View Single Post
  #2 (permalink)   Top
Old 25th February 2010, 02:26 PM
Albert Lionheart's Avatar
Albert Lionheart Albert Lionheart is offline
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Hi
bularaja.dll is a known carrier of trojans - it looks as if the program file has been removed but something is still trying to load it. If you google it you will see a number of suggested fixes.
From the HiJackthis log you should fix the following entries
C:\Program Files\SANYO\XactiScreenCapture\SetClip.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {6c0c7db2-30e3-4319-b704-1482d6e517fb} - (no file)
O4 - HKLM\..\Run: [yukukayoj] "Rundll32.exe" "c:\windows\system32\bularaja.dll",a
O16 - DPF: {354D91A8-E3C9-491F-BB89-0FB27DEEED86} (ImgXTwain6.ImgXTwain) - https://eagent.farmersinsurance.com/...mgXTwain61.cab
O16 - DPF: {45EEDB84-57BC-4FBD-8065-7AB8E971B545} (ImgXDialog6.ImgXDialog) - https://eagent.farmersinsurance.com/...gXDialog61.cab
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - Oops! We cannot find the page you're looking for.
O16 - DPF: {7E8DC73D-69CD-4F67-99B1-8DC6E42F6246} (Atalasoft ImgXCtrl6.ImgXCtrl (CAB)) - https://eagent.farmersinsurance.com/...veX/ImgX61.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - MySpace
O17 - HKLM\System\CCS\Services\Tcpip\..\{2E2A1C07-A47A-4527-B369-07B9AAA3BA9D}: NameServer = 206.13.29.12,206.13.30.12
O20 - AppInit_DLLs: nitedetu.dll c:\windows\system32\dihevure.dll c:\windows\system32\bularaja.dll
O21 - SSODL: witolehot - {f38e0665-5c04-410c-a23f-99d7f4d9b714} - (no file)
O21 - SSODL: tututikez - {3c0c967c-b8ee-402b-859b-e4a87c55001f} - (no file)
O22 - SharedTaskScheduler: gahurihor - {f38e0665-5c04-410c-a23f-99d7f4d9b714} - (no file)
O22 - SharedTaskScheduler: kupuhivus - {3c0c967c-b8ee-402b-859b-e4a87c55001f} - (no file)
O23 - Service: Alerter AlerterAlerterALG (AlerterAlerterALG) - Unknown owner - C:\WINDOWS\system32\g.exe (file missing)
__________________
Confuse and Prosper.
Reply With Quote