Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\htycimwt
*******************
Script file located at: \??\C:\sfhppurr.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\qomliij.dll not found!
Deletion of file C:\WINDOWS\system32\qomliij.dll failed!
Could not process line:
C:\WINDOWS\system32\qomliij.dll
Status: 0xc0000034
File C:\WINDOWS\system32\ddaba.dll not found!
Deletion of file C:\WINDOWS\system32\ddaba.dll failed!
Could not process line:
C:\WINDOWS\system32\ddaba.dll
Status: 0xc0000034
File C:\WINDOWS\system32\ocmfowln.dll not found!
Deletion of file C:\WINDOWS\system32\ocmfowln.dll failed!
Could not process line:
C:\WINDOWS\system32\ocmfowln.dll
Status: 0xc0000034
File C:\WINDOWS\system32\irmrubsj.dll not found!
Deletion of file C:\WINDOWS\system32\irmrubsj.dll failed!
Could not process line:
C:\WINDOWS\system32\irmrubsj.dll
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.
Logfile of HijackThis v1.99.1
Scan saved at 00:00:27, on 18-07-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\HP_Administrator\Desktop\alternativ.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.carclub.nu/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {166632E8-C1EC-4572-BCE2-236D59B352AC} - C:\WINDOWS\system32\qomliij.dll (file missing)
O2 - BHO: (no name) - {52649826-9D72-4B51-A48A-29574B981525} - C:\WINDOWS\system32\ddaba.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Tilslutningshjælp - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) -
http://downol.dr.dk/download/netradio/Rawflow.cabO16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewido.net/ewidoOnlineScan.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 23:44:20 17-07-2007
Listing files found while scanning....
C:\WINDOWS\system32\abadd.bak1
C:\WINDOWS\system32\abadd.bak2
C:\WINDOWS\system32\abadd.ini
C:\WINDOWS\system32\abadd.ini2
C:\windows\system32\bbwkfefn.dll
C:\windows\system32\cgjvjhnc.dll
C:\windows\system32\cqecurtn.dll
C:\windows\system32\cstoergm.dll
C:\WINDOWS\system32\ddaba.dll
C:\windows\system32\exnrvvdt.dll
C:\windows\system32\faihhvtr.dll
C:\WINDOWS\system32\irmrubsj.dll
C:\windows\system32\jsburmri.ini
C:\windows\system32\kcpmddka.dll
C:\windows\system32\kyhphfxn.dll
C:\windows\system32\lmdxhwol.dll
C:\windows\system32\mcsbjvyo.dll
C:\windows\system32\mdvpuwav.dll
C:\windows\system32\mtrpjpnd.dll
C:\windows\system32\ntruceqc.ini
C:\WINDOWS\system32\ocmfowln.dll
C:\windows\system32\ovgxapor.ini
C:\windows\system32\qmlraunt.dll
C:\windows\system32\qomliij.dll
C:\windows\system32\qsqwvydr.dll
C:\windows\system32\rgentnkq.dll
C:\windows\system32\ropaxgvo.dll
C:\windows\system32\roxkeydn.dll
C:\windows\system32\ruqdyxqr.dll
C:\windows\system32\sqcvxxfg.dll
C:\windows\system32\sqvrpxpt.dll
C:\windows\system32\tjxeikub.dll
C:\windows\system32\txasqooe.dll
C:\windows\system32\vawupvdm.ini
C:\windows\system32\vawupvdm.tmp
C:\windows\system32\xivbstfo.dll
C:\windows\system32\ymnkyvuq.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\abadd.bak1
C:\WINDOWS\system32\abadd.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\abadd.bak2
C:\WINDOWS\system32\abadd.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\abadd.ini
C:\WINDOWS\system32\abadd.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\abadd.ini2
C:\WINDOWS\system32\abadd.ini2 Has been deleted!
Attempting to delete C:\windows\system32\bbwkfefn.dll
C:\windows\system32\bbwkfefn.dll Has been deleted!
Attempting to delete C:\windows\system32\cgjvjhnc.dll
C:\windows\system32\cgjvjhnc.dll Has been deleted!
Attempting to delete C:\windows\system32\cqecurtn.dll
C:\windows\system32\cqecurtn.dll Has been deleted!
Attempting to delete C:\windows\system32\cstoergm.dll
C:\windows\system32\cstoergm.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ddaba.dll
C:\WINDOWS\system32\ddaba.dll Has been deleted!
Attempting to delete C:\windows\system32\exnrvvdt.dll
C:\windows\system32\exnrvvdt.dll Has been deleted!
Attempting to delete C:\windows\system32\faihhvtr.dll
C:\windows\system32\faihhvtr.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\irmrubsj.dll
C:\WINDOWS\system32\irmrubsj.dll Has been deleted!
Attempting to delete C:\windows\system32\jsburmri.ini
C:\windows\system32\jsburmri.ini Has been deleted!
Attempting to delete C:\windows\system32\kcpmddka.dll
C:\windows\system32\kcpmddka.dll Has been deleted!
Attempting to delete C:\windows\system32\kyhphfxn.dll
C:\windows\system32\kyhphfxn.dll Has been deleted!
Attempting to delete C:\windows\system32\lmdxhwol.dll
C:\windows\system32\lmdxhwol.dll Has been deleted!
Attempting to delete C:\windows\system32\mcsbjvyo.dll
C:\windows\system32\mcsbjvyo.dll Has been deleted!
Attempting to delete C:\windows\system32\mdvpuwav.dll
C:\windows\system32\mdvpuwav.dll Has been deleted!
Attempting to delete C:\windows\system32\mtrpjpnd.dll
C:\windows\system32\mtrpjpnd.dll Has been deleted!
Attempting to delete C:\windows\system32\ntruceqc.ini
C:\windows\system32\ntruceqc.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ocmfowln.dll
C:\WINDOWS\system32\ocmfowln.dll Has been deleted!
Attempting to delete C:\windows\system32\ovgxapor.ini
C:\windows\system32\ovgxapor.ini Has been deleted!
Attempting to delete C:\windows\system32\qmlraunt.dll
C:\windows\system32\qmlraunt.dll Has been deleted!
Attempting to delete C:\windows\system32\qomliij.dll
C:\windows\system32\qomliij.dll Could not be deleted.
Attempting to delete C:\windows\system32\qsqwvydr.dll
C:\windows\system32\qsqwvydr.dll Has been deleted!
Attempting to delete C:\windows\system32\rgentnkq.dll
C:\windows\system32\rgentnkq.dll Has been deleted!
Attempting to delete C:\windows\system32\ropaxgvo.dll
C:\windows\system32\ropaxgvo.dll Has been deleted!
Attempting to delete C:\windows\system32\roxkeydn.dll
C:\windows\system32\roxkeydn.dll Has been deleted!
Attempting to delete C:\windows\system32\ruqdyxqr.dll
C:\windows\system32\ruqdyxqr.dll Has been deleted!
Attempting to delete C:\windows\system32\sqcvxxfg.dll
C:\windows\system32\sqcvxxfg.dll Has been deleted!
Attempting to delete C:\windows\system32\sqvrpxpt.dll
C:\windows\system32\sqvrpxpt.dll Has been deleted!
Attempting to delete C:\windows\system32\tjxeikub.dll
C:\windows\system32\tjxeikub.dll Has been deleted!
Attempting to delete C:\windows\system32\txasqooe.dll
C:\windows\system32\txasqooe.dll Has been deleted!
Attempting to delete C:\windows\system32\vawupvdm.ini
C:\windows\system32\vawupvdm.ini Has been deleted!
Attempting to delete C:\windows\system32\vawupvdm.tmp
C:\windows\system32\vawupvdm.tmp Has been deleted!
Attempting to delete C:\windows\system32\xivbstfo.dll
C:\windows\system32\xivbstfo.dll Has been deleted!
Attempting to delete C:\windows\system32\ymnkyvuq.dll
C:\windows\system32\ymnkyvuq.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\qomliij.dll
C:\windows\system32\qomliij.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 23:52:30 17-07-2007
Listing files found while scanning....
No infected files were found.