Thank You Shelflife!!! Below is the Vundofix and Combofix logs. I will post the HJT log in the next post due to the length of the message. Scott
VundoFix V6.5.0
Checking Java version...
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Scan started at 8:31:07 PM 6/11/2007
Listing files found while scanning....
C:\windows\system32\afjkqhod.dll
C:\windows\system32\bmiannkf.exe
C:\windows\system32\cocqymnj.exe
C:\WINDOWS\system32\ddaby.dll
C:\windows\system32\fcyirgig.exe
C:\windows\system32\hxtryjvv.dll
C:\windows\system32\iyulgape.exe
C:\windows\system32\j3211432.dll
C:\windows\system32\muwlaxmg.exe
C:\windows\system32\rvqnduwu.dll
C:\WINDOWS\system32\ujraqsdy.dll
C:\windows\system32\vjqvoxoy.exe
C:\WINDOWS\system32\yayvtqn.dll
C:\WINDOWS\system32\ybadd.bak1
C:\windows\system32\ybadd.bak2
C:\WINDOWS\system32\ybadd.ini
C:\windows\system32\ydsqarju.ini
Beginning removal...
Attempting to delete C:\windows\system32\afjkqhod.dll
C:\windows\system32\afjkqhod.dll Has been deleted!
Attempting to delete C:\windows\system32\bmiannkf.exe
C:\windows\system32\bmiannkf.exe Has been deleted!
Attempting to delete C:\windows\system32\cocqymnj.exe
C:\windows\system32\cocqymnj.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\ddaby.dll Has been deleted!
Attempting to delete C:\windows\system32\fcyirgig.exe
C:\windows\system32\fcyirgig.exe Has been deleted!
Attempting to delete C:\windows\system32\hxtryjvv.dll
C:\windows\system32\hxtryjvv.dll Has been deleted!
Attempting to delete C:\windows\system32\iyulgape.exe
C:\windows\system32\iyulgape.exe Has been deleted!
Attempting to delete C:\windows\system32\j3211432.dll
C:\windows\system32\j3211432.dll Could not be deleted.
Attempting to delete C:\windows\system32\muwlaxmg.exe
C:\windows\system32\muwlaxmg.exe Has been deleted!
Attempting to delete C:\windows\system32\rvqnduwu.dll
C:\windows\system32\rvqnduwu.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ujraqsdy.dll
C:\WINDOWS\system32\ujraqsdy.dll Has been deleted!
Attempting to delete C:\windows\system32\vjqvoxoy.exe
C:\windows\system32\vjqvoxoy.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\yayvtqn.dll
C:\WINDOWS\system32\yayvtqn.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\ybadd.bak1
C:\WINDOWS\system32\ybadd.bak1 Has been deleted!
Attempting to delete C:\windows\system32\ybadd.bak2
C:\windows\system32\ybadd.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ybadd.ini
C:\WINDOWS\system32\ybadd.ini Has been deleted!
Attempting to delete C:\windows\system32\ydsqarju.ini
C:\windows\system32\ydsqarju.ini Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\j3211432.dll
C:\windows\system32\j3211432.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\yayvtqn.dll
C:\WINDOWS\system32\yayvtqn.dll Has been deleted!
Performing Repairs to the registry.
Done!
omboFix 07-06-11.3 - C:\Documents and Settings\Scott\Desktop\ComboFix.exe
"Scott" - 2007-06-11 20:42:14 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Scott\APPLIC~1.\fnts~1
C:\DOCUME~1\Scott\APPLIC~1.\fnts~1\regsvr32.exe
C:\Program Files\Movie Maker\rterelehdu.html
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Temp\0b9
C:\Temp\0b9\tmpTF.log
C:\Temp\tn3
C:\w.exe
C:\WINDOWS\764.exe
C:\WINDOWS\cfg32.exe
C:\WINDOWS\cfg32a.exe
C:\WINDOWS\cs_cache.ini
C:\WINDOWS\dls0523pmw.exe
C:\WINDOWS\rau001978.exe
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\curity~1
C:\WINDOWS\system32\curity~1\smss.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\pog
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T3\am67.exe
C:\WINDOWS\system32\T4
C:\WINDOWS\system32\T4\amst5.exe
C:\WINDOWS\system32\wmvds32.dll
C:\WINDOWS\system32\wnscpsv32.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_CORE
-------\LEGACY_NET_AGENT
-------\core
-------\Net Agent
((((((((((((((((((((((((( Files Created from 2007-05-12 to 2007-06-12 )))))))))))))))))))))))))))))))
2007-06-11 20:41 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-11 20:31 <DIR> d-------- C:\VundoFix Backups
2007-06-09 14:06 18,432 --a------ C:\WINDOWS\sysrlb32.exe
2007-06-09 13:29 4 --a------ C:\WINDOWS\SYSTEM32\stfv.bin
2007-06-09 13:29 12 --a------ C:\WINDOWS\SYSTEM32\sl.bin
2007-06-09 13:28 9,216 --a------ C:\WINDOWS\voiceip.dll
2007-06-09 13:28 9,216 --a------ C:\WINDOWS\SYSTEM32\WER8274.DLL
2007-06-09 13:28 9,216 --a------ C:\WINDOWS\salm.exe
2007-06-09 13:28 8,960 --a------ C:\WINDOWS\saiemod.dll
2007-06-09 13:28 30,976 --a------ C:\WINDOWS\7search.dll
2007-06-09 13:28 30,464 --a------ C:\WINDOWS\wml.exe
2007-06-09 13:28 30,208 --a------ C:\WINDOWS\flt.dll
2007-06-09 13:28 29,440 --a------ C:\WINDOWS\pbar.dll
2007-06-09 13:28 28,416 --a------ C:\WINDOWS\satmat.exe
2007-06-09 13:28 25,344 --a------ C:\WINDOWS\mssvr.exe
2007-06-09 13:28 25,088 --a------ C:\WINDOWS\SYSTEM32\msdn_lib.dll
2007-06-09 13:28 23,296 --a------ C:\WINDOWS\SYSTEM32\MSIXU.DLL
2007-06-09 13:28 22,016 --a------ C:\WINDOWS\stcloader.exe
2007-06-09 13:28 20,736 --a------ C:\WINDOWS\bokja.exe
2007-06-09 13:28 19,456 --a------ C:\WINDOWS\SYSTEM32\wml.exe
2007-06-09 13:28 19,456 --a------ C:\WINDOWS\bi.dll
2007-06-09 13:28 19,200 --a------ C:\WINDOWS\Biprep.exe
2007-06-09 13:28 17,664 --a------ C:\WINDOWS\mspphe.dll
2007-06-09 13:28 17,152 --a------ C:\WINDOWS\180ax.exe
2007-06-09 13:28 15,872 --a------ C:\WINDOWS\2020search2.dll
2007-06-09 13:28 14,336 --a------ C:\WINDOWS\swin32.dll
2007-06-09 13:28 13,568 --a------ C:\WINDOWS\updatetc.exe
2007-06-09 13:28 12,544 --a------ C:\WINDOWS\SYSTEM32\vxddsk.exe
2007-06-09 13:28 12 --a------ C:\WINDOWS\SYSTEM32\gtv_sd.bin
2007-06-09 13:28 11,520 --a------ C:\WINDOWS\2020search.dll
2007-06-09 13:28 11,008 --a------ C:\WINDOWS\SUSP.exe
2007-06-09 13:28 10,496 --a------ C:\WINDOWS\cdsm32.dll
2007-06-09 13:28 10,496 --a------ C:\WINDOWS\bjam.dll
2007-06-09 13:28 10,240 --a------ C:\WINDOWS\vxddsk.exe
2007-06-06 21:11 55,316 --a------ C:\WINDOWS\SYSTEM32\cghvjarg.dll
2007-06-06 19:04 <DIR> d-------- C:\Hijack This
2007-06-04 21:30 <DIR> d-------- C:\Program Files\Common Files\Scanner
2007-06-03 11:26 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-06-03 11:26 <DIR> d-------- C:\Program Files\Windows Defender
2007-06-03 10:31 25,088 --a------ C:\WINDOWS\SYSTEM32\msxml3a.dll
2007-06-02 23:16 932 --a------ C:\WINDOWS\SYSTEM32\winpfz32.sys
2007-06-02 23:16 60,928 --a------ C:\WINDOWS\SYSTEM32\zgqgfuds.dll
2007-06-02 23:16 54,784 --a------ C:\WINDOWS\bawiabh.exe
2007-06-02 23:16 49,152 --a------ C:\WINDOWS\TISKY009.exe
2007-06-02 23:16 326,352 -r-hs---- C:\WINDOWS\bawiabhA.exe
2007-06-02 23:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\TQ0
2007-06-02 23:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\T9
2007-06-02 23:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\T7
2007-06-02 23:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\T6
2007-06-02 23:16 <DIR> d-------- C:\WINDOWS\SYSTEM32\T1QaSQ
2007-06-02 23:16 <DIR> d-------- C:\Temp\x2b
2007-06-02 23:16 <DIR> d-------- C:\Temp
2007-06-02 23:16 <DIR> d-------- C:\Program Files\myCleanerPC
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-12 00:45:46 -------- d-----w C:\Program Files\Movie Maker
2007-06-05 01:30:15 -------- d-----w C:\Program Files\Yahoo!
2007-06-03 22:51:07 1,620 ----a-w C:\DOCUME~1\Scott\APPLIC~1\wklnhst.dat
2007-06-03 15:34:45 -------- d-----w C:\Program Files\NetZero
2007-06-03 15:12:28 -------- d-----w C:\Program Files\Verizon Games on Demand Player
2007-06-03 15:12:23 -------- d-----w C:\Program Files\QuickTime
2007-06-03 15:12:22 -------- d-----w C:\Program Files\OfficeUpdate11
2007-06-03 15:12:20 -------- d-----w C:\Program Files\Modem Helper
2007-06-03 15:12:19 -------- d-----w C:\Program Files\McAfee.com
2007-06-03 15:12:14 -------- d-----w C:\Program Files\Intel
2007-06-03 15:12:11 -------- d-----w C:\Program Files\Connection Wizard
2007-06-03 15:12:09 -------- d-----w C:\Program Files\Common Files\aolshare
2007-06-03 15:12:06 -------- d-----w C:\Program Files\America Online 9.0
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2005-10-19 03:18:19 28,173 --sh--w C:\WINDOWS\SYSTEM32\gebyx.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-11-21 15:54]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03 15:17]
{330A62FE-74C1-4F19-B3A2-DDB4982A5397}=C:\WINDOWS\system32\qmjloadd.dll [2006-08-18 20:03]
{38847C4B-1AB1-4A47-9026-9A6CF7B43D31}=C:\WINDOWS\system32\msdn_lib.dll [2007-06-09 13:28]
{4D25F921-B9FE-4682-BF72-8AB8210D6D75}=C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll [2004-09-27 20:57]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 02:04]
{5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\system32\dla\tfswshx.dll [2004-12-06 02:05]
{691B44DC-BA2A-4198-B2BA-9B59FCDFFF1c}=C:\WINDOWS\system32\qmjloadd.dll [2006-08-18 20:03]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar4.dll [2007-01-20 00:55]
{C30C4F4F-D78A-D17C-8A0F-F8ADA89024EA}=C:\WINDOWS\system32\zgqgfuds.dll [2007-05-21 09:59]
{E36C6AAD-2D39-4202-9309-15336C3C7BF8}=C:\WINDOWS\system32\ddaby.dll []
{E7097B63-2A6D-4CCE-8432-2775B60B1FDe}=C:\WINDOWS\system32\qmjloadd.dll [2006-08-18 20:03]
{FEC22291-64EB-4D3F-89BE-229F7E121384}=C:\WINDOWS\system32\qmjloadd.dll [2006-08-18 20:03]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 18:48]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 21:12]
"CTSysVol"="C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 11:43]
"P17Helper"="P17.dll" [2004-06-10 12:51 C:\WINDOWS\SYSTEM32\P17.dll]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 17:54]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 02:01]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-11-07 16:41]
"MimBoot"="C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe" [2006-11-07 16:41]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-10-22 18:49]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [2005-06-28 15:23]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2003-10-14 05:15]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-02-02 22:39]
"Uaol"="C:\WINDOWS\system32\CURITY~1\smss.exe" []
"Bdmd"="C:\Documents and Settings\Scott\Application Data\F?nts\regsvr32.exe" []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= C:\Program Files\Movie Maker\rterelehdu.html
FriendlyName=
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source= C:\WINDOWS\warnhp.html
FriendlyName= Desktop Uninstall
Contents of the 'Scheduled Tasks' folder
2007-05-08 18:24:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-12 00:40:14 C:\WINDOWS\tasks\MP Scheduled Scan.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-11 20:48:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-11 20:49:47 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-11 20:49
--- E O F ---