![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jun 2007
Location: KC
Posts: 13
OS: xp
|
cannot remove pmnooli.dll, vundo file
Hi. I'm new to post here because I am badly in need of help. On 6/22 I somehow acquired some adware / malware. Based on the symptoms and regristry entries, it looked very much like the vundo infection. I have run vundo fix v6.5.0.1 serveral times. It often finds additional files to delete and deletes the ones it finds, but it keeps coming back. The consistent problem seems to be a file and registry entry for \windows\system32\pmnooli.dll. I have tried to remove the file myself, including using the hijackthis utility "remove on reboot", but it is always still there.
I have googled for more information for this file, but found only two entries, one of which was on this site in a thread entitled "Purity Scan" from user cimshady. Any help is appreciated. Here is my hijackthis log: "Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 2:52:54 PM, on 6/27/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\System32\DSentry.exe C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\zane\My Documents\temp\hijackthis\HiJackThis_v2.exe C:\WINDOWS\system32\wuauclt.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (C:\Documents and Settings\ZANE\Application Data\Mozilla\Profiles\default\jel2oqe9.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\ZANE\Application Data\Mozilla\Profiles\default\jel2oqe9.slt\prefs.js) O2 - BHO: (no name) - {AA72DDA4-672D-4783-8FD4-4BB3CDE8A409} - C:\WINDOWS\system32\mljji.dll (file missing) O2 - BHO: (no name) - {DC192567-65F9-4AB6-ADB7-E13575F81726} - C:\WINDOWS\system32\pmnooli.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://webmail.dstsystems.com/,Dana...java+dwa7W.cab O20 - Winlogon Notify: pmnooli - C:\WINDOWS\SYSTEM32\pmnooli.dll O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe -- End of file - 3344 bytes " |
|
|
| Sponsored Links |
|
|
#2 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 23,265
OS: N/A
|
Re: cannot remove pmnooli.dll, vundo file
1. Download & save this file to Desktop -> http://download.bleepingcomputer.com...a/ComboFix.exe
2. Double click on combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log & a fresh HJT log in your next reply Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
__________________
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Jun 2007
Location: KC
Posts: 13
OS: xp
|
Re: cannot remove pmnooli.dll, vundo file
It appears that the combofix got rid of the pmnooli.dll and registry entry.
Here is the combofix log.txt and a fresh hijackthis log. BTW, I forgot to mention that I had also ran an adaware personal scan and a spybot search and destroy scan, both of which failed to clean it. ""zane" - 2007-06-27 17:56:12 - ComboFix 07-06-28.2 - Service Pack 2 NTFS (((((((((((((((((((((((((((((((((((((((((((( V Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\geedd.dll C:\WINDOWS\SYSTEM32\ddeeg.bak1 C:\WINDOWS\SYSTEM32\ddeeg.ini C:\WINDOWS\SYSTEM32\ddeeg.bak1 C:\WINDOWS\SYSTEM32\ddeeg.ini C:\WINDOWS\system32\pmnooli.dll * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007 C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode C:\Documents and Settings\zane.\err.log C:\temp\0b9 C:\temp\0b9\tmpTF.log C:\temp\iee C:\temp\iee\tmpZTF.log C:\temp\tn3 C:\WINDOWS\b122.exe C:\WINDOWS\system32\myoqonit.exe C:\WINDOWS\system32\vtrqajon.exe ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_CORE -------\LEGACY_DOMAINSERVICE -------\LEGACY_IPRIP -------\LEGACY_NET_AGENT -------\LEGACY_WINDOWS_OVERLAY_COMPONENTS -------\core -------\DomainService -------\Iprip -------\Net Agent -------\Windows Overlay Components ((((((((((((((((((((((((( Files Created from 2007-05-27 to 2007-06-27 ))))))))))))))))))))))))))))))) 2007-06-27 17:55 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-27 16:03 66,112 --a------ C:\WINDOWS\SYSTEM32\chbianhu.dll 2007-06-27 16:03 128,576 --a------ C:\WINDOWS\SYSTEM32\eqwkepwa.dll 2007-06-22 14:13 <DIR> d-------- C:\VundoFix Backups 2007-06-13 11:22 7,680 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motccgpfl.sys 2007-06-13 11:22 6,400 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motswch.sys 2007-06-13 11:22 21,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motport.sys 2007-06-13 11:22 21,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motmodem.sys 2007-06-13 11:22 17,792 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motccgp.sys 2007-06-13 11:22 1,419,232 --a------ C:\WINDOWS\SYSTEM32\wdfcoinstaller01005.dll 2007-06-13 11:21 <DIR> d----c--- C:\WINDOWS\SYSTEM32\DRVSTORE 2007-06-13 11:21 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-27 23:03:43 3,813 ----a-w C:\WINDOWS\system32\fxst3pd.dat 2007-06-27 23:03:43 2,406,389 ----a-w C:\WINDOWS\system32\nvrsnkpq.dat 2007-06-27 23:03:43 1,071 ----a-w C:\WINDOWS\system32\wmdmloa.dat 2007-06-27 23:03:30 16,118 ----a-w C:\WINDOWS\system32\tablet.dat 2007-06-27 03:00:55 14,772 ----a-w C:\WINDOWS\system32\mydocef.dat 2007-06-27 00:04:43 24 ----a-w C:\WINDOWS\system32\docpsop2.dat 2007-06-27 00:04:43 24 ----a-w C:\WINDOWS\system32\activedy.dat 2007-06-22 16:29:15 -------- d-----w C:\Program Files\Windows NT 2007-06-13 16:23:32 -------- d-----w C:\Program Files\Motorola Phone Tools 2007-05-28 14:25:51 -------- d-----w C:\DOCUME~1\zane\APPLIC~1\Azureus 2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-04-28 18:54:31 -------- d-----w C:\Program Files\Kodak Digital Science 2007-04-28 18:54:31 -------- d-----w C:\Program Files\Common Files\Kodak 2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-17 03:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-17 03:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-17 03:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-17 03:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {AA72DDA4-672D-4783-8FD4-4BB3CDE8A409}=C:\WINDOWS\system32\mljji.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-03-29 14:12] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] @= [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "SpecifyDefaultButtons"=0 (0x0) "Btn_Search"=0 (0x0) "NoBandCustomize"=0 (0x0) "NoToolbarCustomize"=0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg] C:\WINDOWS\UpdReg.EXE HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA851-CC51-11CF-AAFA-00AA00B6015C} rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\wpie4x86.inf,PerUserStub ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-27 18:03:53 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-27 18:04:55 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-06-27 18:04 --- E O F ---" "Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 6:12:01 PM, on 6/27/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Netscape\Netscape\Netscp.exe C:\Documents and Settings\zane\My Documents\temp\hijackthis\HiJackThis_v2.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843 N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (C:\Documents and Settings\ZANE\Application Data\Mozilla\Profiles\default\jel2oqe9.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\ZANE\Application Data\Mozilla\Profiles\default\jel2oqe9.slt\prefs.js) O2 - BHO: (no name) - {AA72DDA4-672D-4783-8FD4-4BB3CDE8A409} - C:\WINDOWS\system32\mljji.dll (file missing) O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://webmail.dstsystems.com/,Dana...java+dwa7W.cab O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe -- End of file - 3030 bytes" |
|
|
|
|
#4 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 23,265
OS: N/A
|
Re: cannot remove pmnooli.dll, vundo file
Before fixing anything, open notepad and Copy/Paste the text in the box below into it:
Code:
@echo off For %%g in ( C:\WINDOWS\SYSTEM32\chbianhu.dll C:\WINDOWS\SYSTEM32\eqwkepwa.dll ) do catchme -l nul -k %%g >nul For %%g in ( C:\WINDOWS\system32\nvrsnkpq.dat ) do ( catchme -l nul -c %%g "%%~g.vir" catchme -l nul -k "%%~g.vir" if exist "%%~g.vir" del /a/f "%%~g.vir" )>nul 2>&1 echo.Please submit the file, catchme.zip located on Desktop pause exit Double click on Submit.bat & allow it to generate a zipped file on your Desktop called catchme.zip Please submit catchme.zip to this site → http://www.bleepingcomputer.com/subm....php?channel=4 The file must be uploaded before proceeding to the next step. --------------- Do a HijackThis scan & place a check next to these items and select "Fix checked": R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: (no name) - {AA72DDA4-672D-4783-8FD4-4BB3CDE8A409} - C:\WINDOWS\system32\mljji.dll (file missing) --------------- Open notepad and copy/paste the text in the quotebox below into it: Code:
File::
C:\WINDOWS\SYSTEM32\chbianhu.dll
C:\WINDOWS\SYSTEM32\eqwkepwa.dll
Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA72DDA4-672D-4783-8FD4-4BB3CDE8A409}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
![]() Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe Then post the resultant log --------------- Please perform an online scan using Internet Explorer at http://www.kaspersky.com/virusscanner Answer Yes, when prompted to install an ActiveX component.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%. --------------- In your next post, please include fresh logs from:
__________________
|
|
|
|
|
#5 (permalink) |
|
Registered User
Join Date: Jun 2007
Location: KC
Posts: 13
OS: xp
|
Re: cannot remove pmnooli.dll, vundo file
OK. Sorry, but too late for me not to fix anything. I had already removed the entry
O2 - BHO: (no name) - {AA72DDA4-672D-4783-8FD4-4BB3CDE8A409} - C:\WINDOWS\system32\mljji.dll (file missing) from the registry using hijackthis, before I received your reply. I went ahead with your instructions. Upload of catchme.zip went ok. Used hijackthis to remove the single entry for "about:blank". Ran the combofix with combofix-do.txt. Tried to run virusscanner in IE, clicked yes for ActiveX, but IE would not allow it to run anyway. So here are the logs I have for fresh hijackthis, and combofix: "Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 10:41:22 AM, on 6/28/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe C:\Program Files\Netscape\Netscape\Netscp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\zane\My Documents\temp\hijackthis\HiJackThis_v2.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (C:\Documents and Settings\ZANE\Application Data\Mozilla\Profiles\default\jel2oqe9.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\ZANE\Application Data\Mozilla\Profiles\default\jel2oqe9.slt\prefs.js) O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://webmail.dstsystems.com/,Dana...java+dwa7W.cab O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe -- End of file - 2907 bytes" ""zane" - 2007-06-28 10:12:29 - ComboFix 07-06-28.2 - Service Pack 2 NTFS Command switches used :: C:\Documents and Settings\zane\My Documents\temp\combofix-do.txt ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\SYSTEM32\chbianhu.dll C:\WINDOWS\SYSTEM32\eqwkepwa.dll ((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-28 ))))))))))))))))))))))))))))))) 2007-06-27 17:55 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-22 14:13 <DIR> d-------- C:\VundoFix Backups 2007-06-13 11:22 7,680 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motccgpfl.sys 2007-06-13 11:22 6,400 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motswch.sys 2007-06-13 11:22 21,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motport.sys 2007-06-13 11:22 21,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motmodem.sys 2007-06-13 11:22 17,792 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motccgp.sys 2007-06-13 11:22 1,419,232 --a------ C:\WINDOWS\SYSTEM32\wdfcoinstaller01005.dll 2007-06-13 11:21 <DIR> d----c--- C:\WINDOWS\SYSTEM32\DRVSTORE 2007-06-13 11:21 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-28 15:15:16 16 ----a-w C:\WINDOWS\system32\docpsop2.dat 2007-06-28 15:15:16 16 ----a-w C:\WINDOWS\system32\activedy.dat 2007-06-28 15:15:16 14,772 ----a-w C:\WINDOWS\system32\mydocef.dat 2007-06-28 13:22:17 3,821 ----a-w C:\WINDOWS\system32\fxst3pd.dat 2007-06-28 13:22:17 2,421,321 ----a-w C:\WINDOWS\system32\nvrsnkpq.dat 2007-06-28 13:22:16 1,079 ----a-w C:\WINDOWS\system32\wmdmloa.dat 2007-06-28 13:21:16 16,118 ----a-w C:\WINDOWS\system32\tablet.dat 2007-06-22 16:29:15 -------- d-----w C:\Program Files\Windows NT 2007-06-13 16:23:32 -------- d-----w C:\Program Files\Motorola Phone Tools 2007-05-28 14:25:51 -------- d-----w C:\DOCUME~1\zane\APPLIC~1\Azureus 2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-04-28 18:54:31 -------- d-----w C:\Program Files\Kodak Digital Science 2007-04-28 18:54:31 -------- d-----w C:\Program Files\Common Files\Kodak 2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-17 03:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-17 03:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-17 03:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-17 03:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-03-29 14:12] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "SpecifyDefaultButtons"=0 (0x0) "Btn_Search"=0 (0x0) "NoBandCustomize"=0 (0x0) "NoToolbarCustomize"=0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg] C:\WINDOWS\UpdReg.EXE [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4c09cef3-4187-11d8-bb24-806d6172696f}] AutoRun\command- D:\slideshow.exe HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA851-CC51-11CF-AAFA-00AA00B6015C} rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\wpie4x86.inf,PerUserStub ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-28 10:15:38 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... cmd.exe [2504] scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-28 10:16:11 C:\ComboFix-quarantined-files.txt ... 2007-06-28 10:16 C:\ComboFix2.txt ... 2007-06-27 18:04 --- E O F ---" |
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Jun 2007
Location: KC
Posts: 13
OS: xp
|
Re: cannot remove pmnooli.dll, vundo file
Oh dear. Something did not go right in that last string of instructions. I really did try to follow everything in order, verbatim, but it got screwed up somehow.
So, for some reason the hijackthis to remove the "about:blank" entry did not finish, and so the combofix and last hijackthis run still shows it in the registry. I went back to hijackthis, and it removed it fine, so that it is gone now, but I'm not sure whether that completely invalidates some of the later steps (like the combofix). I will attach yet another hijackthis log, and await a reply before doing anything else, and will do my best to follow further instructions. "Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 11:17:34 AM, on 6/28/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Documents and Settings\zane\My Documents\temp\hijackthis\HiJackThis_v2.exe C:\Program Files\Netscape\Netscape\Netscp.exe N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (C:\Documents and Settings\ZANE\Application Data\Mozilla\Profiles\default\jel2oqe9.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\ZANE\Application Data\Mozilla\Profiles\default\jel2oqe9.slt\prefs.js) O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\SYSTEM32\WTablet\TabUserW.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://webmail.dstsystems.com/,Dana...java+dwa7W.cab O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: dlbt_device - Dell - C:\WINDOWS\System32\dlbtcoms.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe -- End of file - 2829 bytes" |
|
|
|
|
#7 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 23,265
OS: N/A
|
Re: cannot remove pmnooli.dll, vundo file
No worry. Everything is in order.
Since Kaspersky won't work for you, let's use another scanner. ![]() Please perform an online scan using Internet Explorer at this website - http://www.bitdefender.com/scan8/ie.html Under SCANNING OPTIONS, use the following Settings:
Once finished, click on the Details button to view the results. To the upper right of the results you will see an option saying "Click here to export the scan results" Post the log of the scan results in your next reply
__________________
|
|
|
|
|
#8 (permalink) |
|
Registered User
Join Date: Jun 2007
Location: KC
Posts: 13
OS: xp
|
Re: cannot remove pmnooli.dll, vundo file
Here is the bitdefender log. I changed the ActiveX options in IE and I can run the Kaspersky too and post the log in another post.
It looks like I have lots of other bad stuff on my computer. Thanks for your continued support. "Statistics Time 00:50:08 Files 239043 Folders 8426 Boot Sectors 3 Archives 5639 Packed Files 10278 Results Identified Viruses 25 Infected Files 64 Suspect Files 0 Warnings 0 Disinfected 0 Deleted Files 0 Engines Info Virus Definitions 607600 Engine build AVCORE v1.0 (build 2410) (i386) (Jun 12 2007 21:08:27) Scan plugins 14 Archive plugins 38 Unpack plugins 6 E-mail plugins 6 System plugins 1 Scan Settings First Action Report Second Action None Heuristics Yes Enable Warnings Yes Scanned Extensions *; Exclude Extensions Scan Emails Yes Scan Archives Yes Scan Packed Yes Scan Files Yes Scan Boot Yes Scanned File Status C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv55.jar-13af7ed2-422418f7.zip=>Counter.class Infected with: Java.Trojan.Exploit.Bytverify C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv55.jar-13af7ed2-422418f7.zip=>Dummy.class Infected with: Java.Trojan.Exploit.Bytverify C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv55.jar-13af7ed2-422418f7.zip=>Matrix.class Infected with: Java.Trojan.Downloader.OpenStream.C C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv55.jar-13af7ed2-422418f7.zip=>Parser.class Infected with: Java.Trojan.Exploit.Bytverify C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loadertraff.jar-428149e2-628101e6.zip=>Counter.class Infected with: Java.Trojan.Exploit.Bytverify C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loadertraff.jar-428149e2-628101e6.zip=>Dummy.class Infected with: Java.Trojan.Exploit.Bytverify C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loadertraff.jar-428149e2-628101e6.zip=>Matrix.class Infected with: Java.Trojan.Downloader.OpenStream.C C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loadertraff.jar-428149e2-628101e6.zip=>Parser.class Infected with: Java.Trojan.Exploit.Bytverify C:\Documents and Settings\haley\Local Settings\Temp\ekwgeqfm.exe Infected with: Trojan.Fotomoto.A C:\Documents and Settings\haley\Local Settings\Temp\ksrcwwfu.exe Infected with: Trojan.Fotomoto.A C:\Documents and Settings\haley\Local Settings\Temp\Outerinfo-1281.exe=>(NSIS o)=>zlib_nsis0005=>(NSIS o)=>zlib_nsis0001 Infected with: Trojan.PurityScan.DL C:\Documents and Settings\haley\Local Settings\Temp\Outerinfo-1281.exe=>(NSIS o)=>zlib_nsis0005=>(NSIS o)=>zlib_nsis0003 Infected with: Trojan.PurityScan.DL C:\Documents and Settings\haley\Local Settings\Temp\Outerinfo-1281.exe=>(NSIS o)=>zlib_nsis0008 Infected with: Trojan.PurityScan.DL C:\Documents and Settings\haley\Local Settings\Temp\pdxakpdb.exe Infected with: Trojan.Fotomoto.A C:\Documents and Settings\haley\Local Settings\Temp\pkgycuht.exe Infected with: Trojan.Clicker.Agent.NP C:\Documents and Settings\haley\Local Settings\Temp\txxnvito.exe Infected with: Trojan.Fotomoto.A C:\Documents and Settings\haley\Local Settings\Temp\umvoryfv.exe Infected with: Trojan.Fotomoto.A C:\Documents and Settings\haley\Local Settings\Temp\vorajwdj.exe Infected with: Trojan.LowZones.SA C:\Documents and Settings\haley\Local Settings\Temp\wfewpnxa.exe Infected with: Trojan.Fotomoto.A C:\Documents and Settings\haley\Local Settings\Temp\wfihlexk.exe Infected with: Trojan.Fotomoto.A C:\Documents and Settings\haley\Local Settings\Temp\wigqhrix.exe Infected with: Trojan.Fotomoto.A C:\Documents and Settings\haley\Local Settings\Temp\wr-1-2000219.exe Infected with: Trojan.Downloader.JISG C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups\backup-20050311-142313-578.dll Infected with: Generic.AFCore.31537E6A C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups\backup-20050311-143617-315.dll Infected with: Generic.AFCore.31537E6A C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups\backup-20050311-163250-136.dll Infected with: Generic.AFCore.31537E6A C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups\backup-20050311-165213-158.dll Infected with: Generic.AFCore.31537E6A C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups\backup-20070622-113933-101.dll Infected with: Trojan.Downloader.Adload.NCJ C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups\backup-20070622-113933-748.dll Infected with: Trojan.Agent.AOM C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups\backup-20070622-113933-763.dll Infected with: Trojan.PurityScan.DL C:\Program Files\ComPlus Applications\hoke83122.dll Infected with: Trojan.Downloader.Adload.NCJ C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir=>(NSIS o)=>lzma_solid_nsis0002 Infected with: Trojan.Popwin.BK C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\myoqonit.exe.vir Infected with: Trojan.Fotomoto.A C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\vtrqajon.exe.vir Infected with: Trojan.Fotomoto.A C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1099\A0127928.dll Infected with: Trojan.PurityScan.DL C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1099\A0127929.dll Infected with: Trojan.Agent.AOM C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0127945.exe Infected with: Trojan.Popwin.BK C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0127946.exe Infected with: Trojan.Popwin.BK C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128004.exe Infected with: Trojan.Fakealert.BX C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128033.exe Infected with: Trojan.Downloader.Zlob.BQW C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128036.exe Infected with: Trojan.Zlob.AVP C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128037.exe Infected with: Trojan.Click.JX C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128038.exe Infected with: Trojan.Downloader.Agent.AMG C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128040.exe Infected with: Trojan.Downloader.Agent.YFI C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128041.exe Infected with: Trojan.Downloader.Agent.YFI C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128043.exe Infected with: Trojan.Downloader.Zlob.BQW C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128047.exe Infected with: Trojan.Downloader.JISG C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128048.exe Infected with: Dropped:Trojan.Downloader.Adload.NCJ C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128049.exe Infected with: MemScan:Trojan.Zlob.AVP C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128143.exe Infected with: MemScan:Trojan.Agent.AOM C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128146.exe Infected with: Trojan.PurityScan.DL C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128160.sys Infected with: Rootkit.Agent.EV C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128166.exe Infected with: Trojan.PurityScan.DL C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0128167.exe Infected with: Trojan.Popwin.BK C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1100\A0129179.exe Infected with: Trojan.Clicker.Agent.NP C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1103\A0129275.exe Infected with: Trojan.Fotomoto.A C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1104\A0129369.exe Infected with: Trojan.Fotomoto.A C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1104\A0129370.exe=>(NSIS o)=>lzma_solid_nsis0002 Infected with: Trojan.Popwin.BK C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1104\A0129384.exe Infected with: Trojan.Fotomoto.A C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1104\A0129388.exe Infected with: Trojan.Fotomoto.A C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1104\A0129391.exe Infected with: Trojan.LowZones.SA C:\WINDOWS\browserxtras\pn\remove.exe=>(NSIS o)=>zlib_nsis0001=>(NSIS o)=>zlib_nsis0002 Infected with: Trojan.Downloader.Keenval.F C:\WINDOWS\notepad.exe.tmp Infected with: Trojan.Dropper.Small.HY C:\WINDOWS\SYSTEM32\IPXMONPR.dll Infected with: Generic.AFCore.02AB5C57 C:\WINDOWS\winmain.exe Infected with: Trojan.Downloader.Agent.ZD" Last edited by sUBs; 06-29-2007 at 02:50 PM. |
|
|
|
|
#9 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 23,265
OS: N/A
|
Re: cannot remove pmnooli.dll, vundo file
Open notepad and copy/paste the text in the quotebox below into it:
Code:
File:: C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv55.jar-13af7ed2-422418f7.zip C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loadertraff.jar-428149e2-628101e6.zip C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups C:\Program Files\ComPlus Applications\hoke83122.dll C:\WINDOWS\notepad.exe.tmp C:\WINDOWS\SYSTEM32\IPXMONPR.dll C:\WINDOWS\winmain.exe ![]() Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe Then post the resultant log
__________________
|
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: Jun 2007
Location: KC
Posts: 13
OS: xp
|
Re: cannot remove pmnooli.dll, vundo file
Here is the combofix with combofix-do log:
""zane" - 2007-06-29 17:49:56 - ComboFix 07-06-28.2 - Service Pack 2 NTFS Command switches used :: C:\Documents and Settings\zane\My Documents\temp\combofix-do.txt ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv55.jar-13af7ed2-422418f7.zip C:\Documents and Settings\haley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loadertraff.jar-428149e2-628101e6.zip C:\Documents and Settings\zane\My Documents\temp\hijackthis\backups C:\Program Files\ComPlus Applications\hoke83122.dll C:\WINDOWS\notepad.exe.tmp C:\WINDOWS\SYSTEM32\IPXMONPR.dll C:\WINDOWS\winmain.exe ((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-29 ))))))))))))))))))))))))))))))) 2007-06-28 17:47 <DIR> d-------- C:\WINDOWS\BDOSCAN8 2007-06-28 10:25 <DIR> d-------- C:\WINDOWS\SYSTEM32\Kaspersky Lab 2007-06-28 10:25 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab 2007-06-27 17:55 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-22 14:13 <DIR> d-------- C:\VundoFix Backups 2007-06-13 11:22 7,680 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motccgpfl.sys 2007-06-13 11:22 6,400 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motswch.sys 2007-06-13 11:22 21,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motport.sys 2007-06-13 11:22 21,504 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motmodem.sys 2007-06-13 11:22 17,792 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\motccgp.sys 2007-06-13 11:22 1,419,232 --a------ C:\WINDOWS\SYSTEM32\wdfcoinstaller01005.dll 2007-06-13 11:21 <DIR> d----c--- C:\WINDOWS\SYSTEM32\DRVSTORE 2007-06-13 11:21 <DIR> d-------- C:\Program Files\Common Files\Motorola Shared (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-29 22:54:02 16,118 ----a-w C:\WINDOWS\system32\tablet.dat 2007-06-29 22:52:57 3,821 ----a-w C:\WINDOWS\system32\fxst3pd.dat 2007-06-29 22:52:57 2,438,030 ----a-w C:\WINDOWS\system32\nvrsnkpq.dat 2007-06-29 22:52:57 1,079 ----a-w C:\WINDOWS\system32\wmdmloa.dat 2007-06-29 02:28:32 15,678 ----a-w C:\WINDOWS\system32\mydocef.dat 2007-06-28 15:16:17 24 ----a-w C:\WINDOWS\system32\docpsop2.dat 2007-06-28 15:16:17 24 ----a-w C:\WINDOWS\system32\activedy.dat 2007-06-22 16:29:15 -------- d-----w C:\Program Files\Windows NT 2007-06-13 16:23:32 -------- d-----w C:\Program Files\Motorola Phone Tools 2007-05-28 14:25:51 -------- d-----w C:\DOCUME~1\zane\APPLIC~1\Azureus 2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-04-28 18:54:31 -------- d-----w C:\Program Files\Kodak Digital Science 2007-04-28 18:54:31 -------- d-----w C:\Program Files\Common Files\Kodak 2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll 2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll 2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-04-17 03:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-04-17 03:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-04-17 03:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-04-17 03:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-03-29 14:12] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "SpecifyDefaultButtons"=0 (0x0) "Btn_Search"=0 (0x0) "NoBandCustomize"=0 (0x0) "NoToolbarCustomize"=0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg] C:\WINDOWS\UpdReg.EXE HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA851-CC51-11CF-AAFA-00AA00B6015C} rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\wpie4x86.inf,PerUserStub ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-29 17:54:27 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-29 17:55:46 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-06-29 17:55 C:\ComboFix2.txt ... 2007-06-28 10:16 C:\ComboFix3.txt ... 2007-06-27 18:04 --- E O F ---" |
|
|
|
|
#11 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 23,265
OS: N/A
|
Re: cannot remove pmnooli.dll, vundo file
Of the stuff BitDefender found earlier,
C:\QooBox\ is ComboFix's quarantine folder. You can safely delete it C:\System Volume Information\ is where System Restore's cache is stored. Whatever is in there can't harm you unless you choose to perform a manual restore. Nevertheless, we shall be reseting/clearing the cache in a little while ---------------------- Now that your system is clean, kindly follow these simple steps in order to keep your computer clean and secure:
Update all these programs regularly. Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released. Follow this list and your potential for being infected again will reduce dramatically. Here are some additional utilities that will further enhance your safety.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein - http://computercops.biz/postlite7736-.html After doing all these, your system will be optimised against future threats. It's okay to delete the Hijack This folder in a couple weeks if everything is working okay. Have a safe & happy computing day. ![]() Please respond to this thread one more time so we can mark this thread as resolved.
__________________
|
|
|
|
|
#12 (permalink) |
|
Registered User
Join Date: Jun 2007
Location: KC
Posts: 13
OS: xp
|
Re: cannot remove pmnooli.dll, vundo file
I am going through the list to stay infection free now. No telling how I would have screwed things up without your help. I'll be telling all of my infected friends about you.
Thank you very very much.
|
|
|
| Thread Tools | |
|
|