This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] trojan horse bho.hdk

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Last month I kept getting an message that said "Windows must now restart becuase the DCOM server process launcher service terminated unexpectedly." I ran AVG and found a TON of spyware and trojan horses on my computer and removed them, but I still get the message. I then gave my computer to a friend in IT and he managed to stop the message from returning. But now I have a new problem. AVG constantly gives me the message that it has found the trojan horse bho.hdk, but when I do a 4 hour system scan nothing is found. I am at my wits end. What can I do?

A BIG thanks in advance!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:33 PM, on 2/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\AOL\1145215855\ee\AOLSoftware.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: (no name) - {DE2E7ADE-ADD6-4728-A8D7-B7833B0F54A1} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1145215855\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKUS\S-1-5-21-3437584145-911590769-1268077221-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-3437584145-911590769-1268077221-1003\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - HKUS\S-1-5-21-3437584145-911590769-1268077221-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
O4 - HKUS\S-1-5-21-3437584145-911590769-1268077221-1003\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User '?')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User '?')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save with Download Manager… - file://C:\Program Files\Ctrax Player\DMDownload.htm
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.gomyhit.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer…DataManager.CAB
O16 - DPF: {CE8267C2-D41A-4A50-A69D-F32B5C289F14} (FileOpenInstaller) - http://www.cramster.com/DRM/Client/FileOpen.CAB
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: ,
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pharos Systems ComTaskMaster - Pharos Systems International - C:\PROGRA~1\PHAROS~1\Core\CTskMstr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

–
End of file - 12037 bytes
Hello and welcome to Posted Image

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HJT log now, I will post back shortly with instructions.
Hello joyful,

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):
O2 - BHO: (no name) - {DE2E7ADE-ADD6-4728-A8D7-B7833B0F54A1} - (no file)
O15 - Trusted Zone: *.antimalwareguard.com
O15 - Trusted Zone: *.gomyhit.com
O15 - Trusted Zone: *.antimalwareguard.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT

I need you to run the following program - first please ensure AVG is disabled - it sometimes complains this program is a virus - please be assured this program is safe to run, so allow it to do so.
Thank-you.

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Hi joyful,

Please do the following:

Start OTScanIt2. Copy/Paste the information inside the codebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Driver Services - Safe List]
NY -> (mehfuwbg) mehfuwbg [Kernel | Boot | Stopped] -> %SystemRoot%\mehfuwbg
[Registry - Safe List]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3437584145-911590769-1268077221-1003\] > -> HKEY_USERS\S-1-5-21-3437584145-911590769-1268077221-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\\"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" [HKLM] -> [Reg Error: Key error.]
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\
YN -> {4FB96231-14C7-43BF-971E-5B502756B5BE} -> ()
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
NY -> C:\WINDOWS\system32\urqRIbba -> 
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \{0be223cf-c30d-11dd-949d-001500486ed5} -> 
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell -> 
YN -> \{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\\"" -> [AutoRun]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\AutoRun -> 
YN -> \{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\AutoRun\\"" -> [Auto&Play]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\AutoRun\command -> 
YN -> \{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe -a]
YN -> \{12ee8781-93a5-11dc-942c-00038a000015} -> 
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell -> 
YN -> \{12ee8781-93a5-11dc-942c-00038a000015}\Shell\\"" -> [AutoRun]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell\AutoRun -> 
YN -> \{12ee8781-93a5-11dc-942c-00038a000015}\Shell\AutoRun\\"" -> [Auto&Play]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell\AutoRun\command -> 
YN -> \{12ee8781-93a5-11dc-942c-00038a000015}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe]
YN -> \{48d22f26-1ab7-11dc-93fd-00038a000015} -> 
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell -> 
YN -> \{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\\"" -> [AutoRun]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\AutoRun -> 
YN -> \{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\AutoRun\\"" -> [Auto&Play]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\AutoRun\command -> 
YN -> \{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe -a]
YN -> \{5a4e0816-f78a-11dd-94c5-00038a000015} -> 
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell -> 
YN -> \{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\\"" -> [Autorun]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\AutoRun -> 
YN -> \{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\AutoRun\\"" -> [Auto&Play]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\Open\command -> 
YN -> \{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\Open\command\\"" -> E:\resycled\ntldr.com [E:\resycled\ntldr.com e:]
YN -> \{8c495b1a-d783-11da-9206-0016362594bf} -> 
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c495b1a-d783-11da-9206-0016362594bf}\Shell\AutoRun\command -> 
YN -> \{8c495b1a-d783-11da-9206-0016362594bf}\Shell\AutoRun\command\\"" -> E:\setupSNK.exe [E:\setupSNK.exe]
YN -> \{9e3388de-0a31-11dc-93f9-00038a000015} -> 
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell -> 
YN -> \{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\\"" -> [AutoRun]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\AutoRun -> 
YN -> \{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\AutoRun\\"" -> [Auto&Play]
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\AutoRun\command -> 
YN -> \{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe -a]
[Files/Folders - Created Within 30 Days]
NY -> lofajemi -> %SystemRoot%\System32\lofajemi
NY -> MRT.INI -> %SystemRoot%\System32\MRT.INI
NY -> muzika.xm -> %SystemRoot%\System32\muzika.xm
NY -> seneka.sys -> %SystemRoot%\System32\drivers\seneka.sys
NY -> senekavnsruxlw.dat -> %SystemRoot%\System32\senekavnsruxlw.dat
NY -> senekaewfoowyf.sys -> %SystemRoot%\System32\drivers\senekaewfoowyf.sys
NY -> senekaiyqxnost.dat -> %SystemRoot%\System32\senekaiyqxnost.dat
NY -> senekafmqrdkry.dat -> %SystemRoot%\System32\senekafmqrdkry.dat
NY -> Crack by TEAM FFF -> %SystemDrive%\Crack by TEAM FFF
[Files/Folders - Modified Within 30 Days]
NY -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> 65 C:\Documents and Settings\Owner\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Owner\Local Settings\Temp\*.tmp
NY -> 65 C:\Documents and Settings\Owner\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Owner\Local Settings\Temp\*.tmp
NY -> 6 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
NY -> 6 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
NY -> uygjskdw.job -> %SystemRoot%\tasks\uygjskdw.job
NY -> seneka.sys -> %SystemRoot%\System32\drivers\seneka.sys
NY -> senekaewfoowyf.sys -> %SystemRoot%\System32\drivers\senekaewfoowyf.sys
NY -> MRT.INI -> %SystemRoot%\System32\MRT.INI
NY -> imsins.BAK -> %SystemRoot%\imsins.BAK
NY -> senekavnsruxlw.dat -> %SystemRoot%\System32\senekavnsruxlw.dat
NY -> muzika.xm -> %SystemRoot%\System32\muzika.xm
NY -> Perflib_Perfdata_574.dat -> %UserProfile%\Local Settings\Temp\Perflib_Perfdata_574.dat
NY -> senekaiyqxnost.dat -> %SystemRoot%\System32\senekaiyqxnost.dat
NY -> senekafmqrdkry.dat -> %SystemRoot%\System32\senekafmqrdkry.dat
NY -> senekaejbpbofi.dat -> %SystemRoot%\System32\senekaejbpbofi.dat
NY -> senekauhixorvt.dat -> %SystemRoot%\System32\senekauhixorvt.dat
NY -> tmp14D.exe -> %SystemRoot%\Temp\tmp14D.exe
NY -> tmpA.exe -> %SystemRoot%\Temp\tmpA.exe
NY -> index.dat -> %SystemRoot%\Temp\Temporary Internet Files\Content.IE5\index.dat
NY -> index.dat -> %SystemRoot%\Temp\History\History.IE5\index.dat
NY -> index.dat -> %SystemRoot%\Temp\Cookies\index.dat
[File - Lop Check]
NY -> uygjskdw.job -> C:\WINDOWS\Tasks\uygjskdw.job
[Empty Temp Folders]
[Start Explorer]

The fix should only take a very short time.
When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix.
If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix.
Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine.
After the reboot, OTScanIt2 will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.

NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


In your next reply I need
  • OTScanIt2 log
  • MBAM log
also advise how your computer is running now.
I ran the code and the first time the program stop responding. I have included the report that was made. So I unplugged my laptop and rebooted then tried to run the code again. The code is attached for the second OT scan as well. I then ran Malabyte program and it found no infections but AVG came up during the scanning and said it deteched trojan horse generic 12.babc. As for updates on my computer, nothing has changed, webpages still load slowly, but i havent recieved a message regarding trojan horse bho.hdk. Files moved on Reboot… C:\Documents and Settings\Owner\Local Settings\Temp\fla5A.tmp moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\~DFDF71.tmp moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\NAILogs\UpdaterUI_YOUR-4105E587B6.log moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\etilqs_ymRa9ngcsM3PZ2I3OSV9 moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\hpodvd09.log moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\Pharos\UpdaterLog.txt scheduled to be moved on reboot. Registry entries deleted on Reboot… —————————————– Process Explorer.EXE killed successfully! [Driver Services - Safe List] No service named mehfuwbg was found to stop! No service named mehfuwbg was found to delete! File C:\WINDOWS\mehfuwbg not found. [Registry - Safe List] Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found. Registry value HKEY_USERS\S-1-5-21-3437584145-911590769-1268077221-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_USERS\S-1-5-21-3437584145-911590769-1268077221-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{4FB96231-14C7-43BF-971E-5B502756B5BE}\\ updated successfully. Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\urqRIbba scheduled to be deleted on reboot. File not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0be223cf-c30d-11dd-949d-001500486ed5}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\AutoRun\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\AutoRun not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\AutoRun\command\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0be223cf-c30d-11dd-949d-001500486ed5}\Shell\AutoRun\command not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{12ee8781-93a5-11dc-942c-00038a000015}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell\AutoRun\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell\AutoRun not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell\AutoRun\command\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{12ee8781-93a5-11dc-942c-00038a000015}\Shell\AutoRun\command not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{48d22f26-1ab7-11dc-93fd-00038a000015}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\AutoRun\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\AutoRun not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\AutoRun\command\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48d22f26-1ab7-11dc-93fd-00038a000015}\Shell\AutoRun\command not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5a4e0816-f78a-11dd-94c5-00038a000015}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\AutoRun\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\AutoRun not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\Open\command\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5a4e0816-f78a-11dd-94c5-00038a000015}\Shell\Open\command not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c495b1a-d783-11da-9206-0016362594bf}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8c495b1a-d783-11da-9206-0016362594bf}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c495b1a-d783-11da-9206-0016362594bf}\Shell\AutoRun\command\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8c495b1a-d783-11da-9206-0016362594bf}\Shell\AutoRun\command not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9e3388de-0a31-11dc-93f9-00038a000015}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\AutoRun\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\AutoRun not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\AutoRun\command\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e3388de-0a31-11dc-93f9-00038a000015}\Shell\AutoRun\command not found. [Files/Folders - Created Within 30 Days] File C:\WINDOWS\System32\lofajemi not found! File C:\WINDOWS\System32\MRT.INI not found! File C:\WINDOWS\System32\muzika.xm not found! File C:\WINDOWS\System32\drivers\seneka.sys not found! File C:\WINDOWS\System32\senekavnsruxlw.dat not found! File C:\WINDOWS\System32\drivers\senekaewfoowyf.sys not found! File C:\WINDOWS\System32\senekaiyqxnost.dat not found! File C:\WINDOWS\System32\senekafmqrdkry.dat not found! File C:\Crack by TEAM FFF not found! [Files/Folders - Modified Within 30 Days] File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF1571.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF1571.tmp scheduled to be deleted on reboot. File C:\WINDOWS\tasks\uygjskdw.job not found! File C:\WINDOWS\System32\drivers\seneka.sys not found! File C:\WINDOWS\System32\drivers\senekaewfoowyf.sys not found! File C:\WINDOWS\System32\MRT.INI not found! File C:\WINDOWS\imsins.BAK not found! File C:\WINDOWS\System32\senekavnsruxlw.dat not found! File C:\WINDOWS\System32\muzika.xm not found! File C:\Documents and Settings\Owner\Local Settings\Temp\Perflib_Perfdata_574.dat not found! File C:\WINDOWS\System32\senekaiyqxnost.dat not found! File C:\WINDOWS\System32\senekafmqrdkry.dat not found! File C:\WINDOWS\System32\senekaejbpbofi.dat not found! File C:\WINDOWS\System32\senekauhixorvt.dat not found! File C:\WINDOWS\Temp\tmp14D.exe not found! File C:\WINDOWS\Temp\tmpA.exe not found! File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat not found! File C:\WINDOWS\Temp\History\History.IE5\index.dat not found! File C:\WINDOWS\Temp\Cookies\index.dat not found! [File - Lop Check] File C:\WINDOWS\Tasks\uygjskdw.job not found! [Empty Temp Folders] File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\NAILogs\UpdaterUI_YOUR-4105E587B6.log scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\hpodvd09.log scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Owner\Local Settings\Temp\~DF1571.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Pharos\UpdaterLog.txt scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. RecycleBin -> emptied. Explorer started successfully < End of fix log > OTScanIt2 by OldTimer - Version 1.0.8.0 fix logfile created on 07012004_010650 Files moved on Reboot… File C:\Documents and Settings\Owner\Local Settings\Temp\~DF1571.tmp not found! C:\Documents and Settings\Owner\Local Settings\Temp\NAILogs\UpdaterUI_YOUR-4105E587B6.log moved successfully. C:\Documents and Settings\Owner\Local Settings\Temp\hpodvd09.log moved successfully. File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\Pharos\UpdaterLog.txt scheduled to be moved on reboot. Registry entries deleted on Reboot… Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\urqRIbba scheduled to be deleted on reboot. ————————————— 📎mbam_log_2004_07_01__02_29_00_.txt
Hi joyful

Please do the following.

You will need to use IE for this scan.

Go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

  • Please include a fresh HJT log along with the Kaspersky report in your next reply.
I cannot run the online scan becuase it said I needed to install Java. I went to the java website download the software then clicked installed and now I get an error message. I copied the screen and have attached the picture. Should I try running the scan in firefox? Does it matter? 📎java2.JPG
Hi joyful,

please try this to see if we can get java installed properly

Please go to Start> Control Panel > Performance and Maintenance > Administrative tools > Services

Double click the Services Icon.

Locate the Windows Installer in the right pane - click on it.

Click on the 'start' link on the left. (it's highlighted in blue)

This will enable your windows installer so Java may install

then go to http://www.java.com/en/download/index.jsp
and give the Java down load another go

(the scan wont work in Firefox)
Hi joyful,

Please explain what "trojan infection" notice you are getting as your logs look clean. :thumbup:

If you are referring to the Kaspersky scan - AOL does come bundled with some adware, but nothing to be concerned about.


Your system needs to 'reboot' to clean up the left overs, so please allow it to do so.

Now it's time to clean up after ourselves.

Please go to Start > Control Panel > Add/Remove Programs
A list of Installed programs will populate:

Locate J2SE Runtime Environment 5.0 and select REMOVE

NEXT

Download and run this small program and hit the cleanup button.

It will remove all the programs we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use change those settings.
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

NEXT

Now we need to set a new system restore point.

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

To do this: Click Start > Run > copy and paste the following into the run box:


%SystemRoot%\System32\restore\rstrui.exe


Press OK. Choose Create a Restore Point then click Next.
Name it (something you'll remember) and click Create,
when the confirmation screen shows the restore point has been created click Close.

Now remove all previous Restore Points:

Click Start > Run > copy and paste the following into the run box:


cleanmgr


At the top, click on More Options tab. Click the Clean up button in the System Restore box.
Click on the Yes button.
When finished, click on Cancel button to exit.

Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.
  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
  • For Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.
  • Please read the guide by Rorschach112 on how to prevent malware and about safe computing here


Thank you for your patience, and performing all of the procedures requested.
OK joyful, I will check on that and get back to you shortly, I may have to send you over to our tech's for that as it's to do with those administrative services I had you enable previously. At least you are now free of Malware :thumbup: So hopefully we can get this other Windows Installer issue resolved/ CB
Hi joyful,

Please download a fresh copy of the windows installer from here



your copy may have been corrupted by the malware.

If that still doesn't work then post a new topic in our tech forums HERE and one of our tech experts will be able to help you - link them to this thread so they know you are clear of Malware…

hope this solves the issue

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI