Default Malware/Virus won't stay gone
My computer has lots of fake virus software pop ups and keeps logging me off. I've removed the threats several times, but they return. Please help.
I cannot post HJT log because my computer will not let me log in. It immediately logs me off.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:53:09 AM, on 2/12/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\temp\fold1\FAH504-Console.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Robert Varnadore\Application Data\SystemProc\lsass.exe
C:\Program Files\Common Files\AOL\1139368192\ee\AOLSoftware.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\MDM.EXE
C:\temp\fold1\FahCore_78.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\smss32.exe
C:\Program Files\InternetSecurity2010\IS2010.exe
C:\Documents and Settings\Robert Varnadore\Desktop\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon32.exe
O2 - BHO: C:\WINDOWS\system32\srveota.dll - {C4BF49A2-94F1-42BD-F034-3604811C807D} - C:\WINDOWS\system32\srveota.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139368192\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [vogipavibo] Rundll32.exe "kulagira.dll",s
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKLM\..\Run: [mizoruveg] Rundll32.exe "c:\windows\system32\gunowini.dll",a
O4 - HKLM\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Gxegerisuba] rundll32.exe "C:\WINDOWS\efedicuv.dll",Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
O4 - HKCU\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10d.exe
O4 - HKLM\..\Policies\Explorer\Run: [RTHDBPL] C:\Documents and Settings\Robert Varnadore\Application Data\SystemProc\lsass.exe
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http://*.buy-internetsecurity10.com
O15 - Trusted Zone: http://*.buy-is2010.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.is-software-download25.com
O15 - Trusted Zone: http://*.is10-soft-download.com
O15 - Trusted Zone: http://*.buy-internetsecurity10.com (HKLM)
O15 - Trusted Zone: http://*.buy-is2010.com (HKLM)
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\kbdsock.dll,voginuhu.dll c:\windows\system32\gunowini.dll c:\windows\system32\hibunevo.dll
O21 - SSODL: hulololef - {cab7e239-3160-47a1-a725-507ece1040d1} - c:\windows\system32\zuragiwu.dll (file missing)
O21 - SSODL: yawoforiw - {cf4cad8e-5b15-4484-9f4e-c6f091950e06} - c:\windows\system32\sobamehu.dll (file missing)
O21 - SSODL: feputohig - {ea111da5-6b61-4fa3-be46-5d0acc0418b5} - c:\windows\system32\sobamehu.dll (file missing)
O21 - SSODL: golagukez - {e826b5cb-2e45-4636-9e61-503bc9f2e654} - c:\windows\system32\sobamehu.dll (file missing)
O21 - SSODL: vevugejoz - {b86e294b-9bbb-489c-8a77-247035dc576f} - c:\windows\system32\hibunevo.dll
O21 - SSODL: natibaker - {872c8655-65c6-4919-8fc5-46d8c4f54395} - c:\windows\system32\riguhoyu.dll (file missing)
O21 - SSODL: sohewolih - {f9be83aa-ca92-4c67-a8c6-b2b0416c1ec7} - c:\windows\system32\kehitulo.dll (file missing)
O21 - SSODL: forufibig - {b33b8422-a6a6-4713-9d77-392b41681c73} - c:\windows\system32\riguhoyu.dll (file missing)
O21 - SSODL: hojobuduz - {96a21697-a5b4-4665-a1f2-557093ca4064} - c:\windows\system32\hibunevo.dll
O21 - SSODL: pimihebag - {74cc9f53-0d09-49b2-8462-379b4b8f0876} - c:\windows\system32\hibunevo.dll
O21 - SSODL: tijubopib - {35c061d0-836a-4749-aa45-414aa3e5eaef} - c:\windows\system32\hibunevo.dll
O21 - SSODL: korinales - {277483f4-169e-4283-8d0a-44eeeff2cc31} - c:\windows\system32\hibunevo.dll
O21 - SSODL: tewepitim - {3c82df3f-11ef-41df-ac75-1cb4a62440ed} - c:\windows\system32\hibunevo.dll
O21 - SSODL: vuzozojut - {bf148403-d621-4c2b-a52e-318659fbc453} - c:\windows\system32\hibunevo.dll
O21 - SSODL: tizujuluw - {d1e54f74-f1dc-43b2-8cf5-3349fcdd600e} - c:\windows\system32\gunowini.dll
O21 - SSODL: luwavowul - {79683124-4c1c-468b-96c3-215479c67e25} - c:\windows\system32\gunowini.dll
O22 - SharedTaskScheduler: kupuhivus - {cab7e239-3160-47a1-a725-507ece1040d1} - c:\windows\system32\zuragiwu.dll (file missing)
O22 - SharedTaskScheduler: tokatiluy - {cf4cad8e-5b15-4484-9f4e-c6f091950e06} - c:\windows\system32\sobamehu.dll (file missing)
O22 - SharedTaskScheduler: mujuzedij - {ea111da5-6b61-4fa3-be46-5d0acc0418b5} - c:\windows\system32\sobamehu.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {e826b5cb-2e45-4636-9e61-503bc9f2e654} - c:\windows\system32\sobamehu.dll (file missing)
O22 - SharedTaskScheduler: mujuzedij - {b86e294b-9bbb-489c-8a77-247035dc576f} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: tokatiluy - {872c8655-65c6-4919-8fc5-46d8c4f54395} - c:\windows\system32\riguhoyu.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {f9be83aa-ca92-4c67-a8c6-b2b0416c1ec7} - c:\windows\system32\kehitulo.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {b33b8422-a6a6-4713-9d77-392b41681c73} - c:\windows\system32\riguhoyu.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {96a21697-a5b4-4665-a1f2-557093ca4064} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: gahurihor - {74cc9f53-0d09-49b2-8462-379b4b8f0876} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: gahurihor - {35c061d0-836a-4749-aa45-414aa3e5eaef} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: jugezatag - {277483f4-169e-4283-8d0a-44eeeff2cc31} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: mujuzedij - {3c82df3f-11ef-41df-ac75-1cb4a62440ed} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: kupuhivus - {bf148403-d621-4c2b-a52e-318659fbc453} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: gahurihor - {d1e54f74-f1dc-43b2-8cf5-3349fcdd600e} - c:\windows\system32\gunowini.dll
O22 - SharedTaskScheduler: kupuhivus - {79683124-4c1c-468b-96c3-215479c67e25} - c:\windows\system32\gunowini.dll
O22 - SharedTaskScheduler: lkjah87hfijgnfasidofgysgiughnjfkgfgdfgf - {C4BF49A2-94F1-42BD-F034-3604811C807D} - C:\WINDOWS\system32\srveota.dll (file missing)
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service:
- Stanford University - C:\temp\fold1\FAH504-Console.exe
O23 - Service: Google Update Service (gupdate1c9e48f2e706486) (gupdate1c9e48f2e706486) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
O23 - Service: Sony TVTA Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
--
End of file - 15326 bytes
My computer has lots of fake virus software pop ups and keeps logging me off. I've removed the threats several times, but they return. Please help.
I cannot post HJT log because my computer will not let me log in. It immediately logs me off.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:53:09 AM, on 2/12/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\temp\fold1\FAH504-Console.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Robert Varnadore\Application Data\SystemProc\lsass.exe
C:\Program Files\Common Files\AOL\1139368192\ee\AOLSoftware.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\MDM.EXE
C:\temp\fold1\FahCore_78.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\smss32.exe
C:\Program Files\InternetSecurity2010\IS2010.exe
C:\Documents and Settings\Robert Varnadore\Desktop\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R3 - URLSearchHook: IAOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL Toolbar\aoltb.dll
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
R3 - URLSearchHook: (no name) - - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon32.exe
O2 - BHO: C:\WINDOWS\system32\srveota.dll - {C4BF49A2-94F1-42BD-F034-3604811C807D} - C:\WINDOWS\system32\srveota.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL Toolbar\aoltb.dll
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139368192\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [vogipavibo] Rundll32.exe "kulagira.dll",s
O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
O4 - HKLM\..\Run: [mizoruveg] Rundll32.exe "c:\windows\system32\gunowini.dll",a
O4 - HKLM\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Gxegerisuba] rundll32.exe "C:\WINDOWS\efedicuv.dll",Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
O4 - HKCU\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10d.exe
O4 - HKLM\..\Policies\Explorer\Run: [RTHDBPL] C:\Documents and Settings\Robert Varnadore\Application Data\SystemProc\lsass.exe
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\helper32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O15 - Trusted Zone: http://*.buy-internetsecurity10.com
O15 - Trusted Zone: http://*.buy-is2010.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.is-software-download25.com
O15 - Trusted Zone: http://*.is10-soft-download.com
O15 - Trusted Zone: http://*.buy-internetsecurity10.com (HKLM)
O15 - Trusted Zone: http://*.buy-is2010.com (HKLM)
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\kbdsock.dll,voginuhu.dll c:\windows\system32\gunowini.dll c:\windows\system32\hibunevo.dll
O21 - SSODL: hulololef - {cab7e239-3160-47a1-a725-507ece1040d1} - c:\windows\system32\zuragiwu.dll (file missing)
O21 - SSODL: yawoforiw - {cf4cad8e-5b15-4484-9f4e-c6f091950e06} - c:\windows\system32\sobamehu.dll (file missing)
O21 - SSODL: feputohig - {ea111da5-6b61-4fa3-be46-5d0acc0418b5} - c:\windows\system32\sobamehu.dll (file missing)
O21 - SSODL: golagukez - {e826b5cb-2e45-4636-9e61-503bc9f2e654} - c:\windows\system32\sobamehu.dll (file missing)
O21 - SSODL: vevugejoz - {b86e294b-9bbb-489c-8a77-247035dc576f} - c:\windows\system32\hibunevo.dll
O21 - SSODL: natibaker - {872c8655-65c6-4919-8fc5-46d8c4f54395} - c:\windows\system32\riguhoyu.dll (file missing)
O21 - SSODL: sohewolih - {f9be83aa-ca92-4c67-a8c6-b2b0416c1ec7} - c:\windows\system32\kehitulo.dll (file missing)
O21 - SSODL: forufibig - {b33b8422-a6a6-4713-9d77-392b41681c73} - c:\windows\system32\riguhoyu.dll (file missing)
O21 - SSODL: hojobuduz - {96a21697-a5b4-4665-a1f2-557093ca4064} - c:\windows\system32\hibunevo.dll
O21 - SSODL: pimihebag - {74cc9f53-0d09-49b2-8462-379b4b8f0876} - c:\windows\system32\hibunevo.dll
O21 - SSODL: tijubopib - {35c061d0-836a-4749-aa45-414aa3e5eaef} - c:\windows\system32\hibunevo.dll
O21 - SSODL: korinales - {277483f4-169e-4283-8d0a-44eeeff2cc31} - c:\windows\system32\hibunevo.dll
O21 - SSODL: tewepitim - {3c82df3f-11ef-41df-ac75-1cb4a62440ed} - c:\windows\system32\hibunevo.dll
O21 - SSODL: vuzozojut - {bf148403-d621-4c2b-a52e-318659fbc453} - c:\windows\system32\hibunevo.dll
O21 - SSODL: tizujuluw - {d1e54f74-f1dc-43b2-8cf5-3349fcdd600e} - c:\windows\system32\gunowini.dll
O21 - SSODL: luwavowul - {79683124-4c1c-468b-96c3-215479c67e25} - c:\windows\system32\gunowini.dll
O22 - SharedTaskScheduler: kupuhivus - {cab7e239-3160-47a1-a725-507ece1040d1} - c:\windows\system32\zuragiwu.dll (file missing)
O22 - SharedTaskScheduler: tokatiluy - {cf4cad8e-5b15-4484-9f4e-c6f091950e06} - c:\windows\system32\sobamehu.dll (file missing)
O22 - SharedTaskScheduler: mujuzedij - {ea111da5-6b61-4fa3-be46-5d0acc0418b5} - c:\windows\system32\sobamehu.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {e826b5cb-2e45-4636-9e61-503bc9f2e654} - c:\windows\system32\sobamehu.dll (file missing)
O22 - SharedTaskScheduler: mujuzedij - {b86e294b-9bbb-489c-8a77-247035dc576f} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: tokatiluy - {872c8655-65c6-4919-8fc5-46d8c4f54395} - c:\windows\system32\riguhoyu.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {f9be83aa-ca92-4c67-a8c6-b2b0416c1ec7} - c:\windows\system32\kehitulo.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {b33b8422-a6a6-4713-9d77-392b41681c73} - c:\windows\system32\riguhoyu.dll (file missing)
O22 - SharedTaskScheduler: jugezatag - {96a21697-a5b4-4665-a1f2-557093ca4064} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: gahurihor - {74cc9f53-0d09-49b2-8462-379b4b8f0876} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: gahurihor - {35c061d0-836a-4749-aa45-414aa3e5eaef} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: jugezatag - {277483f4-169e-4283-8d0a-44eeeff2cc31} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: mujuzedij - {3c82df3f-11ef-41df-ac75-1cb4a62440ed} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: kupuhivus - {bf148403-d621-4c2b-a52e-318659fbc453} - c:\windows\system32\hibunevo.dll
O22 - SharedTaskScheduler: gahurihor - {d1e54f74-f1dc-43b2-8cf5-3349fcdd600e} - c:\windows\system32\gunowini.dll
O22 - SharedTaskScheduler: kupuhivus - {79683124-4c1c-468b-96c3-215479c67e25} - c:\windows\system32\gunowini.dll
O22 - SharedTaskScheduler: lkjah87hfijgnfasidofgysgiughnjfkgfgdfgf - {C4BF49A2-94F1-42BD-F034-3604811C807D} - C:\WINDOWS\system32\srveota.dll (file missing)
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Digidesign MME Refresh Service (DigiRefresh) - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O23 - Service: digiSPTIService - Digidesign, A Division of Avid Technology, Inc. - C:\Program Files\Digidesign\Pro Tools\digiSPTIService.exe
O23 - Service:
O23 - Service: Google Update Service (gupdate1c9e48f2e706486) (gupdate1c9e48f2e706486) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
O23 - Service: Sony TVTA Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
--
End of file - 15326 bytes
Last edited by a moderator: