Hello Forum,
Your participants have already helped me twice. So thank you again everyone!
This time I've got a problem with upoqimez.dll. My free anti-virus program AntiVir messaged that upoqimez is a virus. I went to safe mode and scanned windows system files with AntiVir.
Here is the report of that scan:
Avira AntiVir Personal
Report file date: 04 June 2010 10:40
Scanning for 2188388 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Save mode
Username : Guych&Jennet
Computer name : HOME
Version information:
BUILD.DAT : 9.0.0.422 21701 Bytes 3/9/2010 10:29:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 10/13/2009 11:26:33
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 10:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 11:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 10:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 07:35:52
VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 22:32:07
VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 22:32:26
VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 22:32:31
VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 22:32:38
VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 12:51:00
VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 21:19:07
VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 21:19:07
VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 21:19:07
VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 21:19:07
VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 21:19:07
VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 21:19:07
VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 21:19:07
VBASE013.VDF : 7.10.7.225 2048 Bytes 6/2/2010 21:19:07
VBASE014.VDF : 7.10.7.226 2048 Bytes 6/2/2010 21:19:07
VBASE015.VDF : 7.10.7.227 2048 Bytes 6/2/2010 21:19:08
VBASE016.VDF : 7.10.7.228 2048 Bytes 6/2/2010 21:19:08
VBASE017.VDF : 7.10.7.229 2048 Bytes 6/2/2010 21:19:08
VBASE018.VDF : 7.10.7.230 2048 Bytes 6/2/2010 21:19:08
VBASE019.VDF : 7.10.7.231 2048 Bytes 6/2/2010 21:19:08
VBASE020.VDF : 7.10.7.232 2048 Bytes 6/2/2010 21:19:08
VBASE021.VDF : 7.10.7.233 2048 Bytes 6/2/2010 21:19:08
VBASE022.VDF : 7.10.7.234 2048 Bytes 6/2/2010 21:19:08
VBASE023.VDF : 7.10.7.235 2048 Bytes 6/2/2010 21:19:08
VBASE024.VDF : 7.10.7.236 2048 Bytes 6/2/2010 21:19:08
VBASE025.VDF : 7.10.7.237 2048 Bytes 6/2/2010 21:19:08
VBASE026.VDF : 7.10.7.238 2048 Bytes 6/2/2010 21:19:08
VBASE027.VDF : 7.10.7.239 2048 Bytes 6/2/2010 21:19:08
VBASE028.VDF : 7.10.7.240 2048 Bytes 6/2/2010 21:19:09
VBASE029.VDF : 7.10.7.241 2048 Bytes 6/2/2010 21:19:09
VBASE030.VDF : 7.10.7.242 2048 Bytes 6/2/2010 21:19:09
VBASE031.VDF : 7.10.7.248 53760 Bytes 6/4/2010 09:30:38
Engineversion : 8.2.2.6
AEVDF.DLL : 8.1.2.0 106868 Bytes 4/23/2010 17:00:10
AESCRIPT.DLL : 8.1.3.31 1352058 Bytes 6/4/2010 09:30:46
AESCN.DLL : 8.1.6.1 127347 Bytes 5/12/2010 22:45:39
AESBX.DLL : 8.1.3.1 254324 Bytes 4/23/2010 17:00:11
AERDL.DLL : 8.1.4.6 541043 Bytes 4/16/2010 09:40:58
AEPACK.DLL : 8.2.1.1 426358 Bytes 3/26/2010 22:32:58
AEOFFICE.DLL : 8.1.1.0 201081 Bytes 5/12/2010 22:45:39
AEHEUR.DLL : 8.1.1.33 2724214 Bytes 6/4/2010 09:30:44
AEHELP.DLL : 8.1.11.5 242038 Bytes 6/4/2010 09:30:39
AEGEN.DLL : 8.1.3.10 377205 Bytes 6/4/2010 09:30:39
AEEMU.DLL : 8.1.2.0 393588 Bytes 4/23/2010 17:00:08
AECORE.DLL : 8.1.15.3 192886 Bytes 5/12/2010 22:45:37
AEBB.DLL : 8.1.1.0 53618 Bytes 4/23/2010 17:00:08
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 08:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 8/26/2009 15:14:02
AVREP.DLL : 8.0.0.7 159784 Bytes 3/26/2010 22:33:05
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 10:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 15:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 10:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 15:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 08:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 10:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 15:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 10/13/2009 12:25:47
Configuration settings for the scan:
Jobname.............................: Windows System Directory
Configuration file..................: d:\program files\avira\antivir desktop\sysdir.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: Intelligent file selection
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Start of the scan: 04 June 2010 10:40
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
11 processes with 11 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
D:\WINDOWS\upoqimez.dll
[DETECTION] Is the TR/ATRAPS.Gen2 Trojan
The registry was scanned ( '70' files ).
Starting the file scan:
Begin scan in 'D:\WINDOWS\system32'
D:\WINDOWS\system32\drivers\azubg.sys
[WARNING] The file could not be opened!
Beginning disinfection:
D:\WINDOWS\upoqimez.dll
[DETECTION] Is the TR/ATRAPS.Gen2 Trojan
[NOTE] The file was moved to '4c77cc4f.qua'!
End of the scan: 04 June 2010 10:48
Used time: 06:56 Minute(s)
The scan has been done completely.
262 Scanned directories
6089 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
1 Files cannot be scanned
6087 Files not concerned
14 Archives were scanned
1 Warnings
1 Notes
Here is the report by HiJackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:23, on 04/06/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\WLTRYSVC.EXE
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
D:\WINDOWS\system32\WLTRAY.exe
D:\Program Files\T-Mobile Mobile Broadband\T-Mobile Mobile Broadband Manager\UIExec.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\vsnp2uvc.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\T-Mobile Mobile Broadband\T-Mobile Mobile Broadband Manager\AssistantServices.exe
D:\Program Files\Trusteer\Rapport\bin\RapportService.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
d:\program files\avira\antivir desktop\avcenter.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\Program Files\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - D:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - D:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - D:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [UIExec] "D:\Program Files\T-Mobile Mobile Broadband\T-Mobile Mobile Broadband Manager\UIExec.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PAC7302_Monitor] D:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [combofix] "D:\ComboFix\CF14105.cfxxe" /c "D:\ComboFix\C.bat"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Wvomugojudoya] rundll32.exe "D:\WINDOWS\upoqimez.dll",Startup
O4 - HKLM\..\Run: [snp2uvc] D:\WINDOWS\vsnp2uvc.exe
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\Guych&Jennet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: &Download All with FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Mail.Ru ????? - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - D:\Program Files\Mail.Ru\Agent\magent.exe
O9 - Extra 'Tools' menuitem: Mail.Ru ????? - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - D:\Program Files\Mail.Ru\Agent\magent.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - (no file) (HKCU)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - D:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1269387173078
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1269825212750
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - D:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: UI Assistant Service - Unknown owner - D:\Program Files\T-Mobile Mobile Broadband\T-Mobile Mobile Broadband Manager\AssistantServices.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - D:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 9979 bytes
Since I removed the upoqimez.dll (it disappeared from the windows folder), windows after starting the computer brings up a message: "error loading d:/windows/upoqimez.dll. The specified module could not be found". After this message on computer start up everything works OK.
Could you please help me remove this annoying message?
Regards,
Guych.
Your participants have already helped me twice. So thank you again everyone!
This time I've got a problem with upoqimez.dll. My free anti-virus program AntiVir messaged that upoqimez is a virus. I went to safe mode and scanned windows system files with AntiVir.
Here is the report of that scan:
Avira AntiVir Personal
Report file date: 04 June 2010 10:40
Scanning for 2188388 virus strains and unwanted programs.
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Save mode
Username : Guych&Jennet
Computer name : HOME
Version information:
BUILD.DAT : 9.0.0.422 21701 Bytes 3/9/2010 10:29:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 10/13/2009 11:26:33
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 10:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 11:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 10:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 07:35:52
VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 22:32:07
VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 22:32:26
VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 22:32:31
VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 22:32:38
VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 12:51:00
VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 21:19:07
VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 21:19:07
VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 21:19:07
VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 21:19:07
VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 21:19:07
VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 21:19:07
VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 21:19:07
VBASE013.VDF : 7.10.7.225 2048 Bytes 6/2/2010 21:19:07
VBASE014.VDF : 7.10.7.226 2048 Bytes 6/2/2010 21:19:07
VBASE015.VDF : 7.10.7.227 2048 Bytes 6/2/2010 21:19:08
VBASE016.VDF : 7.10.7.228 2048 Bytes 6/2/2010 21:19:08
VBASE017.VDF : 7.10.7.229 2048 Bytes 6/2/2010 21:19:08
VBASE018.VDF : 7.10.7.230 2048 Bytes 6/2/2010 21:19:08
VBASE019.VDF : 7.10.7.231 2048 Bytes 6/2/2010 21:19:08
VBASE020.VDF : 7.10.7.232 2048 Bytes 6/2/2010 21:19:08
VBASE021.VDF : 7.10.7.233 2048 Bytes 6/2/2010 21:19:08
VBASE022.VDF : 7.10.7.234 2048 Bytes 6/2/2010 21:19:08
VBASE023.VDF : 7.10.7.235 2048 Bytes 6/2/2010 21:19:08
VBASE024.VDF : 7.10.7.236 2048 Bytes 6/2/2010 21:19:08
VBASE025.VDF : 7.10.7.237 2048 Bytes 6/2/2010 21:19:08
VBASE026.VDF : 7.10.7.238 2048 Bytes 6/2/2010 21:19:08
VBASE027.VDF : 7.10.7.239 2048 Bytes 6/2/2010 21:19:08
VBASE028.VDF : 7.10.7.240 2048 Bytes 6/2/2010 21:19:09
VBASE029.VDF : 7.10.7.241 2048 Bytes 6/2/2010 21:19:09
VBASE030.VDF : 7.10.7.242 2048 Bytes 6/2/2010 21:19:09
VBASE031.VDF : 7.10.7.248 53760 Bytes 6/4/2010 09:30:38
Engineversion : 8.2.2.6
AEVDF.DLL : 8.1.2.0 106868 Bytes 4/23/2010 17:00:10
AESCRIPT.DLL : 8.1.3.31 1352058 Bytes 6/4/2010 09:30:46
AESCN.DLL : 8.1.6.1 127347 Bytes 5/12/2010 22:45:39
AESBX.DLL : 8.1.3.1 254324 Bytes 4/23/2010 17:00:11
AERDL.DLL : 8.1.4.6 541043 Bytes 4/16/2010 09:40:58
AEPACK.DLL : 8.2.1.1 426358 Bytes 3/26/2010 22:32:58
AEOFFICE.DLL : 8.1.1.0 201081 Bytes 5/12/2010 22:45:39
AEHEUR.DLL : 8.1.1.33 2724214 Bytes 6/4/2010 09:30:44
AEHELP.DLL : 8.1.11.5 242038 Bytes 6/4/2010 09:30:39
AEGEN.DLL : 8.1.3.10 377205 Bytes 6/4/2010 09:30:39
AEEMU.DLL : 8.1.2.0 393588 Bytes 4/23/2010 17:00:08
AECORE.DLL : 8.1.15.3 192886 Bytes 5/12/2010 22:45:37
AEBB.DLL : 8.1.1.0 53618 Bytes 4/23/2010 17:00:08
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 08:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 8/26/2009 15:14:02
AVREP.DLL : 8.0.0.7 159784 Bytes 3/26/2010 22:33:05
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 10:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 15:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 10:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 15:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 08:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 10:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 15:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 10/13/2009 12:25:47
Configuration settings for the scan:
Jobname.............................: Windows System Directory
Configuration file..................: d:\program files\avira\antivir desktop\sysdir.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: Intelligent file selection
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Start of the scan: 04 June 2010 10:40
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
11 processes with 11 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
D:\WINDOWS\upoqimez.dll
[DETECTION] Is the TR/ATRAPS.Gen2 Trojan
The registry was scanned ( '70' files ).
Starting the file scan:
Begin scan in 'D:\WINDOWS\system32'
D:\WINDOWS\system32\drivers\azubg.sys
[WARNING] The file could not be opened!
Beginning disinfection:
D:\WINDOWS\upoqimez.dll
[DETECTION] Is the TR/ATRAPS.Gen2 Trojan
[NOTE] The file was moved to '4c77cc4f.qua'!
End of the scan: 04 June 2010 10:48
Used time: 06:56 Minute(s)
The scan has been done completely.
262 Scanned directories
6089 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
1 Files cannot be scanned
6087 Files not concerned
14 Archives were scanned
1 Warnings
1 Notes
Here is the report by HiJackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:30:23, on 04/06/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\WLTRYSVC.EXE
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Avira\AntiVir Desktop\sched.exe
D:\Program Files\Avira\AntiVir Desktop\avguard.exe
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
D:\WINDOWS\system32\WLTRAY.exe
D:\Program Files\T-Mobile Mobile Broadband\T-Mobile Mobile Broadband Manager\UIExec.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\Avira\AntiVir Desktop\avgnt.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\vsnp2uvc.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\T-Mobile Mobile Broadband\T-Mobile Mobile Broadband Manager\AssistantServices.exe
D:\Program Files\Trusteer\Rapport\bin\RapportService.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
d:\program files\avira\antivir desktop\avcenter.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\Program Files\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - D:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - D:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - D:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] D:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [UIExec] "D:\Program Files\T-Mobile Mobile Broadband\T-Mobile Mobile Broadband Manager\UIExec.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PAC7302_Monitor] D:\WINDOWS\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [combofix] "D:\ComboFix\CF14105.cfxxe" /c "D:\ComboFix\C.bat"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Wvomugojudoya] rundll32.exe "D:\WINDOWS\upoqimez.dll",Startup
O4 - HKLM\..\Run: [snp2uvc] D:\WINDOWS\vsnp2uvc.exe
O4 - HKCU\..\Run: [Google Update] "D:\Documents and Settings\Guych&Jennet\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler.exe
O8 - Extra context menu item: &Download All with FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - D:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Mail.Ru ????? - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - D:\Program Files\Mail.Ru\Agent\magent.exe
O9 - Extra 'Tools' menuitem: Mail.Ru ????? - {7558B7E5-7B26-4201-BEDB-00D5FF534523} - D:\Program Files\Mail.Ru\Agent\magent.exe
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - D:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - (no file) (HKCU)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - D:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1269387173078
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1269825212750
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - D:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: UI Assistant Service - Unknown owner - D:\Program Files\T-Mobile Mobile Broadband\T-Mobile Mobile Broadband Manager\AssistantServices.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - D:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 9979 bytes
Since I removed the upoqimez.dll (it disappeared from the windows folder), windows after starting the computer brings up a message: "error loading d:/windows/upoqimez.dll. The specified module could not be found". After this message on computer start up everything works OK.
Could you please help me remove this annoying message?
Regards,
Guych.