PDA

View Full Version : Infection, I can't format, I can't do anything.



cpqazwsx
2009-03-11, 23:05
Posted over the weekend, opted to reformat. Current log is posted below. REGEDIT is disabled, I get an error message however I try to format C:. I attempted to just put my WinXP CD in, and when I try to launch it, it says the current version of the OS is newer than the one I'm trying to install and won't do anything.

Any help would be appreciated.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:54:16 PM, on 3/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\Q2FtZXJvbiBQZXJzb25ldHQ\command.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\WINDOWS\TEMP\winlogon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [lrijh8s73jhbfgfd] C:\DOCUME~1\CAMERO~1\LOCALS~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [CPM2bab20b4] Rundll32.exe "c:\windows\system32\buwuwati.dll",a
O4 - HKLM\..\Run: [28981328] rundll32.exe "C:\WINDOWS\system32\gigijomo.dll",b
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [Firewall auto setup] C:\WINDOWS\TEMP\winlogon.exe
O4 - HKCU\..\Policies\Explorer\Run: [{28981387-0574-1033-0627-051114200001}] "C:\Program Files\Common Files\{28981387-0574-1033-0627-051114200001}\Update.exe" mc-110-12-0000140
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [wegikajeje] Rundll32.exe "C:\WINDOWS\system32\yevapoli.dll",s (User '?')
O4 - HKUS\S-1-5-21-3265194449-2610212797-1443940987-1006\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (User '?')
O4 - HKUS\S-1-5-21-3265194449-2610212797-1443940987-1006\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (User '?')
O4 - HKUS\S-1-5-21-3265194449-2610212797-1443940987-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-3265194449-2610212797-1443940987-1006\..\Run: [Firewall auto setup] C:\WINDOWS\TEMP\winlogon.exe (User '?')
O4 - HKUS\S-1-5-21-3265194449-2610212797-1443940987-1006\..\Policies\Explorer\Run: [{28981387-0574-1033-0627-051114200001}] "C:\Program Files\Common Files\{28981387-0574-1033-0627-051114200001}\Update.exe" mc-110-12-0000140 (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: c:\windows\system32\buwuwati.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\buwuwati.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\buwuwati.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Q2FtZXJvbiBQZXJzb25ldHQ\command.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 6443 bytes


http://forums.spybot.info/showthread.php?t=46493

Shaba
2009-03-12, 17:16
Hi cpqazwsx

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.

cpqazwsx
2009-03-16, 03:28
ComboFix 09-03-13.02 - Cameron Personett 2009-03-15 20:33:11.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.132 [GMT -5:00]
Running from: c:\documents and settings\Cameron Personett\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\windows\Q2FtZXJvbiBQZXJzb25ldHQ\asappsrv.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Cameron Personett\Application Data\GetModule
c:\documents and settings\Cameron Personett\Application Data\GetModule\dicik.gz
c:\documents and settings\Cameron Personett\Application Data\GetModule\kwdik.gz
c:\documents and settings\Cameron Personett\Application Data\GetModule\ofadik.gz
c:\documents and settings\Cameron Personett\Application Data\inst.exe
c:\documents and settings\Cameron Personett\Application Data\PPPATC~1
c:\documents and settings\Cameron Personett\Application Data\SpeedRunner
c:\documents and settings\Cameron Personett\Application Data\SpeedRunner\config.cfg
c:\documents and settings\Cameron Personett\gside.exe
c:\documents and settings\Cameron Personett\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Cameron Personett\Start Menu\Programs\ucmore - the search accelerator
c:\documents and settings\Cameron Personett\Start Menu\Programs\ucmore - the search accelerator\How To Uninstall.lnk
c:\documents and settings\Cameron Personett\Start Menu\Programs\ucmore - the search accelerator\UCmore - The Search Accelerator.lnk
c:\documents and settings\Cameron Personett\Start Menu\Programs\ucmore - the search accelerator\UCmore Tour.lnk
c:\documents and settings\Cameron Personett\z.exe
c:\documents and settings\Other User (not me)\Start Menu\Programs\Startup\Deewoo.lnk
c:\program files\Common Files\{28981~1
c:\program files\Common Files\{38981~1
c:\program files\Common Files\{38981~1\Bar888.dll
c:\program files\Common Files\fnts~1
c:\program files\Common Files\icroso~1.net
c:\program files\Common Files\Yazzle1122OinUninstaller.exe
c:\program files\Common Files\Yazzle1281OinUninstaller.exe
c:\program files\Common Files\Yazzle1396OinUninstaller.exe
c:\program files\GetModule
c:\program files\GetModule\GetModule34.exe
c:\program files\GetModule\GetModule35.exe
c:\program files\GetModule\GetModule36.exe
c:\program files\GetPack
c:\program files\GetPack\dictame.gz
c:\program files\GetPack\GetPack28.exe
c:\program files\GetPack\trgtame.gz
c:\program files\iCheck
c:\program files\iCheck\Uninstall.exe
c:\program files\inetget2
c:\program files\ipwindows
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
c:\program files\Mjcore
c:\program files\Mjcore\Mjcore.dll
c:\program files\network monitor
c:\program files\network monitor\netmon.exe
c:\program files\outlook
c:\program files\thesearchaccelerator
c:\program files\thesearchaccelerator\INSTALL.LOG
c:\program files\thesearchaccelerator\IUCmore.dll
c:\program files\thesearchaccelerator\logo.ico
c:\program files\thesearchaccelerator\TBlogin.users.ucmore.com.4.5.40.0
c:\program files\thesearchaccelerator\toolbar.cfg
c:\program files\thesearchaccelerator\UCMTSAIE.dll
c:\program files\thesearchaccelerator\UNWISE.EXE
c:\program files\VnrPack
c:\program files\VnrPack\dicts.gz
c:\program files\VnrPack\trgts.gz
c:\temp\0b9
c:\temp\0b9\tmpTF.log
c:\windows\Q2FtZXJvbiBQZXJzb25ldHQ\
c:\windows\Q2FtZXJvbiBQZXJzb25ldHQ\\asappsrv.dll.vir
c:\windows\Q2FtZXJvbiBQZXJzb25ldHQ\\command.exe
c:\windows\Q2FtZXJvbiBQZXJzb25ldHQ\\kZIQtrLSv21ktrLWvZc5xJk.vbs
c:\windows\Q2FtZXJvbiBQZXJzb25ldHQ\command.exe
c:\windows\system32\ahixqdnb.ini
c:\windows\system32\ahtn.htm
c:\windows\system32\amuradug.ini
c:\windows\system32\anewewij.ini
c:\windows\system32\app.exe
c:\windows\system32\atmtd.dll
c:\windows\system32\atmtd.dll._
c:\windows\system32\bdKkRCcf.ini
c:\windows\system32\bdKkRCcf.ini2
c:\windows\system32\bidiwaye.dll
c:\windows\system32\bokeneja.dll
c:\windows\system32\cmd.com
c:\windows\system32\cptnof.ini
c:\windows\system32\cptnof.ini2
c:\windows\system32\cptnof.tmp
c:\windows\system32\dwdsregt.exe
c:\windows\system32\ebilizod.ini
c:\windows\system32\efvnbw.dll
c:\windows\system32\iksokb.dll
c:\windows\system32\imwgxmub.ini
c:\windows\system32\JmVDcJlm.ini
c:\windows\system32\JmVDcJlm.ini2
c:\windows\system32\kntpboiw.ini
c:\windows\system32\ligwxeyj.ini
c:\windows\system32\mcrh.tmp
c:\windows\system32\msnav32.ax
c:\windows\system32\mysidesearch_sidebar.dll
c:\windows\system32\mysidesearch_sidebar_uninstall.exe
c:\windows\system32\myss_sb_uninstall.exe
c:\windows\system32\netstat.com
c:\windows\system32\npfrxhfo.ini
c:\windows\system32\ochmobpu.ini
c:\windows\system32\ohkwjmaw.ini
c:\windows\system32\omojigig.ini
c:\windows\system32\pakiguwu.dll
c:\windows\system32\ping.com
c:\windows\system32\qeyufcay.ini
c:\windows\system32\qrqrgddy.ini
c:\windows\system32\qsAGNqss.ini
c:\windows\system32\qsAGNqss.ini2
c:\windows\system32\regedit.com
c:\windows\system32\sft.res
c:\windows\system32\sgkrmiid.ini
c:\windows\system32\sonlqb.dll
c:\windows\system32\T2
c:\windows\system32\T2\dlb66.exe
c:\windows\system32\T3
c:\windows\system32\T4
c:\windows\system32\T6
c:\windows\system32\taskkill.com
c:\windows\system32\tasklist.com
c:\windows\system32\tracert.com
c:\windows\system32\twain32
c:\windows\system32\twain32\local.ds
c:\windows\system32\twain32\user.ds
c:\windows\system32\uniq.tll
c:\windows\system32\vdcfadhf.ini
c:\windows\system32\vebeleje.dll
c:\windows\system32\vvkkbeov.ini
c:\windows\system32\vyadd.ini2
c:\windows\system32\vyadd.tmp
c:\windows\system32\wadfebsn.ini
c:\windows\system32\wapiisv32.exe
c:\windows\system32\warning.gif
c:\windows\system32\winpfz32.sys
c:\windows\system32\winpfz33.sys
c:\windows\system32\wmfcejim.ini
c:\windows\system32\wpv801232809034.cpx
c:\windows\system32\wpv821232320584.cpx
c:\windows\system32\wpv931233435391.cpx
c:\windows\system32\xuqeebhi.ini
c:\windows\system32\yvfovv.dll
c:\windows\system32\zxdnt3d.cfg
c:\windows\Tasks\lumqmkao.job
c:\windows\Tasks\ytvngaag.job
c:\windows\uninstall_nmon.vbs
c:\windows\wiaserviv.log
c:\windows\winhelp.ini
E:\autorun.inf
F:\autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

Shaba
2009-03-16, 06:14
Combofix log cuts off.

Please resend it :)

cpqazwsx
2009-03-18, 02:13
ComboFix 09-03-13.02 - Cameron Personett 2009-03-17 18:49:50.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.236 [GMT -5:00]
Running from: c:\documents and settings\Cameron Personett\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\omojigig.ini

.
((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.

2009-03-11 16:20 . 2009-03-11 16:20 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\AVG7
2009-03-10 21:27 . 2009-03-10 21:27 244 --ah----- C:\sqmnoopt17.sqm
2009-03-10 21:27 . 2009-03-10 21:27 244 --ah----- C:\sqmdata17.sqm
2009-03-10 19:31 . 2009-03-10 19:31 244 --ah----- C:\sqmnoopt16.sqm
2009-03-10 19:31 . 2009-03-10 19:31 244 --ah----- C:\sqmdata16.sqm
2009-03-08 13:58 . 2005-08-26 15:44 <DIR> d-------- c:\documents and settings\Administrator.D8QGV981\Application Data\Symantec
2009-03-08 13:58 . 2005-08-26 15:31 <DIR> d-------- c:\documents and settings\Administrator.D8QGV981\Application Data\Jasc Software Inc
2009-03-08 13:58 . 2009-03-17 18:38 <DIR> d-------- c:\documents and settings\Administrator.D8QGV981
2009-03-05 22:45 . 2009-03-05 22:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\Azureus
2009-03-05 22:43 . 2009-03-08 10:07 <DIR> d-------- c:\documents and settings\Cameron Personett\Application Data\Azureus
2009-03-05 22:42 . 2009-03-05 22:42 <DIR> d-------- c:\program files\AskBarDis
2009-03-05 22:38 . 2009-03-05 22:39 <DIR> d-------- c:\program files\Vuze
2009-03-03 18:02 . 2009-03-03 18:02 36,912 --a------ c:\documents and settings\Cameron Personett\zbc00.exe
2009-03-01 11:03 . 2009-03-01 11:03 36,912 --a------ c:\documents and settings\Other User (not me)\zbc00.exe
2009-02-20 17:11 . 2009-02-20 17:11 <DIR> d-------- c:\program files\Microsoft Games
2009-02-17 22:15 . 2002-03-29 13:58 396,509 --a------ C:\Picture1.jpg
2009-02-17 22:15 . 2002-03-29 13:59 382,843 --a------ C:\Picture2.jpg
2009-02-17 13:25 . 2009-02-17 13:27 <DIR> d-------- c:\program files\EwisoftWeb

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 23:39 --------- d-----w c:\documents and settings\All Users\Application Data\Avg7
2009-03-17 23:38 --------- d-----w c:\documents and settings\Other User (not me)\Application Data\AVG7
2009-03-17 23:38 --------- d-----w c:\documents and settings\Cameron Personett\Application Data\AVG7
2009-03-16 01:33 0 ----a-w c:\windows\system32\drivers\aec.sys
2009-03-11 00:39 --------- d-----w c:\program files\Microsoft AntiSpyware
2009-03-11 00:32 --------- d-----w c:\program files\DivX
2009-03-11 00:03 --------- d-----w c:\program files\Pinnacle
2009-03-10 02:55 34 ----a-w c:\documents and settings\Other User (not me)\jagex_runescape_preferences.dat
2009-03-10 00:07 34 ----a-w c:\documents and settings\Cameron Personett\jagex_runescape_preferences.dat
2009-03-09 15:13 84,992 --sha-w c:\windows\system32\buwuwati.dll
2009-03-09 15:13 79,872 --sha-w c:\windows\system32\gigijomo.dll
2009-03-09 03:13 84,992 --sha-w c:\windows\system32\nuzuwugu.dll
2009-03-09 03:13 79,872 --sha-w c:\windows\system32\dozilibe.dll
2009-03-08 15:12 84,992 --sha-w c:\windows\system32\bovenage.dll
2009-03-08 15:12 79,872 ------w c:\windows\system32\jiwewena.dll
2009-03-08 03:10 84,992 --sha-w c:\windows\system32\difemura.dll
2009-03-08 03:10 79,872 --sha-w c:\windows\system32\gudaruma.dll
2009-03-07 15:10 84,992 --sha-w c:\windows\system32\zuhojeka.dll
2009-03-07 03:10 84,992 --sha-w c:\windows\system32\yojuyivo.dll
2009-03-06 15:10 84,992 --sha-w c:\windows\system32\punaheki.dll
2009-02-27 21:42 63,893 ----a-w c:\windows\system32\{3b3012a2-25ae-ff78-84ad-cf0f1ce20213}.dll-uninst.exe
2009-02-18 04:47 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-17 17:32 --------- d-----w c:\documents and settings\Other User (not me)\Application Data\gtk-2.0
2009-02-17 02:06 --------- d-----w c:\documents and settings\Cameron Personett\Application Data\Vso
2009-02-16 04:02 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-02-16 04:02 47,360 ----a-w c:\documents and settings\Cameron Personett\Application Data\pcouffin.sys
2009-02-16 04:01 --------- d-----w c:\program files\VSO
2009-02-14 22:12 --------- d-----w c:\documents and settings\Cameron Personett\Application Data\gtk-2.0
2009-02-13 04:01 --------- d-----w c:\program files\GIMP-2.0
2009-02-12 22:55 536,684 ----a-w c:\windows\system32\rwinsndi.exe
2009-02-05 16:16 548,972 ----a-w c:\windows\system32\rwinsndj.exe
2009-02-05 10:16 47,596 ----a-w c:\windows\system32\mzkufaxpeeup.exe
2009-02-03 02:06 --------- d-----w c:\program files\Trend Micro
2009-02-03 00:05 91,696 ----a-w c:\windows\system32\xsqjdbdn.dll
2009-02-01 22:20 199,113 ----a-w c:\documents and settings\Other User (not me)\gand.exe
2009-01-31 23:58 199,035 ----a-w c:\documents and settings\Other User (not me)\gsnd.exe
2009-01-28 15:57 47,596 ----a-w c:\windows\system32\kyoqyivzdg.exe
2009-01-28 05:03 --------- d-----w c:\program files\Common Files\Common Share
2009-01-28 04:45 --------- d-----w c:\program files\MIKSOFT
2009-01-26 04:51 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-25 18:59 --------- d-----w c:\documents and settings\Cameron Personett\Application Data\Twain
2009-01-25 18:09 --------- d-----w c:\program files\Google
2009-01-25 16:43 --------- d-----w c:\program files\WebShow
2009-01-25 08:31 --------- d-----w c:\program files\Free YouTube Downloader Converter
2009-01-25 08:20 --------- d-----w c:\program files\NCH Software
2009-01-25 08:20 --------- d-----w c:\documents and settings\Cameron Personett\Application Data\NCH Software
2009-01-25 08:17 --------- d-----w c:\documents and settings\All Users\Application Data\NCH Software
2009-01-25 08:07 --------- d-----w c:\program files\Common Files\AVSMedia
2009-01-25 08:07 --------- d-----w c:\program files\AVS4YOU
2009-01-25 07:42 --------- d-----w c:\documents and settings\Cameron Personett\Application Data\AVS4YOU
2009-01-25 07:22 --------- d-----w c:\program files\Free FLV Converter
2009-01-25 07:19 --------- d-----w c:\documents and settings\Cameron Personett\Application Data\Dealio
2009-01-25 07:04 --------- d-----w c:\program files\Common Files\Download Manager
2009-01-24 02:38 69,027 ----a-w c:\windows\system32\fwufznesgmcasg.dll-uninst.exe
2009-01-19 11:50 551,424 ----a-w c:\windows\system32\fwufznesgmcasg.dll
2009-01-16 05:46 199,029 ----a-w c:\documents and settings\Cameron Personett\gsnd.exe
2009-01-15 17:46 199,113 ----a-w c:\documents and settings\Cameron Personett\gand.exe
2009-01-15 02:22 379,392 ----a-w c:\windows\system32\ivggxokxelkbmhq.dll
2009-01-08 14:16 389,632 ----a-w c:\windows\system32\swhslqvcrzpc.dll
2008-12-24 14:02 274,432 ----a-w c:\windows\system32\TubeFinder.exe
2008-12-18 19:38 351,744 ----a-w c:\windows\system32\avisynth.dll
2008-10-10 22:55 153,513 ----a-w c:\documents and settings\Other User (not me)\g58.exe
2008-07-13 04:29 4,169,614 ----a-w c:\program files\ptr2.til
2008-04-12 00:01 399,466 ----a-w c:\documents and settings\Cameron Personett\g58.exe
2002-07-26 22:02 153,088 ----a-w c:\program files\UNWISE.EXE
2006-06-21 22:56 56 --sh--r c:\windows\system32\01DBFB6396.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-12-09 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-22 67128]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\Msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-02-15 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-02-15 126976]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2006-07-04 190024]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"CPM2bab20b4"="c:\windows\system32\buwuwati.dll" [2009-03-09 84992]
"28981328"="c:\windows\system32\gigijomo.dll" [2009-03-09 79872]
"ISUSPM Startup"="c:\progra~1\common~1\instal~1\update~1\isuspm.exe" [2004-07-27 221184]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 68856]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil9f.exe" [2008-03-24 218496]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-22 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\buwuwati.dll" [2009-03-09 84992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\buwuwati.dll [2009-03-09 84992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\buwuwati.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPX"= PICVideo MJPEG Codec

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Trial\\halo.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=

S2 DVC150;DVC 150B;c:\windows\system32\drivers\DVC150B.sys [2007-05-18 31924]
S4 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [2009-03-05 464264]
S4 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-03-05 234888]
S4 gupdate1c97f1797aa1010;Google Update Service (gupdate1c97f1797aa1010);c:\program files\Google\Update\GoogleUpdate.exe [2009-01-25 133104]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6a4a253b-1a73-11da-8eb6-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee4746bb-f520-11db-90e0-00123fe5829b}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL autorun.exe
\Shell\Explore\command - E:\autorun.exe
\Shell\Open\command - E:\autorun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5EB96953-7D02-4594-AC15-F55FC9AACFCB}]
rundll32 msfacat32.dll,InitModule
.
Contents of the 'Scheduled Tasks' folder

2009-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 17:13]

2009-03-11 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-01-25 13:04]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Cameron Personett\Application Data\Mozilla\Firefox\Profiles\e95hrkq5.default\
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: c:\program files\Google\Update\1.2.133.37\npGoogleOneClick7.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-17 18:55:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:2e,e8,e1,00,eb,16,2b,de,04,e1,e2,ce,98,
f1,86,b7,e2,63,26,f1,3f,c8,ff,68,46,5a,08,e3,54,4b,82,21,e2,63,26,f1,3f,c8,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,e9,e0,23,8a,3b,
c8,89,75,6a,9c,d6,61,af,45,84,18,1d,b1,08,6e,1b,6d,29,1e,6a,9c,d6,61,af,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,d9,30,db,d4,6a,
92,6b,94,ff,7c,85,e0,43,d4,0e,fe,2e,34,80,17,90,95,61,b7,ff,7c,85,e0,43,d4,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,d5,5e,41,b7,58,
4e,78,84,86,8c,21,01,be,91,eb,e7,e7,d2,fa,f3,e5,d6,70,e7,86,8c,21,01,be,91,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,28,5c,e4,48,0b,
6f,0d,da,f5,1d,4d,73,a8,13,5c,05,04,6b,ba,e6,f8,e2,9f,ff,f5,1d,4d,73,a8,13,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,be,c8,ad,f9,b2,
62,6c,bc,df,20,58,62,78,6b,cf,c8,2d,3e,3e,4e,61,ca,50,86,df,20,58,62,78,6b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:31,77,e1,ba,b1,f8,68,02,ce,63,7b,6c,2b,
fa,ee,f8,fb,a7,78,e6,12,2f,9a,ea,21,08,cd,c8,10,50,e2,0f,fb,a7,78,e6,12,2f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,19,f5,33,0c,56,
dc,10,ae,01,3a,48,fc,e8,04,4a,f1,55,3f,d1,b2,27,43,03,3b,01,3a,48,fc,e8,04,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:b2,46,9a,e2,1b,fe,1b,94,db,ae,d9,3f,fc,
cb,b5,22,f6,0f,4e,58,98,5b,89,c9,2e,c7,7f,70,b6,18,c1,f8,f6,0f,4e,58,98,5b,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,d9,e1,dc,68,fd,
be,25,b2,3d,ce,ea,26,2d,45,aa,78,6a,c7,38,e0,10,10,2d,98,3d,ce,ea,26,2d,45,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,a7,60,a2,e4,8c,
c3,57,fd,2a,b7,cc,b5,b9,7f,41,e7,41,41,ba,95,bf,32,65,5d,2a,b7,cc,b5,b9,7f,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,c0,83,ea,35,74,
7b,3c,e0,6c,43,2d,1e,aa,22,2f,9c,62,75,45,9e,06,09,3c,50,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(464)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-03-17 19:00:07
ComboFix-quarantined-files.txt 2009-03-17 23:58:49
ComboFix2.txt 2009-03-16 02:04:41

Pre-Run: 7,927,865,344 bytes free
Post-Run: 7,906,971,648 bytes free

282 --- E O F --- 2009-01-14 09:06:16

Shaba
2009-03-18, 06:13
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

http://img.bleepingcomputer.com/tutorials/hijackthis/uninstall-man.jpg

5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.

cpqazwsx
2009-03-18, 16:12
Action Replay Code Manager
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
ALPS Touch Pad Driver
AOLIcon
Apple Software Update
Audacity 1.2.6
AviSynth 2.5
Banctec Service Agreement
BitLord 1.1
Broadcom Management Programs 2
CamStudio
Conexant D110 MDC V.9x Modem
ConvertXtoDVD 3.4.7.121
Dealio Toolbar
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Media Experience
Dell Photo Printer 720
Dell Photo Printer 720 Logger
Dell Picture Studio v3.0
Dell Support Center
Dell Wireless WLAN Card
DellSupport
Digital Line Detect
DivX Content Uploader
DivX Web Player
EPSON Web-To-Page
GIMP 2.6.3
Google Gears
Google Toolbar for Internet Explorer
Google Update
Google Video Player
GTK+ 2.10.6-1 runtime environment
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
HyperCam 2
Intel(R) Graphics Media Accelerator Driver for Mobile
Internal Network Card Power Management
Internet Explorer Default Page
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro 8 Dell Edition
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Java(TM) SE Development Kit 6 Update 1
Java(TM) SE Runtime Environment 6 Update 1
LastChaos
Learn2 Player (Uninstall Only)
LG USB Drivers
LG USB Modem driver
Logitech Desktop Messenger
Logitech Print Service
Logitech QuickCam Software
Logitech® Camera Driver
Macromedia Extension Manager
Macromedia Flash 8 Video Encoder
Macromedia Flash Player 8 Plugin
Macromedia Shockwave Player
Messenger Plus! 3
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft AntiSpyware
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Halo Trial
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Professional
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Modem Helper
Morpheus 5.1 (remove only)
Mozilla Firefox (3.0.7)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
Musicmatch for Windows Media Player
NetWaiting
OIN
oRipa Screen Recorder
Outerinfo
Pinnacle device drivers
Power Tab Editor 1.7
PowerDVD 5.5
Prism Video Converter
Project64 1.6
QuickSet
QuickTime
RAPID (Studio 10)
RealPlayer Basic
RealWorld Cursor Editor
Rhapsody Player Engine
Rhythm Rascal
RON Too1 Du-little
RON Too1 Freedomltd
Screen Recorder Gold
Search Assistant Mysidesearch
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
SmartSound Quicktracks Plugin
Sonic DLA
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sony Media Manager 2.2
SwiftKit
The Legend of Zelda: A Twist of Fate
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
V CAST Music
V CAST Music Manager
Video mp3 Extractor
Videora iPod Converter 3.05
Viewpoint Media Player
Vuze
Vuze Toolbar
WebCyberCoach 3.2 Dell
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB893086
WinRAR archiver
WinZip
Wisdom-soft Toolbar
WordPerfect Office 12
Yahoo! Toolbar for Internet Explorer
YouTube FLV to AVI converter Pro 2.1.0
YouTube Robot 2.0.2008.331
Zelda Classic 2.10w
zelda Screensaver
ZillaTube 3.1

Shaba
2009-03-18, 16:15
IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

BitLord 1.1
Morpheus 5.1 (remove only)
Vuze
Vuze Toolbar

I'd like you to read the this thread (http://forums.spybot.info/showthread.php?t=282).

Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

Uninstall also these:

RON Too1 Du-little
RON Too1 Freedomltd
Search Assistant Mysidesearch

Please run a new uninstall list scan when finished and post the log back here.

cpqazwsx
2009-03-18, 22:22
Morpheus does not seem to want to uninstall, it keeps hanging and freezing. The computer does not have internet access currently, that my be the issue with the uninstall.

Action Replay Code Manager
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Reader 6.0.1
ALPS Touch Pad Driver
AOLIcon
Apple Software Update
Audacity 1.2.6
AviSynth 2.5
Banctec Service Agreement
Broadcom Management Programs 2
CamStudio
Conexant D110 MDC V.9x Modem
ConvertXtoDVD 3.4.7.121
Dealio Toolbar
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Media Experience
Dell Photo Printer 720
Dell Photo Printer 720 Logger
Dell Picture Studio v3.0
Dell Support Center
Dell Wireless WLAN Card
DellSupport
Digital Line Detect
DivX Content Uploader
DivX Web Player
EPSON Web-To-Page
GIMP 2.6.3
Google Gears
Google Toolbar for Internet Explorer
Google Update
Google Video Player
GTK+ 2.10.6-1 runtime environment
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
HyperCam 2
Intel(R) Graphics Media Accelerator Driver for Mobile
Internal Network Card Power Management
Internet Explorer Default Page
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro 8 Dell Edition
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Java(TM) SE Development Kit 6 Update 1
Java(TM) SE Runtime Environment 6 Update 1
LastChaos
Learn2 Player (Uninstall Only)
LG USB Drivers
LG USB Modem driver
Logitech Desktop Messenger
Logitech Print Service
Logitech QuickCam Software
Logitech® Camera Driver
Macromedia Extension Manager
Macromedia Flash 8 Video Encoder
Macromedia Flash Player 8 Plugin
Macromedia Shockwave Player
Messenger Plus! 3
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft AntiSpyware
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Halo Trial
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 Professional
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Modem Helper
Morpheus 5.1 (remove only)
Mozilla Firefox (3.0.7)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
Musicmatch for Windows Media Player
NetWaiting
OIN
oRipa Screen Recorder
Outerinfo
Pinnacle device drivers
Power Tab Editor 1.7
PowerDVD 5.5
Prism Video Converter
Project64 1.6
QuickSet
QuickTime
RAPID (Studio 10)
RealPlayer Basic
RealWorld Cursor Editor
Rhapsody Player Engine
Rhythm Rascal
Screen Recorder Gold
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
SmartSound Quicktracks Plugin
Sonic DLA
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sony Media Manager 2.2
SwiftKit
The Legend of Zelda: A Twist of Fate
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
V CAST Music
V CAST Music Manager
Video mp3 Extractor
Videora iPod Converter 3.05
Viewpoint Media Player
WebCyberCoach 3.2 Dell
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB893086
WinRAR archiver
WinZip
Wisdom-soft Toolbar
WordPerfect Office 12
Yahoo! Toolbar for Internet Explorer
YouTube FLV to AVI converter Pro 2.1.0
YouTube Robot 2.0.2008.331
Zelda Classic 2.10w
zelda Screensaver
ZillaTube 3.1

Shaba
2009-03-19, 06:18
OK we will remove it by other means.

Please post a fresh hijackthis log next.

cpqazwsx
2009-03-19, 20:47
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:44:11 PM, on 3/19/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [CPM2bab20b4] Rundll32.exe "c:\windows\system32\buwuwati.dll",a
O4 - HKLM\..\Run: [28981328] rundll32.exe "C:\WINDOWS\system32\gigijomo.dll",b
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: c:\windows\system32\buwuwati.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\buwuwati.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\buwuwati.dll
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 5241 bytes

Shaba
2009-03-19, 20:58
Looks like you have been reinfected.

Looking over your log, it seems you don''t have any evidence of an anti-virus software.

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

1) Antivir PersonalEdition Classic (http://www.free-av.com/)- Free anti-virus software for Windows. Free support.
2) avast! 4 Home Edition (http://www.avast.com/eng/avast_4_home.html) - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
3) AVG Anti-Virus Free Edition (http://free.grisoft.com/ww.homepage) - Free edition of the AVG anti-virus program for Windows.

You should run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and results in program conflicts and false virus alerts.

After that, please post back a fresh hijackthis log and we will continue with cleaning.

cpqazwsx
2009-03-19, 23:29
Each time I ran ComboFix, it said that I had to disable AVG Anti virus to continue, even though I didn't have it running..so I uninstalled it for the occasion. Although I'm not sure how I could have been reinfected, as my computer was not connected to the internet ever since I took it off earlier this week.

Shaba
2009-03-20, 06:16
Reinfection has been happened internally.

Please rerun combofix, if it asks to update itself allow it to do so, post back its log and a fresh hijsckthis log.

Shaba
2009-03-24, 07:52
Due to the lack of feedback this Topic is closed.

If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.