PLEASE HELP! THIS PROBLEM HAS BEEN GOING ON FOR A MONTH!
Page 1 of 3 123 LastLast
Results 1 to 15 of 35

Thread: PLEASE HELP! THIS PROBLEM HAS BEEN GOING ON FOR A MONTH!

  1. #1
    Join Date
    Apr 2009
    Posts
    245

    Post PLEASE HELP! THIS PROBLEM HAS BEEN GOING ON FOR A MONTH!

    Hi, I have a major problem! I seem to have gotten very badly infected, and nothing I do seems to help! I have a friend who is very good at this, and even doing what he has said so far hasn't helped. I have windows XP, emachines T3418. any other spec info you need just let me know.

    Ok here's what has happened:

    1. keyboard started acting weird.
    2. computer started freezing
    3. IE keeps popping up (even now, and I don't have IE anymore)
    4. could not open spybot or advanced care.
    5. Now I can only run in safe mode.
    6. Doesn't recognize some of my drives
    7. Cannot hear sound!

    Ok, so now I have run a scan with AVG this is what it says:

    AVG 8.5 Anti-Virus command line scanner
    Copyright (c) 1992 - 2009 AVG Technologies
    Program version 8.0.268, engine 8.0.285
    Virus Database: Version 270.12.2/2072 2009-04-21

    \\?\globalroot\systemroot\system32\UACxotndlto.dll Virus identified Win32/Cryptor
    C:\WINDOWS\system32\svchost.exe (428) Virus identified Win32/Cryptor
    \\?\globalroot\systemroot\system32\UACxotndlto.dll Virus identified Win32/Cryptor Object was moved to Virus Vault.
    C:\WINDOWS\system32\svchost.exe (536) Virus identified Win32/Cryptor Object was moved to Virus Vault.
    \\?\globalroot\systemroot\system32\UACxotndlto.dll Virus identified Win32/Cryptor Object was moved to Virus Vault.
    C:\WINDOWS\system32\svchost.exe (576) Virus identified Win32/Cryptor Object was moved to Virus Vault.
    \\?\globalroot\systemroot\system32\UACxotndlto.dll Virus identified Win32/Cryptor Object was moved to Virus Vault.
    C:\Program Files\Internet Explorer\iexplore.exe (896) Virus identified Win32/Cryptor Object was moved to Virus Vault.
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
    C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
    C:\Documents and Settings\Administrator\NTUSER.DAT Locked file. Not tested.
    C:\Documents and Settings\Administrator\ntuser.dat.LOG Locked file. Not tested.
    C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Locked file. Not tested.
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Locked file. Not tested.
    C:\Documents and Settings\NetworkService\NTUSER.DAT Locked file. Not tested.
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Locked file. Not tested.
    C:\Documents and Settings\Ramirez.BIANCA\Local Settings\Application Data\Mozilla\Firefox\Profiles\aeum9j4x.default\Cache(2)\1A0CAD09d01 Virus identified Win32/Cryptor.dropper Object was moved to Virus Vault.
    C:\Documents and Settings\Ramirez.BIANCA\Local Settings\Temp\ovfsthxuwriqhpmpo.tmp Trojan horse Dropper.Generic.ALMG Object was moved to Virus Vault.
    C:\pagefile.sys Locked file. Not tested.
    C:\System Volume Information\ Locked file. Not tested.
    C:\WINDOWS\pss\ChkDisk.dllStartup Trojan horse BackDoor.Generic11.HAM Object was moved to Virus Vault.
    C:\WINDOWS\system32\autochk.dll Trojan horse BackDoor.Generic11.HAM Object was moved to Virus Vault.
    C:\WINDOWS\system32\config\default Locked file. Not tested.
    C:\WINDOWS\system32\config\default.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\SAM Locked file. Not tested.
    C:\WINDOWS\system32\config\SAM.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\SECURITY Locked file. Not tested.
    C:\WINDOWS\system32\config\SECURITY.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\software Locked file. Not tested.
    C:\WINDOWS\system32\config\software.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\system Locked file. Not tested.
    C:\WINDOWS\system32\config\system.LOG Locked file. Not tested.
    C:\WINDOWS\system32\config\systemprofile\protect.dll Trojan horse BackDoor.Generic11.HAM Object was moved to Virus Vault.
    C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll Trojan horse BackDoor.Generic11.HAM Object was moved to Virus Vault.
    C:\WINDOWS\system32\fulewoge.exe Trojan horse BHO.IKM Object was moved to Virus Vault.
    C:\WINDOWS\system32\galaduja.dll_old Trojan horse Generic13.HQS Object was moved to Virus Vault.
    C:\WINDOWS\system32\jozoyona.dll_old Trojan horse Generic13.GVU Object was moved to Virus Vault.
    C:\WINDOWS\system32\ligutafo.dll_old Trojan horse Generic13.EIA Object was moved to Virus Vault.
    C:\WINDOWS\system32\nopayopa.dll.tmp Trojan horse SHeur2.ABJI Object was moved to Virus Vault.
    C:\WINDOWS\system32\oembios.exe Locked file. Not tested.
    C:\WINDOWS\system32\piyuzuju.dll.tmp Trojan horse SHeur2.ABJI Object was moved to Virus Vault.
    C:\WINDOWS\system32\poinstall.exe Adware Generic3.KQH Object was moved to Virus Vault.
    C:\WINDOWS\system32\rubelupe.dll Trojan horse Generic13.AAZN Object was moved to Virus Vault.
    C:\WINDOWS\system32\sysproc64\sysproc32.sys Locked file. Not tested.
    C:\WINDOWS\system32\sysproc64\sysproc86.sys Locked file. Not tested.
    C:\WINDOWS\system32\tomewope.exe Trojan horse Vundo.GF Object was moved to Virus Vault.
    C:\WINDOWS\system32\zomiduvi.dll.tmp Trojan horse SHeur2.ABJI Object was moved to Virus Vault.
    C:\WINDOWS\Temp\160.tmp Trojan horse SHeur2.AABJ Object was moved to Virus Vault.
    C:\WINDOWS\Temp\msb.dll Trojan horse BackDoor.Generic11.HAM Object was moved to Virus Vault.

    ------------------------------------------------------------
    Objects scanned : 197930
    Found infections : 25
    Found PUPs : 1
    Healed infections : 23
    Healed PUPs : 1
    Warnings : 0
    ------------------------------------------------------------


    then I restarted my PC, still only allowed to enter Safe Mode I have done a registry clean with SpywareBlaster, MV RegClean 5.9, and CCleaner. All went smoothly except for CCleaner which will not finish its "run cleaner'' it get's to 98% and then stays there, never finishing. Sooo, after doing that restarted my pc...and still only safe mode. Also have a Hijack Report that I did before the AVG scan, so if you need that let me know.

    Now before it got this bad I tried to get some help at another forum, that was about a month ago, and have not received any responses...so I beg PLEASE HELP!!!

    The AVG report shows all the viruses/trojans that I have. They were saved to the vault even though I told it to '' clean automatically''

    if you need any other info. let me know!!!

  2. #2
    Join Date
    Apr 2000
    Location
    Sheboygan, WI
    Posts
    53,391
    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under Configuration and Preferences, click the Preferences button.
    * Under [b]General and Startup" tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
    - Close browsers before scanning.
    - Scan for tracking cookies.
    - Terminate memory threats before quarantining.

    * Click the Close button to leave the control center screen.
    * Back on the main screen, under Scan for Harmful Software click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under Complete Scan, choose Perform Complete Scan.
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
    * Make sure everything has a checkmark next to it and click Next.
    * A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
    * If asked if you want to reboot, click Yes.
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
    - Click Preferences, then click the Statistics/Logs tab.
    - Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    - If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
    - Please copy and paste the Scan Log results in your next reply.

    * Click Close to exit the program.
    Post SUPERAntiSpyware log.
    NOTE: Tracking cookies can be omitted from the log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    2. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    3. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button..
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.

    RESTART COMPUTER

    4. Download, install, and run HijackThis:
    http://www.snapfiles.com/get/hijackthis.html
    Post HijackThis log.
    Do NOT attempt to "fix" anything!


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

    (Above layout courtesy of Broni)

  3. #3
    Join Date
    Apr 2009
    Posts
    245
    hi!! ok, first....THANK YOU FOR SUCH A QUICK RESPONSE!!!!

    ok, now on to business....starting with the first download...no matter how I try to get to that link, it will not open. Says unknown error?!?!?! ah, lie. I did download it from cnet.com but it will not let me open it, once it's downloaded and I try to run it from there it says "SUPRAnitSpyware Free Edition has encountered a problem and needs to close. We are sorry for the inconvenience. Tried changing the name like you said, and now it says that '' the system administrator has set policies to prevent this installation.'' NO I HAVEN'T!!! hehe, soooo....what do I do??

    thanks you rock!!

  4. #4
    Join Date
    Jul 1998
    Location
    Toronto
    Posts
    26,541
    Continue on to the next items on the list until you get something that will run. If still no go then try the installs and scans in safe mode.
    _____________________
    cat lovers click here

  5. #5
    Join Date
    Apr 2009
    Posts
    245
    ok, The only one I was able to download and actually use was the Hijackthis, and that only after changing it's name. I am only able to run in Safe Mode. I cannot get out of safe mode, I have tried.
    So here is the report, I did not fix anything just ran the report and saved it:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 5:49:11 AM, on 4/27/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Safari\Safari.exe
    C:\DOCUME~1\RAMIRE~1.BIA\LOCALS~1\Temp\Saf30C.tmp\setupxv.exe
    C:\DOCUME~1\RAMIRE~1.BIA\LOCALS~1\Temp\7zS30F.tmp\MSIStart.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\DOCUME~1\RAMIRE~1.BIA\LOCALS~1\Temp\Temporary Directory 1 for gmerEN.zip\gmer.exe
    C:\DOCUME~1\RAMIRE~1.BIA\LOCALS~1\Temp\Temporary Directory 2 for gmerEN.zip\gmer.exe
    C:\DOCUME~1\RAMIRE~1.BIA\LOCALS~1\Temp\Temporary Directory 3 for gmerEN.zip\gmer.exe
    C:\DOCUME~1\RAMIRE~1.BIA\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
    R3 - URLSearchHook: shARES Toolbar - {9c905b42-976e-43c1-bc30-fc5937017909} - C:\Program Files\shARES\tbshAR.dll
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\oembios.exe,
    O1 - Hosts: 82.98.231.89 url.adtrgt.com
    O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    O1 - Hosts: ********* <removed by="" moderator="" -="" dangerous="" site=""></removed>removed by mod - dangerous site
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7bcf46cb-c28d-4bb4-80c7-fd32e7499ad1} - C:\WINDOWS\system32\zalahobe.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [yupofukane] Rundll32.exe "C:\WINDOWS\system32\fiboduzu.dll",s
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2c03aae3] rundll32.exe "C:\WINDOWS\system32\nunupofa.dll",b
    O4 - HKLM\..\Run: [CPM2f30997f] Rundll32.exe "C:\WINDOWS\system32\mawihisa.dll",a
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-21-567987002-3058614968-1683713116-1006\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Search - ?p=ZNman000
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab
    O16 - DPF: {4DCA1E08-4147-4A3D-8CA6-E095DF189FAB} (CPlayFirstNightshiftControl Object) - http://games.bigfishgames.com/en_nig...eb.1.0.0.9.cab
    O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - http://games.bigfishgames.com/en_dre...eb.1.0.0.9.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {D40F5876-A494-4124-8161-82625BB28C06} (CPlayFirstChocolatieControl Object) - http://games.bigfishgames.com/en_cho...b.1.0.0.10.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\yaponema.dll c:\windows\system32\mawihisa.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mawihisa.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mawihisa.dll
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WUSB300NSvc - Unknown owner - C:\Program Files\Linksys\WUSB300N\WLService.exe

    --
    End of file - 8429 bytes
    Thanks again for your help, hope to hear from you soon!!!

  6. #6
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    I'm assuming you tried to do a System Restore already and it didn't help matters any. With what you appear to have I doubt it would, but it can't hurt to try if you already haven't done so.

    Otherwise, run HJT again, and check the boxes next to the following items:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\oembios.exe,
    O1 - Hosts: 82.98.231.89 url.adtrgt.com
    O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    O1 - Hosts: www. 150freesms.de
    O2 - BHO: (no name) - {7bcf46cb-c28d-4bb4-80c7-fd32e7499ad1} - C:\WINDOWS\system32\zalahobe.dll
    O4 - HKLM\..\Run: [yupofukane] Rundll32.exe "C:\WINDOWS\system32\fiboduzu.dll",s
    O4 - HKLM\..\Run: [2c03aae3] rundll32.exe "C:\WINDOWS\system32\nunupofa.dll",b
    O4 - HKLM\..\Run: [CPM2f30997f] Rundll32.exe "C:\WINDOWS\system32\mawihisa.dll",a
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mawihisa.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mawihisa.dll


    With your browser window(s) closed, click fix checked. Don't reboot yet.

    Navigate to Start | All Programs | Accessories | System Tools | System Restore; on the left side of the System Restore window, click System Restore Settings. In the resulting window, check the box marked Turn Off System Restore on all drives. OK your way out, then reboot. You should be able to rename SuperAntiSypyware and MalwareBytes programs now. If not, repeat the above but try renaming the apps before rebooting.

    Make sure you downloaded (saved) the above program installers to your desktop for installation. Trying to install directly from the internet (selecting "run" instead of "save") unpacks the install files in temp folders and they get deleted on reboot. It's too easy to get a corrupted install that way. Once you've installed the program, you need to rename the pertinent .exe files - for example, rename HijackThis from hjt.exe to heyyou.exe. Renaming the folder does nothing. I'm sure you already know this but I'm mentioning it anyhow for the benefit of our lurking viewers.
    Last edited by lgbpop; April 27th, 2009 at 10:31 AM.

  7. #7
    Join Date
    Apr 2009
    Posts
    245

    Exclamation

    yes i've been trying to do a system restore for a while now, it won't let, that was one of my first signs that something was wrong.

    ok, so I redid the scan, but I didn't have these:
    O1 - Hosts: www. 150freesms.de
    O4 - HKLM\..\Run: [2c03aae3] rundll32.exe "C:\WINDOWS\system32\nunupofa.dll",b
    O4 - HKLM\..\Run: [CPM2f30997f] Rundll32.exe "C:\WINDOWS\system32\mawihisa.dll",a
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mawihisa.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mawihisa.dll


    but in place of those I found these:
    01-Hosts:.0.1 17-plus.com
    04-HKLM\..\Run:[2c03aae3] rundll32.exe"C:\WINDOWS\system32\yiyigini.dll",b
    O4 - HKLM\..\Run: [CPM2f30997f] Rundll32.exe "C:\WINDOWS\system32\firedobo.dll",a
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\firedobo.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\firedobo.dll

    I'm guessing their the same files you wanted me to delete, but I want to make 100% sure before I do it! thanks!!!!

  8. #8
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    Then you didn't follow the directions I gave you. You did have those entries in your post above (#5) so you must be doing something other than, or in addition to what you were asked to do. Otherwise they'd still be there for removal. If I'm mistaken, I apologize - but I've been through this dozens of times.

    Let's start over. Please run a new HJT scan and post its log back here. If you can run the Malwarebytes and SuperAntiSpyware programs, that will be great too. Post all of the logs that you can, and also make sure the SystemRestore is turned off on all drives.

  9. #9
    Join Date
    Apr 2009
    Posts
    245
    hi, maybe I didn't, all i did was open hijack and run a scan again. should I have run the scan w/ save the log instead of just a scan? well I kept it open, and I will send you that one I did, and then do another one again right now, and send that one also...here's the one i did
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:28:49 PM, on 4/28/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Safari\Safari.exe
    C:\Program Files\Internet Explorer\Iexplore.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
    R3 - URLSearchHook: shARES Toolbar - {9c905b42-976e-43c1-bc30-fc5937017909} - C:\Program Files\shARES\tbshAR.dll
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\oembios.exe,
    O1 - Hosts: 82.98.231.89 url.adtrgt.com
    O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    O1 - Hosts: .0.1 17-plus.com
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7bcf46cb-c28d-4bb4-80c7-fd32e7499ad1} - C:\WINDOWS\system32\zalahobe.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [yupofukane] Rundll32.exe "C:\WINDOWS\system32\fiboduzu.dll",s
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2c03aae3] rundll32.exe "C:\WINDOWS\system32\yiyigini.dll",b
    O4 - HKLM\..\Run: [CPM2f30997f] Rundll32.exe "C:\WINDOWS\system32\firedobo.dll",a
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-21-567987002-3058614968-1683713116-1006\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Search - ?p=ZNman000
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab
    O16 - DPF: {4DCA1E08-4147-4A3D-8CA6-E095DF189FAB} (CPlayFirstNightshiftControl Object) - http://games.bigfishgames.com/en_nig...eb.1.0.0.9.cab
    O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - http://games.bigfishgames.com/en_dre...eb.1.0.0.9.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {D40F5876-A494-4124-8161-82625BB28C06} (CPlayFirstChocolatieControl Object) - http://games.bigfishgames.com/en_cho...b.1.0.0.10.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\yaponema.dll c:\windows\system32\firedobo.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\firedobo.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\firedobo.dll
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WUSB300NSvc - Unknown owner - C:\Program Files\Linksys\WUSB300N\WLService.exe

    --
    End of file - 8004 bytes




    Now, I am going to run another one right this minute and send u the log on that one....

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:30:43 PM, on 4/28/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\Program Files\Safari\Safari.exe
    C:\Program Files\Internet Explorer\Iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
    R3 - URLSearchHook: shARES Toolbar - {9c905b42-976e-43c1-bc30-fc5937017909} - C:\Program Files\shARES\tbshAR.dll
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\oembios.exe,
    O1 - Hosts: 82.98.231.89 url.adtrgt.com
    O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    O1 - Hosts: .0.1 17-plus.com
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: (no name) - {7bcf46cb-c28d-4bb4-80c7-fd32e7499ad1} - C:\WINDOWS\system32\zalahobe.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [yupofukane] Rundll32.exe "C:\WINDOWS\system32\fiboduzu.dll",s
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [2c03aae3] rundll32.exe "C:\WINDOWS\system32\yiyigini.dll",b
    O4 - HKLM\..\Run: [CPM2f30997f] Rundll32.exe "C:\WINDOWS\system32\firedobo.dll",a
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-21-567987002-3058614968-1683713116-1006\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &Search - ?p=ZNman000
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab
    O16 - DPF: {4DCA1E08-4147-4A3D-8CA6-E095DF189FAB} (CPlayFirstNightshiftControl Object) - http://games.bigfishgames.com/en_nig...eb.1.0.0.9.cab
    O16 - DPF: {775879E2-7309-4619-BB02-AADE41F4B690} (CPlayFirstdreamControl Object) - http://games.bigfishgames.com/en_dre...eb.1.0.0.9.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O16 - DPF: {D40F5876-A494-4124-8161-82625BB28C06} (CPlayFirstChocolatieControl Object) - http://games.bigfishgames.com/en_cho...b.1.0.0.10.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\yaponema.dll c:\windows\system32\firedobo.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\firedobo.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\firedobo.dll
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: WUSB300NSvc - Unknown owner - C:\Program Files\Linksys\WUSB300N\WLService.exe

    --
    End of file - 8004 bytes


    the other superspyware and malwarebytes I still cannot open. And I didn't get as far as going into the system restore and turning it off, I was waiting to hear about those files before I deleted them. Really, I appreciate everything!!! thanks!

  10. #10
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    ladytinkerbell
    I apologize for butting in, but when dealing with an infection, it's very important to:
    1. Follow all instructions to the "dot".
    2. Don't take ANY other steps, than prescribed ones.

  11. #11
    Join Date
    Apr 2009
    Posts
    245
    that's ok, all advice gladly accepted, but I did follow the instructions....just like I did again. I reread them. He said to do a scan, that's what I did. What changed, I have no clue, my pc's been off since the day before he sent that message. So, If I did something wrong, it was not because I tried to do anything differently. As a matter of fact when I saw the difference I wrote back instead of finishing what it said to do until I got further instructions. So now i'm waiting! I can use a pc pretty good, know my way around kinda good...but when it gets into the details of how these things work i'm a lost soul.....*sigh*

  12. #12
    Join Date
    Apr 2009
    Posts
    245

    Lightbulb update

    Ok, I did follow your directions, and yes you are right the ones you told me to delete were on that report I posted, and the changes I showed you did exist, and now, today I ran another report, and the same files have changed names again. Soo, it's not anything that I am doing. I have not done anything different to my pc. and have not tried to do anything until you updated me.

    now the end of the file's name is widinole.dll everything in front of it is the same. So, should I then assume that these are the same files??? and if they keep changing names will I beable to get rid of them???

  13. #13
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Simply wait for lgbpop.
    He'll help you out.

  14. #14
    Join Date
    Jun 2005
    Location
    Ft Myers FL
    Posts
    8,520
    At this point, you should be able to at least run Malwarebytes and SAS in safe mode if you deleted those entries and disabled System Restore. Doing the latter is important. If you don't do so, the malware re-establishes itself upon the next boot.

    Run HJT and delete the following:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\oembios.exe,
    O1 - Hosts: 82.98.231.89 url.adtrgt.com
    O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    O1 - Hosts: .0.1 17-plus.com
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: (no name) - {7bcf46cb-c28d-4bb4-80c7-fd32e7499ad1} - C:\WINDOWS\system32\zalahobe.dll
    O4 - HKLM\..\Run: [yupofukane] Rundll32.exe "C:\WINDOWS\system32\fiboduzu.dll",s
    O4 - HKLM\..\Run: [2c03aae3] rundll32.exe "C:\WINDOWS\system32\yiyigini.dll",b
    O4 - HKLM\..\Run: [CPM2f30997f] Rundll32.exe "C:\WINDOWS\system32\firedobo.dll",a
    O20 - AppInit_DLLs: C:\WINDOWS\system32\yaponema.dll c:\windows\system32\firedobo.dll
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\firedobo.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\firedobo.dll


    With your browser(s) closed, click fix checked. (If the names seem to change, look for the gobbledegook names - that's their pattern.) Then disable System Restore on all drives as explained earlier. Then, reboot and see if you can run those renamed MB and SAS programs.

    To be honest, if this doesn't get you going you may need to do a Windows reinstall. I used to recommend Combofix but it fell out of favor and I'm not sure it's effective anymore - and I'm rusty myself. But, let's see how you do.

  15. #15
    Join Date
    Apr 2009
    Posts
    245
    ok, it seems, what I thought was obvious wasn't so. I have tried to change the .exe file names, but am unsuccessful, or at least I'm pretty sure I am. Where do I go to change it? I thought it would be in properties, but it seems i'm not so lucky for it to be soo easy. I tried to change it when It was installing, still no go. the orig. file is still the same name. Sooo, hehe, my intelligence is seeming more and more limited! sorry!

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •