This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New computer already infected

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi people
I'm having the following problems with an (almost) brand new computer and really hope you can help:
1. IE keeps coming up with "This page cannot be displayed", and this garbage appears in the address bar
res://rlvqr.dll/http_404.htm
2. Annoying and very persistent pop-ups (one even advertising free spyware and adware scans!)
3. A couple of links to nasty and unwanted porn sites in my Favourites folder which will NOT go away, no matter how often I delete them.
I've run Spybot SD and Ad-Aware SE scans - the Spybot told everything was fine, but the scan only took a few seconds (seems a bit quick to me). The Ad-Aware scan twice got stuck at
C:\WINDOWS\system32\trayres
and would go no further.
By the way, I'm okay at driving a computer but when it comes to tinkering under the hood/bonnet, I'm clueless.
This is my HJT log, and thanks for being there


Logfile of HijackThis v1.99.1
Scan saved at 17:38:00, on 08/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\system32\winup32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Class - {3486D353-DD52-CE8D-13DF-21EF33F536A7} - C:\WINDOWS\appxf32.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [E-KeyWork] C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
O4 - HKLM\..\Run: [netpw32.exe] C:\WINDOWS\netpw32.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [winup32.exe] C:\WINDOWS\system32\winup32.exe
O4 - HKLM\..\RunOnce: [crkt.exe] C:\WINDOWS\crkt.exe
O4 - HKLM\..\RunOnce: [crkb32.exe] C:\WINDOWS\crkb32.exe
O4 - HKLM\..\RunOnce: [iewi32.exe] C:\WINDOWS\system32\iewi32.exe
O4 - HKLM\..\RunOnce: [msbd.exe] C:\WINDOWS\msbd.exe
O4 - HKLM\..\RunOnce: [atlie.exe] C:\WINDOWS\atlie.exe
O4 - HKLM\..\RunOnce: [javapd.exe] C:\WINDOWS\system32\javapd.exe
O4 - HKLM\..\RunOnce: [crsa.exe] C:\WINDOWS\system32\crsa.exe
O4 - HKLM\..\RunOnce: [addlk.exe] C:\WINDOWS\system32\addlk.exe
O4 - HKLM\..\RunOnce: [sdkss.exe] C:\WINDOWS\sdkss.exe
O4 - HKLM\..\RunOnce: [netkj.exe] C:\WINDOWS\system32\netkj.exe
O4 - HKLM\..\RunOnce: [nethh.exe] C:\WINDOWS\nethh.exe
O4 - HKLM\..\RunOnce: [msun.exe] C:\WINDOWS\msun.exe
O4 - HKLM\..\RunOnce: [ipny.exe] C:\WINDOWS\ipny.exe
O4 - HKLM\..\RunOnce: [sdkmm32.exe] C:\WINDOWS\system32\sdkmm32.exe
O4 - HKLM\..\RunOnce: [ntke32.exe] C:\WINDOWS\system32\ntke32.exe
O4 - HKLM\..\RunOnce: [mfcpp32.exe] C:\WINDOWS\system32\mfcpp32.exe
O4 - HKLM\..\RunOnce: [ntjt.exe] C:\WINDOWS\system32\ntjt.exe
O4 - HKLM\..\RunOnce: [netjv32.exe] C:\WINDOWS\netjv32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BullGuard 5.0] "C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe"
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.3.0.53/supe…o-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.3.0.53/popf…u-ob-assets.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aolsvc.co.uk/molbin/sha…84/mcinsctl.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aolsvc.co.uk/molbin/sha…,21/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\sysnm32.exe" /s (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\\aolserv.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard, Ltd. - C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
O23 - Service: BullGuard Main (BGMainSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard File Monitoring (BsFileSpy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Firewall (BsFirewall) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Email Monitoring (BsMailProxy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\system32\lxcgcoms.exe
Hello and Welcome to TomCoyote Forums Before we are fixing your problems I want to get a good view on the programs installed on your computer i would like you to do the following: * Open HiJackThis * Click on the configure button on the bottom right * Click on the tab "Misc Tools" * Click on the Box that says "Uninstall Manager" * Click on the button "Save list" * Copy and past the List from notepad into your post I want to tell you that it's really busy on the forums as you probably noticed, but now we will fix your problems
Hi Perculator Thanks for getting back to me. Here is the list you asked for. ABBYY FineReader 6.0 Sprint Ad-Aware SE Personal Adobe Acrobat 5.0 Adobe Photoshop Album 2.0 Starter Edition Ahead Nero Burning ROM AOL Coach Version 1.0(Build:20040229.1 uk) AOL Connectivity Services AOL Spyware Protection AOL UK (Choose which version to remove) AOL You've Got Pictures Screensaver Big Kahuna Reef Deluxe BroadJump Client Foundation BullGuard 5.0 EasyKey 1.00 HijackThis 1.99.1 Home Search Assistent Interactive Piano Course Keyboard Coach Learn2 Player (Uninstall Only) Lexmark 2300 Series Lexmark Fax Solutions Microsoft Works 2000 PowerDVD QuickTime RealPlayer Basic Realtek AC'97 Audio REALTEK Gigabit and Fast Ethernet NIC Driver Search Extender Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB901214) Shopping Wizard SiS VGA Utilities Spybot - Search & Destroy 1.4 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Viewpoint Media Player Windows Installer 3.1 (KB893803) Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WK-3500 Music Data Management Software Yahoo! Toolbar Zuma Deluxe Hope you can help John
You have one of the nasiest infections out there. Please post a new hijackthis log and try not to reboot until I get the fix for you. That will be tomoroow (Friday) evening.
Hi Siggyx
Here is the new HJT Log you asked for

Logfile of HijackThis v1.99.1
Scan saved at 16:38:37, on 16/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\crkt.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\system32\winup32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 5 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Class - {3486D353-DD52-CE8D-13DF-21EF33F536A7} - C:\WINDOWS\appxf32.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [E-KeyWork] C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
O4 - HKLM\..\Run: [netpw32.exe] C:\WINDOWS\netpw32.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [winup32.exe] C:\WINDOWS\system32\winup32.exe
O4 - HKLM\..\RunOnce: [crkt.exe] C:\WINDOWS\crkt.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BullGuard 5.0] "C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe"
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.3.0.53/supe…o-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.3.0.53/popf…u-ob-assets.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aolsvc.co.uk/molbin/sha…84/mcinsctl.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aolsvc.co.uk/molbin/sha…,21/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\sysnm32.exe" /s (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\\aolserv.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard, Ltd. - C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
O23 - Service: BullGuard Main (BGMainSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard File Monitoring (BsFileSpy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Firewall (BsFirewall) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Email Monitoring (BsMailProxy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\system32\lxcgcoms.exe
The Fix:

Step#1:Getting Ready

Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available.

After downloading the tools, you must disconnect from the internet totally, because staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer and Outlook Express closed throughout as opening either will reinstall the infection.

To replace Internet Explorer to use during this fix, please use Internet Explorer once to download and install FireFox, to be used as your alternate browser throughout this fix.

Close Outlook Express and Internet Explorer for the duration of this fix

Read through all the instructions so that you can ask any questions now, before you disconnect from the Internet.

Please start by downloading the tools you will need to clean this infection with FireFox. If you have a problem or question with any please continue to follow the list step by step to the end and ask the questions when you are asked to reply. Just be sure to let us know what the problem was when you finally reply.



Step#2:Show All Hidden Files Very Important

Please download and open the following zip file. Double-click on the file inside the zip and when it asks you if you would like to merge the file into your registry, please answer yes. This will make sure all files are visible on your computer.
http://www.davehigham.zen.co.uk/downloads/xphidden.zip


Step#3:Download CWShredder Do Not Use Yet

1. Please Download the most recent version of CWShredder, from CWSInstall.exe

2. Check for Updates but please Do NOT use it yet


Step#4:Download About Buster Do Not Use Yet

1. Please download About:Buster from here: http://www.malwarebytes.biz/AboutBuster5.zip.

2. Once it is downloaded extract it to c:\aboutbuster.

3. Check to make sure it is up-to-date. Please Do NOT use it yet



Step#5:Download Registrar Lite Do Not Use Yet

Another program to download is Registrar Lite for use later: Please download Registrar Lite and install it to C:\Program Files\RegLite\ . This is a registry editor that is very easy to use. Caution should be exercised when editing the registry as it is very easy to render a Computer unbootable by deleting the wrong key



Step#6:Download Ewido Security Suite Only For Windows 2000 and XP Do Not Use Yet
  • Download and install Ewido security suite
  • Right Click on the “E” icon in your taskbar and open Ewido Security Suite then click “update” to get the most recent definitions for it to use.
  • When it prompts you to update, click the OK button.
  • download the updates and when they are finished installing, close the window
  • Please Do Not Use It Yet

Step#6:Download A Registry File to Remove Registry Entries Do Not Use Yet
  • Please download the following zip file to your desktop:
    HSfix
  • Double Click on HSfix.zip and it will unzip to a new folder it makes on your desktop, called HSfix
  • Do Not Use It Yet


Please disconnect from the Internet


Step#7:Disable The Bad Service ** Very Important!!**
  • Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE
  • Click on start > control panel > administrative programs > services. Look for a service called Remote Procedure Call (RPC) Helper . Double click on that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.

Step#8:Stop The Running Processes

(only for Win2k/XP)

Press control-alt-delete to get into the task manager and end the following processes if they exist:


crkt.exe
winup32.exe
sysnm32.exe
netpw32.exe


Step#9:Delete About Blank Bad Files

I now need you to delete the following files:

C:\WINDOWS\appxf32.dll
C:\WINDOWS\netpw32.exe
C:\WINDOWS\system32\winup32.exe
C:\WINDOWS\crkt.exe
C:\WINDOWS\system32\sysnm32.exe


If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Step#10:Cleaning With HijackThis

Then close all programs and windows and run hijackthis. Put a checkmark next to each of these entries and click 'fix checked' button when ready (some may be gone after uninstalling some programs):



R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {3486D353-DD52-CE8D-13DF-21EF33F536A7} - C:\WINDOWS\appxf32.dll

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O4 - HKLM\..\Run: [netpw32.exe] C:\WINDOWS\netpw32.exe
O4 - HKLM\..\Run: [winup32.exe] C:\WINDOWS\system32\winup32.exe
O4 - HKLM\..\RunOnce: [crkt.exe] C:\WINDOWS\crkt

O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\sysnm32.exe" /s (file missing)






click "fix checked"



Step#11: Backup The Registry

In the next step we are going to remove a service that gets installed by this malware.

1. Open Registrar Lite and run it.

2. Copy and paste the bold text below into the address bar of Registrar Lite:(this is making a Registry backup for safety in case of error)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

Go to File> Export and and save as (in the C:\Program Files\Registrar Lite (Reglite) folder):

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)



Step#12: Use the HSfix.reg file
  • Navigate to the HSfix folder on your Desktop
  • Then double-click on the HSfix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.
  • if you have a popup from any of your protection programs asking if you want to make a change to the registry, say Yes or Accept it

Step#13:Fixing With CWShredder
  • CLOSE ALL WINDOWS except CWShredder
  • Run the program by clicking 'fix' and letting it fix all CWS remnants.


Step#14:Fixing With About Buster

This is the step where we will use About:Buster that you had downloaded previously.
  • Navigate to the c:\aboutbuster directory
  • double-click on aboutbuster.exe
  • When the tool opens press the OK button, then Start button, then the OK button
  • then finally the Yes button. It will start scanning your computer for files.
  • If it asks if you would like to do a second pass, allow it to do so.
  • Post the log file in your next reply


Step#15:Scan With Ewido Security Suite
  • Launch Ewido again
  • Click on Scanner>Complete System Scan.
  • Let the program scan your PC.
  • When the scan asks to clean files click OK.
  • When scan is completed, click Save report. to your desktop.
  • Post the report in your next reply.

Reboot your computer back to normal mode and

Reconnect To The Internet



Step#16:Scan and Post a New HJT log with other logs
  • Scan again with HijackThis.
  • Post your logs from HijackThis, About Buster, and Ewido Security Suite here in this thread with any questions or problems that you have run into.
  • There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.
Good Luck!
Hi Siggyx Thanks for the Fix - I just have one problem. I've managed to successfully download all the tools except About:Buster. I keep getting this message: "www.malwarebytes.biz could not be found" I tried downloading it from a couple of other locations but with the same result. Hoping you can help and thanks again John
Hi Siggyx
After a very fraught morning where I've almost descended into a nervous wreck, here are the logs you asked for. :rofl:
Everything went pretty smoothly except the Registra Lite bit (Step 11) - couldn't find the files you specified, so I just gritted my teeth and hoped for the best!

Logfile of HijackThis v1.99.1
Scan saved at 16:19:53, on 18/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\crtm.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 6 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Class - {E93E5DF9-7154-6D62-FCAA-EFF62B854878} - C:\WINDOWS\appye.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [E-KeyWork] C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BullGuard 5.0] "C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe"
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.3.0.53/supe…o-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.3.0.53/popf…u-ob-assets.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aolsvc.co.uk/molbin/sha…84/mcinsctl.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aolsvc.co.uk/molbin/sha…,21/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\crtm.exe" /s (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\\aolserv.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard, Ltd. - C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
O23 - Service: BullGuard Main (BGMainSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard File Monitoring (BsFileSpy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Firewall (BsFirewall) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Email Monitoring (BsMailProxy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\system32\lxcgcoms.exe

AboutBuster 5.0 reference file 28
Scan started on [18/09/2005] at [10:45:54]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
Removed File! : C:\Windows\System32\rlvqr.dll
Removed File! : C:\Windows\System32\eapyr.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:46:40

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 16:15:54, 18/09/2005
+ Report-Checksum: E8DA20E8

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{04256906-BECE-83AC-2058-27ABA38B11A3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{30C5202D-2CDD-8C6D-6CD3-86CBAC73988B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3A1550DD-FD7B-8D6E-989A-49A66DF1433F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7868EC16-8C67-1DBD-6D5A-EBB325881BD9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9B9D4A7D-1232-E364-432D-B58ECFAE5AF4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A0B249A8-05AF-32B0-992B-DB1CAFDEB3E4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BCA18F7D-4CAB-D300-286E-432722FFB0FB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C42CF26E-2B02-05DE-7D7B-A16C5C2095BB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DD25AEF3-3DC7-625D-F3C6-DE10B7C6BF82} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F2255AF4-092C-0BF6-52CF-8484B194FCC4} -> Spyware.CoolWebSearch : Cleaned with backup
C:\WINDOWS\system32\ipyy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ij.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atltv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiva.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iekf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaye32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipgl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netlf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlmt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netbd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3xo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaxa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysvw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addku32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlgl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipkp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieox.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msas32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipvn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msab32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winnr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\bwaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\izpwob.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup
C:\WINDOWS\lfhvhy.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sveznm.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ljdtmw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\wopsnu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\dfaras.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\twpgym.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\yrhjxa.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vrzzwi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\d3bd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\riwbmn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\tmgxhu.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netuw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\n_lauyta.txt -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipiz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\fsfcwx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\gdpzrd.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\rsolrd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sdzhej.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkuu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ymkrvd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iaglzk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bkdlsr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bigbwg.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\okahof.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\dtrxim.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cdritr.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\syskh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\qcjrur.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\saznrr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\jfunhy.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addzp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\xtdrmb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\n_nzuife.txt -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\reefcn.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\n_ildfvp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\thwcxu.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mixtdw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winup32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cznabp.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\n_luciad.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\fpgtye.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sysfw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkzv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\svkxwz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mquxuq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netnh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipwr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\alzuwx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\d3bs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\imorun.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ffarmh.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\zisozo.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\wntnqb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addnu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addav32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aloznr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iekt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\gysdhu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\systf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\osmuon.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\hmwqmg.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\jphmzm.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\oylciu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iptc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\hneyaq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\n_ywpehf.txt -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\igjakt.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntyy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiru.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\diduex.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\lysrwv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mjxlgy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ikkbuv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\jnvqpc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\pquagb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\qtnwti.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\yyyjjh.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\abigwo.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\xubtqy.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\zfmpde.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\birgrw.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vepeog.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vakdhl.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\pvibev.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\eygiqk.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\gtwzou.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\uubdsi.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vxurfp.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\yqvhgo.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\zbfdtv.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\esonpa.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\xdgjcg.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ngieum.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\pcgvsw.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ctbvzx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\epzlwg.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\avpdju.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bgizea.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ugdfuv.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vrwcgb.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\oasaxa.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\pdlwkg.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\fovrcm.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\hklizw.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ubgihx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\oxeheg.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iknhcx.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\kglyzh.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntohsd.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\owzenk.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\epkjhu.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ioaerk.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\yozpej.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\szklzq.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iwnyso.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\jzfvfu.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ouwjyt.txt -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\bjkept.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vnubba.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mtpptb.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\owhlgh.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\pfkcij.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\raatft.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\gjjvsf.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\zucsfm.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\zsfqut.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\cndhrc.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\qsfcha.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\rvxyug.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ecfwow.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\dagort.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\eeqdda.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ujjyuz.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ouuuhg.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mnfzbq.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ojdyyz.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\plipmr.dat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\rwblhy.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ajrkdl.dat -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Documents and Settings\User\Cookies\[removed][1].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\User\Cookies\[removed][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@valueclick[2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\User\Cookies\[removed][1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@adviva[1].txt -> Spyware.Cookie.Adviva : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Documents and Settings\User\Cookies\[removed][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@xxxcounter[1].txt -> Spyware.Cookie.Xxxcounter : Cleaned with backup
C:\Documents and Settings\User\Cookies\[removed][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@sexlist[1].txt -> Spyware.Cookie.Sexlist : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@tradedoubler[2].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\User\Cookies\[removed][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@revenue[1].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\User\Cookies\[removed][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP81\A0024619.EXE -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP81\A0024881.DLL -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024935.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024955.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024956.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024957.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024958.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024961.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024962.EXE -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024963.EXE -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP82\A0024965.exe -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP84\A0025711.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP86\A0027156.EXE -> Trojan.Agent.bi : Cleaned with backup
C:\System Volume Information\_restore{560A53C5-2BA9-43F5-9FB0-DC305EF524FB}\RP86\A0027189.dll -> Spyware.SearchPage : Cleaned with backup
C:\Recycled\Dc42.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Recycled\Dc71.EXE -> TrojanDownloader.Agent.bq : Cleaned with backup


::Report End

Thanks a whole bunch for your help
John
Looking much better

Step#1:Restore Deleted System Files

Now we need to see if we need to restore some deleted files:Please check for the following files using the Windows Search Engine:
  • control.exe
  • rundll32.exe
  • wmplayer.exe
  • msconfig.exe
  • notepad.exe
  • shell.dll
  • SDHelper.dll
If any are missing or not working properly then you can download new copies from
Merijn's Files and following the instructions at that site to have them where they belong for your OS.
  • If you are having any difficulty with Notepad, please go to Merijn's Files and choose 'Windows Files' from the menu on the left hand side of the page. Then choose 'Notepad' from the list and download it to C:\Windows and C:\Windows\System32
  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • This infection often deletes some system files that need to be replaced. The most frequent one it deletes is shell.dll in Win2K or XP. In XP there are two copies of this file, one in Windows (WINNT) and one in Windows\System32. It does not delete the one in Windows\System so it does not affect Win9x/ME. If you find it missing, please copy the shell.dll from c:\windows\system32\dllcache into both \Windows (WINNT) and Windows\System32 .
  • The other system file which is most frequently deleted is control.exe. Please check to make sure that you have this file and it is the correct size. If not Please check for the existence of this file by going to to Merijn's Files (sdhelper) and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to the information at this website. The control.exe is more often deleted in Win9x/ME.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
Step#2:Download CCleaner
  • Download Ccleaner to clean temp files from your computer.
  • Double click on Ccleaner to install the program, with its default settings, selecting language and agreeing to the license agreement.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • Click Options > Advanced and uncheck "Only delete files in Windows Temp folders older than 48 hours".



    Step#3:Complete An Online AntiVirus Scan

    Run an online antivirus scan at:

    Trend Micro-Housecall Online AV

    Reboot



    Step#4:Find the Infected Files On Your Hard Drive
    • Navigate to C:\Windows
    • look for files that were created at the approximate time and date as the infection occurred.
    • look for those that end in exe, DAT and DLL and if found, right click on the file and check properties. Legitimate files should be copyrighted by Microsoft
    • if you determine they are bad files, right click on them and choose delete
    • Navigate to C:\Windows\System or C:\Windows\System32 (depending on the OS) and repeat each of the above steps to check for those ending in exe, DAT and/or DLL
    • if the above files will not delete, then make a new folder on your desktop by right clicking on the desktop and choosing New > Folder. Name the folder CWS Files.
    • Move the files from C:\Windows or C:\Windows\System or C:\Windows\system32
      to the new folder CWS Files.
    Step#5:Using your Windows CD to replace System Files

    ** In cases where many system files are missing you have no alternative but to have them insert their Windows OS disk and run sfc /scannow from the Run box if able or from Recovery Console if not able to get into windows



    Step#6:Scan And Post a New HijackThis Log

    1. Scan again with HijackThis

    2. POST your log file using Add Reply to see what is left to fix.
Hi again siggyx Thanks for the latest batch of instructions All the files you told me to look for appear to be there, although whether or not they're working properly, I don't know how to tell. Only problem I had was when I downloaded the Hoster. I kept getting the following message: "The compressed (zipped file) is invalid or corrupt" The online anti-virus scan found TROJ_DLOADER HP in these C:\WINDOWS\files atlie.exe crdf32.exe crkb32.exe msbd.exe system32\ipkd32.exe system32\msmc.exe Thought I'd better await your advice before taking any further action
Hi Siggyx
Here are the logs you asked for



AboutBuster 5.0 reference file 28
Scan started on [21/09/2005] at [17:19:25]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 17:20:09


Logfile of HijackThis v1.99.1
Scan saved at 17:25:03, on 21/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crtm.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Class - {E93E5DF9-7154-6D62-FCAA-EFF62B854878} - C:\WINDOWS\appye.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [E-KeyWork] C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BullGuard 5.0] "C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe"
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.3.0.53/supe…o-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.3.0.53/popf…u-ob-assets.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aolsvc.co.uk/molbin/sha…84/mcinsctl.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aolsvc.co.uk/molbin/sha…,21/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\crtm.exe" /s (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\\aolserv.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard, Ltd. - C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
O23 - Service: BullGuard Main (BGMainSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard File Monitoring (BsFileSpy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Firewall (BsFirewall) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Email Monitoring (BsMailProxy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\system32\lxcgcoms.exe
Start > Run In the box, type in services.msc then hit (or click OK) In the Name column, look for Network Security Service. it. In the dialogue box that pops up, check in the "Path to executable" box, it will say: C:\WINDOWS\system32\crtm.exe (That's how to tell you have the right one) Now, click Stop to stop that rogue process. In the Startup type box, change it to Disabled, then click Apply then OK. Then post a new hijackthis log please.
I followed your instructions and this is the new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 17:19:36, on 22/09/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Class - {E93E5DF9-7154-6D62-FCAA-EFF62B854878} - C:\WINDOWS\appye.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [E-KeyWork] C:\PROGRA~1\ELTech\Keyboard\Easymain.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BullGuard 5.0] "C:\Program Files\BullGuard Software\BullGuard 5.0\bullguard.exe"
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.3.0.53/supe…o-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.3.0.53/popf…u-ob-assets.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aolsvc.co.uk/molbin/sha…84/mcinsctl.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aolsvc.co.uk/molbin/sha…,21/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\\aolserv.exe
O23 - Service: BullGuard LiveUpdate (BGLiveSvc) - BullGuard, Ltd. - C:\Program Files\BullGuard Software\BullGuard 5.0\BullGuardUpdate.exe
O23 - Service: BullGuard Main (BGMainSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard File Monitoring (BsFileSpy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Firewall (BsFirewall) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: BullGuard Email Monitoring (BsMailProxy) - Unknown owner - C:\WINDOWS\System32\svchost.exe" -k bg5 (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\system32\lxcgcoms.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI