A couple days ago suddenly my computer was getting all sorts of messages in the bottom right about my computer being infected, sending credit card numbers, etc. Also those fake scans were popping up and running. When I went to run Malwarebytes it wouldn't run. Also my anti-virus and other programs wouldn't run. I tried some self-help things and eventually got my avira anti-virus to run. It picked up some things and my computer is now usable, without all those pop-ups, but I'm seeing a number of pop-up ads that I never do when I browse the internet still and Malwarebytes still won't run. HEre is the hijackthis log, thanks:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:18:16 PM, on 10/26/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16915)

Boot mode: Normal

Running processes:










C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Bonjour\mDNSResponder.exe


C:\Program Files\Java\jre6\bin\jqs.exe


C:\Program Files\Viewpoint\Common\ViewpointService.exe


C:\Program Files\WZCBDL Service\WZCBDLS.exe


C:\Program Files\CheckPoint\Integrity Client\iclient.exe


C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe


C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\AIM6\aim6.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\AIM6\aolsoftware.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pbs.org/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pbs.org/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>;*.local

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32



O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [D-Link AirXpert Utility] C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [V0250Mon.exe] C:\WINDOWS\V0250Mon.exe

O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [lofuzirif] Rundll32.exe "c:\windows\system32\zogovaro.dll",a

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

O4 - HKCU\..\Run: [bitComet] "C:\Program Files\BitComet\BitComet.exe" /tray

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1121293151687

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1154431940934

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM

O20 - AppInit_DLLs: c:\windows\system32\fupuvuyu.dll c:\progra~1\ThunMail\testabd.dll c:\windows\system32\supekede.dll c:\windows\system32\zogovaro.dll,sitevahi.dll

O21 - SSODL: mosukitet - {dfbe63ba-c954-4da8-b295-758795abe3e7} - c:\windows\system32\supekede.dll

O22 - SharedTaskScheduler: jugezatag - {dfbe63ba-c954-4da8-b295-758795abe3e7} - c:\windows\system32\supekede.dll

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)

O23 - Service: ISSI EZUpdate (ISSIMon) - Unknown owner - c:\sdwork\issimsvc.exe (file missing)

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe


End of file - 8272 bytes

  • Staff


I see you have Viewpoint installed...

Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 read this article: http://www.clickz.com/news/article.php/3561546

I suggest you remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.

  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player

To run malwarebytes when you get the error code 2 during install, or mbam.exe gets deleted, please see here:


Once malwarebytes opens, click the "Update" tab, click "Check for Updates" in order to download the updates.

Then run the scan, let mbam quarantine/delete what it found and reboot afterwards.

After reboot, post the malwarebytes log together with a new HijackThislog.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 3:08:48 PM, on 10/28/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16915)

Boot mode: Normal

Running processes:










C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Bonjour\mDNSResponder.exe


C:\Program Files\Java\jre6\bin\jqs.exe




C:\Program Files\WZCBDL Service\WZCBDLS.exe

C:\Program Files\CheckPoint\Integrity Client\iclient.exe


C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe


C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\AIM6\aim6.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe


C:\Program Files\AIM6\aolsoftware.exe

C:\Program Files\iPod\bin\iPodService.exe


C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avwsc.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pbs.org/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pbs.org/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>;*.local

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32



O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE

O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [D-Link AirXpert Utility] C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [V0250Mon.exe] C:\WINDOWS\V0250Mon.exe

O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "E:\Malwarebytes' Anti-Malware\explorer.exe.exe" /runcleanupscript

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp

O4 - HKCU\..\Run: [bitComet] "C:\Program Files\BitComet\BitComet.exe" /tray

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"

O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\LOCALS~1\ntuser.dll,_IWMPEvents@0

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.com

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1121293151687

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1154431940934

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COM

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COM

O20 - AppInit_DLLs: sitevahi.dll

O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)

O23 - Service: ISSI EZUpdate (ISSIMon) - Unknown owner - c:\sdwork\issimsvc.exe (file missing)

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

O23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe


End of file - 8099 bytes

Malwarebytes' Anti-Malware 1.41

Database version: 3047

Windows 5.1.2600 Service Pack 3

10/28/2009 3:05:39 PM

mbam-log-2009-10-28 (15-05-39).txt

Scan type: Full Scan (A:\|C:\|D:\|E:\|)

Objects scanned: 174225

Time elapsed: 1 hour(s), 33 minute(s), 30 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 3

Registry Keys Infected: 1

Registry Values Infected: 5

Registry Data Items Infected: 2

Folders Infected: 0

Files Infected: 27

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

C:\WINDOWS\system32\calc.dll (Trojan.Agent) -> Delete on reboot.

c:\WINDOWS\system32\supekede.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\system32\wezisuve.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:

HKEY_CLASSES_ROOT\CLSID\{49e0d174-473c-4e87-bc8f-7a03c2d8f07c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lofuzirif (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\calc (Trojan.Agent) -> Delete on reboot.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{49e0d174-473c-4e87-bc8f-7a03c2d8f07c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\befitegud (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\calc (Trojan.Agent) -> Delete on reboot.

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\supekede.dll -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\supekede.dll -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

c:\WINDOWS\system32\supekede.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\system32\calc.dll (Trojan.Agent) -> Delete on reboot.

C:\WINDOWS\system32\wezisuve.dll (Trojan.Vundo) -> Delete on reboot.

C:\WINDOWS\system32\febobafi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\gipidiwu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\kegovahe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\puzesale.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\rivuyepu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\tegareto.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\wihudiyu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\wisepale.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\dedisuri.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\domohodu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\pefasiyu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\joyurowe.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\fodudoto.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\volizita.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\zogovaro.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrator\ntuser.dll (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrator\Local Settings\temp\rundll32.dll (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZIC73R6G\update2[2].exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\scandisk.dll (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\LocalService\ntuser.dll (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\SelfDel.bat (Malware.Trace) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrator\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.

C:\Documents and Settings\Administrator\Local Settings\temp\nsrbgxod.bak (Trojan.Agent) -> Delete on reboot.

  • Staff


* Please visit this webpage for instructions for downloading and running ComboFix:


Post the log from ComboFix in your next reply.

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix..This because Security Software may see some components ComboFix uses (prep.com for example) as suspicious and blocks the tool, or even deletes it. Please visit HERE if you don't know how.

ComboFix 09-10-27.08 - dmullen 10/28/2009 16:22.2.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.608 [GMT -4:00]

Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe

AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

FW: Integrity Flex Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


c:\documents and settings\Administrator\ntuser.dll

c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.dll

c:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.lnk

c:\documents and settings\NetworkService\ntuser.dll

c:\program files\Mozilla Firefox\extensions\{0A391708-8F13-4FC9-BD21-2E68EFE00381}

c:\program files\Mozilla Firefox\extensions\{0A391708-8F13-4FC9-BD21-2E68EFE00381}\chrome.manifest

c:\program files\Mozilla Firefox\extensions\{0A391708-8F13-4FC9-BD21-2E68EFE00381}\chrome\content\overlay.xul

c:\program files\Mozilla Firefox\extensions\{0A391708-8F13-4FC9-BD21-2E68EFE00381}\install.rdf







((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))



((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 )))))))))))))))))))))))))))))))


2009-10-28 16:45 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-10-28 16:45 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-10-25 19:21 . 2009-10-25 19:32 -------- d-----w- c:\windows\Symbols

2009-10-25 03:09 . 2009-10-25 23:38 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

2009-10-25 03:05 . 2009-10-25 03:05 -------- d--h--w- c:\windows\PIF

2009-10-14 15:20 . 2009-10-17 13:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Soulseek

2009-10-14 06:00 . 2009-10-14 06:00 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AIM

2009-10-03 14:39 . 2009-10-03 14:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))


2009-10-28 17:31 . 2007-09-04 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater

2009-10-28 16:46 . 2009-01-12 18:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-10-28 04:02 . 2007-09-04 19:42 1744 ----a-w- c:\windows\system32\d3d9caps.dat

2009-10-27 14:42 . 2009-06-29 11:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint

2009-10-27 14:42 . 2007-09-05 17:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Viewpoint

2009-10-25 23:39 . 2009-01-12 05:38 -------- d-----w- c:\program files\SUPERAntiSpyware

2009-10-25 14:32 . 2009-04-24 02:02 75096 ----a-w- c:\windows\system32\drivers\avipbb.sys

2009-10-25 02:02 . 2007-08-25 15:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype

2009-10-25 01:43 . 2009-04-06 08:50 -------- d-----r- c:\program files\Skype

2009-10-25 01:42 . 2007-08-25 15:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype

2009-09-21 21:41 . 2007-10-18 02:20 -------- d-----w- c:\program files\Java

2009-09-11 14:18 . 2004-08-04 05:00 136192 ----a-w- c:\windows\system32\msv1_0.dll

2009-09-10 07:09 . 2008-08-19 04:04 -------- d-----w- c:\program files\Microsoft Silverlight

2009-09-04 21:03 . 2004-08-04 05:00 58880 ----a-w- c:\windows\system32\msasn1.dll

2009-08-29 07:36 . 2004-08-04 05:00 832512 ----a-w- c:\windows\system32\wininet.dll

2009-08-29 07:36 . 2009-01-05 22:41 78336 ----a-w- c:\windows\system32\ieencode.dll

2009-08-29 07:36 . 2004-08-04 05:00 17408 ----a-w- c:\windows\system32\corpol.dll

2009-08-26 08:00 . 2004-08-04 05:00 247326 ----a-w- c:\windows\system32\strmdll.dll

2009-08-06 23:24 . 2005-04-04 17:42 327896 ----a-w- c:\windows\system32\wucltui.dll

2009-08-06 23:24 . 2005-04-04 17:42 209632 ----a-w- c:\windows\system32\wuweb.dll

2009-08-06 23:24 . 2005-07-13 22:19 44768 ----a-w- c:\windows\system32\wups2.dll

2009-08-06 23:24 . 2005-04-04 17:57 35552 ----a-w- c:\windows\system32\wups.dll

2009-08-06 23:24 . 2005-04-04 17:42 53472 ----a-w- c:\windows\system32\wuauclt.exe

2009-08-06 23:24 . 2004-08-04 05:00 96480 ----a-w- c:\windows\system32\cdm.dll

2009-08-06 23:23 . 2005-04-04 17:57 575704 ----a-w- c:\windows\system32\wuapi.dll

2009-08-06 23:23 . 2006-08-01 11:32 274288 ----a-w- c:\windows\system32\mucltui.dll

2009-08-06 23:23 . 2005-05-26 08:19 215920 ----a-w- c:\windows\system32\muweb.dll

2009-08-06 23:23 . 2005-04-04 17:42 1929952 ----a-w- c:\windows\system32\wuaueng.dll

2009-08-05 09:01 . 2004-08-04 05:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll

2009-08-05 00:44 . 2004-08-04 05:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe

2009-08-04 14:20 . 2004-08-03 22:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe

2009-08-03 19:07 . 2009-08-03 19:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll

2009-08-03 19:07 . 2009-08-03 19:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll

2009-08-03 19:07 . 2009-08-03 19:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))



*Note* empty entries & legit default entries are not shown



"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-12-05 2356088]


"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]

"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]

"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]

"Zone Labs Client"="c:\program files\CheckPoint\Integrity Client\iclient.exe" [2005-10-26 931584]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-11 39792]

"D-Link AirXpert Utility"="c:\program files\D-Link\AirXpert Utility\AirXCFG.exe" [2003-07-10 2691072]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]

"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]

"V0250Mon.exe"="c:\windows\V0250Mon.exe" [2006-06-08 32768]

"AVFX Engine"="c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-06-09 24576]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

"Mouse Suite 98 Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2002-03-14 45056]

"AtiPTA"="atiptaxx.exe" - c:\windows\system32\atiptaxx.exe [2001-09-27 245760]


"NoDevMgrUpdate"= 1 (0x1)


"NoSetActiveDesktop"= 1 (0x1)

"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]

BootExecute REG_MULTI_SZ autocheck autochk *\0bcasnative32

[HKEY_LOCAL_MACHINE\software\microsoft\security center]




[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]



"EnableFirewall"= 0 (0x0)



"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=

"c:\\Program Files\\AIM6\\aim6.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\guardgui.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"c:\\Program Files\\iPod\\bin\\iPodService.exe"=


"16984:TCP"= 16984:TCP:BitComet 16984 TCP

"16984:UDP"= 16984:UDP:BitComet 16984 UDP

R1 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMouse.SYS [7/31/2006 1:34 PM 16384]

R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [9/27/2002 6:21 PM 22912]

R2 WZCBDLService;WZCBDL Service;c:\program files\WZCBDL Service\WZCBDLS.exe [3/19/2002 12:15 PM 36864]

R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [8/23/2008 12:29 AM 320320]

S0 brhadby;brhadby;c:\windows\system32\drivers\kirqvkx.sys --> c:\windows\system32\drivers\kirqvkx.sys [?]

S1 SABKUTIL;SABKUTIL;\??\c:\documents and settings\Administrator\My Documents\Downloads\SABKUTIL.sys --> c:\documents and settings\Administrator\My Documents\Downloads\SABKUTIL.sys [?]

S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]

S3 BCASPROT;SpyDefy;\??\c:\program files\ByteCrusher\SpyDefy\bcasprot32.sys --> c:\program files\ByteCrusher\SpyDefy\bcasprot32.sys [?]

S3 pelps2m;PS/2 Mouse Filter Driver;c:\windows\system32\drivers\pelps2m.sys [7/31/2006 1:34 PM 18048]

S3 V0250Dev;Live! Cam Notebook Pro;c:\windows\system32\drivers\V0250Dev.sys [2/1/2008 2:02 AM 185504]

S3 V0250Vfx;V0250Vfx;c:\windows\system32\drivers\V0250Vfx.sys [2/1/2008 2:02 AM 6272]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr


Contents of the 'Scheduled Tasks' folder

2009-10-21 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-10-28 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-04 22:30]



------- Supplementary Scan -------


uStart Page = hxxp://www.pbs.org/

uInternet Connection Wizard,ShellNext = hxxp://www.pbs.org/

uInternet Settings,ProxyOverride = ;<local>;*.local

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\x6rjcfib.default\

FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll

FF - HiddenExtension: XUL Cache: {114B283E-19AE-4CB3-97AD-11CC73610945} - c:\documents and settings\Administrator\Local Settings\Application Data\{114B283E-19AE-4CB3-97AD-11CC73610945}

FF - HiddenExtension: XUL Cache: {6EA45995-D0DB-41F2-A913-06047118E723} - c:\windows\system32\config\systemprofile\Local Settings\Application Data\{6EA45995-D0DB-41F2-A913-06047118E723}\

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\


FF - user.js: yahoo.homepage.dontask - true.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

HKCU-Run-BitComet - c:\program files\BitComet\BitComet.exe

HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe

HKLM-Run-Malwarebytes Anti-Malware (reboot) - e:\malwarebytes' anti-malware\explorer.exe.exe

AddRemove-InFlac - c:\program files\Winamp\InFlac-Uninstall.exe


catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-10-28 16:37

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0



--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1764756388-1742547241-4250478557-500\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (Administrator)






@DACL=(02 0000)




@DACL=(02 0000)





@DACL=(02 0000)




--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3152)








------------------------ Other Running Processes ------------------------


c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe

c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Java\jre6\bin\jqs.exe


c:\program files\iPod\bin\iPodService.exe

c:\program files\AIM6\aolsoftware.exe






Completion time: 2009-10-28 16:46 - machine was rebooted

ComboFix-quarantined-files.txt 2009-10-28 20:46

ComboFix2.txt 2009-01-13 02:57

Pre-Run: 28,959,449,088 bytes free

Post-Run: 29,334,745,088 bytes free

- - End Of File - - 3F5F3B263C730345516E3EA2E7CE0936

  • Staff


Go to start > run and copy and paste next command in the field: sc delete brhadby Hit enter.

Then, * Go to start > run and copy and paste next command in the field:

ComboFix /u

Make sure there's a space between Combofix and /

Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

Let me know in your next reply how things are now.

  • Staff

Glad I could help. :)

Please read my Prevention page with lots of info and tips how to prevent this in the future.

And if you want to improve speed/system performance after malware removal, take a look here.

Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Happy Surfing again!

