Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Trojan/Virus back and I've done nothing since last time!

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Trojan/Virus back and I've done nothing since last time!

Unread postby makem » January 14th, 2008, 11:42 am

Hi, A few weeks ago I had a problem with:
O4 - HKLM\..\Run: [6cdc9ce0] rundll32.exe "F:\WINDOWS\system32\yujugjhw.dll",b
and
O4 - HKLM\..\Run: [nod32kui] "F:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
which have both returned since your help to remove them.

viewtopic.php?f=12&t=26552&st=0&sk=t&sd=a

It happened when I restarted the machine after buying 2 games (Steam and EAGames) and burning them to CD (not installed). That was the day before yesterday and was the first time the machine has been used since you cleaned it.
I have tried following your previous help again but it does not work this time.
Something must be hiding somewhere, can you help again please?

I cannot turn Teatimer off as the reg. entry change is denied. NOD32 is not installed and does not exist in Program Files.

These are my logs:

Absolute Uninstaller 1.51
ACDSee 7.0 PowerPack
ACE Mega CoDecS Pack
Ad-Aware SE Professional
Adobe Common File Installer
Adobe Flash Player 9 ActiveX
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8
Adobe Stock Photos 1.0
Agnitum Outpost Firewall Pro
AnyDVD
Apple Mobile Device Support
Apple Software Update
Asus Probe V2.64.03
AVG 7.5
AVG Anti-Spyware 7.5
Azureus 2.0.7.1_CVS
Brad Smith Easy SFV Creator
C-Media WDM Audio Driver
Counter-Strike
Counter-Strike: Source
Day of Defeat
Day of Defeat: Source
Deathmatch Classic
Dell Color Printer 725
DigiGuide TV Guide
DIKO 0.78 Beta 1
Diskeeper Professional Edition
DivX Player
dvdSanta 4.00
eMule
Family Tree Maker 2006
ffdshow [rev 739] [2007-01-05]
FlashGet 1.9.0.1012
FTPRush 1.0.0.612 Unicode
GuildFTPd FTP Deamon
Half-Life 2: Deathmatch
Hauppauge WinTV NT4/Win2000 Drivers
Hauppauge WinTV2000
HijackThis 2.0.0
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
ImgBurn (Remove Only)
IrfanView (remove only)
iTunes
Java(TM) 6 Update 3
Kaspersky Online Scanner
Lemmings for Windows 95
Macromedia Dreamweaver MX
Macromedia Extension Manager
Magic DVD Ripper V3.0
MailWasher Pro
MainConcept MJPEG Codec Demo
MainConcept MJPG software codec (Remove Only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft ActiveSync 3.8
Microsoft Bootvis
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money
Microsoft Money for the Pocket PC
Microsoft Money System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office FrontPage 2003
Microsoft Office Professional Edition 2003
Microsoft Office Visio Professional 2003
mIRC
MobSync
Monkey's Audio
Mozilla Firefox (2.0.0.11)
Nero 7 Premium
NETGEAR Print Server Software
nLite 1.0 RC5
No-IP.com DUC (remove only)
Norton AntiVirus 2004
NVIDIA Drivers
NVIDIA WDM Drivers
Poi Edit v4.0
Poi Edit v4.5.1
PowerISO
PowerQuest PartitionMagic 8.0
QuickTime
RealPlayer
Realtek AC'97 Audio
Resco Explorer 2003
Saved Folders (remove only)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Sony Sound Forge Audio Studio 8.0a
Spybot - Search & Destroy
Spybot - Search & Destroy 1.4
SpywareGuard v2.2
Steam
SUPERAntiSpyware Free Edition
System Requirements Lab
Total Commander (Remove or Repair)
TuneUp Utilities 2007
Ulead DVD Workshop 2
UltraISO V7.2 Media Edition
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
VideoLAN VLC media player 0.8.4a
WhereIsIP
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinRAR archiver
XviD Video Codec 15012003-1 (Koepi's developer build)

ComboFix 08-01-14.1 - makem 2008-01-14 15:23:26.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.867 [GMT 0:00]
Running from: F:\Documents and Settings\makem.HAL\Desktop\FireFox Downloads\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

F:\WINDOWS\system32\msacm32.drv

.
((((((((((((((((((((((((( Files Created from 2007-12-14 to 2008-01-14 )))))))))))))))))))))))))))))))
.

2008-01-14 15:22 . 2000-08-31 08:00 51,200 --a------ F:\WINDOWS\NirCmd.exe
2008-01-13 11:55 . 2008-01-13 11:55 <DIR> d-------- F:\Program Files\iTunes
2008-01-13 11:55 . 2008-01-13 11:55 <DIR> d-------- F:\Program Files\iPod
2008-01-13 11:55 . 2008-01-13 11:55 <DIR> d-------- F:\Documents and Settings\makem.HAL\Application Data\Apple Computer
2008-01-13 11:54 . 2008-01-13 11:55 <DIR> d-------- F:\Program Files\QuickTime
2008-01-13 11:54 . 2008-01-13 11:54 <DIR> d-------- F:\Program Files\Apple Software Update
2008-01-13 11:54 . 2008-01-13 11:55 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-13 11:53 . 2008-01-13 11:53 <DIR> d-------- F:\Program Files\Common Files\Apple
2008-01-13 11:53 . 2008-01-13 11:53 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Apple
2008-01-13 11:53 . 2007-10-31 14:09 30,464 --a------ F:\WINDOWS\system32\drivers\usbaapl.sys
2008-01-04 18:55 . 2004-08-04 00:56 96,768 -----c--- F:\WINDOWS\system32\dllcache\dpcdll.dll
2008-01-04 15:46 . 2008-01-04 15:46 <DIR> d-------- F:\WINDOWS\system32\Kaspersky Lab
2008-01-04 15:46 . 2008-01-04 15:46 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-04 14:36 . 2007-10-10 23:55 6,065,664 --a--c--- F:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-04 14:36 . 2007-07-01 03:31 2,455,488 --a--c--- F:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-04 14:36 . 2007-07-01 03:36 991,232 --a--c--- F:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-04 14:36 . 2007-10-10 23:55 459,264 --a--c--- F:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-04 14:36 . 2007-10-10 23:55 383,488 --a--c--- F:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-04 14:36 . 2007-10-10 23:55 267,776 --a--c--- F:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-04 14:36 . 2007-10-10 23:55 63,488 --a--c--- F:\WINDOWS\system32\dllcache\icardie.dll
2008-01-04 14:36 . 2007-10-10 23:55 52,224 --a--c--- F:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-04 14:36 . 2007-08-13 18:54 33,792 --a--c--- F:\WINDOWS\system32\dllcache\custsat.dll
2008-01-04 14:36 . 2007-10-10 10:59 13,824 --a--c--- F:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-04 13:56 . 2004-08-04 00:56 10,752 --a------ F:\WINDOWS\system32\smtpapi.dll
2008-01-04 13:56 . 2004-08-04 00:56 9,728 --a------ F:\WINDOWS\system32\rwnh.dll
2008-01-04 13:14 . 2008-01-04 13:14 685,816 --a------ F:\WINDOWS\system32\drivers\sptd.sys
2008-01-03 21:29 . 2008-01-03 21:29 <DIR> d-------- F:\Program Files\Java
2008-01-03 21:29 . 2007-09-24 23:31 69,632 --a------ F:\WINDOWS\system32\javacpl.cpl
2008-01-02 22:32 . 2008-01-02 23:27 <DIR> d-------- F:\Program Files\Dl_cats
2008-01-02 22:32 . 2008-01-02 22:32 <DIR> d-------- F:\Program Files\Dell Color Printer 725
2008-01-02 22:32 . 2006-11-07 16:30 344,064 --a------ F:\WINDOWS\system32\dlcfcoin.dll
2008-01-02 22:32 . 2006-08-28 20:57 126,059 --a------ F:\WINDOWS\system32\dlcfceip.chm
2008-01-02 22:32 . 2005-08-18 10:26 40,960 --a------ F:\WINDOWS\system32\dlcfvs.dll
2008-01-02 22:29 . 2004-08-03 23:01 25,856 --a------ F:\WINDOWS\system32\drivers\usbprint.sys
2008-01-02 22:29 . 2004-08-03 23:01 25,856 --a--c--- F:\WINDOWS\system32\dllcache\usbprint.sys
2007-12-25 00:39 . 2007-12-25 00:39 <DIR> d-------- F:\Program Files\Common Files\Agnitum Shared
2007-12-25 00:39 . 2007-12-25 00:39 <DIR> d-------- F:\Program Files\Agnitum

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-14 15:05 --------- d-----w F:\Documents and Settings\makem.HAL\Application Data\AVG7
2008-01-13 13:18 --------- d-----w F:\Program Files\Steam
2008-01-03 22:49 --------- d-----w F:\Program Files\ICQLite
2008-01-03 20:49 --------- d-----w F:\Program Files\Common Files\Symantec Shared
2007-12-25 17:20 --------- d-----w F:\Program Files\FlashGet
2007-12-25 16:24 --------- d-----w F:\Program Files\SpywareGuard
2007-12-08 00:26 --------- d-----w F:\Documents and Settings\All Users\Application Data\NVIDIA
2007-12-08 00:15 --------- d-----w F:\Program Files\NVIDIA
2007-12-08 00:10 --------- d-----w F:\Program Files\SystemRequirementsLab
2007-12-08 00:10 --------- d-----w F:\Documents and Settings\makem.HAL\Application Data\SystemRequirementsLab
2007-12-07 18:02 --------- d-----w F:\Documents and Settings\makem.HAL\Application Data\MailWasherPro
2007-12-03 19:57 --------- d-----w F:\Documents and Settings\makem.HAL\Application Data\vlc
2007-12-03 19:19 --------- d-----w F:\Documents and Settings\makem.HAL\Application Data\NewsLeecher
2007-11-18 17:43 --------- d-----w F:\Documents and Settings\All Users\Application Data\Avg7
2007-11-18 17:40 --------- d-----w F:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-18 17:39 --------- d-----w F:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-18 17:22 --------- d-----w F:\Program Files\SUPERAntiSpyware
2007-11-18 17:20 --------- d-----w F:\Program Files\Common Files\Wise Installation Wizard
2007-11-18 17:20 --------- d-----w F:\Documents and Settings\makem.HAL\Application Data\SUPERAntiSpyware.com
2007-11-18 17:20 --------- d-----w F:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-16 11:02 1,422 ----a-w F:\Documents and Settings\makem.HAL\clean.reg
2006-03-11 17:55 457 ----a-w F:\Program Files\INSTALL.LOG
2001-11-23 12:08 712,704 ----a-w F:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"msnmsgr"="-F:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"SpybotSD TeaTimer"="F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 15:46 1460560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="-cmicnfg.cpl" []
"NeroFilterCheck"="-F:\WINDOWS\System32\NeroCheck.exe" [ ]
"IMEKRMIG6.1"="-F:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [ ]
"SoundMan"="-SOUNDMAN.EXE" []
"QuickTime Task"="F:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"!AVG Anti-Spyware"="F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25 6731312]
"DiskeeperSystray"="F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-22 16:38 221184]
"AVG7_CC"="F:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-24 18:48 579072]
"NvCplDaemon"="F:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 F:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="F:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]
"DLCFCATS"="F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll" [2006-10-20 21:48 73728]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 12:10 267048]
"ICQ Lite"="-F:\Program Files\ICQLite\ICQLite.exe" [ ]
"6cdc9ce0"="F:\WINDOWS\system32\yujugjhw.dll" [ ]
"nod32kui"="F:\Program Files\Eset\nod32kui.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="F:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
"AVG7_Run"="F:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-18 17:39 219136]

F:\Documents and Settings\makem\Start Menu\Programs\Startup\
DigiGuide.lnk - F:\Program Files\DigiGuide TV Guide\Client.exe [2005-10-30 22:55:56]

F:\Documents and Settings\makem.HAL\Start Menu\Programs\Startup\
SpywareGuard.lnk - F:\Program Files\SpywareGuard\sgmain.exe [2003-08-29 19:05:35]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"Norun"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"DisableReistryTools"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= F:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Acronis Scheduler2 Service"="F:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
"SunJavaUpdateSched"=F:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

R1 SandBox;Outpost Firewall Sandbox Driver;F:\Program Files\Agnitum\Outpost Firewall\kernel\Sandbox.SYS [2006-12-13 14:23]
R1 VFILT;Outpost Firewall Kernel Driver;F:\Program Files\Agnitum\Outpost Firewall\kernel\FILTNT.SYS [2006-12-18 12:39]
R2 AsProbe;AsProbe;F:\WINDOWS\System32\drivers\AsProbe.sys [2004-06-24 10:37]
R2 UxTuneUp;TuneUp Design Expansion;F:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL [2006-12-18 12:40]
R3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\ARP.DLL [2006-12-18 12:40]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\CONTENT.DLL [2006-12-18 12:40]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL [2006-12-18 12:39]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL [2006-12-18 12:40]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL [2006-12-18 12:39]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL [2006-12-18 12:39]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL [2006-12-18 12:40]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL [2006-12-18 12:40]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL [2006-12-18 12:40]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL [2006-12-18 12:40]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\PROTECT.DLL [2006-12-18 12:40]
R3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);F:\Program Files\Agnitum\Outpost Firewall\kernel\SECRET.DLL [2006-12-18 12:40]
S3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter;F:\WINDOWS\system32\DRIVERS\AN983.sys [2002-08-29 05:59]
S3 AvFlt;Antivirus Filter Driver;F:\WINDOWS\system32\drivers\av5flt.sys []
S3 HCW848NT;Hauppauge Win/TV;F:\WINDOWS\system32\DRIVERS\hcw848nt.sys [2000-06-12 14:54]
S3 HWACCESS;HWACCESS;F:\WINDOWS\system32\HWACCESS.SYS [2007-03-03 23:02]
S3 mirrorv3;mirrorv3;F:\WINDOWS\system32\DRIVERS\rminiv3.sys [2006-05-08 15:46]
S3 scsiscan;SCSI Scanner Driver;F:\WINDOWS\system32\DRIVERS\scsiscan.sys [2001-08-17 13:53]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contents of the 'Scheduled Tasks' folder
"2008-01-04 17:15:01 F:\WINDOWS\Tasks\1-Click Maintenance.job"
- F:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-14 15:29:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-14 15:31:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-14 15:31:03
.
2008-01-13 13:47:30 --- E O F ---

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 15:36:40, on 14/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\WINDOWS\system32\dlcfcoms.exe
F:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
F:\WINDOWS\system32\nvsvc32.exe
F:\Program Files\Agnitum\Outpost Firewall\outpost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\PROGRA~1\Grisoft\AVG7\avgcc.exe
F:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\Program Files\SpywareGuard\sgmain.exe
F:\Program Files\SpywareGuard\sgbhp.exe
F:\WINDOWS\system32\wuauclt.exe
F:\WINDOWS\system32\notepad.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\makem.HAL\Desktop\FireFox Downloads\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - F:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - F:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - F:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [Cmaudio] -RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroFilterCheck] -F:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [IMEKRMIG6.1] -F:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [SoundMan] -SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AVG7_CC] F:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DLCFCATS] rundll32 F:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ICQ Lite] -"F:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [6cdc9ce0] rundll32.exe "F:\WINDOWS\system32\yujugjhw.dll",b
O4 - HKLM\..\Run: [nod32kui] "F:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] -"F:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] F:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: SpywareGuard.lnk = F:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: &Download All with FlashGet - F:\PROGRA~1\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - F:\PROGRA~1\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - F:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Money Viewer - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - F:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partne ... nicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0175246499
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 0177533779
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/s ... wflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O20 - Winlogon Notify: !SASWinLogon - F:\WINDOWS\
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - F:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - F:\WINDOWS\System32\browseui.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - F:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: dlcf_device - - F:\WINDOWS\system32\dlcfcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - F:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Unknown owner - -F:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (file missing)
O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - -"F:\Program Files\MSN Messenger\usnsvc.exe" (file missing)

--
End of file - 9282 bytes
makem
Regular Member
 
Posts: 45
Joined: November 10th, 2007, 3:31 pm
Advertisement
Register to Remove

Re: Trojan/Virus back and I've done nothing since last time!

Unread postby makem » January 17th, 2008, 4:49 pm

I am leaving the Country on Sunday until April. Please ignore my request for help. I will reinstall when I return. Thanks.
makem
Regular Member
 
Posts: 45
Joined: November 10th, 2007, 3:31 pm

Re: Trojan/Virus back and I've done nothing since last time!

Unread postby Elrond » January 23rd, 2008, 2:01 pm

This topic is now closed. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
User avatar
Elrond
Admin/Teacher Emeritus
 
Posts: 8818
Joined: February 17th, 2005, 9:14 pm
Location: Jerusalem


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 569 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware