View Single Post
Old 02-22-2007, 07:01 AM   #3 (permalink)
tsf1jay
Registered User
 
Join Date: Feb 2007
Posts: 21
OS: XP home edition


I am done with SDFix step and HJT log following SDfix. Posting those logs, I will continue from VundoFix step onwards this evening and let you know.

Contents of SDFix Report.txt
==================
SDFix: Version 1.67

Run by Owner - Wed 02/21/2007 @ 2241.70

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
EXAMPLE

Path:
"C:\WINDOWS\system32\svchosts.exe" -e te-110-12-0000271
\??\C:\WINDOWS\system32\main.sys

Client IP-IPX Deleted
EXAMPLE Deleted

Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\SYSTEM32\DNS.EXE - Deleted
C:\WINDOWS\system32\ma.exe.exe - Deleted
C:\WINDOWS\system32\pp.exe.exe - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\hd4.tmp - Deleted
C:\DOCUME~1\Owner\LOCALS~1\Temp\hd5.tmp - Deleted
C:\as.txt - Deleted
C:\WINDOWS\system32\adirss.exe - Deleted
C:\WINDOWS\system32\dlh9jkd1q6.exe - Deleted
C:\WINDOWS\system32\dlh9jkd1q7.exe - Deleted
C:\WINDOWS\system32\dlh9jkd1q8.exe - Deleted
C:\WINDOWS\system32\dxdlg32.exe - Deleted
C:\WINDOWS\system32\kernels88.exe - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\system32\svchosts.exe - Deleted
C:\WINDOWS\system32\svcp.csv - Deleted
C:\WINDOWS\system32\taskdir.exe - Deleted
C:\WINDOWS\system32\vxga1me4t1.exe - Deleted
C:\WINDOWS\system32\vxga3me2.exe - Deleted
C:\WINDOWS\system32\vxga4m1et4.exe - Deleted
C:\WINDOWS\system32\vxga4me1.exe - Deleted
C:\WINDOWS\system32\vxga5me3.exe - Deleted
C:\WINDOWS\system32\vxg3am1et3.exe - Deleted
C:\WINDOWS\system32\vxg4am1et2.exe - Deleted
C:\WINDOWS\system32\vxg6ame4.exe - Deleted
C:\WINDOWS\system32\wincom32.ini - Deleted
C:\WINDOWS\system32\winsub.xml - Deleted
C:\WINDOWS\system32\zlbw.dll - Deleted
C:\WINDOWS\Uninst2.htm - Deleted
C:\WINDOWS\Unist1.htm - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted

Could Not Remove C:\WINDOWS\Temp\wuauclt.exe


ADS Check:

C:\WINDOWS\system32
No streams found.


Final Check:

Remaining Services:
------------------



Remaining Files:
---------------
C:\WINDOWS\Temp\wuauclt.exe Found

Backups Folder: - C:\SDFix\backups\backups.zip


Checking For Files with Hidden Attributes :

C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe
C:\Program Files\Picasa2\setup.exe
C:\WINDOWS\Downloaded Program Files\WebDriverFullInstall.exe
C:\WINDOWS\F?nts\chkdsk.exe
C:\CONFIG.SYS
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL0246.tmp
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL0460.tmp
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL0476.tmp
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL1277.tmp
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL1313.tmp
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL1343.tmp
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL2326.tmp
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL2665.tmp
C:\Documents and Settings\Owner\Application Data\Microsoft\Word\~WRL3020.tmp
C:\HUSE100\~WRL0067.tmp
C:\HUSE100\~WRL0311.tmp
C:\HUSE100\~WRL1168.tmp
C:\HUSE100\~WRL1705.tmp
C:\HUSE100\~WRL1776.tmp
C:\HUSE100\~WRL2041.tmp
C:\HUSE100\~WRL2478.tmp
C:\HUSE100\~WRL2812.tmp
C:\HUSE100\~WRL3401.tmp
C:\HUSE100\~WRL3402.tmp
C:\My Pics\smartCardcopy\DCIM\100_PANA\SIV8.tmp
C:\WINDOWS\temp\BIT3B.tmp
C:\WINDOWS\temp\BIT3B1.tmp
C:\WINDOWS\temp\BITE2.tmp
C:\WINDOWS\temp\win16C7.tmp
C:\WINDOWS\temp\win55DD.tmp
C:\WINDOWS\temp\winBC04.tmp
C:\WRIT121\Paper II\~WRL0004.tmp
C:\WRIT121\Paper II\~WRL0193.tmp
C:\WRIT121\Paper II\~WRL0240.tmp
C:\WRIT121\Paper II\~WRL0266.tmp
C:\WRIT121\Paper II\~WRL0339.tmp
C:\WRIT121\Paper II\~WRL0411.tmp
C:\WRIT121\Paper II\~WRL0470.tmp
C:\WRIT121\Paper II\~WRL0471.tmp
C:\WRIT121\Paper II\~WRL0525.tmp
C:\WRIT121\Paper II\~WRL0661.tmp
C:\WRIT121\Paper II\~WRL0800.tmp
C:\WRIT121\Paper II\~WRL1180.tmp
C:\WRIT121\Paper II\~WRL1272.tmp
C:\WRIT121\Paper II\~WRL1373.tmp
C:\WRIT121\Paper II\~WRL1408.tmp
C:\WRIT121\Paper II\~WRL1414.tmp
C:\WRIT121\Paper II\~WRL1534.tmp
C:\WRIT121\Paper II\~WRL1700.tmp
C:\WRIT121\Paper II\~WRL1746.tmp
C:\WRIT121\Paper II\~WRL1809.tmp
C:\WRIT121\Paper II\~WRL1834.tmp
C:\WRIT121\Paper II\~WRL2129.tmp
C:\WRIT121\Paper II\~WRL2180.tmp
C:\WRIT121\Paper II\~WRL2205.tmp
C:\WRIT121\Paper II\~WRL2317.tmp
C:\WRIT121\Paper II\~WRL2318.tmp
C:\WRIT121\Paper II\~WRL2432.tmp
C:\WRIT121\Paper II\~WRL2434.tmp
C:\WRIT121\Paper II\~WRL2506.tmp
C:\WRIT121\Paper II\~WRL2755.tmp
C:\WRIT121\Paper II\~WRL2851.tmp
C:\WRIT121\Paper II\~WRL2852.tmp
C:\WRIT121\Paper II\~WRL2868.tmp
C:\WRIT121\Paper II\~WRL2871.tmp
C:\WRIT121\Paper II\~WRL3175.tmp
C:\WRIT121\Paper II\~WRL3318.tmp
C:\WRIT121\Paper II\~WRL3605.tmp
C:\WRIT121\Paper II\~WRL3614.tmp
C:\WRIT121\Paper II\~WRL3939.tmp
C:\WRIT121\Paper II\~WRL3945.tmp
C:\WRIT121\Paper II\~WRL3956.tmp

Add/Remove Programs List:

ECHO is off.
7-Zip 4.12 beta
Adobe Acrobat 5.0
Adobe Shockwave Player
Adobe Download Manager 2.0 (Remove Only)
Blue's Art Time Activities
Britannica Ready Reference
CleanUp!
Clifford Thinking Adventures
Conexant SoftK56 Modem(M)
Grammar Games
HijackThis 1.99.1
Pinnacle Hollywood FX for Studio
Chutes and Ladders
SmartSound Quicktracks Plugin
Java 2 Runtime Environment Standard Edition v1.3.1
Java 2 Runtime Environment Standard Edition v1.3.1_02
JumpStart Music
Microsoft Data Access Components KB870669
Kid Pix Studio Deluxe
Logitech Print Service
Magic School Bus - Rainforest
MSN Toolbar
Netscape 6 (6.2.1)
Outerinfo
Panda ActiveScan
Phonics
Picasa 2
Logitechr Camera Driver
QuickTime
RC Daredevil
RealPlayer
Registry Mechanic 6.0
Adobe Flash Player 9 ActiveX
SoundCapture
Learn2 Player (Uninstall Only)
Study Helpers Math Booster
TaxCut 2003
TaxCut 2004
TaxCut Deluxe 2005
Winamp (remove only)
Windows XP Service Pack 2
Yahoo! Browser Services
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Photos Easy Upload Tool 1v7
Outerinfo
Yahoo! Install Manager
Microsoft Office 2000 Premium
Google Talk (remove only)
Jasc Paint Shop Photo Album 5
Google Earth
Logitech QuickCam
SmartSound Quicktracks Plugin
SD Viewer for DSC
Windows XP Junglebook Compatiblity Fix
PowerDVD
NetZero
Windows Backup Utility
Intel(R) Extreme Graphics Driver
Disney's The Jungle Book Learning
Logitech Desktop Messenger
Studio 9
Dora the Explorer: Animal Adventures
SpyWare Killer Pro
Adobe Reader 7.0.9
Genesys USB Mass Storage Device
ArcSoft Software Suite
TuneUp Utilities 2007
Search for the Secret Keys
Pinnacle Instant DVD Recorder
Microsoft Works 6.0
Realtek AC'97 Audio
Multimedia Keyboard Driver

Finished

HijackThis log after SDFix
===================
Logfile of HijackThis v1.99.1
Scan saved at 10:19:41 PM, on 2/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Messenger\msmsgs.exe
c:\program files\internet explorer\iexplore.exe
C:\WINDOWS\FNTS~1\chkdsk.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://portal.mailaka.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal.mailaka.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ofb1 - {3E1500AC-87A5-416b-A211-82E848649DA9} - C:\PROGRA~1\Ofb1\ofb1.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {5ccaab50-41e0-4574-a1c6-5a4847a9ce57} - C:\WINDOWS\system32\ideoept.dll
O2 - BHO: (no name) - {60D3AAEB-AA39-4AE0-B2F9-E4AF0613A2A3} - C:\PROGRA~1\Cosmi\SPYWAR~1\pop\ABG_PL~1.DLL
O2 - BHO: (no name) - {8049C913-2385-5D21-8848-2A909BA33FE9} - C:\WINDOWS\system32\gka.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [dns.exe] C:\WINDOWS\system32\dns.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\bak\exec.exe regrun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Usrr] "C:\WINDOWS\FNTS~1\chkdsk.exe" -vt yazb
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Show All Original Images - "res://C:\Program Files\NetZero\qsacc\appres.dll/228"
O8 - Extra context menu item: Show Original Image - "res://C:\Program Files\NetZero\qsacc\appres.dll/227"
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msnetax.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://www.systemdoctor.com/download...reeInstall.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {C946EF6D-296D-4907-A6E1-ED0E8E5AF024} (LycosMail Upload Control) - http://mail.lycos.com/hanmail-ax/AttachMail.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/c...cab?v=1,0,0,37
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - mk:@MSITStore:C:\DOCUME~1\Owner\LOCALS~1\Temp\winfix.chm::/SystemDoctor2006FreeInstall.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{48FF8732-2D9A-45D2-AC39-928DFE93D2A1}: NameServer = 165.76.12.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{6C946AAC-89EC-4E1D-807A-18480BAD72A1}: NameServer = 165.76.12.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{D5B499E2-243B-40DC-A325-188732468138}: NameServer = 165.76.12.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECA75678-EDD3-48EB-8F6C-0B68EB1251BA}: NameServer = 165.76.12.2
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: ideoept - C:\WINDOWS\SYSTEM32\ideoept.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: WINS Client (RpcPatch) - Unknown owner - C:\WINDOWS\System32\wins\DLLHOST.EXE (file missing)
O23 - Service: Network Connections Sharing (RpcTftpd) - Unknown owner - C:\WINDOWS\System32\wins\svchost.exe (file missing)
tsf1jay is offline