pdragonfly
2008-03-30, 20:42
Please advise next steps. Thanks so much!!
Following steps from another post here are my logs:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:46:56 AM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
E:\ESET\egui.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Roboform\RoboTaskBarIcon.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
E:\ESET\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
E:\FireFox\firefox.exe
E:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eggs-pysanky.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Dragonfly
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - E:\Roboform\roboform.dll
O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [systray] C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [egui] "E:\ESET\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SpybotSnD] "E:\Spybot - Search & Destroy\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [acea525f] rundll32.exe "C:\WINDOWS\system32\njhwovox.dll",b
O4 - HKLM\..\RunOnce: [SpybotDeletingA7343] command /c del "C:\WINDOWS\system32\mljjj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6489] cmd /c del "C:\WINDOWS\system32\mljjj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6410] command /c del "C:\WINDOWS\system32\njhwovox.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3383] cmd /c del "C:\WINDOWS\system32\njhwovox.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6297] command /c del "C:\WINDOWS\system32\tufhhwyq.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3017] cmd /c del "C:\WINDOWS\system32\tufhhwyq.dll_old"
O4 - HKCU\..\Run: [RoboForm] "E:\Roboform\RoboTaskBarIcon.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8232] command /c del "C:\WINDOWS\system32\mljjj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4282] cmd /c del "C:\WINDOWS\system32\mljjj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7794] command /c del "C:\WINDOWS\system32\njhwovox.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6384] cmd /c del "C:\WINDOWS\system32\njhwovox.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7980] command /c del "C:\WINDOWS\system32\tufhhwyq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2868] cmd /c del "C:\WINDOWS\system32\tufhhwyq.dll_old"
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Customize Menu - file://E:\Roboform\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://E:\Roboform\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://E:\Roboform\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://E:\Roboform\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://E:\Roboform\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://E:\Roboform\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://E:\Roboform\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CCS\Services\Tcpip\..\{33B811CA-4458-4EC9-B255-3EC64FCF7EEF}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CS2\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - E:\ESET\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - E:\ESET\ekrn.exe
--
End of file - 5901 bytes
Username "Dragonfly" - 03/30/2008 12:01:14 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"systray"="C:\\Program Files\\Dell\\Dell Mobile Broadband\\systray.exe"
"SigmatelSysTrayApp"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,53,69,\
67,6d,61,54,65,6c,5c,43,2d,4d,61,6a,6f,72,20,41,75,64,69,6f,5c,57,44,4d,5c,\
73,74,73,79,73,74,72,61,2e,65,78,65,00
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"egui"="\"E:\\ESET\\egui.exe\" /hide /waitservice"
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\ipoint.exe\""
"SpybotSnD"="\"E:\\Spybot - Search & Destroy\\Spybot - Search & Destroy\\SpybotSD.exe\""
"acea525f"="rundll32.exe \"C:\\WINDOWS\\system32\\njhwovox.dll\",b"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="\"E:\\Roboform\\RoboTaskBarIcon.exe\""
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:34 PM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\ESET\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
E:\ESET\egui.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Spybot - Search & Destroy\Spybot - Search & Destroy\SpybotSD.exe
E:\Roboform\RoboTaskBarIcon.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Digital Line Detect\DLG.exe
E:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eggs-pysanky.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Dragonfly
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {20CC6076-D7FE-46BB-9CF0-D80014D3BD0B} - C:\WINDOWS\system32\mljjj.dll (file missing)
O2 - BHO: (no name) - {3FECA576-7AD2-4E11-A6AD-6B59D4FB5DB9} - C:\WINDOWS\system32\vturonn.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - E:\Roboform\roboform.dll
O2 - BHO: (no name) - {B34A017C-651D-4162-BB5F-C2A7EFE0E245} - C:\WINDOWS\system32\vtstu.dll (file missing)
O2 - BHO: (no name) - {B5D55D95-6AF6-4F4E-B0BD-C33006804600} - C:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: SBBho Class - {c9803b12-f0a0-11dc-95ff-0800200c9a66} - C:\WINDOWS\TinyBHO.dll
O2 - BHO: (no name) - {D270F3C8-81B4-4E7E-9C6F-215BBB4F7220} - C:\WINDOWS\system32\awvtu.dll (file missing)
O2 - BHO: (no name) - {FC723391-F488-4168-B46A-6447E304E742} - C:\WINDOWS\system32\jkhfc.dll (file missing)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - E:\Roboform\roboform.dll
O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [systray] C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [egui] "E:\ESET\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SpybotSnD] "E:\Spybot - Search & Destroy\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [acea525f] rundll32.exe "C:\WINDOWS\system32\njhwovox.dll",b
O4 - HKCU\..\Run: [RoboForm] "E:\Roboform\RoboTaskBarIcon.exe"
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Customize Menu - file://E:\Roboform\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://E:\Roboform\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://E:\Roboform\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://E:\Roboform\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://E:\Roboform\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://E:\Roboform\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://E:\Roboform\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CCS\Services\Tcpip\..\{33B811CA-4458-4EC9-B255-3EC64FCF7EEF}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CS2\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O20 - Winlogon Notify: vturonn - C:\WINDOWS\SYSTEM32\vturonn.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - E:\ESET\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - E:\ESET\ekrn.exe
--
End of file - 5978 bytes
VundoFix V7.0.3
Scan started at 12:21:41 PM 3/30/2008
Listing files found while scanning....
C:\windows\system32\qrutv.ini
C:\windows\system32\qrutv.ini2
C:\windows\system32\vturq.dll
Beginning removal...
Attempting to delete C:\windows\system32\qrutv.ini
C:\windows\system32\qrutv.ini Has been deleted!
Attempting to delete C:\windows\system32\qrutv.ini2
C:\windows\system32\qrutv.ini2 Has been deleted!
Attempting to delete C:\windows\system32\vturq.dll
C:\windows\system32\vturq.dll Has been deleted!
Performing Repairs to the registry.
Done!
rest is in next post because it was too many characters.
Following steps from another post here are my logs:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:46:56 AM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
E:\ESET\egui.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Roboform\RoboTaskBarIcon.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
E:\ESET\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
E:\FireFox\firefox.exe
E:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eggs-pysanky.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Dragonfly
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - E:\Roboform\roboform.dll
O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [systray] C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [egui] "E:\ESET\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SpybotSnD] "E:\Spybot - Search & Destroy\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [acea525f] rundll32.exe "C:\WINDOWS\system32\njhwovox.dll",b
O4 - HKLM\..\RunOnce: [SpybotDeletingA7343] command /c del "C:\WINDOWS\system32\mljjj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6489] cmd /c del "C:\WINDOWS\system32\mljjj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6410] command /c del "C:\WINDOWS\system32\njhwovox.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3383] cmd /c del "C:\WINDOWS\system32\njhwovox.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6297] command /c del "C:\WINDOWS\system32\tufhhwyq.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3017] cmd /c del "C:\WINDOWS\system32\tufhhwyq.dll_old"
O4 - HKCU\..\Run: [RoboForm] "E:\Roboform\RoboTaskBarIcon.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8232] command /c del "C:\WINDOWS\system32\mljjj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4282] cmd /c del "C:\WINDOWS\system32\mljjj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7794] command /c del "C:\WINDOWS\system32\njhwovox.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6384] cmd /c del "C:\WINDOWS\system32\njhwovox.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7980] command /c del "C:\WINDOWS\system32\tufhhwyq.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2868] cmd /c del "C:\WINDOWS\system32\tufhhwyq.dll_old"
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Customize Menu - file://E:\Roboform\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://E:\Roboform\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://E:\Roboform\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://E:\Roboform\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://E:\Roboform\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://E:\Roboform\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://E:\Roboform\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CCS\Services\Tcpip\..\{33B811CA-4458-4EC9-B255-3EC64FCF7EEF}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CS2\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - E:\ESET\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - E:\ESET\ekrn.exe
--
End of file - 5901 bytes
Username "Dragonfly" - 03/30/2008 12:01:14 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"systray"="C:\\Program Files\\Dell\\Dell Mobile Broadband\\systray.exe"
"SigmatelSysTrayApp"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,53,69,\
67,6d,61,54,65,6c,5c,43,2d,4d,61,6a,6f,72,20,41,75,64,69,6f,5c,57,44,4d,5c,\
73,74,73,79,73,74,72,61,2e,65,78,65,00
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"egui"="\"E:\\ESET\\egui.exe\" /hide /waitservice"
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\ipoint.exe\""
"SpybotSnD"="\"E:\\Spybot - Search & Destroy\\Spybot - Search & Destroy\\SpybotSD.exe\""
"acea525f"="rundll32.exe \"C:\\WINDOWS\\system32\\njhwovox.dll\",b"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="\"E:\\Roboform\\RoboTaskBarIcon.exe\""
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:13:34 PM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
E:\ESET\ekrn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
E:\ESET\egui.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Spybot - Search & Destroy\Spybot - Search & Destroy\SpybotSD.exe
E:\Roboform\RoboTaskBarIcon.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Digital Line Detect\DLG.exe
E:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eggs-pysanky.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Dragonfly
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {20CC6076-D7FE-46BB-9CF0-D80014D3BD0B} - C:\WINDOWS\system32\mljjj.dll (file missing)
O2 - BHO: (no name) - {3FECA576-7AD2-4E11-A6AD-6B59D4FB5DB9} - C:\WINDOWS\system32\vturonn.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - E:\Roboform\roboform.dll
O2 - BHO: (no name) - {B34A017C-651D-4162-BB5F-C2A7EFE0E245} - C:\WINDOWS\system32\vtstu.dll (file missing)
O2 - BHO: (no name) - {B5D55D95-6AF6-4F4E-B0BD-C33006804600} - C:\WINDOWS\system32\gebyv.dll (file missing)
O2 - BHO: SBBho Class - {c9803b12-f0a0-11dc-95ff-0800200c9a66} - C:\WINDOWS\TinyBHO.dll
O2 - BHO: (no name) - {D270F3C8-81B4-4E7E-9C6F-215BBB4F7220} - C:\WINDOWS\system32\awvtu.dll (file missing)
O2 - BHO: (no name) - {FC723391-F488-4168-B46A-6447E304E742} - C:\WINDOWS\system32\jkhfc.dll (file missing)
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - E:\Roboform\roboform.dll
O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [systray] C:\Program Files\Dell\Dell Mobile Broadband\systray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [egui] "E:\ESET\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SpybotSnD] "E:\Spybot - Search & Destroy\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [acea525f] rundll32.exe "C:\WINDOWS\system32\njhwovox.dll",b
O4 - HKCU\..\Run: [RoboForm] "E:\Roboform\RoboTaskBarIcon.exe"
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Customize Menu - file://E:\Roboform\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://E:\Roboform\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://E:\Roboform\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://E:\Roboform\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://E:\Roboform\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://E:\Roboform\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://E:\Roboform\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://E:\Roboform\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CCS\Services\Tcpip\..\{33B811CA-4458-4EC9-B255-3EC64FCF7EEF}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O17 - HKLM\System\CS2\Services\Tcpip\..\{1358E145-6882-4B59-B489-372E82A183DD}: NameServer = 68.237.161.12,71.250.0.12
O20 - Winlogon Notify: vturonn - C:\WINDOWS\SYSTEM32\vturonn.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - E:\ESET\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - E:\ESET\ekrn.exe
--
End of file - 5978 bytes
VundoFix V7.0.3
Scan started at 12:21:41 PM 3/30/2008
Listing files found while scanning....
C:\windows\system32\qrutv.ini
C:\windows\system32\qrutv.ini2
C:\windows\system32\vturq.dll
Beginning removal...
Attempting to delete C:\windows\system32\qrutv.ini
C:\windows\system32\qrutv.ini Has been deleted!
Attempting to delete C:\windows\system32\qrutv.ini2
C:\windows\system32\qrutv.ini2 Has been deleted!
Attempting to delete C:\windows\system32\vturq.dll
C:\windows\system32\vturq.dll Has been deleted!
Performing Repairs to the registry.
Done!
rest is in next post because it was too many characters.