Very very thank Mr.wolf
Congratulations for work made here :yes:
here the logs Mr.wolf
thank again
Explorer killed successfully
[Processes - Safe List]
Unable to kill process 46f8ygn6.exe .
C:\WINDOWS\system32\46f8yGN6.exe moved successfully.
[Registry - Safe List]
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7480a470-c769-4d29-b238-be482283a486}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7480a470-c769-4d29-b238-be482283a486}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CPM4f5b2926 deleted successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\halegibu.dll
C:\WINDOWS\system32\halegibu.dll NOT unregistered.
C:\WINDOWS\system32\halegibu.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\wepebisara deleted successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\punawuwu.dll
C:\WINDOWS\system32\punawuwu.dll NOT unregistered.
C:\WINDOWS\system32\punawuwu.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\vupewoka.dll deleted successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vupewoka.dll
C:\WINDOWS\system32\vupewoka.dll NOT unregistered.
C:\WINDOWS\system32\vupewoka.dll moved successfully.
Unable to delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\halegibu.dll .
File C:\WINDOWS\system32\halegibu.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\SSODL deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"\ not found.
File C:\WINDOWS\system32\halegibu.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\ deleted successfully.
File C:\WINDOWS\system32\halegibu.dll not found.
[Files/Folders - Created Within 30 Days]
File C:\WINDOWS\System32\46f8yGN6.exe not found!
C:\WINDOWS\System32\46f8yGN6.exe.a_a moved successfully.
C:\WINDOWS\System32\arirahom.ini moved successfully.
C:\WINDOWS\System32\iketenad.ini moved successfully.
C:\WINDOWS\System32\uruholis.ini moved successfully.
C:\WINDOWS\System32\adorozig.ini moved successfully.
C:\WINDOWS\System32\ofalulif.ini moved successfully.
C:\WINDOWS\tasks\At48.job moved successfully.
C:\WINDOWS\tasks\At47.job moved successfully.
C:\WINDOWS\tasks\At46.job moved successfully.
C:\WINDOWS\tasks\At45.job moved successfully.
C:\WINDOWS\tasks\At44.job moved successfully.
C:\WINDOWS\tasks\At43.job moved successfully.
C:\WINDOWS\tasks\At42.job moved successfully.
C:\WINDOWS\tasks\At41.job moved successfully.
C:\WINDOWS\tasks\At40.job moved successfully.
C:\WINDOWS\tasks\At39.job moved successfully.
C:\WINDOWS\tasks\At38.job moved successfully.
C:\WINDOWS\tasks\At37.job moved successfully.
C:\WINDOWS\tasks\At36.job moved successfully.
C:\WINDOWS\tasks\At35.job moved successfully.
C:\WINDOWS\tasks\At34.job moved successfully.
C:\WINDOWS\tasks\At33.job moved successfully.
C:\WINDOWS\tasks\At32.job moved successfully.
C:\WINDOWS\tasks\At31.job moved successfully.
C:\WINDOWS\tasks\At30.job moved successfully.
C:\WINDOWS\tasks\At29.job moved successfully.
C:\WINDOWS\tasks\At28.job moved successfully.
C:\WINDOWS\tasks\At27.job moved successfully.
C:\WINDOWS\tasks\At26.job moved successfully.
C:\WINDOWS\tasks\At25.job moved successfully.
C:\WINDOWS\System32\ilitiraw.ini moved successfully.
C:\WINDOWS\tasks\At9.job moved successfully.
C:\WINDOWS\tasks\At8.job moved successfully.
C:\WINDOWS\tasks\At7.job moved successfully.
C:\WINDOWS\tasks\At6.job moved successfully.
C:\WINDOWS\tasks\At5.job moved successfully.
C:\WINDOWS\tasks\At4.job moved successfully.
C:\WINDOWS\tasks\At3.job moved successfully.
C:\WINDOWS\tasks\At24.job moved successfully.
C:\WINDOWS\tasks\At23.job moved successfully.
C:\WINDOWS\tasks\At22.job moved successfully.
C:\WINDOWS\tasks\At21.job moved successfully.
C:\WINDOWS\tasks\At20.job moved successfully.
C:\WINDOWS\tasks\At2.job moved successfully.
C:\WINDOWS\tasks\At19.job moved successfully.
C:\WINDOWS\tasks\At18.job moved successfully.
C:\WINDOWS\tasks\At17.job moved successfully.
C:\WINDOWS\tasks\At16.job moved successfully.
C:\WINDOWS\tasks\At15.job moved successfully.
C:\WINDOWS\tasks\At14.job moved successfully.
C:\WINDOWS\tasks\At13.job moved successfully.
C:\WINDOWS\tasks\At12.job moved successfully.
C:\WINDOWS\tasks\At11.job moved successfully.
C:\WINDOWS\tasks\At10.job moved successfully.
C:\WINDOWS\System32\6O2ql5w2.exe.a_a moved successfully.
C:\WINDOWS\System32\6O2ql5w2.exe moved successfully.
C:\WINDOWS\tasks\At1.job moved successfully.
C:\Documents and Settings\Rick Bennett\My Documents\~$rd Atwood Addition.doc moved successfully.
C:\Documents and Settings\Rick Bennett\My Documents\~$ford.doc moved successfully.
[Files/Folders - Modified Within 30 Days]
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
C:\WINDOWS\System32\tikezohu moved successfully.
File C:\WINDOWS\System32\46f8yGN6.exe.a_a not found!
File C:\WINDOWS\System32\46f8yGN6.exe not found!
File C:\WINDOWS\tasks\At9.job not found!
File C:\WINDOWS\tasks\At33.job not found!
File C:\WINDOWS\tasks\At24.job not found!
File C:\WINDOWS\tasks\At48.job not found!
File C:\WINDOWS\tasks\At23.job not found!
File C:\WINDOWS\tasks\At47.job not found!
File C:\WINDOWS\System32\arirahom.ini not found!
File C:\WINDOWS\System32\halegibu.dll not found!
DllUnregisterServer procedure not found in C:\WINDOWS\System32\moharira.dll
C:\WINDOWS\System32\moharira.dll NOT unregistered.
C:\WINDOWS\System32\moharira.dll moved successfully.
File C:\WINDOWS\tasks\At22.job not found!
File C:\WINDOWS\tasks\At46.job not found!
File C:\WINDOWS\tasks\At21.job not found!
File C:\WINDOWS\tasks\At45.job not found!
File C:\WINDOWS\tasks\At20.job not found!
File C:\WINDOWS\tasks\At44.job not found!
File C:\WINDOWS\tasks\At19.job not found!
File C:\WINDOWS\tasks\At43.job not found!
File C:\WINDOWS\tasks\At18.job not found!
File C:\WINDOWS\tasks\At42.job not found!
File C:\WINDOWS\tasks\At15.job not found!
File C:\WINDOWS\tasks\At39.job not found!
File C:\WINDOWS\tasks\At14.job not found!
File C:\WINDOWS\tasks\At38.job not found!
File C:\WINDOWS\tasks\At13.job not found!
File C:\WINDOWS\tasks\At37.job not found!
File C:\WINDOWS\tasks\At12.job not found!
File C:\WINDOWS\tasks\At36.job not found!
File C:\WINDOWS\tasks\At11.job not found!
File C:\WINDOWS\tasks\At35.job not found!
File C:\WINDOWS\System32\iketenad.ini not found!
DllUnregisterServer procedure not found in C:\WINDOWS\System32\gitalobo.dll
C:\WINDOWS\System32\gitalobo.dll NOT unregistered.
C:\WINDOWS\System32\gitalobo.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\daneteki.dll
C:\WINDOWS\System32\daneteki.dll NOT unregistered.
C:\WINDOWS\System32\daneteki.dll moved successfully.
File C:\WINDOWS\tasks\At10.job not found!
File C:\WINDOWS\tasks\At34.job not found!
File C:\WINDOWS\tasks\At4.job not found!
File C:\WINDOWS\tasks\At28.job not found!
File C:\WINDOWS\tasks\At3.job not found!
File C:\WINDOWS\tasks\At27.job not found!
File C:\WINDOWS\tasks\At2.job not found!
File C:\WINDOWS\tasks\At26.job not found!
File C:\WINDOWS\tasks\At25.job not found!
File C:\WINDOWS\tasks\At1.job not found!
File C:\WINDOWS\System32\uruholis.ini not found!
DllUnregisterServer procedure not found in C:\WINDOWS\System32\fareruta.dll
C:\WINDOWS\System32\fareruta.dll NOT unregistered.
C:\WINDOWS\System32\fareruta.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\silohuru.dll
C:\WINDOWS\System32\silohuru.dll NOT unregistered.
C:\WINDOWS\System32\silohuru.dll moved successfully.
File C:\WINDOWS\System32\adorozig.ini not found!
DllUnregisterServer procedure not found in C:\WINDOWS\System32\gizoroda.dll
C:\WINDOWS\System32\gizoroda.dll NOT unregistered.
C:\WINDOWS\System32\gizoroda.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\vowayore.dll
C:\WINDOWS\System32\vowayore.dll NOT unregistered.
C:\WINDOWS\System32\vowayore.dll moved successfully.
File C:\WINDOWS\tasks\At41.job not found!
File C:\WINDOWS\tasks\At17.job not found!
File C:\WINDOWS\tasks\At40.job not found!
File C:\WINDOWS\tasks\At16.job not found!
File C:\WINDOWS\System32\ofalulif.ini not found!
DllUnregisterServer procedure not found in C:\WINDOWS\System32\zujopuhe.dll
C:\WINDOWS\System32\zujopuhe.dll NOT unregistered.
C:\WINDOWS\System32\zujopuhe.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\filulafo.dll
C:\WINDOWS\System32\filulafo.dll NOT unregistered.
C:\WINDOWS\System32\filulafo.dll moved successfully.
File C:\WINDOWS\tasks\At32.job not found!
File C:\WINDOWS\tasks\At31.job not found!
File C:\WINDOWS\tasks\At30.job not found!
File C:\WINDOWS\tasks\At29.job not found!
File C:\WINDOWS\System32\ilitiraw.ini not found!
DllUnregisterServer procedure not found in C:\WINDOWS\System32\waritili.dll
C:\WINDOWS\System32\waritili.dll NOT unregistered.
C:\WINDOWS\System32\waritili.dll moved successfully.
C:\WINDOWS\System32\sawubiyi.dll_old moved successfully.
File C:\WINDOWS\tasks\At8.job not found!
File C:\WINDOWS\tasks\At7.job not found!
File C:\WINDOWS\tasks\At6.job not found!
File C:\WINDOWS\tasks\At5.job not found!
File C:\WINDOWS\System32\6O2ql5w2.exe.a_a not found!
File C:\WINDOWS\System32\6O2ql5w2.exe not found!
File C:\Documents and Settings\Rick Bennett\My Documents\~$rd Atwood Addition.doc not found!
File C:\Documents and Settings\Rick Bennett\My Documents\~$ford.doc not found!
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DF41D7.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DF76A4.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DF8D76.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB1DB.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB1F0.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB231.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB244.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB274.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB283.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB974.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFBADA.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\~DF70D2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\~DF70FC.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt2 by OldTimer - Version 1.0.0.33b fix logfile created on 11122008_134119
Files moved on Reboot...
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DF41D7.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DF76A4.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DF8D76.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB1DB.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB1F0.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB231.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB244.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB274.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB283.tmp not found!
File C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFB974.tmp not found!
C:\Documents and Settings\Rick Bennett\Local Settings\Temp\~DFBADA.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\~DF70D2.tmp moved successfully.
C:\WINDOWS\temp\~DF70FC.tmp moved successfully.
Scanning Report
Wednesday, November 12, 2008 14:37:01 - 15:44:12
Computer name: D1WZ0L91
Scanning type: Scan system for malware, rootkits
Target: C:\
--------------------------------------------------------------------------------
Result: 10 malware found
TrackingCookie.Questionmarket (spyware)
System
TrackingCookie.Revsci (spyware)
System
Trojan.Win32.Agent.aljf (virus)
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\BACKUPS\BACKUP-20081110-174357-531.DLL (Renamed)
Vundo.FBW (virus)
C:\_OTSCANIT\MOVEDFILES\11122008_134119\C_WINDOWS\SYSTEM32\ADOROZIG.INI
C:\_OTSCANIT\MOVEDFILES\11122008_134119\C_WINDOWS\SYSTEM32\ARIRAHOM.INI
C:\_OTSCANIT\MOVEDFILES\11122008_134119\C_WINDOWS\SYSTEM32\IKETENAD.INI
C:\_OTSCANIT\MOVEDFILES\11122008_134119\C_WINDOWS\SYSTEM32\ILITIRAW.INI
C:\_OTSCANIT\MOVEDFILES\11122008_134119\C_WINDOWS\SYSTEM32\OFALULIF.INI
C:\_OTSCANIT\MOVEDFILES\11122008_134119\C_WINDOWS\SYSTEM32\URUHOLIS.INI
C:\WINDOWS\SYSTEM32\ASEZURAY.INI
--------------------------------------------------------------------------------
Statistics
Scanned:
Files: 38309
System: 2870
Not scanned: 7
Actions:
Disinfected: 0
Renamed: 1
Deleted: 0
None: 9
Submitted: 0
Files not scanned:
C:\HIBERFIL.SYS
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SYSTEM32\CONFIG\SAM
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
--------------------------------------------------------------------------------
Options
Scanning engines:
F-Secure USS: 2.40.0
F-Secure Hydra: 2.8.8110, 2008-11-12
F-Secure AVP: 7.0.171, 2008-11-12
F-Secure Pegasus: 1.20.0, 2008-10-09
F-Secure Blacklight: 2.4.1093
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JPG LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
Use Advanced heuristics
--------------------------------------------------------------------------------
Copyright © 1998-2007 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
:yes::yes::yes::yes: