Several weeks ago Spybot Search & Destroy picked up Smitfraud888. Following this my anti-virus (CA) and Windows Defender, picked both Smitfraud and Virtumonde. I attempted to remove them and until recently, the symptoms were undr control and mostly non-existent. However, recently the symptoms have come back and the files have been re-detected, not to mention almost none of my scanners and removal tools are operaintg I already went through the collecting of log files and will post them in a few lines;however, I thought it might be important to note that in recent times what I thought was a near controlled problem is beginning to spin out of control. Spybot and Windows Defender, along with many other applications, are beginning to malfunction. Spybot no longer even scans, it pops up with "nothing found" the second I press look for problems button. Internet explorer is useless and now even Firefox is beginning to crash randomly. Here are the logs that the forum requested I include when seeking help, I hope that my computer can be saved from total catastrophe.
These were the results following the eTrust Antivirus Scanner
Scan Results: 70195 files scanned. 16 viruses were detected.
File Infection Status Path
efcabxx.dll Win32/Chisyne!generic infected C:\WINDOWS\system32\
geeby.dll Win32/Vundo!generic infected C:\WINDOWS\system32\
A0027641.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP149\
A0028018.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0028019.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0029230.exe Win32/Abetear.A infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP155\
A0029287.dll Win32/Darksma.X infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP157\
A0029430.EXE Win32/Abetear.A infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP161\
A0031329.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031330.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031332.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031333.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031334.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031335.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031336.exe Win32/Abetear.A infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031337.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
Scan Results w/ listing of what can be cured
efcabxx.dll Win32/Chisyne!generic cannot cure C:\WINDOWS\system32\
geeby.dll Win32/Vundo!generic cannot cure C:\WINDOWS\system32\
A0027641.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP149\
A0028018.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0028019.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0029230.exe Win32/Abetear.A cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP155\
A0029287.dll Win32/Darksma.X cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP157\
A0029430.EXE Win32/Abetear.A cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP161\
A0031329.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031330.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031332.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031333.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031334.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031335.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031336.exe Win32/Abetear.A cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031337.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE
Scan Results w/listing of what can be deleted
efcabxx.dll Win32/Chisyne!generic cannot delete C:\WINDOWS\system32\
geeby.dll Win32/Vundo!generic cannot delete C:\WINDOWS\system32\
A0027641.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP149\
A0028018.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0028019.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0029230.exe Win32/Abetear.A deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP155\
A0029287.dll Win32/Darksma.X deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP157\
A0029430.EXE Win32/Abetear.A deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP161\
A0031329.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031330.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031332.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031333.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031334.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031335.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031336.exe Win32/Abetear.A deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031337.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
/////////NOTE: Spybot Search & Destroy is not functioning at all in safe mode, it will not start////////////
HijackThis Log
Logfile of HijackThis v1.99.1
Scan saved at 1:25:36 PM, on 6/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Arcade\PCMService.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\PROGRA~1\YAHOO!\YOP\yop.exe
C:\PROGRA~1\YAHOO!\browser\ybrwicon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\Joshua\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\YAHOO!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\YAHOO!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6066\SiteAdv.exe"
O4 - HKLM\..\Run: [WinPatrol] "C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" -quiet
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\YAHOO!\COMMON\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172436832359
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} - http://www.gamengame.com/KALogoutComponent.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
Before closing I thought a list of the symptoms might help (whether or not it will)
-exploere.exe closes and restarts every few minutes
-Spbot Search & Destroy does not scan in normal Windows and will no longer function when Windows is in safe mode
-Internet Exploere is inoperable; however, prior to it's inoperability I was being bombarded with pop-ups for Winfix 2007
-Firefox is randomly crashing
-I found over 500 new random dll's in System 32 that did not exist prior to my infection they have allbeen created with in one hour of one another approximately one week ago.
-Lavasoft Ad-Aware cannot find the infection
-Windows Defender and Spybot couldn't remove any infections prior to their now inoperable states
-CA can detect , but not delete or properly clean the infected files
I hope that should be enough to go off of to start. I could really use some help, I'm usually well versed and protected fom this type of things (or so I thought) but since I;ve never been infected before, I'm not exactly sure how to go about fixing this. I woud really appreciate the help.
These were the results following the eTrust Antivirus Scanner
Scan Results: 70195 files scanned. 16 viruses were detected.
File Infection Status Path
efcabxx.dll Win32/Chisyne!generic infected C:\WINDOWS\system32\
geeby.dll Win32/Vundo!generic infected C:\WINDOWS\system32\
A0027641.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP149\
A0028018.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0028019.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0029230.exe Win32/Abetear.A infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP155\
A0029287.dll Win32/Darksma.X infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP157\
A0029430.EXE Win32/Abetear.A infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP161\
A0031329.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031330.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031332.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031333.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031334.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031335.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031336.exe Win32/Abetear.A infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031337.dll Win32/Vundo!generic infected C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
Scan Results w/ listing of what can be cured
efcabxx.dll Win32/Chisyne!generic cannot cure C:\WINDOWS\system32\
geeby.dll Win32/Vundo!generic cannot cure C:\WINDOWS\system32\
A0027641.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP149\
A0028018.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0028019.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0029230.exe Win32/Abetear.A cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP155\
A0029287.dll Win32/Darksma.X cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP157\
A0029430.EXE Win32/Abetear.A cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP161\
A0031329.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031330.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031332.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031333.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031334.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031335.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031336.exe Win32/Abetear.A cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031337.dll Win32/Vundo!generic cannot cure C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE
Scan Results w/listing of what can be deleted
efcabxx.dll Win32/Chisyne!generic cannot delete C:\WINDOWS\system32\
geeby.dll Win32/Vundo!generic cannot delete C:\WINDOWS\system32\
A0027641.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP149\
A0028018.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0028019.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP153\
A0029230.exe Win32/Abetear.A deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP155\
A0029287.dll Win32/Darksma.X deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP157\
A0029430.EXE Win32/Abetear.A deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP161\
A0031329.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031330.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031332.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031333.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031334.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031335.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031336.exe Win32/Abetear.A deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
A0031337.dll Win32/Vundo!generic deleted C:\System Volume Information\_restore{B6387AD4-48E1-4511-AA40-A245D4C401AE}\RP169\
/////////NOTE: Spybot Search & Destroy is not functioning at all in safe mode, it will not start////////////
HijackThis Log
Logfile of HijackThis v1.99.1
Scan saved at 1:25:36 PM, on 6/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Arcade\PCMService.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\PROGRA~1\YAHOO!\YOP\yop.exe
C:\PROGRA~1\YAHOO!\browser\ybrwicon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\Joshua\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\YAHOO!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\YAHOO!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6066\SiteAdv.exe"
O4 - HKLM\..\Run: [WinPatrol] "C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" -quiet
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\YAHOO!\COMMON\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1172436832359
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} - http://www.gamengame.com/KALogoutComponent.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
Before closing I thought a list of the symptoms might help (whether or not it will)
-exploere.exe closes and restarts every few minutes
-Spbot Search & Destroy does not scan in normal Windows and will no longer function when Windows is in safe mode
-Internet Exploere is inoperable; however, prior to it's inoperability I was being bombarded with pop-ups for Winfix 2007
-Firefox is randomly crashing
-I found over 500 new random dll's in System 32 that did not exist prior to my infection they have allbeen created with in one hour of one another approximately one week ago.
-Lavasoft Ad-Aware cannot find the infection
-Windows Defender and Spybot couldn't remove any infections prior to their now inoperable states
-CA can detect , but not delete or properly clean the infected files
I hope that should be enough to go off of to start. I could really use some help, I'm usually well versed and protected fom this type of things (or so I thought) but since I;ve never been infected before, I'm not exactly sure how to go about fixing this. I woud really appreciate the help.