AndreaD
2007-04-15, 02:26
I recently had alot of malware on my pc, inc smitfraud-C toolbar888, I managed to clean some of it using Clean Up, XoftSpySe, Spybot and AVG Anti-Spyware & Anti Virus. I googled name of the toolbar & saw this forum answering "Mel05 2006-11-24, 07:51 smitfraud-C toolbar888" with simular prob. Fllowed instructions she received from you guys [changing all program settings as suggested] It appears I have IE back but would like u to check this out & let me know what i need/don't need to fix, This is what I've done so far, inc logs:
Ran VundoFix.exe
SmifraudFix
AVG Anti- Spyware (with ewido update)
Spybot in safe mode (with Resident tea timer unchecked)
Hijack this v 1.99.0.1
ATF Cleaner (no log)
Here are the logs from scans etc.
XOFTSPYSSE
- <XoftSpy>
<Meta info="XoftSpySE-SP1 Tech-Support Log" time="14-04-2007-14-01-02" />
<ScanSettings scanActive="true" scanRegistry="true" scanSysFolders="true" scanDrives="true" scanHosts="true" scanAdvScan="true" />
- <Debug>
<DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\ZOE.INTEL1100\Cookies\zoe@mediaplex[1].txt" system-message="There are no more files." malwareName="mediaplex cookie" />
<DebugMsg event="FILE_QUARANTINE_SUCCESS" data="mediaplex cookie" system-message="The operation completed successfully." malwareName="mediaplex cookie" />
<DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\ZOE.INTEL1100\Cookies\zoe@mediaplex[1].txt" system-message="The operation completed successfully." malwareName="" />
</Debug>
</XoftSpy>
**********************************************************
THE VUNDOFIX LOG :)
C:\WINDOWS\system32\audanpws.exe
C:\WINDOWS\system32\cbxvuss.dll
C:\WINDOWS\system32\dylicjqx.exe
C:\WINDOWS\system32\fihbvohw.ini
C:\WINDOWS\system32\hjiii.bak1
C:\WINDOWS\system32\hjiii.bak2
C:\WINDOWS\system32\hjiii.ini
C:\WINDOWS\system32\iiijh.dll
C:\WINDOWS\system32\khfgghh.dll
C:\WINDOWS\system32\nuclpfkc.exe
C:\WINDOWS\system32\oivaxwoa.dll
C:\WINDOWS\system32\pmnmmji.dll
C:\WINDOWS\system32\pyqbrunk.exe
C:\WINDOWS\system32\qincclin.dll
C:\WINDOWS\system32\qopqr.dll
C:\WINDOWS\system32\rmnueawy.exe
C:\WINDOWS\system32\sjtgjqnh.dll
C:\WINDOWS\system32\srpckkdc.exe
C:\WINDOWS\system32\uwmecuha.exe
C:\WINDOWS\system32\whovbhif.dll
C:\WINDOWS\system32\xteevdou.dll
**********************************************************
THE SMITFRAUDFIX LOG :)
This scan was done a 2nd time to produce this log ?
SmitFraudFix v2.168
Scan done at 7:00:04.94, Sun 15/04/2007
Run from C:\Documents and Settings\ZOE.INTEL1100\Desktop\Downloads\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\NOTEPAD.EXE
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ZOE.INTEL1100
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ZOE.INTEL1100\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ZOE~1.INT\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Intel(R) PRO/100 VE Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 10.1.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{76B77BBC-A8DF-4DEA-9806-8479E8004823}: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{76B77BBC-A8DF-4DEA-9806-8479E8004823}: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{76B77BBC-A8DF-4DEA-9806-8479E8004823}: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=10.1.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
**********************************************************
SPYBOT SEARCH & DESTROY
14.04.2007 15:17:15 - ##### check started #####
14.04.2007 15:17:15 - ### Version: 1.4
14.04.2007 15:17:15 - ### Date: 14/04/2007 3:17:15 PM
14.04.2007 15:17:16 - ##### checking bots #####
14.04.2007 15:24:55 - found: Smitfraud-C.Toolbar888 Settings
14.04.2007 15:24:56 - found: Smitfraud-C.Toolbar888 Settings
14.04.2007 15:26:45 - found: Microsoft.WindowsSecurityCenter.UpdateDisableNotify Settings
14.04.2007 15:36:16 - ##### check finished #####
**********************************************************
HIJACKTHIS LOG :)
StartupList report, 15/04/2007, 5:31:59 AM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\ZOE.INTEL1100\Desktop\Downloads\HiJackThis_v2.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\ZOE.INTEL1100\Desktop\Downloads\HiJackThis_v2.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AVG7_CC = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
SoundService = rundll32.exe "C:\WINDOWS\system32\whovbhif.dll",setvm
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
adirka = C:\WINDOWS\system32\adirka.exe
igndlm.exe = C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\WINDOWS\system32\qopqr.dll (file missing) - {09F8C9DF-3645-4BAB-86CE-69943AE2ED1D}
(no name) - C:\WINDOWS\system32\iiijh.dll (file missing) - {2A86A2F8-3BDF-4F92-871A-71579D0DBC87}
(no name) - C:\WINDOWS\system32\qincclin.dll (file missing) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6}
(no name) - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:\WINDOWS\system32\avcuovkh.dll - {9347E481-A9C5-4F4D-8D06-76C30B918A7f}
(no name) - C:\PROGRA~1\MASSDO~1\MDHELPER.DLL - {B930BA63-9E5A-11D3-A288-0000E80E2EDE}
--------------------------------------------------
Enumerating Task Scheduler jobs:
XoftSpySE 2.job
XoftSpySE.job
--------------------------------------------------
Enumerating Download Program Files:
[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
CODEBASE = http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
[{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}]
[CDownloadCtrl Object]
InProcServer32 = C:\Program Files\Download Manager\DLMControl.dll
CODEBASE = http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
[WUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1175530912791
[Symantec RuFSI Utility Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
--------------------------------------------------
Enumerating Winsock LSP files:
Protocol #12: rsvp32_2.dll (file MISSING)
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
--------------------------------------------------
End of report, 5,494 bytes
Report generated in 0.050 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
**********************************************************
Thanks guys
AndreaD
ps when I reboot since doing VunoFix I get this error msg
Error loading C:\WINDOWS\System32\whovbhif.dll missing the specified module doesn't exist
Ran VundoFix.exe
SmifraudFix
AVG Anti- Spyware (with ewido update)
Spybot in safe mode (with Resident tea timer unchecked)
Hijack this v 1.99.0.1
ATF Cleaner (no log)
Here are the logs from scans etc.
XOFTSPYSSE
- <XoftSpy>
<Meta info="XoftSpySE-SP1 Tech-Support Log" time="14-04-2007-14-01-02" />
<ScanSettings scanActive="true" scanRegistry="true" scanSysFolders="true" scanDrives="true" scanHosts="true" scanAdvScan="true" />
- <Debug>
<DebugMsg event="FILE_FOUND" data="c:\Documents and Settings\ZOE.INTEL1100\Cookies\zoe@mediaplex[1].txt" system-message="There are no more files." malwareName="mediaplex cookie" />
<DebugMsg event="FILE_QUARANTINE_SUCCESS" data="mediaplex cookie" system-message="The operation completed successfully." malwareName="mediaplex cookie" />
<DebugMsg event="FILE_DELETE_SUCCESS" data="c:\Documents and Settings\ZOE.INTEL1100\Cookies\zoe@mediaplex[1].txt" system-message="The operation completed successfully." malwareName="" />
</Debug>
</XoftSpy>
**********************************************************
THE VUNDOFIX LOG :)
C:\WINDOWS\system32\audanpws.exe
C:\WINDOWS\system32\cbxvuss.dll
C:\WINDOWS\system32\dylicjqx.exe
C:\WINDOWS\system32\fihbvohw.ini
C:\WINDOWS\system32\hjiii.bak1
C:\WINDOWS\system32\hjiii.bak2
C:\WINDOWS\system32\hjiii.ini
C:\WINDOWS\system32\iiijh.dll
C:\WINDOWS\system32\khfgghh.dll
C:\WINDOWS\system32\nuclpfkc.exe
C:\WINDOWS\system32\oivaxwoa.dll
C:\WINDOWS\system32\pmnmmji.dll
C:\WINDOWS\system32\pyqbrunk.exe
C:\WINDOWS\system32\qincclin.dll
C:\WINDOWS\system32\qopqr.dll
C:\WINDOWS\system32\rmnueawy.exe
C:\WINDOWS\system32\sjtgjqnh.dll
C:\WINDOWS\system32\srpckkdc.exe
C:\WINDOWS\system32\uwmecuha.exe
C:\WINDOWS\system32\whovbhif.dll
C:\WINDOWS\system32\xteevdou.dll
**********************************************************
THE SMITFRAUDFIX LOG :)
This scan was done a 2nd time to produce this log ?
SmitFraudFix v2.168
Scan done at 7:00:04.94, Sun 15/04/2007
Run from C:\Documents and Settings\ZOE.INTEL1100\Desktop\Downloads\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\NOTEPAD.EXE
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ZOE.INTEL1100
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ZOE.INTEL1100\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ZOE~1.INT\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Intel(R) PRO/100 VE Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 10.1.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{76B77BBC-A8DF-4DEA-9806-8479E8004823}: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{76B77BBC-A8DF-4DEA-9806-8479E8004823}: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{76B77BBC-A8DF-4DEA-9806-8479E8004823}: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.1.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=10.1.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
**********************************************************
SPYBOT SEARCH & DESTROY
14.04.2007 15:17:15 - ##### check started #####
14.04.2007 15:17:15 - ### Version: 1.4
14.04.2007 15:17:15 - ### Date: 14/04/2007 3:17:15 PM
14.04.2007 15:17:16 - ##### checking bots #####
14.04.2007 15:24:55 - found: Smitfraud-C.Toolbar888 Settings
14.04.2007 15:24:56 - found: Smitfraud-C.Toolbar888 Settings
14.04.2007 15:26:45 - found: Microsoft.WindowsSecurityCenter.UpdateDisableNotify Settings
14.04.2007 15:36:16 - ##### check finished #####
**********************************************************
HIJACKTHIS LOG :)
StartupList report, 15/04/2007, 5:31:59 AM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\ZOE.INTEL1100\Desktop\Downloads\HiJackThis_v2.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\ZOE.INTEL1100\Desktop\Downloads\HiJackThis_v2.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AVG7_CC = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
SoundService = rundll32.exe "C:\WINDOWS\system32\whovbhif.dll",setvm
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
adirka = C:\WINDOWS\system32\adirka.exe
igndlm.exe = C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\WINDOWS\system32\qopqr.dll (file missing) - {09F8C9DF-3645-4BAB-86CE-69943AE2ED1D}
(no name) - C:\WINDOWS\system32\iiijh.dll (file missing) - {2A86A2F8-3BDF-4F92-871A-71579D0DBC87}
(no name) - C:\WINDOWS\system32\qincclin.dll (file missing) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6}
(no name) - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - C:\WINDOWS\system32\avcuovkh.dll - {9347E481-A9C5-4F4D-8D06-76C30B918A7f}
(no name) - C:\PROGRA~1\MASSDO~1\MDHELPER.DLL - {B930BA63-9E5A-11D3-A288-0000E80E2EDE}
--------------------------------------------------
Enumerating Task Scheduler jobs:
XoftSpySE 2.job
XoftSpySE.job
--------------------------------------------------
Enumerating Download Program Files:
[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
CODEBASE = http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
[{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}]
[CDownloadCtrl Object]
InProcServer32 = C:\Program Files\Download Manager\DLMControl.dll
CODEBASE = http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cab
[WUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1175530912791
[Symantec RuFSI Utility Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
--------------------------------------------------
Enumerating Winsock LSP files:
Protocol #12: rsvp32_2.dll (file MISSING)
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
--------------------------------------------------
End of report, 5,494 bytes
Report generated in 0.050 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
**********************************************************
Thanks guys
AndreaD
ps when I reboot since doing VunoFix I get this error msg
Error loading C:\WINDOWS\System32\whovbhif.dll missing the specified module doesn't exist