1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

can't access antivirus websites

Discussion in 'Malware and Virus Removal Archive' started by hivoltg, 2009/02/08.

  1. 2009/02/08
    hivoltg

    hivoltg Inactive Thread Starter

    Joined:
    2009/02/08
    Messages:
    3
    Likes Received:
    0
    I know a lot of people had this same issue. Can't access antivirus websites. I was finally able to run HJT by renaming it. Here is my HJT log.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:29:08 PM, on 2/8/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0011)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\AVG\AVG8\avgscanx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cox.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cox.net
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.cox.net
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Cox High Speed Internet
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: {425c82cf-0390-2288-2ff4-58869d90d862} - {268d09d9-6885-4ff2-8822-0930fc28c524} - C:\WINDOWS\system32\cxqheo.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {745c7346-19b5-47dc-abd1-ded907cf5f66} - C:\WINDOWS\system32\suverasu.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
    O3 - Toolbar: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - (no file)
    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
    O4 - HKLM\..\Run: [nufazegiya] Rundll32.exe "C:\WINDOWS\system32\tolipihi.dll ",s
    O4 - HKLM\..\Run: [CPM73c475c5] Rundll32.exe "c:\windows\system32\kepuyobi.dll ",a
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [nufazegiya] Rundll32.exe "C:\WINDOWS\system32\tolipihi.dll ",s (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [nufazegiya] Rundll32.exe "C:\WINDOWS\system32\tolipihi.dll ",s (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.cox.net
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\luhijonu.dll c:\windows\system32\kepuyobi.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kepuyobi.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kepuyobi.dll
    O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE (file missing)
    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)

    --
    End of file - 6261 bytes

    Attach.txt
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-02-01.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume1
    Install Date: 4/18/2006 5:15:08 PM
    System Uptime: 2/8/2009 9:01:45 AM (5 hours ago)

    Motherboard: Hewlett-Packard | | 3085
    Processor: AMD Athlon(tm) 64 Processor 3200+ | U23 | 1994/mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 75 GiB total, 59.88 GiB free.
    D: is CDROM ()
    E: is Removable

    ==== Disabled Device Manager Items =============

    Class GUID:
    Description: Video Controller (VGA Compatible)
    Device ID: PCI\VEN_1002&DEV_5955&SUBSYS_3085103C&REV_00\4&2C0D4F31&0&2808
    Manufacturer:
    Name: Video Controller (VGA Compatible)
    PNP Device ID: PCI\VEN_1002&DEV_5955&SUBSYS_3085103C&REV_00\4&2C0D4F31&0&2808
    Service:

    ==== System Restore Points ===================

    No restore point in system.

    ==== Installed Programs ======================

    Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
    Adobe Flash Player 10 ActiveX
    Adobe Reader 8.1.2
    AVG Free 8.0
    Broadcom 802.11 Wireless LAN Adapter
    Conexant AC-Link Audio
    CorrectConnect
    CP_AtenaShokunin1Config
    cp_dwSharkTaleAlbums1
    cp_dwSharkTaleCards1
    cp_dwShrek2Albums1
    cp_dwShrek2Cards1
    CP_PLSBusinessFlyers
    CreativeProjects
    CreativeProjectsTemplates
    CueTour
    Data Fax SoftModem with SmartCP
    Destinations
    Director
    DVD Decoder Pak for Windows XP
    Free Internet Eraser 2.50
    Google Toolbar for Internet Explorer
    HijackThis 2.0.2
    History Cleaner - Free Version
    Home Theater
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB909394)
    Hotfix for Windows XP (KB914440)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB926239)
    Hotfix for Windows XP (KB952287)
    HP Image Zone 4.8.5
    HP Image Zone Plus 4.8.5
    HP Pavillion zv6000 User Guides
    HP Software Update
    HPIZplus450
    InstantShare
    InterActual Player
    InterVideo WinDVD
    J2SE Runtime Environment 5.0 Update 11
    Java(TM) SE Runtime Environment 6 Update 1
    LG USB Drivers
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Excel Viewer 2003
    Microsoft Office XP Professional with FrontPage
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Works
    Mozilla Firefox (3.0.5)
    MSXML 4.0 SP2 (KB925672)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    PanoStandAlone
    PhotoGallery
    QFolder
    Security Update for CAPICOM (KB931906)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB890046)
    Security Update for Windows XP (KB893756)
    Security Update for Windows XP (KB896358)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB896424)
    Security Update for Windows XP (KB896428)
    Security Update for Windows XP (KB899587)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB900725)
    Security Update for Windows XP (KB901017)
    Security Update for Windows XP (KB901190)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB902400)
    Security Update for Windows XP (KB904706)
    Security Update for Windows XP (KB905414)
    Security Update for Windows XP (KB905749)
    Security Update for Windows XP (KB908519)
    Security Update for Windows XP (KB908531)
    Security Update for Windows XP (KB911562)
    Security Update for Windows XP (KB911567)
    Security Update for Windows XP (KB911927)
    Security Update for Windows XP (KB912812)
    Security Update for Windows XP (KB912919)
    Security Update for Windows XP (KB913446)
    Security Update for Windows XP (KB913580)
    Security Update for Windows XP (KB914388)
    Security Update for Windows XP (KB914389)
    Security Update for Windows XP (KB916281)
    Security Update for Windows XP (KB917159)
    Security Update for Windows XP (KB917344)
    Security Update for Windows XP (KB917422)
    Security Update for Windows XP (KB917953)
    Security Update for Windows XP (KB918118)
    Security Update for Windows XP (KB918439)
    Security Update for Windows XP (KB918899)
    Security Update for Windows XP (KB919007)
    Security Update for Windows XP (KB920213)
    Security Update for Windows XP (KB920214)
    Security Update for Windows XP (KB920670)
    Security Update for Windows XP (KB920683)
    Security Update for Windows XP (KB920685)
    Security Update for Windows XP (KB921398)
    Security Update for Windows XP (KB921503)
    Security Update for Windows XP (KB921883)
    Security Update for Windows XP (KB922616)
    Security Update for Windows XP (KB922760)
    Security Update for Windows XP (KB922819)
    Security Update for Windows XP (KB923191)
    Security Update for Windows XP (KB923414)
    Security Update for Windows XP (KB923694)
    Security Update for Windows XP (KB923980)
    Security Update for Windows XP (KB924191)
    Security Update for Windows XP (KB924270)
    Security Update for Windows XP (KB924496)
    Security Update for Windows XP (KB924667)
    Security Update for Windows XP (KB925486)
    Security Update for Windows XP (KB925902)
    Security Update for Windows XP (KB926255)
    Security Update for Windows XP (KB926436)
    Security Update for Windows XP (KB927779)
    Security Update for Windows XP (KB927802)
    Security Update for Windows XP (KB928255)
    Security Update for Windows XP (KB928843)
    Security Update for Windows XP (KB929123)
    Security Update for Windows XP (KB930178)
    Security Update for Windows XP (KB931261)
    Security Update for Windows XP (KB931784)
    Security Update for Windows XP (KB932168)
    Security Update for Windows XP (KB933729)
    Security Update for Windows XP (KB935839)
    Security Update for Windows XP (KB935840)
    Security Update for Windows XP (KB936021)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB938829)
    Security Update for Windows XP (KB941202)
    Security Update for Windows XP (KB941568)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB941644)
    Security Update for Windows XP (KB941693)
    Security Update for Windows XP (KB943055)
    Security Update for Windows XP (KB943460)
    Security Update for Windows XP (KB943485)
    Security Update for Windows XP (KB944653)
    Security Update for Windows XP (KB945553)
    Security Update for Windows XP (KB946026)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB948590)
    Security Update for Windows XP (KB948881)
    Security Update for Windows XP (KB950749)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    SkinsHP1
    Sonic Data Module
    Sonic Express Labeler
    Sonic MyDVD Plus
    Sonic Update Manager
    Synaptics Pointing Device Driver
    Texas Instruments PCIxx21/x515 drivers.
    TIxx21
    TrayApp
    Unload
    Update for Windows XP (KB894391)
    Update for Windows XP (KB898461)
    Update for Windows XP (KB900485)
    Update for Windows XP (KB904942)
    Update for Windows XP (KB910437)
    Update for Windows XP (KB911280)
    Update for Windows XP (KB916595)
    Update for Windows XP (KB920872)
    Update for Windows XP (KB922582)
    Update for Windows XP (KB927891)
    Update for Windows XP (KB929338)
    Update for Windows XP (KB930916)
    Update for Windows XP (KB931836)
    Update for Windows XP (KB932823-v3)
    Update for Windows XP (KB933360)
    Update for Windows XP (KB938828)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    WebFldrs XP
    WebReg
    Windows Defender Signatures
    Windows Installer 3.1 (KB893803)
    Windows Media Player 10 Hotfix - KB894476
    Windows XP Hotfix - KB873333
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB883667
    Windows XP Hotfix - KB884575
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885464
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885836
    Windows XP Hotfix - KB885855
    Windows XP Hotfix - KB885884
    Windows XP Hotfix - KB886185
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB887742
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888239
    Windows XP Hotfix - KB888302
    Windows XP Hotfix - KB890047
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB890859
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB892559

    ==== Event Viewer Messages From Past Week ========

    2/1/2009 9:44:55 AM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
    2/1/2009 9:43:41 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments " " in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    2/1/2009 9:16:56 AM, error: Service Control Manager [7000] - The Upload Manager service failed to start due to the following error: The account specified for this service is different from the account specified for other services running in the same process.
    2/1/2009 9:16:56 AM, error: Service Control Manager [7000] - The Windows User Mode Driver Framework service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    2/1/2009 9:16:56 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows User Mode Driver Framework service to connect.
    2/1/2009 9:16:56 AM, error: Service Control Manager [7000] - The Automatic LiveUpdate Scheduler service failed to start due to the following error: The system cannot find the path specified.
    2/1/2009 9:16:56 AM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The filename, directory name, or volume label syntax is incorrect.
    2/1/2009 9:16:26 AM, error: BITS [16391] - The BITS job list is not in a recognized format. It may have been created by a different version of BITS. The job list has been cleared.
    2/1/2009 9:03:32 AM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 0014A5174BCD has been denied by the DHCP server 10.10.2.1 (The DHCP Server sent a DHCPNACK message).
    2/4/2009 4:40:02 AM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer JOSIE that believes that it is the master browser for the domain on transport NetBT_Tcpip_{599441F3-CDF7-4C49-865. The master browser is stopping or an election is being forced.
    2/8/2009 8:25:56 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    2/8/2009 8:26:34 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 eabfiltr eeCtrl Fips Processor

    ==== End Of File ===========================

    DDS.txt
    DDS (Ver_09-02-01.01) - NTFSx86
    Run by JIMMYRENTERIA at 14:03:07.20 on Sun 02/08/2009
    Internet Explorer: 6.0.2900.2180
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.201 [GMT -9:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated)

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Documents and Settings\JIMMYRENTERIA\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uWindow Title = Microsoft Internet Explorer provided by Cox High Speed Internet
    uStart Page = hxxp://www.cox.net
    uDefault_Page_URL = hxxp://www.cox.net
    mDefault_Page_URL = hxxp://www.cox.net
    mDefault_Search_URL = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
    uInternet Settings,ProxyOverride = <local>
    uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    mSearchAssistant = hxxp://www.google.com/ie
    BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
    BHO: NoExplorer - No File
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: {425c82cf-0390-2288-2ff4-58869d90d862}: {268d09d9-6885-4ff2-8822-0930fc28c524} - c:\windows\system32\cxqheo.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: {745c7346-19b5-47dc-abd1-ded907cf5f66} - c:\windows\system32\suverasu.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
    BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
    TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
    TB: HP view: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hp\digital imaging\bin\HPDTLK02.dll
    TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - No File
    TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [nufazegiya] Rundll32.exe "c:\windows\system32\tolipihi.dll ",s
    mRun: [CPM73c475c5] Rundll32.exe "c:\windows\system32\kepuyobi.dll ",a
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\ssv.dll
    IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F}
    IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F}
    DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    AppInit_DLLs: c:\windows\system32\luhijonu.dll c:\windows\system32\kepuyobi.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kepuyobi.dll
    STS: STS: {ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} - c:\windows\system32\kepuyobi.dll
    LSA: Notification Packages = c:\windows\system32\madipoha.dll c:\windows\system32\luhijonu.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\jimmyr~1\applic~1\mozilla\firefox\profiles\7a6vjzqb.default\
    FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
    FF - component: c:\program files\avg\avg8\toolbarff\components\vmAVGConnector.dll

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-29 325128]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-29 27656]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-29 107272]
    R1 papycpu;papycpu;c:\windows\system32\drivers\papycpu.sys [2007-7-21 1984]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-29 298264]
    R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2006-4-18 200192]
    S3 cpuz128;cpuz128;\??\c:\docume~1\jimmyr~1\locals~1\temp\cpuz_x32.sys --> c:\docume~1\jimmyr~1\locals~1\temp\cpuz_x32.sys [?]

    =============== Created Last 30 ================

    2009-02-08 12:28 <DIR> --d----- c:\program files\Trend Micro
    2009-02-08 08:14 140,497 a--sh--- c:\windows\system32\okqmwm.dll
    2009-02-08 08:14 1,592,526 a--sh--- c:\windows\system32\omusehal.ini
    2009-02-03 22:24 1,592,526 ---sh--- c:\windows\system32\ujozegas.ini
    2009-02-03 22:24 134,349 a------- c:\windows\system32\rcgjnh.dll
    2009-02-03 10:23 1,592,526 ---sh--- c:\windows\system32\ugureset.ini
    2009-02-03 10:23 134,345 a------- c:\windows\system32\vgbncs.dll
    2009-02-02 22:23 133,799 a------- c:\windows\system32\wzerwj.dll
    2009-02-02 22:23 1,570,219 ---sh--- c:\windows\system32\okudozis.ini
    2009-02-02 10:23 1,570,219 ---sh--- c:\windows\system32\utedezub.ini
    2009-02-02 10:23 134,362 a------- c:\windows\system32\npxgbk.dll
    2009-02-01 21:17 135,265 a--sh--- c:\windows\system32\rqnzuh.dll
    2009-02-01 21:17 1,592,526 ---sh--- c:\windows\system32\esezukig.ini
    2009-02-01 09:45 66,048 a------- c:\windows\ieResetIcons.exe
    2009-02-01 09:44 <DIR> --d----- C:\log
    2009-02-01 09:17 133,208 a--sh--- c:\windows\system32\bqzcpk.dll
    2009-02-01 09:17 1,413,666 ---sh--- c:\windows\system32\abusonap.ini
    2009-01-31 20:36 1,413,946 a--sh--- c:\windows\system32\ujobeviy.ini
    2009-01-31 08:36 133,239 a--sh--- c:\windows\system32\xhlyqg.dll
    2009-01-31 08:36 1,413,946 ---sh--- c:\windows\system32\ojamuteg.ini
    2009-01-30 20:36 135,493 a--sh--- c:\windows\system32\rpsiuk.dll
    2009-01-30 20:36 1,413,946 ---sh--- c:\windows\system32\uretezaz.ini
    2009-01-30 08:35 1,413,946 ---sh--- c:\windows\system32\onokodoj.ini
    2009-01-29 20:35 1,432,064 ---sh--- c:\windows\system32\ifobabiy.ini
    2009-01-29 20:15 <DIR> --d-h--- C:\$AVG8.VAULT$
    2009-01-29 20:09 107,272 a------- c:\windows\system32\drivers\avgtdix.sys
    2009-01-29 20:09 10,520 a------- c:\windows\system32\avgrsstx.dll
    2009-01-29 20:09 325,128 a------- c:\windows\system32\drivers\avgldx86.sys
    2009-01-29 20:09 <DIR> --d----- c:\windows\system32\drivers\Avg
    2009-01-29 20:09 <DIR> --d----- c:\docume~1\jimmyr~1\applic~1\AVGTOOLBAR
    2009-01-29 20:09 <DIR> --d----- c:\program files\AVG
    2009-01-29 20:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
    2009-01-25 13:25 71,168 a------- c:\windows\system32\~.exe
    2009-01-25 12:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Downloaded Installations
    2009-01-25 11:10 224 a------- C:\regbak.reg
    2009-01-25 10:43 960 a------- c:\windows\hist_cln
    2009-01-25 10:43 1,384,649 ---sh--- c:\windows\system32\anagefal.ini
    2009-01-25 10:43 134,374 a--sh--- c:\windows\system32\cxqheo.dll
    2009-01-25 10:41 209,192 a------- c:\windows\system32\Tabctl32.ocx
    2009-01-25 10:41 115,016 a------- c:\windows\system32\Msinet.ocx
    2009-01-25 10:41 7,716 a------- c:\windows\system32\URLHIST.tlb
    2009-01-25 10:41 71 a------- c:\windows\system32\Settings.stg
    2009-01-25 10:41 <DIR> --d----- c:\program files\History Cleaner
    2009-01-25 09:58 15,504 a------- c:\windows\system32\drivers\mbam.sys
    2009-01-25 09:58 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-01-25 09:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-01-25 09:58 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-01-25 09:43 133,385 a--sh--- c:\windows\system32\ecsybu.dll
    2009-01-22 05:58 2,713 ---sh--- c:\windows\system32\jazefeme.exe
    2009-01-21 11:57 2,713 ---sh--- c:\windows\system32\hujepaka.exe
    2009-01-20 17:57 133,281 a--sh--- c:\windows\system32\dhlqke.dll
    2009-01-20 17:57 1,382,781 ---sh--- c:\windows\system32\uharibus.ini
    2009-01-20 09:23 3,281 a------- c:\windows\system32\spupdsvc.inf
    2009-01-19 06:25 133,361 a--sh--- c:\windows\system32\pxujsb.dll
    2009-01-19 06:25 1,354,880 ---sh--- c:\windows\system32\ofedawiv.ini
    2009-01-18 18:25 1,354,509 ---sh--- c:\windows\system32\ajotodul.ini
    2009-01-18 18:25 133,442 a--sh--- c:\windows\system32\qxkajy.dll
    2009-01-18 13:23 136,970 a------- c:\windows\system32\reimage.rep
    2009-01-18 13:19 311,879 a------- c:\windows\system32\reimageu.nat
    2009-01-18 13:19 129,022 a------- c:\windows\system32\reimage.nat
    2009-01-18 12:37 13,824 a------- c:\windows\system32\Native.exe
    2009-01-18 12:37 <DIR> --d----- C:\ReimageUndo
    2009-01-18 12:37 262 a------- c:\windows\reimage.ini
    2009-01-18 12:36 <DIR> --d----- C:\rei
    2009-01-18 11:08 <DIR> --d----- c:\program files\PrivacyEraser Computing

    ==================== Find3M ====================

    2009-02-08 08:14 73,405 a--sh--- c:\windows\system32\vipukeyu.dll
    2009-02-08 08:14 140,497 a--sh--- c:\windows\system32\lapujide.dll
    2009-02-08 08:14 108,788 a--sh--- c:\windows\system32\sujibiwi.dll
    2009-02-08 08:14 103,174 a--sh--- c:\windows\system32\lahesumo.dll
    2009-02-03 22:24 134,349 a------- c:\windows\system32\tizokuya.dll
    2009-02-03 22:24 99,613 a------- c:\windows\system32\hehoniwu.dll
    2009-02-03 10:23 100,058 a------- c:\windows\system32\lihuhaso.dll
    2009-02-03 10:23 91,799 -------- c:\windows\system32\teserugu.dll
    2009-02-03 10:23 134,345 a------- c:\windows\system32\julakaso.dll
    2009-02-02 22:23 133,799 a------- c:\windows\system32\tisitami.dll
    2009-02-02 22:23 101,004 a------- c:\windows\system32\nemehuma.dll
    2009-02-02 22:23 93,491 -------- c:\windows\system32\sizoduko.dll
    2009-02-02 10:23 134,362 a------- c:\windows\system32\huwuniva.dll
    2009-02-02 10:23 99,609 a------- c:\windows\system32\bakivige.dll
    2009-02-02 10:23 93,379 -------- c:\windows\system32\buzedetu.dll
    2009-02-02 09:17 64,289 a--sh--- c:\windows\system32\jitodiyo.dll
    2009-02-01 21:17 100,458 a--sh--- c:\windows\system32\kepuyobi.dll
    2009-02-01 21:17 135,265 a--sh--- c:\windows\system32\mofanedo.dll
    2009-02-01 21:17 86,766 -------- c:\windows\system32\gikuzese.dll
    2009-02-01 09:17 100,425 a--sh--- c:\windows\system32\vegozadi.dll
    2009-02-01 09:17 133,208 a--sh--- c:\windows\system32\fibikavi.dll
    2009-02-01 09:17 86,772 -------- c:\windows\system32\panosuba.dll
    2009-01-31 20:36 135,368 a--sh--- c:\windows\system32\renigeta.dll
    2009-01-31 20:36 86,277 a--sh--- c:\windows\system32\yiveboju.dll
    2009-01-31 08:36 133,239 a--sh--- c:\windows\system32\siliyada.dll
    2009-01-31 08:36 100,428 a--sh--- c:\windows\system32\wofusuhe.dll
    2009-01-31 08:36 86,121 -------- c:\windows\system32\getumajo.dll
    2009-01-30 20:36 135,493 a--sh--- c:\windows\system32\nuyafeku.dll
    2009-01-30 20:36 100,549 a--sh--- c:\windows\system32\japivufi.dll
    2009-01-30 08:35 100,642 a--sh--- c:\windows\system32\bobebeji.dll
    2009-01-30 08:35 135,385 a--sh--- c:\windows\system32\merilaro.dll
    2009-01-29 20:35 135,372 a--sh--- c:\windows\system32\fevusota.dll
    2009-01-29 19:35 63,743 a--sh--- c:\windows\system32\pofegohu.dll
    2009-01-29 19:35 133,451 a--sh--- c:\windows\system32\herifolu.dll
    2009-01-25 10:43 134,374 a--sh--- c:\windows\system32\wiwejive.dll
    2009-01-25 10:43 99,560 a--sh--- c:\windows\system32\rigebevu.dll
    2009-01-25 09:43 133,385 a--sh--- c:\windows\system32\yajezadi.dll
    2009-01-25 09:43 64,812 a--sh--- c:\windows\system32\rahurite.dll
    2009-01-20 17:56 133,281 a--sh--- c:\windows\system32\rudukiha.dll
    2009-01-20 17:56 65,268 a--sh--- c:\windows\system32\sakidebo.dll
    2009-01-20 17:56 101,049 a--sh--- c:\windows\system32\pavojeha.dll
    2009-01-20 17:56 87,161 a--sh--- c:\windows\system32\subirahu.dll
    2009-01-20 09:14 78,651 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
    2009-01-19 06:25 99,117 a--sh--- c:\windows\system32\vejidoyu.dll
    2009-01-19 06:25 133,361 a--sh--- c:\windows\system32\sujobapi.dll
    2009-01-19 06:25 87,150 a--sh--- c:\windows\system32\viwadefo.dll
    2009-01-18 18:25 97,543 a--sh--- c:\windows\system32\rudagitu.dll
    2009-01-18 18:25 133,442 a--sh--- c:\windows\system32\fikuyelu.dll
    2009-01-18 14:24 100,550 a--sh--- c:\windows\system32\vagiwara.dll
    2009-01-18 14:24 63,167 a--sh--- c:\windows\system32\derinade.dll
    2009-01-18 13:25 183,296 a------- c:\windows\system32\wuaueng1.dll
    2009-01-18 13:25 165,888 a------- c:\windows\system32\wuauclt1.exe
    2009-01-18 13:25 629,760 a------- c:\windows\system32\wpd_ci.dll
    2009-01-18 13:25 356,352 a------- c:\windows\system32\wpdsp.dll
    2009-01-18 13:25 133,632 a------- c:\windows\system32\WPDShServiceObj.dll
    2009-01-18 13:25 2,603,008 a------- c:\windows\system32\WpdShext.dll
    2009-01-18 13:25 38,400 a------- c:\windows\system32\wpdshextres.dll
    2009-01-18 13:25 17,408 a------- c:\windows\system32\wpdshextautoplay.exe
    2009-01-12 20:39 63,772 a--sh--- c:\windows\system32\fabireze.dll
    2008-12-16 21:24 155,995 a------- c:\windows\java\packages\3BRTV177.ZIP
    2008-12-16 21:24 2,232 a------- c:\windows\java\packages\data\ZFX3PBBN.DAT
    2008-12-16 21:24 2,678 a------- c:\windows\java\packages\data\G4DRFL7P.DAT
    2008-12-16 21:24 2,678 a------- c:\windows\java\packages\data\F5RVF9R1.DAT
    2008-12-16 21:24 2,678 a------- c:\windows\java\packages\data\ZR5J1N1F.DAT
    2008-12-16 21:24 2,678 a------- c:\windows\java\packages\data\UPRDB7RT.DAT
    2008-12-16 21:24 2,678 a------- c:\windows\java\packages\data\DNVJZFRD.DAT
    2006-04-19 14:07 0 a------- c:\docume~1\jimmyr~1\applic~1\wklnhst.dat
    0000-00-00 00:00 60,416 a--sh--- c:\windows\system32\jodenosi.dll
    0000-00-00 00:00 100,352 a--sh--- c:\windows\system32\lefodawu.dll
    0000-00-00 00:00 64,289 a--sh--- c:\windows\system32\luhijonu.dll
    0000-00-00 00:00 87,040 a--sh--- c:\windows\system32\rugobiho.dll
    0000-00-00 00:00 64,289 a--sh--- c:\windows\system32\suverasu.dll
    0000-00-00 00:00 64,289 a--sh--- c:\windows\system32\tolipihi.dll

    ============= FINISH: 14:04:15.39 ===============
     
    Last edited: 2009/02/08
  2. 2009/02/08
    aweston

    aweston Banned

    Joined:
    2009/01/23
    Messages:
    91
    Likes Received:
    1
    You can't access antivirus websites because your HOSTS file has been modified. You can find it in C:\Windows\System32\Drivers\ETC. You'll find all the known security sites looped back to the localhost (127.0.0.1)

    Delete the file. Do NOT reboot your computer and try to access the sites. The second you reboot your computer the resident infections will replace the file and you're done.
     

  3. to hide this advert.

  4. 2009/02/08
    hivoltg

    hivoltg Inactive Thread Starter

    Joined:
    2009/02/08
    Messages:
    3
    Likes Received:
    0
    I didn't notice any difference after deleting the HOSTS file. I still could not access the antivirus websites and the antivirus software failed to update. Any other ideas? Want to see another log?
     
  5. 2009/02/08
    jhty01

    jhty01 Guest

    But Still There is a Problem..

    Hey Friend I am still facing this type of problem. And ya congrats man..
    Plz tell me how you do it??
    i shall be highly thankful to you..
     
  6. 2009/02/08
    wildfire

    wildfire Getting Old

    Joined:
    2008/04/21
    Messages:
    4,649
    Likes Received:
    124
    Hi jhty01

    Please start your own thread and follow these instructions:

    Please read this and post the requested logs in a new thread. I should point out that the experts in this forum can be quite busy at times but I'm sure your post will be picked up by one of them as soon as possible.
     
  7. 2009/02/09
    hivoltg

    hivoltg Inactive Thread Starter

    Joined:
    2009/02/08
    Messages:
    3
    Likes Received:
    0
    Worked like a charm!!! Thank you so much!!!!!!!
     
  8. 2009/02/09
    aweston

    aweston Banned

    Joined:
    2009/01/23
    Messages:
    91
    Likes Received:
    1
    No probs :) More scumware bites the dust. :p
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.