Computing.Net > Forums > Security and Virus > Error Message - c:\WINDOWS\system32

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Error Message - c:\WINDOWS\system32

Reply to Message Icon

Original Message
Name: dragontengu
Date: April 8, 2008 at 10:04:05 Pacific
Subject: Error Message - c:\WINDOWS\system32
OS: XP Home
CPU/Ram: 256
Model/Manufacturer: Dell
Comment:

Hi everyone!

A friend of mine is having an issue with her computer. She's getting an error message that pops up and says: c:\WINDOWS\system32\vtsqn.exe cannot be found (or something like that) and sometimes it would kick her off her browser after she clicks "ok".

I highly suspect that it's a virus. I wanted to check with the experts - y'all! Before she goes and blows up her computer, or something. :)

Let me know where to begin.

Thank you and please be patient with this one...it's all relayed through email.


Report Offensive Message For Removal


Response Number 1
Name: Adii
Date: April 8, 2008 at 23:30:32 Pacific
Reply: (edit)

Download the "HijackThis" Installer from this link:

http://www.trendsecure.com/portal/e...


1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.

Post Hijackthis Log in your next reply.

Download Combofix by sUBs and save to your desktop.

(If you have previously downloaded ComboFix,please delete that version now.)


download link HERE:
http://download.bleepingcomputer.co...
http://www.forospyware.com/sUBs/Com...

Note
It is important that it is saved directly to your desktop

Close any open browsers.

Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the entire contents of C:\ComboFix.txt into your next reply.

Note
Do not mouseclick combofix's window while it's running.
That may cause the program to freeze/hang.
Note
In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.

Also post a new Hijackthis log.


*Do Safe Computing*


Report Offensive Follow Up For Removal

Response Number 2
Name: dragontengu
Date: April 9, 2008 at 23:11:33 Pacific
Reply: (edit)

Hi, Adii!

Thanks for taking this task. I really appreciate it!

Here's her Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:59:17 PM, on 4/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/s...
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqn.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: {e4156f3b-d489-087a-6a44-72af1cb38974} - {47983bc1-fa27-44a6-a780-984db3f6514e} - C:\WINDOWS\system32\apddxxlt.dll (file missing)
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: CIEIntegrator Object - {7A7F202E-AF91-4889-9DD5-2FE241085CC1} - C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Tools\pg.dll (file missing)
O2 - BHO: (no name) - {8ABA9A9C-8791-4d61-8D5B-BCC9448EA573} - (no file)
O2 - BHO: (no name) - {A16DACBC-3596-4942-9B3B-2FBB885E6B1A} - C:\WINDOWS\system32\vtsqn.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - C:\WINDOWS\system32\ddcywwu.dll (file missing)
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: IEFW Object - {FAAD2038-C371-473D-86F1-5B11D39C3775} - C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Tools\IEFWBHO.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
O4 - HKLM\..\Run: [d07089fa] rundll32.exe "C:\WINDOWS\system32\pwosphnh.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [BestsellerAntivirus] C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\pgs.exe
O4 - HKLM\..\Run: [ugcw] "C:\PROGRA~1\COMMON~1\BESTSE~1\ugcw.exe" -start
O4 - HKLM\..\Run: [BMd343ba66] Rundll32.exe "C:\WINDOWS\system32\gyjaalgg.dll",s
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [TrustedAntivirus] C:\Program Files\TrustedAntivirus\pgs.exe /min
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.creative.com
O15 - Trusted Zone: *.sbcglobal.net
O15 - Trusted Zone: http://*.sbcglobal.net
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3AA42713-5C1E-48E2-B432-D8BF420DD31D} - http://deuscleaneronline.com/Cleane...
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySp...
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/sj/en/che...
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - Winlogon Notify: ddcywwu - ddcywwu.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: Registry Management Service (RegManServ) - Unknown owner - C:\Program Files\Registry Defragmentation\RegManServ.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O24 - Desktop Component 0: (no name) - http://us.f605.mail.yahoo.com/ym/us...
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\MyHoa\My Documents\My Pictures\StarLynn\cam_data_photo069_edited.jpg
--
End of file - 10862 bytes


And, here's her Combofix log:

ComboFix 08-04-09.8 - MyHoa 2008-04-09 20:59:09.1 - NTFSx86
Running from: C:\Documents and Settings\MyHoa\Local Settings\Temporary Internet Files\Content.IE5\8UR0NYNA\ComboFix[1].exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\All Users\Start Menu\Programs\BestsellerAntivirus
C:\Documents and Settings\All Users\Start Menu\Programs\BestsellerAntivirus\BestsellerAntivirus.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\BestsellerAntivirus\Contact Customer Support.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\BestsellerAntivirus\Uninstall BestsellerAntivirus.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\DriveCleaner Freeware.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\DriveCleaner HomePage.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\DriveCleaner Online Manual.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\DriveCleaner Online Support.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\DriveCleaner Freeware\Uninstall DriveCleaner.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\MyHoa\Application Data\BestsellerAntivirus
C:\Documents and Settings\MyHoa\Application Data\BestsellerAntivirus\avtasks.dat
C:\Documents and Settings\MyHoa\Application Data\BestsellerAntivirus\Logs\av.log
C:\Documents and Settings\MyHoa\Application Data\BestsellerAntivirus\Logs\ga6Support.log
C:\Documents and Settings\MyHoa\Application Data\BestsellerAntivirus\Logs\update.log
C:\Documents and Settings\MyHoa\Application Data\FunWebProducts
C:\Documents and Settings\MyHoa\Application Data\FunWebProducts\Data\MyHoa\avatar.dat
C:\Documents and Settings\MyHoa\Application Data\FunWebProducts\Data\MyHoa\wffavs.dat
C:\Documents and Settings\MyHoa\Start Menu\Programs\MalwareAlarm
C:\Documents and Settings\MyHoa\Start Menu\Programs\MalwareAlarm\MalwareAlarm.lnk
C:\Documents and Settings\MyHoa\Start Menu\Programs\MalwareAlarm\Uninstall.lnk
C:\Program Files\BestsellerAntivirus
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Activate.exe
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Config\pgs.xml
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Dat\Activate.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Dat\BkSites.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Dat\bnlink.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Dat\incmp.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Dat\index.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Dat\pv.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\AWBase\database\enemies.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\AWBase\vbpv.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\PGBase\vbpv.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\BORLNDMM.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANADWR.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANBCDR.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANDLDR.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANDOS1.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANEMUL.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANFUNC.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANKRNL.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANMCR1.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANOTHR.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANSCR.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANTOOL.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANTROJ.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\SCANWIN1.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UNACPU.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UNADBX.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\unamscan.dll
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UNMIME.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UNPACK.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UNPACKS.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UNPACKS2.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UNPEPACK.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UpDate\UA27601.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UpDate\UA27602.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UpDate\UA27603.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UpDate\UA27604.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\UpDate\UADAILY.DLL
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Engines\plugins\vbpv.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\FMTR.sys
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\FWSettings.bin
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\cross.gif
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\ga6p.gif
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\kb.url
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\main.ico
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\mini.ico
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\Online.url
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\rm.url
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\support.ico
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\Support.url
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Graphics\uninstall.ico
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\history.db
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\LA\lapv.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\LA\License.rtf
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\pgs.exe
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\ResErrors.log
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Restart.exe
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\RTasks.exe
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\settings.ini
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\sqlite3.dll
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\sr.log
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\unins000.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\unins000.exe
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Up\ASupdater.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Up\PGupdater.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Up\UBupdater.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Up\up.dat
C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Up\updater.dat
C:\Program Files\Common Files\BestsellerAntivirus
C:\Program Files\internet explorer\msimg32.dll
C:\Program Files\Router
C:\Program Files\WinBudget
C:\Program Files\WinBudget\bin\crap.1201742724.old
C:\Program Files\WinBudget\bin\matrix.dat
C:\Program Files\WinBudget\bin\matrix.dll
C:\WINDOWS\BMd343ba66.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\acjypvgb.ini
C:\WINDOWS\system32\adqxcvhb.ini
C:\WINDOWS\system32\brpusvfg.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\dhosagar.dll
C:\WINDOWS\system32\drivers\fmtr.sys
C:\WINDOWS\system32\eqligapp.ini
C:\WINDOWS\system32\fjqslgji.dll
C:\WINDOWS\system32\fshrngqm.ini
C:\WINDOWS\system32\gmuqphcu.ini
C:\WINDOWS\system32\gyjaalgg.dll
C:\WINDOWS\system32\itkoycmn.dll
C:\WINDOWS\system32\jyianocy.ini
C:\WINDOWS\system32\likeirjt.ini
C:\WINDOWS\system32\lyflpwxj.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mwctuxss.ini
C:\WINDOWS\system32\npfyjhni.ini
C:\WINDOWS\system32\nqstv.ini
C:\WINDOWS\system32\nqstv.ini2
C:\WINDOWS\system32\ovujpyqd.ini
C:\WINDOWS\system32\oxefrclm.ini
C:\WINDOWS\system32\sycksfus.dll
C:\WINDOWS\system32\talqumhm.ini
C:\WINDOWS\system32 \tydkebve.ini
C:\WINDOWS\system32\unntjemo.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_DOMAINSERVICE
-------\Legacy_FMTR
-------\Legacy_NETWORK_MONITOR
-------\Service_fmtr
-------\Service_Network Monitor

((((((((((((((((((((((((( Files Created from 2008-03-10 to 2008-04-10 )))))))))))))))))))))))))))))))
.
2008-04-03 16:50 . 2008-04-03 16:50 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-13 20:09 . 2008-03-13 20:09 <DIR> d-------- C:\Documents and Settings\MyHoa\Application Data\Grisoft
2008-03-13 20:07 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-11 17:45 . 2008-03-22 00:49 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-11 17:41 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-11 17:41 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-11 17:41 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-11 17:41 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-03-11 17:40 . 2008-04-01 22:08 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-03-11 17:40 . 2008-03-11 17:40 <DIR> d-------- C:\Documents and Settings\MyHoa\Application Data\PC Tools
2008-03-11 17:34 . 2008-03-11 21:44 <DIR> d-------- C:\Documents and Settings\MyHoa\Application Data\AVG7
2008-03-11 17:33 . 2008-03-11 17:33 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-11 17:32 . 2008-03-13 20:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-11 17:32 . 2008-03-11 21:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-11 17:18 . 2008-03-11 17:25 1,317,399 --ahs---- C:\WINDOWS\system32\hnhpsowp.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-12 05:25 --------- d-----w C:\Program Files\SpyDefender Pro
2008-03-12 05:25 --------- d-----w C:\Program Files\QuickTime
2008-03-12 05:23 --------- d-----w C:\Program Files\MalwareAlarm
2008-03-12 05:23 --------- d-----w C:\Program Files\DriveCleaner Freeware
2008-03-12 05:23 --------- d-----w C:\Program Files\DellSupport
2008-03-12 05:23 --------- d-----w C:\Program Files\Common Files\TrustedAntivirus
2008-03-12 05:22 --------- d-----w C:\Program Files\Common Files\DriveCleaner Freeware
2008-02-29 03:57 --------- d-----w C:\Documents and Settings\MyHoa\Application Data\TrustedAntivirus
2008-02-21 03:48 --------- d-----w C:\Program Files\Deus Cleaner
2008-02-17 19:59 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-16 07:09 --------- d-----w C:\Program Files\Yahoo!
2008-02-16 07:09 --------- d-----w C:\Program Files\WordPerfect Office 12
2008-02-16 07:09 --------- d-----w C:\Program Files\NetZero
2008-02-16 07:09 --------- d-----w C:\Program Files\HP
2008-02-16 07:09 --------- d-----w C:\Program Files\Dell
2008-02-16 07:09 --------- d-----w C:\Program Files\Common Files\AOL
2008-02-16 06:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-02-16 06:35 --------- d-----w C:\Documents and Settings\Visit\Application Data\AOL
2008-02-16 06:35 --------- d-----w C:\Documents and Settings\MyHoa\Application Data\AOL
2008-02-13 22:52 --------- d-----w C:\Documents and Settings\LocalService\Application Data\COMCASTTOOLBAR
2008-02-11 22:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
2008-02-10 06:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-01-06 15:11 40,183 --sh--w C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
.
[code]


----a-w 579,072 2008-03-12 02:48:31 C:\Program Files\Grisoft\AVG7\avgcc .exe
----a-w 110,592 2008-01-27 21:40:16 C:\Program Files\McAfee\SpamKiller\MS18BE~2 .EXE
----a-w 110,592 2008-02-22 03:02:26 C:\Program Files\McAfee\SpamKiller\MSKAGE~3 .EXE
----a-w 131,072 2008-02-23 15:47:21 C:\Program Files\McAfee.com\Shared\mcappins .exe
----a-w 1,103,240 2008-03-12 02:48:18 C:\Program Files\Spyware Doctor\pctsTray .exe
----a-w 4,670,704 2008-02-28 00:55:37 C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
----a-w 4,670,704 2008-02-28 01:36:34 C:\Program Files\Yahoo!\Messenger\YahooMessenger .exe
----a-w 15,360 2008-03-09 09:42:50 C:\WINDOWS\system32\ctfmon .exe
----a-w 114,688 2008-01-11 15:39:42 C:\WINDOWS\system32\igfxpers .exe
----a-w 94,208 2008-01-12 07:41:25 C:\WINDOWS\system32\igfxtray .exe
----a-w 77,824 2008-02-28 02:20:05 C:\WINDOWS\system32\bak\hkcmd .exe
[/code]

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{47983bc1-fa27-44a6-a780-984db3f6514e}]
C:\WINDOWS\system32\apddxxlt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A16DACBC-3596-4942-9B3B-2FBB885E6B1A}]
C:\WINDOWS\system32\vtsqn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrustedAntivirus"="C:\Program Files\TrustedAntivirus\pgs.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [ ]
"My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" [ ]
"d07089fa"="C:\WINDOWS\system32\pwosphnh.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-11 17:33 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36 806912]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\MyHoa\My Documents\My Pictures\StarLynn\cam_data_photo069_edited.jpg
FriendlyName=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcywwu]
ddcywwu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntivirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
S3 HSFHWCD2;HSFHWCD2;C:\WINDOWS\system32\DRIVERS\HSFHWCD2.sys [2005-01-25 00:26]
.
Contents of the 'Scheduled Tasks' folder
"2008-04-05 00:30:00 C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (MYHOA123005-MyHoa).job"
- c:\program files\mcafee.com\vso\mcmnhdlr.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-09 21:10:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tsd32.dll
.
r Running Proce
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\PROGRA~1\McAfee.com\Agent\McTskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Registry Defragmentation\RegManServ.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-04-09 21:17:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-10 03:17:23
Pre-Run: 65,614,139,392 bytes free
Post-Run: 66,306,830,336 bytes free
.
2008-03-14 10:22:32 --- E O F ---


Thank you for your efforts!!!


Report Offensive Follow Up For Removal

Response Number 3
Name: Adii
Date: April 9, 2008 at 23:43:06 Pacific
Reply: (edit)

Badly Infected!


Please run HijackThis again! and click "Scan." Place checks next to the following entries:



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqn.exe
O2 - BHO: {e4156f3b-d489-087a-6a44-72af1cb38974} - {47983bc1-fa27-44a6-a780-984db3f6514e} - C:\WINDOWS\system32\apddxxlt.dll (file missing)
O2 - BHO: CIEIntegrator Object - {7A7F202E-AF91-4889-9DD5-2FE241085CC1} - C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Tools\pg.dll (file missing)
O2 - BHO: (no name) - {8ABA9A9C-8791-4d61-8D5B-BCC9448EA573} - (no file)
O2 - BHO: (no name) - {A16DACBC-3596-4942-9B3B-2FBB885E6B1A} - C:\WINDOWS\system32\vtsqn.dll (file missing)
O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - C:\WINDOWS\system32\ddcywwu.dll (file missing)
O2 - BHO: IEFW Object - {FAAD2038-C371-473D-86F1-5B11D39C3775} - C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\Tools\IEFWBHO.dll (file missing)
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
O4 - HKLM\..\Run: [d07089fa] rundll32.exe "C:\WINDOWS\system32\pwosphnh.dll",b
O4 - HKLM\..\Run: [BestsellerAntivirus] C:\Program Files\BestsellerAntivirus\Tools\BestsellerAntivirus\pgs.exe
O4 - HKLM\..\Run: [ugcw] "C:\PROGRA~1\COMMON~1\BESTSE~1\ugcw.exe" -start
O4 - HKLM\..\Run: [BMd343ba66] Rundll32.exe "C:\WINDOWS\system32\gyjaalgg.dll",s
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [TrustedAntivirus] C:\Program Files\TrustedAntivirus\pgs.exe /min
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...
O14 - IERESET.INF: START_PAGE_URL=http://www.creative.com
O15 - Trusted Zone: *.sbcglobal.net
O15 - Trusted Zone: http://*.sbcglobal.net
O16 - DPF: {3AA42713-5C1E-48E2-B432-D8BF420DD31D} - http://deuscleaneronline.com/Cleane...
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySp...
O18 - Filter hijack: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - C:\Program Files\RcvSystem\httpdchk.dll
O20 - Winlogon Notify: ddcywwu - ddcywwu.dll (file missing)
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O24 - Desktop Component 1: (no name) - C:\Documents and Settings\MyHoa\My Documents\My Pictures\StarLynn\cam_data_photo069_edited.jpg


Close all browsers and other windows except for HijackThis!, and click "Fix checked".


Go to safe mode and Remove these folders:


C:\Program Files\MyWebSearch
C:\Program Files\RcvSystem
C:\Program Files\Network Monitor
C:\Program Files\BestsellerAntivirus

Disable your all AntiVirus and Antispyware softwares to Clean your computer properly!

Please download Malwarebytes' Anti-Malware to your desktop. This is an Free Antimalware Application tool.

Download link: http://www.malwarebytes.org/mbam/pr...

>DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
>Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
>If an update is found, it will download and install the latest database updates.
>Once the program has loaded, select Perform full scan, then click Scan.
>When the scan is complete, click OK, then Show Results to view the results.
>Be sure that everything is checked, and click Remove Selected.
>When MBAM finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt

Post its Log in your next reply.


THEN:

Download SmitfraudFix.exe from here and save it to your desktop:


Download link: http://siri.urz.free.fr/Fix/Smitfra...


You can also read this for its Tutorial how to us SmitraudFix: http://siri.geekstogo.com/Smitfraud...


>Restart your computer. Before the Windows loading screen appears, keep pressing F8 until you see the boot menu. Select Safe Mode.
>Double-click SmitfraudFix.exe
>Select 2 and press Enter to clean your system by deleting infected files.
>You will be prompted: Do you want to clean the registry ? Answer Y (yes) and press Enter in order to remove the hijacked Desktop background and clean registry keys associated with the infection.
>SmitFraudFix will then check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? Answer Y (yes) and press Enter to restore a clean file.
>You may have to restart your computer in order to finish the spyware removal process. You can find a report on spyware removal at the root of the system drive. Usually it will be located at C:\rapport.txt.


After runing above tools, Scan your pc with Hijackthis and Post Fresh Hijackthis Log along with Malwarebytes Antimalware and SmitfraudFix Logs in your next reply.

*Do Safe Computing*


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge
Poll History




Data Recovery Software