PDA

View Full Version : Hijackthis Log - Vundo?



scottd
2009-02-09, 20:00
Hi, thanks in advance for any help with what looks to be a vundo infection possiby? Here goes:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:51:08 PM, on 2/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trane.com/Default.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [fihamewozo] Rundll32.exe "C:\WINDOWS\system32\wanisupa.dll",s
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [fihamewozo] Rundll32.exe "C:\WINDOWS\system32\pohuzowo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fihamewozo] Rundll32.exe "C:\WINDOWS\system32\pohuzowo.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1204784629906
O20 - AppInit_DLLs: C:\WINDOWS\System32\iasrad32.dll c:\windows\system32\mosoraza.dll xkpbxi.dll sakjaf.dll xlaouu.dll jyjyoy.dll udzkwr.dll gyojyi.dll qyefxn.dll gslslf.dll
O20 - Winlogon Notify: 2033be6c448 - C:\WINDOWS\System32\iasrad32.dll (file missing)
O20 - Winlogon Notify: ywseeruf - C:\Documents and Settings\leeair\Application Data\ywseeruf.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 6147 bytes

pskelley
2009-02-13, 12:02
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance) http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

I apologize for the wait, volunteers are swamped at all forums with infected computers. If you have resolved your issues, please post to let me know so I can close this topic.

If you still need help, and you have read and followed the "Before you Post" directions, post a new HJT log since it has been four days, and I will take a look, please describe any recent symptoms.

TeaTimer is not disabled? read and follow the directions before you post.
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

Thanks

scottd
2009-02-16, 19:35
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:52:10 AM, on 2/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trane.com/Default.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [fihamewozo] Rundll32.exe "C:\WINDOWS\system32\wanisupa.dll",s
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [fihamewozo] Rundll32.exe "C:\WINDOWS\system32\pohuzowo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fihamewozo] Rundll32.exe "C:\WINDOWS\system32\pohuzowo.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9e.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.java.com
O15 - Trusted Zone: http://*.windowsupdate.mocrosoft.com
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1204784629906
O20 - AppInit_DLLs: C:\WINDOWS\System32\iasrad32.dll c:\windows\system32\mosoraza.dll xkpbxi.dll sakjaf.dll xlaouu.dll jyjyoy.dll udzkwr.dll gyojyi.dll qyefxn.dll gslslf.dll
O20 - Winlogon Notify: 2033be6c448 - C:\WINDOWS\System32\iasrad32.dll (file missing)
O20 - Winlogon Notify: ywseeruf - C:\Documents and Settings\leeair\Application Data\ywseeruf.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 6262 bytes

scottd
2009-02-16, 19:38
I cannot install Java, or access certain online email sites. When I try to install Java for instance, it tells me I do not havin admin priveledges to do so, even when I am logged on as admin.

Weird system messages come up from time to time as well, like "CCC.exe" cannot load.

So, to sum up, seems as if something is messing with internet explorer.

Thanks again!

pskelley
2009-02-16, 20:00
Make sure you read and follow the directions, anything else will slow the process and waste both of our time. I suggest you keep this computer offline except when troubleshooting, the junk may download more. If you have any tool I use, delete it and download it new from the link I provide. Read and follow the directions carefully, the tools will not work unless you do.
The junk can be tough to remove, so do not expect fast or easy.

1) Please DO NOT ENABLE Spybot S&D TeaTimer while we work together.

2) A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use

Download ComboFix from here:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
See this Link (http://www.bleepingcomputer.com/forums/topic114351.html) for programs that need to be disabled and instruction on how to disable them.
Remember to re-enable them when we're done.


Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


http://i24.photobucket.com/albums/c30/ken545/RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://i24.photobucket.com/albums/c30/ken545/whatnext.jpg

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Tutorial if needed
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

3) Post also an uninstall list: Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list..." Button.
Save it to your desktop. Copy and paste the contents into your reply.
(You may edit out Microsoft, Hotfixes, Security Update for Windows XP,
Update for Windows XP and Windows XP Hotfix to shorten the list)
Image: http://img.bleepingcomputer.com/tutorials/hijackthis/uninstall-man.jpg

Thanks

scottd
2009-02-23, 17:26
ComboFix 09-02-15.01 - leeair 2009-02-23 10:06:50.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.894.546 [GMT -6:00]
Running from: c:\documents and settings\leeair\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Application Data\0200000045e026e6C.manifest
c:\documents and settings\Administrator\Application Data\0200000045e026e6O.manifest
c:\documents and settings\Administrator\Application Data\0200000045e026e6P.manifest
c:\documents and settings\Administrator\Application Data\0200000045e026e6S.manifest
c:\documents and settings\leeair\Application Data\0200000045e026e6C.manifest
c:\documents and settings\leeair\Application Data\0200000045e026e6O.manifest
c:\documents and settings\leeair\Application Data\0200000045e026e6P.manifest
c:\documents and settings\leeair\Application Data\0200000045e026e6R.manifest
c:\documents and settings\leeair\Application Data\0200000045e026e6S.manifest
c:\documents and settings\leeair\Application Data\comctl32.dll
c:\windows\system32\afuvarul.ini
c:\windows\system32\avujarim.ini
c:\windows\system32\azipilum.ini
c:\windows\system32\bafekefe.dll
c:\windows\system32\balorapi.dll.tmp
c:\windows\system32\defohesi.dll
c:\windows\system32\duhifiho.dll
c:\windows\system32\eweyemip.ini
c:\windows\system32\fapilizu.dll.tmp
c:\windows\system32\fayebuzu.dll
c:\windows\system32\fifugiku.dll
c:\windows\system32\fihasine.dll
c:\windows\system32\fumupofo.dll
c:\windows\system32\gagekije.dll.tmp
c:\windows\system32\ganovesa.dll.tmp
c:\windows\system32\gilavofi.dll.tmp
c:\windows\system32\godanihe.dll.tmp
c:\windows\system32\gokisoso.dll.tmp
c:\windows\system32\gowodohe.dll
c:\windows\system32\gslslf.dll
c:\windows\system32\gyojyi.dll
c:\windows\system32\hemudapa.dll
c:\windows\system32\hinuhilu.dll.tmp
c:\windows\system32\hodajupi.dll
c:\windows\system32\hopawiki.dll.tmp
c:\windows\system32\idulazoy.ini
c:\windows\system32\ilawuhip.ini
c:\windows\system32\ivabevar.ini
c:\windows\system32\jepayala.dll
c:\windows\system32\jusivefa.dll
c:\windows\system32\litunude.dll.tmp
c:\windows\system32\ludotoja.dll.tmp
c:\windows\system32\mirupibe.dll.tmp
c:\windows\system32\muyipeve.dll.tmp
c:\windows\system32\nizefipu.dll
c:\windows\system32\panasoba.dll
c:\windows\system32\qyefxn.dll
c:\windows\system32\roruhore.dll.tmp
c:\windows\system32\sagujele.dll
c:\windows\system32\sanedumi.dll.tmp
c:\windows\system32\sulejere.dll
c:\windows\system32\tadagagu.dll
c:\windows\system32\tebutago.dll.tmp
c:\windows\system32\wanisupa.dll.tmp
c:\windows\system32\wefeyubi.dll
c:\windows\system32\yefapuza.dll.tmp
c:\windows\system32\yijazowi.dll
c:\windows\system32\yirozoyi.dll
c:\windows\system32\yomoviya.dll
c:\windows\system32\yovalono.dll
c:\windows\system32\yugovuji.dll
c:\windows\system32\yujukaku.dll.tmp
c:\windows\system32\zifisehe.dll
c:\windows\system32\zujopuhe.dll.tmp
c:\windows\system32\zuragiwu.dll.tmp
C:\xcrashdump.dat

.
((((((((((((((((((((((((( Files Created from 2009-01-23 to 2009-02-23 )))))))))))))))))))))))))))))))
.

2009-02-09 12:15 . 2009-02-09 12:15 <DIR> d-------- c:\program files\Trend Micro
2009-01-27 14:56 . 2009-01-27 14:56 417,300 --a------ c:\documents and settings\leeair\Application Data\ywseeruf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-20 17:37 --------- d-----w c:\documents and settings\leeair\Application Data\ESC
2009-02-09 18:17 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-06 19:44 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-22 13:16 100,547 ----a-w c:\windows\system32\wiwuzoza.dll
2009-01-21 14:29 99,517 ----a-w c:\windows\system32\pihuyeha.dll
2009-01-21 14:29 134,297 ----a-w c:\windows\system32\detujedu.dll
2009-01-14 22:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 22:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-12-20 23:15 826,368 ----a-w c:\windows\system32\wininet.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-04 149040]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-05-04 161328]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 c:\windows\RTHDCPL.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil9e.exe" [2007-11-20 218496]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ywseeruf]
2009-01-27 14:56 417300 c:\documents and settings\leeair\Application Data\ywseeruf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=gyojyi.dll qyefxn.dll gslslf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\ati2evxx.exe"=
"c:\\Program Files\\Common Files\\LightScribe\\LSSrvc.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\Core-Static\\CCC.exe"=
"c:\\Program Files\\Canon\\IJPLM\\ijplmsvc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=
"c:\\Program Files\\dESCO\\ESC\\coastal.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Lib\\NMIndexStoreSvr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Lib\\NMIndexingService.exe"=
"c:\\Program Files\\Canon\\MyPrinter\\BJMYPRT.EXE"=
"c:\\Program Files\\Common Files\\LightScribe\\LightScribeControlPanel.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe"=
"c:\\Program Files\\Adobe\\Reader 8.0\\Reader\\reader_sl.exe"=
"c:\\Program Files\\ScanSoft\\OmniPageSE4\\OpWareSE4.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\Core-Static\\MOM.exe"=
"c:\\WINDOWS\\RTHDCPL.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
msiexec /fums {A75BF1D0-C7C3-CB55-EE17-3225387FD154} /qb

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2008-12-30 c:\windows\Tasks\At1.job
- c:\windows\system32\eVF100eW.exe []

2009-02-20 c:\windows\Tasks\At10.job
- c:\windows\system32\eVF100eW.exe []

2009-02-20 c:\windows\Tasks\At11.job
- c:\windows\system32\eVF100eW.exe []

2009-02-20 c:\windows\Tasks\At12.job
- c:\windows\system32\eVF100eW.exe []

2009-02-19 c:\windows\Tasks\At13.job
- c:\windows\system32\eVF100eW.exe []

2009-02-19 c:\windows\Tasks\At14.job
- c:\windows\system32\eVF100eW.exe []

2009-02-18 c:\windows\Tasks\At15.job
- c:\windows\system32\eVF100eW.exe []

2009-02-17 c:\windows\Tasks\At16.job
- c:\windows\system32\eVF100eW.exe []

2009-02-17 c:\windows\Tasks\At17.job
- c:\windows\system32\eVF100eW.exe []

2009-02-03 c:\windows\Tasks\At18.job
- c:\windows\system32\eVF100eW.exe []

2009-02-04 c:\windows\Tasks\At19.job
- c:\windows\system32\eVF100eW.exe []

2008-12-30 c:\windows\Tasks\At2.job
- c:\windows\system32\eVF100eW.exe []

2009-01-17 c:\windows\Tasks\At20.job
- c:\windows\system32\eVF100eW.exe []

2009-01-08 c:\windows\Tasks\At21.job
- c:\windows\system32\eVF100eW.exe []

2008-12-30 c:\windows\Tasks\At22.job
- c:\windows\system32\eVF100eW.exe []

2008-12-30 c:\windows\Tasks\At23.job
- c:\windows\system32\eVF100eW.exe []

2008-12-30 c:\windows\Tasks\At24.job
- c:\windows\system32\eVF100eW.exe []

2008-12-30 c:\windows\Tasks\At25.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At26.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At27.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At28.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At29.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At3.job
- c:\windows\system32\eVF100eW.exe []

2008-12-30 c:\windows\Tasks\At30.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At31.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-10 c:\windows\Tasks\At32.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-20 c:\windows\Tasks\At33.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-20 c:\windows\Tasks\At34.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-20 c:\windows\Tasks\At35.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-20 c:\windows\Tasks\At36.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-19 c:\windows\Tasks\At37.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-19 c:\windows\Tasks\At38.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-18 c:\windows\Tasks\At39.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At4.job
- c:\windows\system32\eVF100eW.exe []

2009-02-17 c:\windows\Tasks\At40.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-17 c:\windows\Tasks\At41.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-03 c:\windows\Tasks\At42.job
- c:\windows\system32\5Clj6prb.exe []

2009-02-04 c:\windows\Tasks\At43.job
- c:\windows\system32\5Clj6prb.exe []

2009-01-17 c:\windows\Tasks\At44.job
- c:\windows\system32\5Clj6prb.exe []

2009-01-08 c:\windows\Tasks\At45.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At46.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At47.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At48.job
- c:\windows\system32\5Clj6prb.exe []

2008-12-30 c:\windows\Tasks\At5.job
- c:\windows\system32\eVF100eW.exe []

2008-12-30 c:\windows\Tasks\At6.job
- c:\windows\system32\eVF100eW.exe []

2008-12-30 c:\windows\Tasks\At7.job
- c:\windows\system32\eVF100eW.exe []

2009-02-10 c:\windows\Tasks\At8.job
- c:\windows\system32\eVF100eW.exe []

2009-02-20 c:\windows\Tasks\At9.job
- c:\windows\system32\eVF100eW.exe []
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-fihamewozo - c:\windows\system32\wanisupa.dll
Notify-2033be6c448 - c:\windows\System32\iasrad32.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.trane.com/Default.asp
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: java.com
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: microsoft.com\www.update
Trusted Zone: mocrosoft.com\*.windowsupdate
Trusted Zone: windowsupdate.com
Trusted Zone: windowsupdate.com\download
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-23 10:09:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(508)
c:\windows\system32\Ati2evxx.dll
c:\documents and settings\leeair\Application Data\ywseeruf.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-02-23 10:13:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-23 16:13:29

Pre-Run: 109,520,211,968 bytes free
Post-Run: 109,662,208,000 bytes free

295 --- E O F --- 2009-02-11 21:27:57


:cowboy:
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
AMD Processor Driver
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
ATI Parental Control & Encoder
Canon MP Navigator EX 1.0
Canon MX310 series
Canon MX310 series User Registration
Canon My Printer
Canon Utilities Easy-PhotoPrint EX
Canon Utilities Solution Menu
Electronic Service Control
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)

Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
MSN
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Nero 7 Essentials
PIXMA Extended Survey Program
Presto! PageManager 7.15.16
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
ScanSoft OmniPage SE 4

Spybot - Search & Destroy

Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format Runtime

pskelley
2009-02-23, 18:47
You have a very infected computer here, where did you pick up all of this junk? Looks like it's be morphing and developing since at least 2/10. Where is the HJT log I requested?


C:\ComboFix.txt in your next reply along with a New Hijackthis log.

Please read all directions very carefully.

scottd
2009-02-26, 17:19
It's right after the smiley face in the cowboy hat.

scottd
2009-02-26, 17:20
oops, sorry. I'll get one.

pskelley
2009-03-03, 12:58
Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.