Welcome to MalwareRemoval.com, What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.
MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\jkhhh.dll C:\WINDOWS\system32\jkhhh.dll NOT unregistered. File move failed. C:\WINDOWS\system32\jkhhh.dll scheduled to be moved on reboot.
Created on 11-26-2007 20:39:59
and Kaspersky log
------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT 2007-11-27 07:23 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 27/11/2007 Kaspersky Anti-Virus database records: 466257 -------------------------------------------------------------------------------
Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true
Scan Target - My Computer: C:\ D:\ Y:\
Scan Statistics: Total number of scanned objects: 54147 Number of viruses found: 10 Number of infected objects: 22 Number of suspicious objects: 0 Duration of the scan process: 01:33:13
Infected Object Name / Virus Name / Last Action C:\4da9894165d4025a83db883f803c\%temp%dd_msxml_retMSI.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-11182007-234409.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\DEVSQLSVC\Cookies\index.dat Object is locked skipped C:\Documents and Settings\DEVSQLSVC\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\DEVSQLSVC\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\DEVSQLSVC\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\DEVSQLSVC\Local Settings\Temp\Perflib_Perfdata_22c.dat Object is locked skipped C:\Documents and Settings\DEVSQLSVC\Local Settings\Temp\Perflib_Perfdata_a68.dat Object is locked skipped C:\Documents and Settings\DEVSQLSVC\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\DEVSQLSVC\NTUSER.DAT Object is locked skipped C:\Documents and Settings\DEVSQLSVC\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\skg\Cookies\index.dat Object is locked skipped C:\Documents and Settings\skg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\skg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\skg\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{ED855BF0-8F68-453B-8A29-00C084A98E76} Object is locked skipped C:\Documents and Settings\skg\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\skg\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\skg\NTUSER.DAT Object is locked skipped C:\Documents and Settings\skg\ntuser.dat.LOG Object is locked skipped C:\oracle\product\10.1.0\Client_1\oramts\trace\OracleMTSRecoveryService(588).trc Object is locked skipped C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped C:\Program Files\Juniper Networks\Common Files\NCService.log Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\STAGE.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\STAGE_log.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_70.trc Object is locked skipped C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\SQLAGENT.OUT Object is locked skipped C:\Program Files\Symantec AntiVirus\SAVRT\0429NAV~.TMP Object is locked skipped C:\qoobox\Quarantine\catchme2007-11-22_235722.43.zip/ddayw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ayv skipped C:\qoobox\Quarantine\catchme2007-11-22_235722.43.zip ZIP: infected - 1 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP82\A0014696.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP82\A0014697.exe Infected: Trojan.Win32.Obfuscated.kp skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP83\A0014812.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP83\A0014859.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP83\A0014936.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP83\A0014973.exe/data0006 Infected: Trojan-Downloader.Win32.VB.bto skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP83\A0014973.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP87\A0015155.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ayv skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP87\A0015160.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP89\A0015253.exe Infected: Trojan-Downloader.Win32.PurityScan.ey skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP91\A0015480.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ath skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP91\A0015481.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP91\A0015482.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.apx skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP91\A0015520.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.apn skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP94\A0015720.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.apn skipped C:\System Volume Information\_restore{8F5762AB-FD82-4544-A2F2-FAD52C7EC1D9}\RP94\change.log Object is locked skipped C:\WINDOWS\CSC\00000001 Object is locked skipped C:\WINDOWS\Debug\Netlogon.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\CCM\Logs\CcmExec.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\CertificateMaintenance.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\ClientIDManagerStartup.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\LocationServices.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\mtrmgr.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\PatchInstall.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\PatchUIMonitor.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\PolicyAgent.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\PolicyAgentProvider.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\PolicyEvaluator.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\Scheduler.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\SrcUpdateMgr.log Object is locked skipped C:\WINDOWS\system32\CCM\Logs\StatusAgent.log Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\0000000B.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\0000000B.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\00000006.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\00000006.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\00000003.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\00000003.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\00000003.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\00000003.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000E.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000E.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\00000007.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\00000007.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000004.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000004.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000002.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000002.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\0000003D.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\0000003D.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\00000003.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\00000003.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\00000016.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\00000016.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\0000000G.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\0000000G.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_paz02sec920_mp_locationmanager\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\direct_paz02sec920_mp_locationmanager\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_relayendpoint\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_relayendpoint\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\00000001.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\00000001.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000000C.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000000C.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000U.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000U.que Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\00000008.msg Object is locked skipped C:\WINDOWS\system32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\00000008.que Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\txcemhuv.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\accbwxvo.dll Infected: Trojan.Win32.BHO.zo skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\oukwodny.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\pkuqrmbu.dll Infected: Trojan.Win32.BHO.zo skipped C:\_OTMoveIt\MovedFiles\WINDOWS\system32\xfmrgbvr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 07:30, on 2007-11-27 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal
OK, seems the jkhhh.dll file is one stubborn beastie and doesn't want to be removed, so we're gonna have to try being a bit more forceful next time. Not to worry, there are still tools available that should help us to get rid of it.
First I need to see what else might be on your computer, as by the look of your HJT log the infection has regenerated (at least in part it has).
Please run Combofix again and post me the log.
Stay offline unless posting me the logs or downloading any tools I ask you to use.
It's good to hear that we are coming close to fixing the issue. Here is the Conbofix log
ComboFix 07-11-19.3 - skg 2007-11-27 19:45:40.4 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1404 [GMT -8:00] Running from: C:\Documents and Settings\skg\Desktop\ComboFix.exe .
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msftesql] "ImagePath"="\"C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER" . Completion time: 2007-11-27 19:53:39 - machine was rebooted C:\ComboFix2.txt ... 2007-11-23 14:09 C:\ComboFix3.txt ... 2007-11-23 00:02 . --- E O F ---
and the HJT log
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:55, on 2007-11-27 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal
Files to delete:
C:\WINDOWS\system32\txcemhuv.dll
C:\WINDOWS\system32\ydwhbmir.dll
C:\WINDOWS\system32\jkhhh.dll
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
Start Avenger by double clicking on Avenger.exe.
Check Load script from file:
Click on the folder symbol below and to the right, and browse to RemoveFiles.txt.
Double click it to enter it into Avenger.
Click the green traffic light symbol.
You will be asked if you want to execute the script, answer Yes.
At this point you may get prompts from your protection systems, allow them please.
Avenger will set itself up to run the next time you re-boot, and will prompt you to re-start immediately.
Answer Yes, and allow your computer to re-boot.
Upon re-boot a command window will briefly appear on screen (this is normal).
A Notepad text file will be created C:\avenger.txt.
Copy and Paste it into your next post please.
NEXT
Click Start > Run type Notepad click OK.
This will open an empty Notepad file.
Copy/Paste the contents of the box below into Notepad.
If you are the originator of this topic, and you need it re-opened please send an email to 'admin at malwareremoval.com', including a link to this topic.
If you have been helped and wish to donate to help with the costs of this volunteer site, please readDonations For Malware Removal
Please do not contact us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Users browsing this forum: No registered users and 168 guests
Contact us:
Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.