Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Internet explorer very very slow!

  1. #1
    Member
    Join Date
    Dec 2007
    Posts
    58

    Default Internet explorer very very slow!

    Hi.

    Im having an issue with Internet explorer. It takes very long just to load an web page. About 20 seconds for google and lets be honest google does not have much pictures on its page. Im on 20mb (internet speed). Ive been to www.speedtest.net to test my internet speed. It said i was getting 15560kbps so about 15.5mb. So i tried to download something using internet explorer. When downloading "SPEED IS GREAT!" about 350kbps. Anyways i used AVG to scan computer it found trojan's. i deleted them and then internet explorer was working perfectly. it took 0.5 seconds for google to load and other sites. But the problem came back the next day. So i decided to scan again with AVG, but this time AVG found nothing and Internet explorer is going very very slow!!!!.

    Please help me Spybot team!!!!!

  2. #2
    Member
    Join Date
    Dec 2007
    Posts
    58

    Default

    Here is HJT log.


    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.optusnet.com.au/dsl/favorites/homepage
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: (no name) - {041BFD71-9350-4C06-A707-05C0CE5EB17B} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {16FB8F98-737D-4BCE-B35A-C2E0CBEF8E2E} - (no file)
    O2 - BHO: (no name) - {1A50E6E8-524A-4875-A666-EB37817B80A6} - (no file)
    O2 - BHO: (no name) - {32222621-EF56-4313-9737-AABD357B2C3B} - C:\WINDOWS\system32\mlljj.dll (file missing)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {a3ea07e6-de99-4c5a-9601-46d489a8d39d} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: {84151536-4589-84f8-3a14-ca96f28ccfba} - {abfcc82f-69ac-41a3-8f48-985463515148} - C:\WINDOWS\system32\yalynbub.dll (file missing)
    O2 - BHO: (no name) - {D6B6E738-846C-4258-81A8-4AD28307FA62} - (no file)
    O2 - BHO: (no name) - {F38EF7E6-4092-45E3-A0D4-B0C9F71E5971} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinFixer helper] C:\Program Files\WinFixer 2006\wfxcwr.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [NI.WFX6_0001_N57C0912] "C:\Documents and Settings\Owner\Desktop\WinFixer2006Install.exe" -nag
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [d0b45b06] rundll32.exe "C:\WINDOWS\system32\qostguna.dll",b
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [OptusNet DSL Setup] D:\OptusNet.exe
    O4 - HKCU\..\Run: [Steam] "e:\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = E:\Netgear\WG111v2.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://desktop.optusnet.com.au/dsl/favorites/homepage
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1141428218953
    O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames...1.cab60096.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab
    O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00326F0.dat
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O24 - Desktop Component 0: (no name) - http://images.google.com.au/images?q...03%2520No3.jpg
    O24 - Desktop Component 1: (no name) - http://www.daeya.org/imgs/wallpapers..._1600x1200.jpg

    --
    End of file - 10104 bytes

    Im working on kaspersky scan

  3. #3
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,252

    Default

    Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
    "BEFORE you POST" (READ this Procedure before Requesting Assistance)
    http://forums.spybot.info/showthread.php?t=288
    All advice given is taken at your own risk.
    Please make sure you have read this information so we are on the same page.

    Do not run and post the Kaspersky scan results until I request it.

    You have a Vundo infection (and more) which can be hard to remove. This will take some time and unless you are patient, understand how to follow directions and are comfortable working on your computer, you may want to seek local professional help. If you wish to proceed, read and follow the directions carefully.

    We need first to disable TeaTimer that it doesn't interfere with fixes. You can re-enable it when you're clean again:
    * Run Spybot-S&D in Advanced Mode.
    * If it is not already set to do this Go to the Mode menu select "Advanced Mode"
    * On the left hand side, Click on Tools
    * Then click on the Resident Icon in the List
    * Uncheck "Resident TeaTimer" and OK any prompts.
    * Restart your computer.

    Read and follow the directions carefully, the tools won't work unless you do. If you have either tool onboard, delete it and download it new from the link I provided.

    1) Thanks to Atribune and any others who helped with this fix.

    http://vundofix.atribune.org/ <<< tutorial

    "Download VundoFix" to your Desktop

    http://www.atribune.org/ccount/click.php?id=4

    Double-click VundoFix.exe to run it.
    When VundoFix opens, click the Scan for Vundo button.
    Once it's done scanning, click the Remove Vundo button.
    You will receive a prompt asking if you want to remove the files, click YES
    Once you click yes, your desktop will go blank as it starts removing Vundo.
    When completed, it will prompt that it will reboot your computer, click OK.
    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will attempt run on reboot, simply follow the above instructions starting from "Click
    the Scan for Vundo button." when VundoFix appears at reboot. Vundofix.txt will be on the C:\

    (wait until you finish to post reports and logs)

    2) Thanks to sUBs and anyone else who helped with this fix.

    Download ComboFix from Here or Here to your Desktop
    • Double click combofix.exe and follow the prompts.
    • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply

    Note: Do not mouseclick combofix's window while its running. That may cause it to stall

    Post the Vundofix.txt, combofix log and a new HJT log.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  4. #4
    Member
    Join Date
    Dec 2007
    Posts
    58

    Default

    Attachment 1898

    Attachment 1899

    HJT below:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:19:51 PM, on 12/29/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RunDll32.exe
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    E:\steam\steam.exe
    C:\WINDOWS\system32\ctfmon.exe
    E:\Netgear\WG111v2.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.optusnet.com.au/dsl/favorites/homepage
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {32222621-EF56-4313-9737-AABD357B2C3B} - C:\WINDOWS\system32\mlljj.dll (file missing)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SDHelper.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: {84151536-4589-84f8-3a14-ca96f28ccfba} - {abfcc82f-69ac-41a3-8f48-985463515148} - C:\WINDOWS\system32\yalynbub.dll (file missing)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinFixer helper] C:\Program Files\WinFixer 2006\wfxcwr.exe
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [NI.WFX6_0001_N57C0912] "C:\Documents and Settings\Owner\Desktop\WinFixer2006Install.exe" -nag
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [d0b45b06] rundll32.exe "C:\WINDOWS\system32\qostguna.dll",b
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [OptusNet DSL Setup] D:\OptusNet.exe
    O4 - HKCU\..\Run: [Steam] "e:\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = E:\Netgear\WG111v2.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://desktop.optusnet.com.au/dsl/favorites/homepage
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1141428218953
    O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames...1.cab60096.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O24 - Desktop Component 0: (no name) - http://images.google.com.au/images?q...03%2520No3.jpg
    O24 - Desktop Component 1: (no name) - http://www.daeya.org/imgs/wallpapers..._1600x1200.jpg

    --
    End of file - 9787 bytes

    Vundo and combo fix log are in attachments!

  5. #5
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,252

    Default

    As I requested, please read the instructions:
    Please make sure you have read this information so we are on the same page
    All logs should be copy/pasted into topic and not attached unless requested by helper in that format.
    When adding posts to your topic, do so by clicking ADD REPLY
    Comply with all instructions.

    Thanks
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  6. #6
    Member
    Join Date
    Dec 2007
    Posts
    58

    Default

    ComboFix 07-12-21.4 - Owner 2007-12-29 18:05:21.1 - NTFSx86
    Running from: E:\ComboFix.exe
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Owner\Application Data\install.dat
    C:\Program Files\Common Files\companion wizard
    C:\Program Files\Common Files\Companion Wizard\compwiz.exe
    C:\Program Files\Common Files\companion wizard\WapCHK.dll
    C:\Program Files\Common Files\Companion Wizard\WapCHK{6345E889-7C9D-4D32-A648-4D0A87E85E52}.dll
    C:\Program Files\Common Files\Companion Wizard\WapCHK{815EB2F4-488D-4AD7-82AC-F75D7D6336D2}.dll
    C:\Program Files\Common Files\Companion Wizard\WapCHK{C64A7ED3-0730-4CFA-9566-164A20185252}.dll
    C:\WINDOWS\system32\bwbkcnad
    C:\WINDOWS\system32\bwbkcnad\bg1.gif
    C:\WINDOWS\system32\bwbkcnad\bgtop.gif
    C:\WINDOWS\system32\bwbkcnad\bottom1.gif
    C:\WINDOWS\system32\bwbkcnad\bwbkcnad1.exe
    C:\WINDOWS\system32\bwbkcnad\bwbkcnad2.exe
    C:\WINDOWS\system32\bwbkcnad\bwbkcnad3.exe
    C:\WINDOWS\system32\bwbkcnad\essentials.gif
    C:\WINDOWS\system32\bwbkcnad\icon1.ico
    C:\WINDOWS\system32\bwbkcnad\install1.gif
    C:\WINDOWS\system32\bwbkcnad\left1.gif
    C:\WINDOWS\system32\bwbkcnad\li.gif
    C:\WINDOWS\system32\bwbkcnad\logo.gif
    C:\WINDOWS\system32\bwbkcnad\main.htm
    C:\WINDOWS\system32\bwbkcnad\mainframe.htm
    C:\WINDOWS\system32\bwbkcnad\reinstall1.gif
    C:\WINDOWS\system32\bwbkcnad\right1.gif
    C:\WINDOWS\system32\bwbkcnad\s1.htm
    C:\WINDOWS\system32\bwbkcnad\s2.htm
    C:\WINDOWS\system32\bwbkcnad\s3.htm
    C:\WINDOWS\system32\bwbkcnad\SMTop1.gif
    C:\WINDOWS\system32\bwbkcnad\SMTop2.gif
    C:\WINDOWS\system32\bwbkcnad\SMTop3.gif
    C:\WINDOWS\system32\bwbkcnad\SMTop4.gif
    C:\WINDOWS\system32\bwbkcnad\soft1_off.gif
    C:\WINDOWS\system32\bwbkcnad\soft1_off_ext.gif
    C:\WINDOWS\system32\bwbkcnad\soft1_on.gif
    C:\WINDOWS\system32\bwbkcnad\soft1_on_ext.gif
    C:\WINDOWS\system32\bwbkcnad\soft2_off.gif
    C:\WINDOWS\system32\bwbkcnad\soft2_off_ext.gif
    C:\WINDOWS\system32\bwbkcnad\soft2_on.gif
    C:\WINDOWS\system32\bwbkcnad\soft2_on_ext.gif
    C:\WINDOWS\system32\bwbkcnad\soft3_off.gif
    C:\WINDOWS\system32\bwbkcnad\soft3_off_ext.gif
    C:\WINDOWS\system32\bwbkcnad\soft3_on.gif
    C:\WINDOWS\system32\bwbkcnad\soft3_on_ext.gif
    C:\WINDOWS\system32\bwbkcnad\softbottom_off.gif
    C:\WINDOWS\system32\bwbkcnad\softbottom_on.gif
    C:\WINDOWS\system32\bwbkcnad\softleft_off.gif
    C:\WINDOWS\system32\bwbkcnad\softleft_on.gif
    C:\WINDOWS\system32\bwbkcnad\top1.gif
    C:\WINDOWS\system32\bwbkcnad\top2.gif
    C:\WINDOWS\system32\bwbkcnad\turnoff1.gif
    C:\WINDOWS\system32\bwbkcnad\turnon1.gif
    C:\WINDOWS\system32\conf.dat
    C:\WINDOWS\system32\stera.log
    C:\WINDOWS\system32\xpdx.sys

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .
    -------\LEGACY_DOMAINSERVICE
    -------\LEGACY_FOPN
    -------\LEGACY_VSPF
    -------\LEGACY_VSPF_HK
    -------\xpdx


    ((((((((((((((((((((((((( Files Created from 2007-11-28 to 2007-12-29 )))))))))))))))))))))))))))))))
    .

    2007-12-29 01:53 . 2007-12-29 01:53 <DIR> d-------- C:\Program Files\Trend Micro
    2007-12-28 12:27 . 2007-12-28 12:27 268 --ah----- C:\sqmdata04.sqm
    2007-12-28 12:27 . 2007-12-28 12:27 244 --ah----- C:\sqmnoopt04.sqm
    2007-12-28 01:32 . 2007-12-28 01:32 1,158 --a------ C:\WINDOWS\mozver.dat
    2007-12-28 00:52 . 2007-12-28 00:52 0 --a------ C:\WINDOWS\nsreg.dat
    2007-12-27 13:38 . 2007-12-27 13:38 244 --ah----- C:\sqmnoopt03.sqm
    2007-12-27 13:38 . 2007-12-27 13:38 232 --ah----- C:\sqmdata03.sqm
    2007-12-21 18:41 . 2007-12-21 18:46 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
    2007-12-20 16:52 . 2007-12-20 16:52 21,035 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
    2007-12-20 16:38 . 2007-03-27 04:30 49,904 -ra------ C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
    2007-12-20 16:27 . 2007-12-20 16:52 <DIR> d-------- C:\Netgear
    2007-12-13 20:14 . 2007-12-13 21:49 273 --a------ C:\WINDOWS\game.ini
    2007-12-09 09:35 . 2007-12-09 09:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2007-12-09 09:34 . 2007-12-09 09:34 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
    2007-12-09 09:31 . 2007-12-29 17:37 <DIR> d-------- C:\VundoFix Backups
    2007-12-08 12:13 . 2007-12-15 13:21 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
    2007-12-06 19:15 . 2007-12-24 11:04 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVG7
    2007-12-06 19:15 . 2007-12-06 19:15 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
    2007-12-06 19:14 . 2007-12-06 19:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2007-12-06 19:14 . 2007-12-28 23:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
    2007-12-05 19:25 . 2007-12-05 19:26 <DIR> d-------- C:\WINDOWS\~cua
    2007-12-05 19:25 . 2007-12-05 19:25 94,208 --a------ C:\WINDOWS\system32\SSW32N50.dll
    2007-12-05 19:25 . 2007-12-05 19:25 31,929 --a------ C:\WINDOWS\system32\SSNDIS3.VXD
    2007-12-05 19:25 . 2007-12-05 19:25 17,169 --a------ C:\WINDOWS\system32\SSNDIS5.sys
    2007-12-05 19:25 . 2007-12-05 19:25 16,544 --a------ C:\WINDOWS\system32\SSNDIS4.sys
    2007-12-05 18:53 . 2007-12-06 15:43 834 ---hs---- C:\WINDOWS\system32\kncilimj.ini
    2007-12-04 18:53 . 2007-12-05 17:26 714 --ahs---- C:\WINDOWS\system32\anugtsoq.ini
    2007-12-04 17:47 . 2007-12-04 18:08 474 ---hs---- C:\WINDOWS\system32\qpfcedxa.ini
    2007-12-03 17:45 . 2007-12-04 17:46 414 ---hs---- C:\WINDOWS\system32\wghtcgtr.ini
    2007-12-02 20:49 . 2007-12-03 19:16 <DIR> d-------- C:\Program Files\Symantec
    2007-12-02 20:49 . 2007-12-02 20:49 <DIR> d-------- C:\Program Files\New Folder
    2007-12-02 11:12 . 2007-12-06 18:44 102,031 ---hs---- C:\WINDOWS\system32\jjllm.bak2
    2007-12-01 23:57 . 2007-12-06 19:16 100,437 ---hs---- C:\WINDOWS\system32\jjllm.ini
    2007-12-01 23:57 . 2007-12-01 23:57 6,496 ---hs---- C:\WINDOWS\system32\jjllm.bak1
    2007-12-01 23:13 . 2007-12-01 23:13 107 --a------ C:\WINDOWS\wininit.ini

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-12-25 12:37 --------- d-----w C:\Documents and Settings\Owner\Application Data\Hamachi
    2007-12-22 06:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2007-12-20 05:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-12-03 08:16 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2007-12-03 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2007-12-01 13:21 --------- d--h--w C:\Program Files\ie-improver
    2007-11-22 20:23 --------- d-----w C:\Program Files\Activision
    2007-11-22 11:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2007-11-19 05:06 --------- d-----w C:\Documents and Settings\Owner\Application Data\uTorrent
    2007-11-16 04:40 --------- d-----w C:\Program Files\Java
    2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
    2007-11-11 02:15 --------- d-----w C:\Program Files\Common Files\Adobe
    2006-11-14 07:34 315,624 ----a-w C:\Program Files\direct x 9.0c.exe
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{32222621-EF56-4313-9737-AABD357B2C3B}]
    C:\WINDOWS\system32\mlljj.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{abfcc82f-69ac-41a3-8f48-985463515148}]
    C:\WINDOWS\system32\yalynbub.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "PowerBar"="" []
    "Steam"="e:\steam\steam.exe" [2007-11-30 16:20]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 23:00]
    "MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-04-17 13:49]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 16:10 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
    "Cmaudio"="RunDll32 cmicnfg.cpl" []
    "RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 18:35]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-13 15:52]
    "WinFixer helper"="C:\Program Files\WinFixer 2006\wfxcwr.exe" []
    "MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-04-17 13:49]
    "NI.WFX6_0001_N57C0912"="C:\Documents and Settings\Owner\Desktop\WinFixer2006Install.exe" []
    "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-10-06 12:11]
    "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-10-06 12:13]
    "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-10-06 12:10]
    "NvCplDaemon"="RUNDLL32.exe" [2004-08-04 23:00 C:\WINDOWS\system32\rundll32.exe]
    "nwiz"="nwiz.exe" []
    "Lexmark X6100 Series"="C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe" [2003-09-23 17:01]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 04:48]
    "NvMediaCenter"="RUNDLL32.exe" [2004-08-04 23:00 C:\WINDOWS\system32\rundll32.exe]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
    "d0b45b06"="C:\WINDOWS\system32\qostguna.dll" []
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-21 13:00]
    "OptusNet DSL Setup"="D:\OptusNet.exe" []

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-06 19:14]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\d_kmd.sys]
    @="Driver"

    .
    **************************************************************************

    catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-29 18:09:30
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    PowerBar = ?W?????????????????????????????????????????????????????????????|p??|????m??|?`?w?????????W????@?8?@??????W??c"?s???s??????@?????N'?s?W2?L|?s????????????u??s????????c"?s???s??????@?8?@?N'?s?W2??$@?8?@?8?@??????????W2??B2????s?B2??V2??B2??B2?0i?s????????(W2????

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    PROCESS: C:\WINDOWS\system32\winlogon.exe
    -> C:\WINDOWS\system32\RtlGina2.dll
    .
    Completion time: 2007-12-29 18:10:42 - machine was rebooted
    .
    2007-12-13 10:54:42 --- E O F ---

  7. #7
    Member
    Join Date
    Dec 2007
    Posts
    58

    Default

    VundoFix V6.7.0

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 9:31:47 AM 12/9/2007

    Listing files found while scanning....

    C:\windows\system32\drvtojr.dll

    Beginning removal...

    Attempting to delete C:\windows\system32\drvtojr.dll
    C:\windows\system32\drvtojr.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.7.7

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 5:37:29 PM 12/29/2007

    Listing files found while scanning....

    No infected files were found.


    Beginning removal...

  8. #8
    In Memoriam -Always in our heart pskelley's Avatar
    Join Date
    Oct 2005
    Location
    Clearwater, Florida
    Posts
    20,252

    Default

    G'Day and thanks for returning your information. Read and follow the directions carefully, if you do not understand something, please ask.

    Running from: E:\ComboFix.exe <<< I need to point out the importance of following the directions. The combofix instructions state:
    Download ComboFix from Here or Here to your Desktop
    and you have NOT done this!

    Follow all posted directions from this point on, if you do not understand something, ask. Anything other than this will results in my reconsidering if I am to continue my help.

    Some information about this item for you:
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    http://www.castlecops.com/startuplist-2034.html
    http://inetexplorer.mvps.org/answers/43.html

    See this: http://forums.spybot.info/showpost.p...80&postcount=2
    C:\Program Files\Java\j2re1.4.2\ <<< Java is VERY outdated and likely the reason you are infected. Download the newest version and uninstall all old versions in Add Remove programs.

    1) With TeaTimer still disabled.

    2) How to make files and folders visible:
    Click Start > Open My Computer.
    Select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm. Click OK.
    You may reverse this for safety when we are finished.

    3) Please download ATF Cleaner by Atribune
    http://www.atribune.org/content/view/25/2/
    Save it to your Desktop. We will use this later.

    4) Open a new notepad window
    Paste the list of files from the quote box below into the notepad window.

    C:\WINDOWS\system32\qostguna.dll
    C:\WINDOWS\system32\anugtsoq.ini
    C:\WINDOWS\system32\qpfcedxa.ini
    C:\WINDOWS\system32\wghtcgtr.ini
    C:\WINDOWS\system32\jjllm.bak2
    C:\WINDOWS\system32\jjllm.ini
    C:\WINDOWS\system32\jjllm.bak1
    Save this as vundofix.vft and Save as type "all files".
    Double-click VundoFix.exe to run it.
    Drag vundofix.vft onto the listbox (white box) of VundoFix.
    Click the "Remove Vundo" button.
    You will receive a prompt asking if you want to remove the files, click YES
    Once you click yes, your desktop will go blank as it starts removing Vundo.
    When completed, it will prompt that it will reboot your computer, click OK.
    Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

    5) Start > Control Panel > Add Remove programs and uninstall WinFixer 2006 if there.

    6) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

    O2 - BHO: (no name) - {32222621-EF56-4313-9737-AABD357B2C3B} - C:\WINDOWS\system32\mlljj.dll (file missing)
    O2 - BHO: {84151536-4589-84f8-3a14-ca96f28ccfba} - {abfcc82f-69ac-41a3-8f48-985463515148} - C:\WINDOWS\system32\yalynbub.dll (file missing)
    O4 - HKLM\..\Run: [WinFixer helper] C:\Program Files\WinFixer 2006\wfxcwr.exe
    O4 - HKLM\..\Run: [NI.WFX6_0001_N57C0912] "C:\Documents and Settings\Owner\Desktop\WinFixer2006Install.exe" -nag
    O4 - HKLM\..\Run: [d0b45b06] rundll32.exe "C:\WINDOWS\system32\qostguna.dll",b

    Close all programs but HJT and all browser windows, then click on "Fix Checked"

    7) RIGHT Click on Start then click on Explore. Locate and delete these items:

    C:\WINDOWS\system32\qostguna.dll <<< delete that file if there

    C:\Program Files\WinFixer 2006\ <<< delete that folder

    C:\Documents and Settings\Owner\Desktop\WinFixer2006Install.exe <<< delete that file

    8) Run ATF Cleaner
    Double-click ATF-Cleaner.exe to run the program.
    Click Select All found at the bottom of the list.
    Click the Empty Selected button.
    Click Exit on the Main menu to close the program.

    Restart and post the Vundofix report, a new HJT log and let me know how the computer is running.

    Cheers
    MS-MVP Consumer Security 2007-08-09
    Proud Member ASAP
    UNITE Member 2006

  9. #9
    Member
    Join Date
    Dec 2007
    Posts
    58

    Default

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:10:17 AM, on 12/30/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\ctfmon.exe
    E:\Netgear\WG111v2.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Owner\Desktop\VundoFix.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.optusnet.com.au/dsl/favorites/homepage
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SDHelper.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [OptusNet DSL Setup] D:\OptusNet.exe
    O4 - HKCU\..\Run: [Steam] "e:\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = E:\Netgear\WG111v2.exe
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
    O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://desktop.optusnet.com.au/dsl/favorites/homepage
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10...I.cab55579.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games Buddy Invite) - http://zone.msn.com/BinFrameWork/v10...y.cab55579.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10...t.cab55579.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1141428218953
    O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames...1.cab60096.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games Game Communicator) - http://zone.msn.com/binframework/v10...y.cab55579.cab
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O24 - Desktop Component 0: (no name) - http://images.google.com.au/images?q...03%2520No3.jpg
    O24 - Desktop Component 1: (no name) - http://www.daeya.org/imgs/wallpapers..._1600x1200.jpg

    --
    End of file - 9271 bytes

  10. #10
    Member
    Join Date
    Dec 2007
    Posts
    58

    Default

    VundoFix V6.7.0

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 9:31:47 AM 12/9/2007

    Listing files found while scanning....

    C:\windows\system32\drvtojr.dll

    Beginning removal...

    Attempting to delete C:\windows\system32\drvtojr.dll
    C:\windows\system32\drvtojr.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.7.7

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 5:37:29 PM 12/29/2007

    Listing files found while scanning....

    No infected files were found.


    Beginning removal...

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\anugtsoq.ini
    C:\WINDOWS\system32\anugtsoq.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\jjllm.bak1
    C:\WINDOWS\system32\jjllm.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\jjllm.bak2
    C:\WINDOWS\system32\jjllm.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\jjllm.ini
    C:\WINDOWS\system32\jjllm.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\qpfcedxa.ini
    C:\WINDOWS\system32\qpfcedxa.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\wghtcgtr.ini
    C:\WINDOWS\system32\wghtcgtr.ini Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.7.7

    Checking Java version...

    Java version is 1.5.0.3
    Old versions of java are exploitable and should be removed.

    Scan started at 12:10:01 AM 12/30/2007

    Listing files found while scanning....

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •