VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 2:38:17 AM 7/20/2007
Listing files found while scanning....
C:\windows\system32\ajrxfikl.dll
C:\windows\system32\bkxopxth.dll
C:\windows\system32\bskuxrjb.dll
C:\WINDOWS\system32\byxyxuv.dll
C:\windows\system32\ccgkjcnw.ini
C:\windows\system32\cclngwun.ini
C:\windows\system32\cclngwun.tmp
C:\windows\system32\cqfbghba.dll
C:\windows\system32\dhuoxmos.dll
C:\windows\system32\fgxumlml.dll
C:\windows\system32\ghjsirnj.dll
C:\windows\system32\gtljfmom.dll
C:\WINDOWS\system32\hofjxwgs.dll
C:\windows\system32\hsfpjbse.dll
C:\windows\system32\iitcsyla.dll
C:\windows\system32\ioffcala.dll
C:\windows\system32\isgjxral.dll
C:\windows\system32\iwltkikd.dll
C:\windows\system32\jnrisjhg.ini
C:\windows\system32\kqxykbwo.ini
C:\windows\system32\ktfralqi.dll
C:\windows\system32\kxhvdbni.dll
C:\windows\system32\lmlmuxgf.ini
C:\windows\system32\lxvkclbk.dll
C:\windows\system32\nuwgnlcc.dll
C:\windows\system32\owbkyxqk.dll
C:\windows\system32\oxxbplep.dll
C:\WINDOWS\system32\pmkhf.dll
C:\windows\system32\somxouhd.ini
C:\windows\system32\ssxknaur.dll
C:\WINDOWS\system32\undnagwr.dll
C:\windows\system32\viuqujtk.dll
C:\windows\system32\vjvifmwo.dll
C:\windows\system32\vogowhem.dll
C:\windows\system32\wncjkgcc.dll
C:\windows\system32\wpkyxbjx.ini
C:\windows\system32\xjbxykpw.dll
C:\windows\system32\yoffomlq.dll
C:\windows\system32\yqsawjbt.dll
Beginning removal...
Attempting to delete C:\windows\system32\ajrxfikl.dll
C:\windows\system32\ajrxfikl.dll Has been deleted!
Attempting to delete C:\windows\system32\bkxopxth.dll
C:\windows\system32\bkxopxth.dll Has been deleted!
Attempting to delete C:\windows\system32\bskuxrjb.dll
C:\windows\system32\bskuxrjb.dll Has been deleted!
Attempting to delete C:\windows\system32\ccgkjcnw.ini
C:\windows\system32\ccgkjcnw.ini Has been deleted!
Attempting to delete C:\windows\system32\cclngwun.ini
C:\windows\system32\cclngwun.ini Has been deleted!
Attempting to delete C:\windows\system32\cclngwun.tmp
C:\windows\system32\cclngwun.tmp Has been deleted!
Attempting to delete C:\windows\system32\cqfbghba.dll
C:\windows\system32\cqfbghba.dll Has been deleted!
Attempting to delete C:\windows\system32\dhuoxmos.dll
C:\windows\system32\dhuoxmos.dll Has been deleted!
Attempting to delete C:\windows\system32\fgxumlml.dll
C:\windows\system32\fgxumlml.dll Has been deleted!
Attempting to delete C:\windows\system32\ghjsirnj.dll
C:\windows\system32\ghjsirnj.dll Has been deleted!
Attempting to delete C:\windows\system32\gtljfmom.dll
C:\windows\system32\gtljfmom.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\hofjxwgs.dll
C:\WINDOWS\system32\hofjxwgs.dll Has been deleted!
Attempting to delete C:\windows\system32\hsfpjbse.dll
C:\windows\system32\hsfpjbse.dll Has been deleted!
Attempting to delete C:\windows\system32\iitcsyla.dll
C:\windows\system32\iitcsyla.dll Has been deleted!
Attempting to delete C:\windows\system32\ioffcala.dll
C:\windows\system32\ioffcala.dll Has been deleted!
Attempting to delete C:\windows\system32\isgjxral.dll
C:\windows\system32\isgjxral.dll Has been deleted!
Attempting to delete C:\windows\system32\iwltkikd.dll
C:\windows\system32\iwltkikd.dll Has been deleted!
Attempting to delete C:\windows\system32\jnrisjhg.ini
C:\windows\system32\jnrisjhg.ini Has been deleted!
Attempting to delete C:\windows\system32\kqxykbwo.ini
C:\windows\system32\kqxykbwo.ini Has been deleted!
Attempting to delete C:\windows\system32\ktfralqi.dll
C:\windows\system32\ktfralqi.dll Has been deleted!
Attempting to delete C:\windows\system32\kxhvdbni.dll
C:\windows\system32\kxhvdbni.dll Has been deleted!
Attempting to delete C:\windows\system32\lmlmuxgf.ini
C:\windows\system32\lmlmuxgf.ini Has been deleted!
Attempting to delete C:\windows\system32\lxvkclbk.dll
C:\windows\system32\lxvkclbk.dll Has been deleted!
Attempting to delete C:\windows\system32\nuwgnlcc.dll
C:\windows\system32\nuwgnlcc.dll Has been deleted!
Attempting to delete C:\windows\system32\owbkyxqk.dll
C:\windows\system32\owbkyxqk.dll Has been deleted!
Attempting to delete C:\windows\system32\oxxbplep.dll
C:\windows\system32\oxxbplep.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmkhf.dll
C:\WINDOWS\system32\pmkhf.dll Has been deleted!
Attempting to delete C:\windows\system32\somxouhd.ini
C:\windows\system32\somxouhd.ini Has been deleted!
Attempting to delete C:\windows\system32\ssxknaur.dll
C:\windows\system32\ssxknaur.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\undnagwr.dll
C:\WINDOWS\system32\undnagwr.dll Has been deleted!
Attempting to delete C:\windows\system32\viuqujtk.dll
C:\windows\system32\viuqujtk.dll Has been deleted!
Attempting to delete C:\windows\system32\vjvifmwo.dll
C:\windows\system32\vjvifmwo.dll Has been deleted!
Attempting to delete C:\windows\system32\vogowhem.dll
C:\windows\system32\vogowhem.dll Has been deleted!
Attempting to delete C:\windows\system32\wncjkgcc.dll
C:\windows\system32\wncjkgcc.dll Has been deleted!
Attempting to delete C:\windows\system32\wpkyxbjx.ini
C:\windows\system32\wpkyxbjx.ini Has been deleted!
Attempting to delete C:\windows\system32\xjbxykpw.dll
C:\windows\system32\xjbxykpw.dll Has been deleted!
Attempting to delete C:\windows\system32\yoffomlq.dll
C:\windows\system32\yoffomlq.dll Has been deleted!
Attempting to delete C:\windows\system32\yqsawjbt.dll
C:\windows\system32\yqsawjbt.dll Has been deleted!
Performing Repairs to the registry.
Done!
-----------------------
Logfile of HijackThis v1.99.1
Scan saved at 3:11:40 AM, on 7/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\Rename.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
Yahoo! SearchBar Home Page
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
InboxDollars - Earn CASH for E-Mail, Surveys, Games, and More!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
Yahoo! SearchBar Home Page
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
Yahoo!
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {32391EDE-D335-F892-1C10-898DCD5480B9} - C:\WINDOWS\system32\jzl.dll (file missing)
O2 - BHO: (no name) - {382675ED-8D64-4C83-9CCB-46E63001DDF9} - C:\WINDOWS\system32\pmkhf.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SC2] C:\WINDOWS\system32\scchk32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [gf1.0.0.2] C:\WINDOWS\system32\anArV8xa.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone:
Paid Survey | Get Paid to Take Surveys Online | Greenfield Online
O16 - DPF: ActiveGS.cab -
http://www.virtualapple.org/activegs.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/...toUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) -
http://secure2.comned.com/signuptemp...ogin-devel.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2953BD78-28B7-4EE5-8365-44B6B7644B0E}: NameServer = 194.54.90.226
O17 - HKLM\System\CS1\Services\Tcpip\..\{2953BD78-28B7-4EE5-8365-44B6B7644B0E}: NameServer = 194.54.90.226
O17 - HKLM\System\CS2\Services\Tcpip\..\{2953BD78-28B7-4EE5-8365-44B6B7644B0E}: NameServer = 194.54.90.226
O20 - Winlogon Notify: byxyxuv - byxyxuv.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winrkp32 - winrkp32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe