # Likes : 0

View user profile

Back to top Go down

Re: undetermined problem lost?????

Post by Belahzur on Mon Sep 21, 2009 8:25 am

Nope, that should do it. The malware is gone.

Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to [You must be registered and logged in to see this link.] and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

[You must be registered and logged in to see this link.]
A tutorial on using Ad-Aware to remove spyware from your computer may be found [You must be registered and logged in to see this link.].

[You must be registered and logged in to see this link.]
A tutorial on using Spybot to remove spyware from your computer may be found [You must be registered and logged in to see this link.]. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

[You must be registered and logged in to see this link.]
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found [You must be registered and logged in to see this link.].

[You must be registered and logged in to see this link.]
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found [You must be registered and logged in to see this link.].

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
[You must be registered and logged in to see this link.]
I also recommand the following add-ons for Firefox, they will help keep you safe from malicious scripts or activeX exploits.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

To help you keep your software updated, please considering using this free software program that will check for program updates.
[You must be registered and logged in to see this link.]

5) Finally, consider maintaining a firewall. Some good free firewalls are [You must be registered and logged in to see this link.], or
[You must be registered and logged in to see this link.]
A tutorial on understanding and using firewalls may be found [You must be registered and logged in to see this link.].

Please also read Tony Klein's excellent article: [You must be registered and logged in to see this link.]

If you would take a moment to fill out our feedback form, we would appreciate it.
The link can be found [You must be registered and logged in to see this link.].

Hopefully this should take care of your problems! Good luck. Big Grin


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245069
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum