vundofix.txt &
Hi there.
Here is the vundofix.txt and the hjt.txt
+--------------------------------------------------------
+--------------------------------------------------------
VundoFix V6.3.21
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.10
Java version is 1.5.0.11
Scan started at 8:36:09 9/5/2007
Listing files found while scanning....
C:\WINDOWS\system32\aaccf.bak1
C:\WINDOWS\system32\aaccf.ini
C:\WINDOWS\system32\cfeeg.bak1
C:\WINDOWS\system32\cfeeg.bak2
C:\WINDOWS\system32\cfeeg.ini
C:\WINDOWS\system32\cfeeg.ini2
C:\WINDOWS\system32\cfeeg.tmp
C:\WINDOWS\system32\cxqmtryo.ini
C:\WINDOWS\system32\elwhqoku.dll
C:\WINDOWS\system32\fccaa.dll
C:\WINDOWS\system32\geefc.dll
C:\WINDOWS\system32\gnpilnay.ini
C:\WINDOWS\system32\hcoqcqwx.dll
C:\WINDOWS\system32\hlsuvpbu.dll
C:\WINDOWS\system32\hrykfsjo.dll
C:\WINDOWS\system32\ihiktpts.dll
C:\WINDOWS\system32\iodjluno.dll
C:\WINDOWS\system32\khfdd.dll
C:\WINDOWS\system32\kocflrfj.dll
C:\WINDOWS\system32\kolhqfiu.dll
C:\WINDOWS\system32\likdhpqp.ini
C:\WINDOWS\system32\lkvpnpfm.dll
C:\WINDOWS\system32\mtkwcpgs.dll
C:\WINDOWS\system32\nxcogfyw.dll
C:\WINDOWS\system32\oasckpco.dll
C:\WINDOWS\system32\onuljdoi.ini
C:\WINDOWS\system32\oyrtmqxc.dll
C:\WINDOWS\system32\pqphdkil.dll
C:\WINDOWS\system32\sgpcwktm.ini
C:\WINDOWS\system32\sjixnoiy.dll
C:\WINDOWS\system32\ubpvuslh.ini
C:\WINDOWS\system32\uhtesmnk.dll
C:\WINDOWS\system32\ukoqhwle.ini
C:\WINDOWS\system32\vhevxtpy.dll
C:\WINDOWS\system32\vmnmmpgb.dll
C:\WINDOWS\system32\wvwus.dll
C:\WINDOWS\system32\wyfgocxn.ini
C:\WINDOWS\system32\xnxiwlcp.dll
C:\WINDOWS\system32\xwqcqoch.ini
C:\WINDOWS\system32\yabxx.dll
C:\WINDOWS\system32\yanlipng.dll
C:\WINDOWS\system32\ybircmad.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\aaccf.bak1
C:\WINDOWS\system32\aaccf.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\aaccf.ini
C:\WINDOWS\system32\aaccf.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\cfeeg.bak1
C:\WINDOWS\system32\cfeeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cfeeg.bak2
C:\WINDOWS\system32\cfeeg.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cfeeg.ini
C:\WINDOWS\system32\cfeeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\cfeeg.ini2
C:\WINDOWS\system32\cfeeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cfeeg.tmp
C:\WINDOWS\system32\cfeeg.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\cxqmtryo.ini
C:\WINDOWS\system32\cxqmtryo.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\elwhqoku.dll
C:\WINDOWS\system32\elwhqoku.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\geefc.dll
C:\WINDOWS\system32\geefc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\gnpilnay.ini
C:\WINDOWS\system32\gnpilnay.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\hcoqcqwx.dll
C:\WINDOWS\system32\hcoqcqwx.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\hlsuvpbu.dll
C:\WINDOWS\system32\hlsuvpbu.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\hrykfsjo.dll
C:\WINDOWS\system32\hrykfsjo.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\iodjluno.dll
C:\WINDOWS\system32\iodjluno.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\kocflrfj.dll
C:\WINDOWS\system32\kocflrfj.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\kolhqfiu.dll
C:\WINDOWS\system32\kolhqfiu.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\likdhpqp.ini
C:\WINDOWS\system32\likdhpqp.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\lkvpnpfm.dll
C:\WINDOWS\system32\lkvpnpfm.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\mtkwcpgs.dll
C:\WINDOWS\system32\mtkwcpgs.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\nxcogfyw.dll
C:\WINDOWS\system32\nxcogfyw.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\oasckpco.dll
C:\WINDOWS\system32\oasckpco.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\onuljdoi.ini
C:\WINDOWS\system32\onuljdoi.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\oyrtmqxc.dll
C:\WINDOWS\system32\oyrtmqxc.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pqphdkil.dll
C:\WINDOWS\system32\pqphdkil.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\sgpcwktm.ini
C:\WINDOWS\system32\sgpcwktm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ubpvuslh.ini
C:\WINDOWS\system32\ubpvuslh.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ukoqhwle.ini
C:\WINDOWS\system32\ukoqhwle.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\vhevxtpy.dll
C:\WINDOWS\system32\vhevxtpy.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\vmnmmpgb.dll
C:\WINDOWS\system32\vmnmmpgb.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wyfgocxn.ini
C:\WINDOWS\system32\wyfgocxn.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\xnxiwlcp.dll
C:\WINDOWS\system32\xnxiwlcp.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\xwqcqoch.ini
C:\WINDOWS\system32\xwqcqoch.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\yanlipng.dll
C:\WINDOWS\system32\yanlipng.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ybircmad.dll
C:\WINDOWS\system32\ybircmad.dll Has been deleted!
Performing Repairs to the registry.
Done!
+--------------------------------------------------------
+--------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 8:47:00, on 9/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\spnpinst.exe
C:\WINDOWS\system32\Sysocmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {007A9571-2AA0-4BAC-B175-A65DD1C17911} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0 CE\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0A79858C-FFED-43FE-8D1C-5A96B7A53216} - C:\WINDOWS\system32\fccaa.dll (file missing)
O2 - BHO: (no name) - {182B90A3-F372-438A-800C-6814B4DE417B} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - (no file)
O2 - BHO: (no name) - {30A3130A-A2B5-4A5D-8080-8182A01C2897} - (no file)
O2 - BHO: (no name) - {3F1D5EB0-704F-4C09-BCD6-865136296A97} - C:\WINDOWS\system32\irlhugdm.dll
O2 - BHO: (no name) - {4CAE0F17-7A2D-443A-AE4E-D8DD7438B703} - C:\WINDOWS\system32\geefc.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: (no name) - {5EA64A72-4F8C-4463-A0F6-363A9296FD5E} - (no file)
O2 - BHO: (no name) - {64D5E9A2-F34F-43FF-BFD0-FDFB371D1CA1} - C:\WINDOWS\system32\khfdd.dll (file missing)
O2 - BHO: (no name) - {67F84DF5-09FF-42CC-A649-A9C60E5DB9E8} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {918F4D71-A7E6-4DCD-A101-3BD6BB8A0D99} - (no file)
O2 - BHO: (no name) - {94AB2ADD-DE9F-4389-92AA-FCB50E59BB48} - (no file)
O2 - BHO: (no name) - {9D992E8D-6D03-417E-9656-EA33F55EA3C2} - C:\WINDOWS\system32\wvwus.dll (file missing)
O2 - BHO: (no name) - {D0645271-30A3-45C1-8DAA-A48F8FE4E1F6} - (no file)
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - (no file)
O2 - BHO: (no name) - {DB4398CD-2388-4C04-B620-B891609A3649} - (no file)
O2 - BHO: (no name) - {F4A77A8C-A7A4-4BB0-866F-A7E89B8FDD62} - C:\WINDOWS\system32\yabxx.dll (file missing)
O2 - BHO: (no name) - {FB1A26EE-6BD7-4DDD-B377-DE00684AE95A} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\hnquqksa.dll",setvm
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\rrjbpyvg.dll",setvm
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\huapfqbv.dll",realset
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Ε&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) -
http://class.eap.gr/qp2.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (WficaCtl Object) -
http://ultranet.ekt.gr/wfica.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161671764882
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://www.warwick.ac.uk/newwebcam/AxisCamControl.ocx
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) -
http://centra.eap.gr/SiteRoots/main/Install/CentraDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E0C55DEA-F85E-48FE-B512-45C770C90E7D}: NameServer = 193.92.150.2,194.219.227.2
O20 - Winlogon Notify: fccaa - C:\WINDOWS\system32\fccaa.dll (file missing)
O20 - Winlogon Notify: geefc - C:\WINDOWS\
O20 - Winlogon Notify: khfdd - C:\WINDOWS\system32\khfdd.dll (file missing)
O20 - Winlogon Notify: khfggdb - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wvwus - C:\WINDOWS\system32\wvwus.dll (file missing)
O20 - Winlogon Notify: yabxx - C:\WINDOWS\system32\yabxx.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Ethernet Packet Service (npacketservice) - Nokia - C:\WINDOWS\system32\npacketsvc.exe
+--------------------------------------------------------
+--------------------------------------------------------