This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] twex.exe/malware issues

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi Meiko
Can you tell me if this is the IP of your server:

10.1.1.1

also NEXT:

NEXT:
Make sure Internet Explorer isn't open

Run hijackthis again. Hit None of the above,
Click Do a System Scan Only.
Put a Check in the box on the left side on these: (Not to worry if not there)

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\

Close ALL windows and browsers except HijackThis and click []b]Fix checked
Then reboot

NEXT:
After reboot

post a HijackThis log
good luck mschroe919

hi Meiko
Can you tell me if this is the IP of your server:

10.1.1.1



Yes that's correct.

I removed the 020 avgrsstarter successfully and rebooted. The little pop-up still appears and still no internet connection however in the newest HJT log there appears to be another BHO though I have no idea how that got there unless it was still stuck deep in the system :\


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:15, on 2009-03-01
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\xampp\apache\bin\apache.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\xampp\mysql\bin\mysqld-nt.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\Logi_MwX.Exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\INTERN~2\mum.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Media Key\MagicKey.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Media Key\OSD.EXE
C:\xampp\apache\bin\apache.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: (no name) - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\system32\hplampc.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Media Key.lnk = C:\Program Files\Media Key\MagicKey.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229176476203
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB70EEC9-3211-4B04-8B84-DDA1F06F0D12}: NameServer = 10.1.1.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\apache.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

–
End of file - 10246 bytes
Hi Meiko

NEXT:
Make sure Internet Explorer isn't open

Run hijackthis again. Hit None of the above,
Click Do a System Scan Only.
Put a Check in the box on the left side on these: (Not to worry if not there)

O2 - BHO: (no name) - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)

Close ALL windows and browsers except HijackThis and click []b]Fix checked
Then reboot

NEXT:
After reboot

Delete the files in RED>>not to worry if not there.
C:\WINDOWS\system32\hs78344kjkfd.dll
Let me know when you post a new hjt iof you found
C:\WINDOWS\system32\hs78344kjkfd.dll and if it was deleted
reboot and post a HijackThis log
good luck mschroe919
Hi

BHO removed - the file you asked for me to look for hs78344kjfd.dll was not in the folder so I'm presuming it was deleted if it was there. Still have the pop-up and no internet.

New HJT log below:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:28, on 2009-03-01
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\xampp\apache\bin\apache.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\xampp\mysql\bin\mysqld-nt.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\INTERN~2\mum.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Media Key\MagicKey.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Media Key\OSD.EXE
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\xampp\apache\bin\apache.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\system32\hplampc.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Media Key.lnk = C:\Program Files\Media Key\MagicKey.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229176476203
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB70EEC9-3211-4B04-8B84-DDA1F06F0D12}: NameServer = 10.1.1.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\apache.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

–
End of file - 10139 bytes
Hi
The infection you have affected you dns:
NEXT:
if you connect to the internet via a router do this:

Let’s try to reset the router to its default configuration.
This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
If you don’t know the router's default password, you can look it up. HERE:
You also need to reconfigure any security settings you had in place prior to the reset.
You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.


NEXT

The infection has attacked your DNS, so we need to reset your DNS server and flush your DNS cache.
I suggest you print out these instructions for easy reference:
Go to Start > Control Panel, and choose Network Connections
Right click on your default connection usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
Click the Networking tab
Double-click on the Internet Protocol (TCP/IP) item.
Write down the settings in case you should need to change them back.
Select the radio button that says "Obtain DNS servers automatically".
Click OK twice to get out of the properties screen and restart your computer.
If not prompted to reboot go ahead and reboot manually.

CAUTION: It's possible that your ISP (Internet Service Provider) requires specific DNS settings here. Make sure you know if you need these settings or not BEFORE you make any changes or you may lose your Internet connection. If you're sure you do not need a specific DNS address, then you may proceed.
Now go to Start > Run > type: cmd
Press OK or Hit Enter.
At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
Hit Enter.
You will get a confirmation that the flush was successful.
Close the command box.


NEXT

(if you are unable to directly access the internet still - download and transfer this program to the infected PC)


Download OTScanIt2.exe HERE: to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program. Make sure you close all other programs and don't use the PC while the scan runs.
Under File Age at the top, change it from 30 days to 90 days
Under Additional Scans check the boxes beside Reg - ActiveX StubPath, Reg - App Paths, Reg - ColumnHandlers, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, Reg - ICQ Agent, Reg - NetSvcs, Reg - Print Monitors, Reg - Protocol Filters, Reg - Protocol Handlers, Reg - SafeBoot Minimal, Reg - SafeBoot Network, Reg - Session Manager Settings, Reg - Winsock2 Catalogs, File - Lop Check, File - Purity Scan, Files - Signature Check, and Evnt - EventViewer Logs ( Last 10 Errors).
Under Rootkit Search change it to Yes
Under the Custom Scans box at the bottom left paste the following in

%systemroot%\Prefetch\*.* /s
%systemroot%\system32\drivers\*.dat
%systemroot%\system32\*aef
%systemroot%\system32\drivers\*aef
%systemroot%\Temp\bca4e2da.$$$
%systemroot%\Temp\ed47fa.$
%systemroot%\Temp\fa56d7ec.$$$
%systemroot%\Temp\*.$$$
%systemroot%\System32\antiwpa.dll
%systemroot%\SYSTEM32\wpa.dll
%systemroot%\setup\scripts\biestart.exe
%System%\AcroIeHelpe.dll
%SYSTEMDRIVE%\*.epk
%systemroot%\*.epk
%systemroot%\system32\*.epk
%systemroot%\system32\bb*.dat
%systemroot%\system32\cookie*.dat
%systemroot%\system32\kaxs.dat
%systemroot%\system32\ps*.dat
%systemroot%\system32\*32.sys
%systemroot%\*.dr
%SYSTEMDRIVE%\*.dr
%systemroot%\system32\*.dr
%systemroot%\system32\nods32.dll
%systemroot%\*.res
%SYSTEMDRIVE%\*.res
%systemroot%\system32\*.res
%systemroot%\system32\sockins32.dll
%systemroot%\system32\Spool\*.*
%systemroot%\system32\Spool\*.exe
%systemroot%\system32\Spool\*.rar /s
%systemroot%\system32\Spool\*.zip /s
%systemroot%\system32\Spool\*.dat /s
%ProgramFiles%\MSN Messenger\*.zip
%ProgramFiles%\MSN Messenger\*.exe
%ProgramFiles%\MSN Messenger\*.rar.
%SYSTEMDRIVE%\*.zip
%SYSTEMDRIVE%\*.rar
%SYSTEMDRIVE%\*.exe
%SYSTEMDRIVE%\*.dll
%systemroot%\*.zip
%systemroot%\*.rar
%systemroot%\system32\*.zip
%systemroot%\system32\*.rar
%PROGRAMFILES%\*.*
%DESKTOP%\*.zip
%DESKTOP%\*.rar
%DESKTOP%\*.exe
%PROGRAMFILES%\Common Files\*.*
%PROGRAMFILES%\Common Files\*bak*.
%systemroot%\SYSTEM32\*bak*.
%PROGRAMFILES%\*bak*.
%systemroot%\ime\imjp8_1\*bak*.
%PROGRAMFILES%\QuickTime\*bak*.
%PROGRAMFILES%\Viewpoint\Viewpoint Manager\*bak*.
%PROGRAMFILES%\Analog Devices\Core\*bak*.
%SYSTEMDRIVE%\hp\KBD\*bak*.
%PROGRAMFILES%\Adobe\Photoshop Album Starter Edition\3.2\Apps\*bak*.
%PROGRAMFILES%\BillP Studios\WinPatrol\*bak*.
%PROGRAMFILES%\BroadJump\Client Foundation\*bak*.
%PROGRAMFILES%\Common Files\Real\Update_OB\*bak*.
%PROGRAMFILES%\Common Files\Sonic\Update Manager\*bak*.
%PROGRAMFILES%\\Google\GoogleToolbarNotifier\*bak*.
%PROGRAMFILES%\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\*bak*.
%PROGRAMFILES%\Yahoo!\Messenger\*bak*.
%USERNAME%\*.zip
%USERNAME%\*.rar
%USERNAME%\*.exe
%USERPROFILE%\*.zip
%USERPROFILE%\*.rar
%USERPROFILE%\*.exe
%ALLUSERSPROFILE%\*.zip
%ALLUSERSPROFILE%\*.rar
%ALLUSERSPROFILE%\*.exe
%APPDATA%\*.zip
%APPDATA%\*.rar
%APPDATA%\*.exe
%ALLUSERSSTARTMENU%\*.zip
%ALLUSERSSTARTMENU%\*.rar
%ALLUSERSSTARTMENU%\*.exe
%ALLUSERSSTARTUP%\*.zip
%ALLUSERSSTARTUP%\*.rar
%ALLUSERSSTARTUP%\*.exe
%ALLUSERSPROGRAMS%\*.zip
%ALLUSERSPROGRAMS%\*.rar
%ALLUSERSPROGRAMS%\*.exe
%ALLUSERSAPPDATA%\*.zip
%ALLUSERSAPPDATA%\*.rar
%ALLUSERSAPPDATA%\*.exe
%APPDATA%\*.zip
%APPDATA%\*.rar
%APPDATA%\*.exe
%APPDATA%\*.dat
%APPDATA%\*.dll
%QUICKLAUNCH%\*.zip
%QUICKLAUNCH%\*.rar
%QUICKLAUNCH%\*.exe
%STARTUP%\*.zip
%STARTUP%\*.rar
%STARTUP%\*.exe
%STARTMENU%\*.zip
%STARTMENU%\*.rar
%STARTMENU%\*.exe
%MYDOCUMENTS%\*.zip
%MYDOCUMENTS%\*.rar
%MYDOCUMENTS%\*.exe
%PROGRAMFILES%\Mozilla Firefox\plugins\*.*
%PROGRAMFILES%\Internet Explorer\*.*
%PROGRAMFILES%\Internet Explorer\PLUGINS\*.*
%PROGRAMFILES%\Mozilla Firefox\*.zip /s
%PROGRAMFILES%\Mozilla Firefox\*.rar /s
%PROGRAMFILES%\Mozilla Firefox\*.exe /s
%PROGRAMFILES%\Internet Explorer\*.zip /s
%PROGRAMFILES%\Internet Explorer\*.rar /s
%PROGRAMFILES%\Internet Explorer\*.exe /s
%SYSTEMDRIVE%\*.dat
%SYSTEMDRIVE%\*.sys
%SYSTEMROOT%\*.dat
%SYSTEMROOT%\*.sys
%systemroot%\system32\drivers\*.exe /s
%systemroot%\system32\drivers\*.zip /s
%systemroot%\system32\drivers\*.rar /s
%systemroot%\system\*.exe /s
%systemroot%\system\*.zip /s
%systemroot%\system\*.rar /s
%systemroot%\AppPatch\*.exe /s
%systemroot%\AppPatch\*.zip /s
%systemroot%\AppPatch\*.rar /s
%systemroot%\Cache\*.*
%systemroot%\Downloaded Program Files\*.*
%systemroot%\Fonts\*.exe /s
%systemroot%\Fonts\*.zip /s
%systemroot%\Fonts\*.rar /s
%systemroot%\Fonts\*.dll /s
%systemroot%\Help\*.exe /s
%systemroot%\Help\*.zip /s
%systemroot%\Help\*.rar /s
%systemroot%\Tasks\*.*
%APPDATA%\*.sys
%APPDATA%\Google\*.*
%systemroot%\system32\serauth1.dll
%systemroot%\system32\serauth2.dll
%systemroot%\system32\sysaudio.sys
%systemroot%\system32\wdmaud.sys
%systemroot%\system32\aeaudio.sys
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\serauth1.dll /rs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\serauth2.dll /rs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\sysaudio.sys /rs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\aeaudio.sys /rs
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32|system32\wdmaud.sys /rs
%PROGRAMFILES%\*TinyProxy*.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla|extensions /rs
%systemroot%\system32\inf\*.exe /s
%systemroot%\system32\inf\*.zip /s
%systemroot%\system32\inf\*.rar /s
%systemroot%\system32\inf\*.dll /s
%APPDATA%\Opera\Opera\profile\widgets\*.*
%PROGRAMFILES%\Opera\program\plugins\*.* /s
%APPDATA%\Opera\Opera\profile\toolbar\*.* /s
%systemroot%\Web\*.exe /s
%systemroot%\Web\*.dat /s
%systemroot%\Web\*.dll /s
%systemroot%\Web\*.sys /s
%systemroot%\Web\*.zip /s
%systemroot%\Web\*.rar /s
%systemroot%\Wbem\*.exe /s
%systemroot%\Wbem\*.rar /s
%systemroot%\Wbem\*.zip /s
%systemroot%\Wbem\*.dll /s
%systemroot%\Wbem\*.sys /s
%systemroot%\Wbem\*.dat /s
%systemroot%\twain_32\*.exe
%systemroot%\twain_32\*.dat
%systemroot%\twain_32\*.dll
%systemroot%\twain_32\*.sys /s
%systemroot%\twain_32\*.zip /s
%systemroot%\twain_32\*.rar /s
%systemroot%\system\*.sys /s
%systemroot%\system\*.dat /s
%systemroot%\WinSxS\*.exe /s
%systemroot%\WinSxS\*.dat /s
%systemroot%\WinSxS\*.sys /s
%systemroot%\WinSxS\*.zip /s
%systemroot%\WinSxS\*.rar /s
%systemroot%\Sun\*.dll /s
%systemroot%\Sun\*.rar /s
%systemroot%\Sun\*.zip /s
%systemroot%\Sun\*.exe /s
%systemroot%\Sun\*.sys /s
%systemroot%\Sun\*.dat /s
%systemroot%\srchasst\*.rar /s
%systemroot%\srchasst\*.zip /s
%systemroot%\srchasst\*.exe /s
%systemroot%\srchasst\*.dat /s
%systemroot%\srchasst\*.sys /s
%systemroot%\Shellnew\*.rar /s
%systemroot%\Shellnew\*.zip /s
%systemroot%\Shellnew\*.dat /s
%systemroot%\Shellnew\*.exe /s
%systemroot%\Shellnew\*.sys /s
%systemroot%\Shellnew\*.dll /s
%systemroot%\Security\*.rar /s
%systemroot%\Security\*.zip /s
%systemroot%\Security\*.dat /s
%systemroot%\Security\*.exe /s
%systemroot%\Security\*.sys /s
%systemroot%\Security\*.dll /s
%systemroot%\Resources\*.rar /s
%systemroot%\Resources\*.zip /s
%systemroot%\Resources\*.dat /s
%systemroot%\Resources\*.exe /s
%systemroot%\Resources\*.sys /s
%systemroot%\Repair\*.sys /s
%systemroot%\Repair\*.exe /s
%systemroot%\Repair\*.dll /s
%systemroot%\Repair\*.zip /s
%systemroot%\Repair\*.rar /s
%systemroot%\Registration\*.exe /s
%systemroot%\Registration\*.dat /s
%systemroot%\Registration\*.zip /s
%systemroot%\Registration\*.rar /s
%systemroot%\Registration\*.dll /s
%systemroot%\Registration\*.sys /s
%systemroot%\RegisteredPackages\*.rar /s
%systemroot%\RegisteredPackages\*.zip /s
%systemroot%\pss\*.rar /s
%systemroot%\pss\*.zip /s
%systemroot%\pss\*.exe /s
%systemroot%\pss\*.dll /s
%systemroot%\pss\*.dat /s
%systemroot%\pss\*.sys /s
%systemroot%\Provisioning\*.rar /s
%systemroot%\Provisioning\*.zip /s
%systemroot%\Provisioning\*.exe /s
%systemroot%\Provisioning\*.sys /s
%systemroot%\Provisioning\*.dat /s
%systemroot%\Provisioning\*.dll /s
%systemroot%\PIF\*.*
%systemroot%\PeerNet\*.rar /s
%systemroot%\PeerNet\*.zip /s
%systemroot%\PeerNet\*.dat /s
%systemroot%\PeerNet\*.sys /s
%systemroot%\PeerNet\*.exe /s
%systemroot%\PcTel\*.rar /s
%systemroot%\PcTel\*.zip /s
%systemroot%\Offline Web Pages\*.exe /s
%systemroot%\Offline Web Pages\*.zip /s
%systemroot%\Offline Web Pages\*.rar /s
%systemroot%\Offline Web Pages\*.sys /s
%systemroot%\Offline Web Pages\*.dat /s
%systemroot%\network diagnostic\*.sys /s
%systemroot%\network diagnostic\*.rar /s
%systemroot%\network diagnostic\*.zip /s
%systemroot%\network diagnostic\*.dat /s
%systemroot%\mui\*.*
%systemroot%\msapps\*.*
%systemroot%\msagent\*.zip /s
%systemroot%\msagent\*.rar /s
%systemroot%\msagent\*.sys /s
%systemroot%\msagent\*.dat /s
%systemroot%\minidump\*.*
%systemroot%\media\*.sys /s
%systemroot%\media\*.dat /s
%systemroot%\media\*.rar /s
%systemroot%\media\*.zip /s
%systemroot%\media\*.exe /s
%systemroot%\media\*.dll /s
%systemroot%\Help\*.sys /s
%systemroot%\Help\*.dat /s
%systemroot%\ie7\*.sys /s
%systemroot%\ie7\*.zip /s
%systemroot%\ie7\*.rar /s
%systemroot%\ie7\*.dat /s
%systemroot%\ie7updates\*.sys /s
%systemroot%\ie7updates\*.zip /s
%systemroot%\ie7updates\*.rar /s
%systemroot%\ime\*.sys /s
%systemroot%\ime\*.zip /s
%systemroot%\ime\*.rar /s
%systemroot%\inf\*.sys /s
%systemroot%\inf\*.dat /s
%systemroot%\installer\*.sys /s
%systemroot%\installer\*.zip /s
%systemroot%\installer\*.rar /s
%systemroot%\installer\*.dat /s
%systemroot%\internet logs\*.sys /s
%systemroot%\Cursors\*.rar /s
%systemroot%\Cursors\*.sys /s
%systemroot%\Cursors\*.exe /s
%systemroot%\Cursors\*.dat /s
%systemroot%\Cursors\*.zip /s
%systemroot%\Cursors\*.vbs /s
%systemroot%\Cursors\*.dll /s
%systemroot%\Config\*.*
%systemroot%\Config\*.rar /s
%systemroot%\Config\*.sys /s
%systemroot%\Config\*.exe /s
%systemroot%\Config\*.dat /s
%systemroot%\internet logs\*.dat /s
%systemroot%\Assembly\*sys /s
%systemroot%\Assembly\*.rar /s
%systemroot%\internet logs\*.rar /s
%systemroot%\AppPatch\*.sys
%systemroot%\AppPatch\*.dat
%systemroot%\internet logs\*.zip /s
%systemroot%\internet logs\*.exe /s
%systemroot%\internet logs\*.dll /s
%systemroot%\l2schemas\*.sys /s
%systemroot%\l2schemas\*.dat /s
%systemroot%\l2schemas\*.rar /s
%systemroot%\l2schemas\*.zip /s
%systemroot%\l2schemas\*.exe /s
%systemroot%\l2schemas\*.dll /s
%systemroot%\Fonts\*.dat /s
%systemroot%\Fonts\*.sys /s
%systemroot%\Debug\*.rar /s
%systemroot%\Debug\*.sys /s
%systemroot%\Debug\*.exe /s
%systemroot%\Debug\*.dat /s
%systemroot%\Debug\*.zip /s
%systemroot%\Debug\*.dll /s
%systemroot%\ehome\*.dll /s
%systemroot%\ehome\*.sys /s
%systemroot%\ehome\*.rar /s
%systemroot%\ehome\*.dat /s
%systemroot%\ehome\*.zip /s
%systemroot%\Connection Wizard\*.dat /s
%systemroot%\Connection Wizard\*.exe /s
%systemroot%\Connection Wizard\*.sys /s
%systemroot%\Connection Wizard\*.rar /s
%systemroot%\Connection Wizard\*.zip /s
%systemroot%\Connection Wizard\*.*
%systemroot%\system32\1025\*.*
%systemroot%\system32\1028\*.*
%systemroot%\system32\1031\*.*
%systemroot%\system32\1033\*.exe
%systemroot%\system32\1033\*.sys
%systemroot%\system32\1033\*.zip
%systemroot%\system32\1033\*.rar
%systemroot%\system32\1033\*.dat
%systemroot%\system32\1037\*.*
%systemroot%\system32\1041\*.*
%systemroot%\system32\1042\*.*
%systemroot%\system32\1054\*.*
%systemroot%\system32\2052\*.*
%systemroot%\system32\3076\*.*
%systemroot%\system32\appmgmt\*.exe /s
%systemroot%\system32\appmgmt\*.sys /s
%systemroot%\system32\appmgmt\*.dll /s
%systemroot%\system32\appmgmt\*.dat /s
%systemroot%\system32\appmgmt\*.zip /s
%systemroot%\system32\appmgmt\*.rar /s
%systemroot%\system32\bits\*.rar /s
%systemroot%\system32\bits\*.zip /s
%systemroot%\system32\bits\*.exe /s
%systemroot%\system32\bits\*.dat /s
%systemroot%\system32\bits\*.sys /s
%systemroot%\system32\catroot\*.rar /s
%systemroot%\system32\catroot\*.zip /s
%systemroot%\system32\catroot\*.dll /s
%systemroot%\system32\catroot\*.sys /s
%systemroot%\system32\catroot\*.exe /s
%systemroot%\system32\catroot\*.dat /s
%systemroot%\system32\catroot2\*.rar /s
%systemroot%\system32\catroot2\*.zip /s
%systemroot%\system32\catroot2\*.exe /s
%systemroot%\system32\catroot2\*.dat /s
%systemroot%\system32\catroot2\*.dll /s
%systemroot%\system32\catroot2\*.sys /s
%systemroot%\system32\com\*.sys /s
%systemroot%\system32\com\*.zip /s
%systemroot%\system32\com\*.rar /s
%systemroot%\system32\config\*.rar /s
%systemroot%\system32\config\*.zip /s
%systemroot%\system32\config\*.sys /s
%systemroot%\system32\config\*.dll /s
%systemroot%\system32\config\*.exe /s
%systemroot%\system32\dhcp\*.*
%systemroot%\system32\DirectX\*.rar /s
%systemroot%\system32\DirectX\*.zip /s
%systemroot%\system32\DirectX\*.sys /s
%systemroot%\system32\DirectX\*.dll /s
%systemroot%\system32\DirectX\*.exe /s
%systemroot%\system32\DirectX\*.dat /s
%systemroot%\system32\Dllcache\*.zip /s
%systemroot%\system32\Dllcache\*.rar /s
%systemroot%\system32\drivers\*.dat
%systemroot%\system32\drivers\*.exe /s
%systemroot%\system32\drivers\*.zip /s
%systemroot%\system32\drivers\*.rar /s
%systemroot%\system32\drvstore\*.dat
%systemroot%\system32\drvstore\*.exe /s
%systemroot%\system32\drvstore\*.zip /s
%systemroot%\system32\drvstore\*.rar /s
%systemroot%\system32\en\*.dat /s
%systemroot%\system32\en\*.exe /s
%systemroot%\system32\en\*.zip /s
%systemroot%\system32\en\*.rar /s
%systemroot%\system32\en\*.sys /s
%systemroot%\system32\en\*.sys /s
%systemroot%\system32\en\*.dat /s
%systemroot%\system32\en-us\*.exe /s
%systemroot%\system32\en-us\*.zip /s
%systemroot%\system32\en-us\*.rar /s
%systemroot%\system32\en-us\*.dll /s
%systemroot%\system32\export\*.*
%systemroot%\system32\GroupPolicy\*.sys /s
%systemroot%\system32\GroupPolicy\*.dat /s
%systemroot%\system32\GroupPolicy\*.exe /s
%systemroot%\system32\GroupPolicy\*.zip /s
%systemroot%\system32\GroupPolicy\*.rar /s
%systemroot%\system32\GroupPolicy\*.dll /s
%systemroot%\system32\ias\*.sys /s
%systemroot%\system32\ias\*.dat /s
%systemroot%\system32\ias\*.exe /s
%systemroot%\system32\ias\*.zip /s
%systemroot%\system32\ias\*.rar /s
%systemroot%\system32\ias\*.dll /s
%systemroot%\system32\icsxml\*.sys /s
%systemroot%\system32\icsxml\*.dat /s
%systemroot%\system32\icsxml\*.exe /s
%systemroot%\system32\icsxml\*.zip /s
%systemroot%\system32\icsxml\*.rar /s
%systemroot%\system32\icsxml\*.dll /s
%systemroot%\system32\ime\*.sys /s
%systemroot%\system32\ime\*.dat /s
%systemroot%\system32\ime\*.zip /s
%systemroot%\system32\ime\*.rar /s
%systemroot%\system32\inetsrv\*.sys /s
%systemroot%\system32\inetsrv\*.dat /s
%systemroot%\system32\inetsrv\*.exe /s
%systemroot%\system32\inetsrv\*.zip /s
%systemroot%\system32\inetsrv\*.rar /s
%systemroot%\system32\LogFiles\*.sys /s
%systemroot%\system32\LogFiles\*.dat /s
%systemroot%\system32\LogFiles\*.exe /s
%systemroot%\system32\LogFiles\*.zip /s
%systemroot%\system32\LogFiles\*.rar /s
%systemroot%\system32\LogFiles\*.dll /s
%systemroot%\system32\Macromed\*.sys /s
%systemroot%\system32\Macromed\*.dat /s
%systemroot%\system32\Macromed\*.zip /s
%systemroot%\system32\Macromed\*.rar /s
%systemroot%\system32\Microsoft\*.sys /s
%systemroot%\system32\Microsoft\*.dat /s
%systemroot%\system32\Microsoft\*.exe /s
%systemroot%\system32\Microsoft\*.zip /s
%systemroot%\system32\Microsoft\*.rar /s
%systemroot%\system32\Microsoft\*.dll /s
%systemroot%\system32\Msdtc\*.sys /s
%systemroot%\system32\Msdtc\*.dat /s
%systemroot%\system32\Msdtc\*.exe /s
%systemroot%\system32\Msdtc\*.zip /s
%systemroot%\system32\Msdtc\*.rar /s
%systemroot%\system32\Msdtc\*.dll /s
%systemroot%\system32\Mui\*.sys /s
%systemroot%\system32\Mui\*.dat /s
%systemroot%\system32\Mui\*.exe /s
%systemroot%\system32\Mui\*.zip /s
%systemroot%\system32\Mui\*.rar /s
%systemroot%\system32\npp\*.sys /s
%systemroot%\system32\npp\*.dat /s
%systemroot%\system32\npp\*.zip /s
%systemroot%\system32\npp\*.rar /s
%systemroot%\system32\NtMsData\*.sys /s
%systemroot%\system32\NtMsData\*.dat /s
%systemroot%\system32\NtMsData\*.exe /s
%systemroot%\system32\NtMsData\*.zip /s
%systemroot%\system32\NtMsData\*.rar /s
%systemroot%\system32\NtMsData\*.dll /s
%systemroot%\system32\oobe\*.sys /s
%systemroot%\system32\oobe\*.dat /s
%systemroot%\system32\oobe\*.zip /s
%systemroot%\system32\oobe\*.rar /s
%systemroot%\system32\PreInstall\*.sys /s
%systemroot%\system32\PreInstall\*.dat /s
%systemroot%\system32\PreInstall\*.exe /s
%systemroot%\system32\PreInstall\*.zip /s
%systemroot%\system32\PreInstall\*.rar /s
%systemroot%\system32\PreInstall\*.dll /s
%systemroot%\system32\ras\*.sys /s
%systemroot%\system32\ras\*.dat /s
%systemroot%\system32\ras\*.exe /s
%systemroot%\system32\ras\*.zip /s
%systemroot%\system32\ras\*.rar /s
%systemroot%\system32\ras\*.dll /s
%systemroot%\system32\ReInstallBackups\*.dat /s
%systemroot%\system32\ReInstallBackups\*.zip /s
%systemroot%\system32\ReInstallBackups\*.rar /s
%systemroot%\system32\Restore\*.sys /s
%systemroot%\system32\Restore\*.zip /s
%systemroot%\system32\Restore\*.rar /s
%systemroot%\system32\Restore\*.dll /s
%systemroot%\system32\Scripting\*.sys /s
%systemroot%\system32\Scripting\*.dat /s
%systemroot%\system32\Scripting\*.exe /s
%systemroot%\system32\Scripting\*.zip /s
%systemroot%\system32\Scripting\*.rar /s
%systemroot%\system32\Scripting\*.dll /s
%systemroot%\system32\Setup\*.sys /s
%systemroot%\system32\Setup\*.dat /s
%systemroot%\system32\Setup\*.exe /s
%systemroot%\system32\Setup\*.zip /s
%systemroot%\system32\Setup\*.rar /s
%systemroot%\system32\ShellExt\*.*
%systemroot%\system32\SoftwareDistribution\*.sys /s
%systemroot%\system32\SoftwareDistribution\*.dat /s
%systemroot%\system32\SoftwareDistribution\*.exe /s
%systemroot%\system32\SoftwareDistribution\*.zip /s
%systemroot%\system32\SoftwareDistribution\*.rar /s
%systemroot%\system32\URTTEmp\*.sys /s
%systemroot%\system32\URTTEmp\*.dat /s
%systemroot%\system32\URTTEmp\*.zip /s
%systemroot%\system32\URTTEmp\*.rar /s
%systemroot%\system32\USMT\*.sys /s
%systemroot%\system32\USMT\*.dat /s
%systemroot%\system32\USMT\*.zip /s
%systemroot%\system32\USMT\*.rar /s
%systemroot%\system32\Wbem\*.sys /s
%systemroot%\system32\Wbem\*.zip /s
%systemroot%\system32\Wbem\*.rar /s
%systemroot%\system32\Wins\*.*
%systemroot%\system32\Xircom\*.*
%systemroot%\system32\XPSViewer\*.sys /s
%systemroot%\system32\XPSViewer\*.dat /s
%systemroot%\system32\XPSViewer\*.zip /s
%systemroot%\system32\XPSViewer\*.rar /s
%systemroot%\system32\XPSViewer\*.dll /s
%COMMONPROGRAMFILES%\*.sys /s
%COMMONPROGRAMFILES%\*.zip /s
%COMMONPROGRAMFILES%\*.rar /s
%COMMONPROGRAMFILES%\*.*
%ProgramFiles%\Movie Maker\*.dll
%DriveLetter%\RECYCLER\*S-%d-%d-%d-%d%d%d-%d%d%d-%d%d%d-%d*.
%systemroot%\java\apps\*.*
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
%systemroot%\winstart.bat
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\System\CurrentControlSet\services\VxD
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System\Scripts|Startup /rs
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\MPRServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Accessibility\Utility Manager
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Option
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
%systemroot%\system32\basequu32.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootVerificationProgram
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\BackupPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\ChkDskPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\cleanuppath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath



Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
When the scan is complete Notepad will open with the report file loaded in it.
Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.

Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in.
The last line is < End of Report >, so make sure that is the last line in the attached report.

If the report is too big to upload, then zip the text file and upload it that way

To attach a file, do the following:
Click Add Reply
Under the reply panel is the Attachments Panel
Browse for the attachment file you want to upload, then click the green Upload button
Once it has uploaded, click the Manage Current Attachments drop down box
Click on insert the attachment into your post



In your next reply I need
Update re Internet Access
OTSCANIT log
Thanks mschroe919 I'll get onto that shortly, however I thought I'd post some updates on the pc. When I switched on the computer yesterday the little pop-up appeared once more - this time the menu bar text was unviewable as it was pushed too far up to be able to make out what it read. Usually its just symbols anyway. In the actual pop-up box, however, there were the usual symbols followed by c:\windows\system32. I clicked ok and it continued loading the system. I ran Spybot S&D on the system last night and during its scan, my antivirus software picked up a few viruses (which I removed). The result of the S&D scan was 5 registry keys that it tagged as being trojans (including a BHO) as well as one file which it believed to be dangerous (RegistrySmart scheduled scan.job). I chose to fix the problems and hopefully that's cleared some further issues up. I then ran Malwarebytes Anti-Malware program of which the results are below. One item was found though while the program was running my anti-virus program popped up a few times with virus alerts. I rebooted the PC and the pop-up returned again, however it was just symbols and no file directory as before. Tonight (after work) I switched it on again and once again the pop-up appears, this time the text in the menu bar is readable with a few symbols at the beginning followed by c:\windows\system32\capi20nt.dll. I don't know if any of these pop-ups are related to the virus or not but just wanted to update you on their behaviours as well as the results of the scans I ran. Malwarebytes' Anti-Malware 1.34 Database version: 1749 Windows 5.1.2600 Service Pack 3 2009-03-02 00:38:14 mbam-log-2009-03-02 (00-38-14).txt Scan type: Full Scan (C:\|) Objects scanned: 211275 Time elapsed: 1 hour(s), 8 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5bf49a2-94f3-42bd-f434-3604812c8955} (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I'll post up the results of the DNS issues later.
I've followed the instructions you've given me for trying to get the dns reset - however now I have no internet connection at all (I'm posting this from work). I reset the router however the problem then became apparent as you have to use either IE or any other browser to log into the router's 'page' in order to update its settings. All three browsers refused access (saying it can't connect or there's an error). I then did the ipconfig /flushdns at the command prompt however it came up with the following error message: "Could not flush the DNS Resolver Cache: Function failed during execution" IE and the other browsers still refused access to the router. I had been able to access the router's page via my laptop however even in making changes to the router's details still gave me no access to the internet, even though the router itself said it was connected :\ Also the pop-up appeared again when first turning on the computer and again it was different - mix of symbols followed by acgenral.dll It appears that everytime I start up the computer, the pop-up itself changes. Attached is the OTScanIt log as requested.📎OTScanIt.Txt
HI Meiko,

Sorry about taking so long to get back to you

NEXT

Start OTScanIt2.
Copy/Paste the information inside of the codebox below into the panel where it says "Paste fix here" and then click the Run Fix button.
Don't copy the word code.

[Kill Explorer]
[Unregister Dlls]
[Registry - Safe List]
[Processes - Safe List]
YN -> teatimer.exe -> %ProgramFiles%\Spybot - Search & Destroy\TeaTimer.exe
[Win32 Services - Safe List]
YY -> (SysEnforce) SysEnforce [Win32_Own | Disabled | Stopped] -> 
[Registry - Safe List]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{119DBEDA-9C41-4F97-94B4-B6BCD01133CF}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{A057A204-BACC-4D26-9990-79A187E2698E}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "MSPY2002" -> [C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC]
YN -> "PHIME2002ASync" -> [C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC]
< Mei Startup Folder > -> C:\Documents and Settings\Mei\Start Menu\Programs\Startup
YN -> %UserProfile%\Start Menu\Programs\Startup\Last.fm Helper.lnk -> %ProgramFiles%\Last.fm\LastFMHelper.exe
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{119DBEDA-9c41-4F97-94B4-B6BCD01133CF}" [HKLM] -> [Reg Error: Key error.]
YN -> CmdMapping\\"{E19ADC6E-3909-43E4-9A89-B7B676377EE3}" [HKLM] -> [Reg Error: Key error.]
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\
YN -> {8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11]
YN -> {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab [Reg Error: Key error.]
YN -> {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11]
YN -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab [Java Plug-in 1.6.0_11]
< standard profile authorized applications list > -> hkey_local_machine\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list
yy -> "c:\program files\utorrent\utorrent.exe" -> c:\program files\utorrent\utorrent.exe [c:\program files\utorrent\utorrent.exe:*:enabled:µtorrent]
< mountpoints2 [hkey_current_user] > -> hkey_current_user\software\microsoft\windows\currentversion\explorer\mountpoints2
yn -> \e\shell\autorun\command\\"" -> e:\wd_windows_tools\wdsetup.exe [e:\wd_windows_tools\wdsetup.exe]
[files/folders - created within 90 days]
ny -> 4 c:\windows\system32\*.tmp files -> c:\windows\system32\*.tmp
ny -> flash_disinfector.exe -> %userprofile%\desktop\flash_disinfector.exe
ny -> _otmoveit -> %systemdrive%\_otmoveit
ny -> otmoveit3.exe -> %userprofile%\desktop\otmoveit3.exe
ny -> cf24059.exe -> %systemroot%\system32\cf24059.exe
ny -> combofix -> %systemdrive%\combofix
ny -> cf27620.exe -> %systemroot%\system32\cf27620.exe
ny -> cf24299.exe -> %systemroot%\system32\cf24299.exe
ny -> twain -> %appdata%\twain
[files/folders - modified within 90 days]
ny -> awvnvkgc.dll -> %userprofile%\local settings\temp\awvnvkgc.dll
[file - lop check]
ny -> twain -> c:\documents and settings\mei\application data\twain
[Empty Temp Folders]
[Start Explorer]
[Reboot]

NEXT AFTER REBOOT
Please download GooredFix and save it to your Desktop.
Get it

HERE:

Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.
Post the new logs and a HJT log
good luck mschroe919
Hi mschroe919

I managed to reconnect my laptop to the internet but of course the desktop pc still doesn't connect properly even though it says its connected to the net. :\

OTScanIt log, Goored Log and fresh HLJ log below:

Process Explorer.EXE killed successfully!
[Registry - Safe List]
[Processes - Safe List]
Process teatimer.exe killed successfully!
[Win32 Services - Safe List]
Service SysEnforce stopped successfully!
Service SysEnforce deleted successfully!
File not found.
[Registry - Safe List]
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{119DBEDA-9C41-4F97-94B4-B6BCD01133CF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{119DBEDA-9C41-4F97-94B4-B6BCD01133CF}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MSPY2002 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\PHIME2002ASync deleted successfully.
C:\Documents and Settings\Mei\Start Menu\Programs\Startup\Last.fm Helper.lnk moved successfully.
File C:\Documents and Settings\Mei\Start Menu\Programs\Startup\Last.fm Helper.lnk not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{119DBEDA-9c41-4F97-94B4-B6BCD01133CF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{119DBEDA-9c41-4F97-94B4-B6BCD01133CF}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{E19ADC6E-3909-43E4-9A89-B7B676377EE3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E19ADC6E-3909-43E4-9A89-B7B676377EE3}\ not found.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\Contains\Files\ not found.
not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\Contains\Files\ not found.
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\Contains\Files\ not found.
not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\ deleted successfully.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\Contains\Files\ not found.
not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\Mei\Local Settings\temp\hpodvd09.log scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Mei\Local Settings\temp\~DF61B5.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_41c.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_69c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Opera cache emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt2 by OldTimer - Version 1.0.8.0 fix logfile created on 03052009_185319

Files moved on Reboot…
C:\Documents and Settings\Mei\Local Settings\temp\hpodvd09.log moved successfully.
File C:\Documents and Settings\Mei\Local Settings\temp\~DF61B5.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_41c.dat not found!
File move failed. C:\WINDOWS\temp\Perflib_Perfdata_69c.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot…


GooredFix v1.91 by jpshortstuff
Log created at 18:59 on 05/03/2009 running Option #1 (Mei)
Firefox version 3.0.6 (en-GB)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:01, on 2009-03-05
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\xampp\apache\bin\apache.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\xampp\mysql\bin\mysqld-nt.exe
C:\xampp\apache\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\INTERN~2\mum.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Media Key\MagicKey.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Media Key\OSD.EXE
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [hplampc] C:\WINDOWS\system32\hplampc.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Media Key.lnk = C:\Program Files\Media Key\MagicKey.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229176476203
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} -
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB70EEC9-3211-4B04-8B84-DDA1F06F0D12}: NameServer = 10.1.1.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\apache.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

–
End of file - 9952 bytes
Hi Meiko

Please double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.
when you post that log also let me know what your pc is doing now.
good luck mschroe919
Goored log below - no change to PC status. The program didn't restart the PC but I rebooted anyway. Still have that pop-up appearing before the system loads (changes each time PC is switched on or rebooted) and no internet connection. GooredFix v1.91 by jpshortstuff Log created at 21:14 on 05/03/2009 running Option #2 (Mei) Firefox version 3.0.6 (en-GB) =====Goored Deletions===== =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions] "Components"="C:\Program Files\Mozilla Firefox\components"
Hi Meiko

Download WinSockFix from here or here.

Backing up the Registry
  • Double click on WinsockXPFix.exe to open.
  • On the Winsock and TCP Repair Utility screen, click "ReG-Backup"
  • On the ERDNT Welcome screen, click "OK".
  • On the Backup to: screen, click "OK".
  • On the Folder does not exist question screen click "Yes".
  • You will see a status screen as your registry is being backed up.
  • 1. On the Registry backup is complete! screen, click "OK" and you will go back to the main window.
Resetting the Winsock Stack
  • On the Winsock and TCP Repair Utility screen, click "Fix".
  • On the Apply the VB_Winsock fix? screen click "Yes".
  • The screen will display a status message "repair completed please reboot."
  • On the Repair Completed screen click "OK" to reboot your computer.
  • # If your computer was not using DHCP, you will need to reconfigure TCP/IP.
  • You should have connectivity restored.

good luck mschroe919
Thanks very much, that definitely got it back up and running again. :thumbup: Now how do I get rid of the pesky pop-up box that appears each time I switch on the PC? And do you believe that the worst of the viruses have been removed?
Hi Meiko

This was a tough nut to crack, can you tell me what the pop up box says?
Does it say Windows Messenger?
Also glad your back on internet. The WinSockFix did it . I will wait to see your
answere.

NEXT:

Start your HJT and click on open the misc tools section.
then click on generate startuplist log. then post that log here please.
I will be waitiung for your answeres.
mschroe919
Its like a warning text message that appears with an OK button. When switching or rebooting the PC the windows logo appears followed by what should be the welcome screen, however just as it appears it suddenly goes black and this message box appears. Its different each time I switch on or reboot the PC and usually are a mixture of weird symbols. Sometimes there are references to folders or files that appear both in the message box itself and on the title bar. These are the messages that appear: 1. Mixture of weird symbols appear both in the title bar and within the pop-up box itself along with an ok button 2. Mixture of weird symbols appear in the title bar followed by acgenral.dll; mixture of weird symbols in the pop-up box along with an ok button 3. Same as 2. but instead of acgenral.dll it has c:\windows\system32\capi20nt.dll; 4. Same as 2. but instead of adgenral.dll it has windows\system32\drivers\dxg.sys 5. Mixture of weird symbols appear in the title bar, mixture of symbols in the pop-up box itself followed by c:\windows\system32 I usually click the OK button and it continues loading into the system, however I left it for about 4 or 5 minutes and it disappeared by itself and continued to load the system. I don't know what it is but its annoying and concerns me that there still might be something wrong. I actually took a photo of one of the above versions of the screen that appears if you want me to attach it to my next post?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI