This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

winfixer help

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I need help removing winfixer. Here is my log. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 9:10:58 AM, on 10/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\SuperFlexible\ExtremeSyncService.exe
C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Hmonitor\hmonitor.exe
C:\WINDOWS\SYSTEM\atiptaxx.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Program Files\StarOffice7\program\soffice.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\joe\Desktop\virus programs\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adb…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\msagent\abrdos.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [ATIPTA] C:\WINDOWS\SYSTEM\atiptaxx.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: StarOffice 8.lnk = C:\Program Files\Sun\StarOffice 8\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Global Startup: StarOffice 7.lnk = C:\Program Files\StarOffice7\program\quickstart.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Open PDF in Word - res://C:\Program Files\ScanSoft\OmniPagePro14.0\PdfCnv\IEShellExt.dll /100
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fastaccess.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121826124081
O16 - DPF: {7876E4A5-78B7-4020-B08F-C960A1ED54C9} (WebWatch Class) - http://tlcwatch1.homeip.net/WinWebPush.cab
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - http://transfers.one.microsoft.com/FTM/Tra…ransferCtrl.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://camiwe.brett-robinson.com/activex/AxisCamControl.cab
O20 - Winlogon Notify: abrdos - C:\WINDOWS\msagent\abrdos.dll
O20 - Winlogon Notify: catdb - C:\WINDOWS\Help\catdb.dll (file missing)
O20 - Winlogon Notify: dllcat - C:\WINDOWS\AppPatch\dllcat.dll (file missing)
O20 - Winlogon Notify: dllps - C:\WINDOWS\Web\Wallpaper\dllps.dll (file missing)
O20 - Winlogon Notify: dos - C:\WINDOWS\msagent\chars\dos.dll (file missing)
O20 - Winlogon Notify: doscmd - C:\WINDOWS\repair\Backup\doscmd.dll (file missing)
O20 - Winlogon Notify: dosip - C:\WINDOWS\repair\Backup\dosip.dll (file missing)
O20 - Winlogon Notify: dosjava - C:\WINDOWS\Cursors\dosjava.dll (file missing)
O20 - Winlogon Notify: doswave - C:\WINDOWS\Help\mail\doswave.dll (file missing)
O20 - Winlogon Notify: expfax - C:\WINDOWS\ServicePackFiles\i386\expfax.dll (file missing)
O20 - Winlogon Notify: fonturl - C:\WINDOWS\AppPatch\fonturl.dll (file missing)
O20 - Winlogon Notify: infoad - C:\WINDOWS\Fonts\AdvUninstal\infoad.dll (file missing)
O20 - Winlogon Notify: javaexp - C:\WINDOWS\ServicePackFiles\i386\javaexp.dll (file missing)
O20 - Winlogon Notify: javams - C:\WINDOWS\java\javams.dll (file missing)
O20 - Winlogon Notify: mlllm - mlllm.dll (file missing)
O20 - Winlogon Notify: nutvb - C:\WINDOWS\Cursors\nutvb.dll (file missing)
O20 - Winlogon Notify: oleacc - C:\WINDOWS\ServicePackFiles\i386\oleacc.dll (file missing)
O20 - Winlogon Notify: srvacc - C:\WINDOWS\ServicePackFiles\i386\srvacc.dll (file missing)
O20 - Winlogon Notify: utilinet - C:\WINDOWS\msagent\chars\utilinet.dll (file missing)
O20 - Winlogon Notify: vgabas - C:\WINDOWS\java\Packages\vgabas.dll (file missing)
O20 - Winlogon Notify: vgamfc - C:\WINDOWS\msagent\Intl\vgamfc.dll (file missing)
O20 - Winlogon Notify: vgavss - C:\WINDOWS\ServicePackFiles\i386\vgavss.dll (file missing)
O20 - Winlogon Notify: winun - C:\WINDOWS\msagent\Intl\winun.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ExtremeSync Service (ExtremeSync_Service) - Unknown owner - C:\Program Files\SuperFlexible\ExtremeSyncService.exe
O23 - Service: HP Web Jetadmin (HPWebJetadmin) - Unknown owner - C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Network Time Protocol Daemon (NTP) - Unknown owner - C:\Program Files\NTP\bin\ntpd.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Run Hijack This!

Click the "Open the Misc Tools section" button.

Click the "Open process manager" button.

Check the "Show DLLs" box (upper right).

Click on each item in the upper window, then look in the lower window.

Check to see which processes are using C:\WINDOWS\repair\catip.dll

Post back letting me know all processes using that DLL.

Copy the text in the following quote box into Notepad:

dir C:\WINDOWS\msagent\ /ah > files.txt
dir C:\WINDOWS\msagent\ >> files.txt
dir C:\WINDOWS\Help\ /ah >> files.txt
dir C:\WINDOWS\AppPatch\ /ah >> files.txt
dir C:\WINDOWS\Web\Wallpaper\ /ah >> files.txt
dir C:\WINDOWS\repair\Backup\ /ah >> files.txt
dir C:\WINDOWS\Cursors\ /ah >> files.txt
dir C:\WINDOWS\Help\mail\ /ah >> files.txt
dir C:\WINDOWS\ServicePackFiles\i386\ /ah >> files.txt
dir C:\WINDOWS\Fonts\AdvUninstal\ /ah >> files.txt
dir C:\WINDOWS\java\ /ah >> files.txt
dir C:\WINDOWS\msagent\chars\ /ah >> files.txt
dir C:\WINDOWS\java\Packages\ /ah >> files.txt
dir C:\WINDOWS\msagent\Intl\ /ah >> files.txt
notepad files.txt


Save it to your desktop as ff.bat.

Close Notepad

Now, the ff.bat file on the desktop.

Wait for a Notepad window to open up.

Please paste it's contents into your next post.
:)
Could not find any process using this DLL C:\WINDOWS\repair\catip.dll Here is the output of the batch file: Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\msagent 10/23/2005 10:12 PM 376,619 sodrba.ini 10/22/2005 09:18 PM 376,450 sodrba.bak2 2 File(s) 753,069 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\msagent 09/01/2002 12:54 PM . 09/01/2002 12:54 PM .. 09/01/2002 01:00 PM Intl 06/23/2004 08:10 PM chars 08/04/2004 12:56 AM 39,936 mslwvtts.dll 08/04/2004 12:56 AM 24,064 agtintl.dll 08/03/2004 10:24 PM 18,432 agtctl15.tlb 08/04/2004 12:56 AM 256,512 agentsvr.exe 08/04/2004 12:56 AM 44,032 agentsr.dll 08/04/2004 12:56 AM 24,064 agentpsh.dll 08/04/2004 12:56 AM 49,152 agentmpx.dll 08/04/2004 12:56 AM 41,984 agentdp2.dll 08/04/2004 12:56 AM 214,016 agentctl.dll 08/04/2004 12:56 AM 24,064 agentanm.dll 04/22/2005 01:06 AM 57,344 agentdpv.dll 10/14/2005 09:41 PM 516,116 abrdos.dll 12 File(s) 1,309,716 bytes 4 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\Help 08/22/2002 10:50 PM 9,793 WLANCPA.GID 10/14/2005 10:24 PM 65,536 bdtac.ini 03/27/2004 10:12 PM 8,628 SECAUTH.GID 10/11/2005 09:37 PM 352,796 bdtac.bak2 10/13/2002 07:26 PM 9,793 windows.GID 07/10/2003 09:55 PM 12,910 RecoverNT 35.GID 6 File(s) 459,456 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\AppPatch 09/24/2005 02:25 PM 303 lrutnof.ini 10/10/2005 08:32 PM 303 taclld.ini 2 File(s) 606 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\Web\Wallpaper 09/28/2005 07:27 PM 303 splld.ini 1 File(s) 303 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\repair\Backup 04/23/2005 07:36 PM ServiceState 09/22/2005 08:43 PM 303 dmcsod.ini 10/01/2005 09:28 PM 303 pisod.ini 2 File(s) 606 bytes 1 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\Cursors 10/03/2005 09:14 PM 303 bvtun.ini 10/09/2005 05:21 AM 303 avajsod.ini 2 File(s) 606 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\Help\mail 09/30/2005 09:34 PM 303 evawsod.ini 1 File(s) 303 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\ServicePackFiles\i386 09/15/2005 10:03 PM 422,184 xafpxe.ini 09/06/2005 08:41 PM 178,662 xafpxe.bak1 09/15/2005 08:51 PM 421,737 xafpxe.bak2 09/13/2005 08:50 PM 303 ssvagv.ini 09/17/2005 10:39 AM 303 pxeavaj.ini 09/19/2005 07:03 PM 303 ccavrs.ini 10/05/2005 08:21 PM 303 ccaelo.ini 7 File(s) 1,023,795 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\Fonts\AdvUninstal 10/16/2005 10:17 AM 303 daofni.ini 1 File(s) 303 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\java 10/15/2005 11:12 AM 303 smavaj.ini 1 File(s) 303 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\msagent\chars 09/26/2005 02:55 PM 303 tenilitu.ini 10/06/2005 08:45 PM 303 sod.ini 2 File(s) 606 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\java\Packages 09/09/2005 08:24 PM 303 sabagv.ini 1 File(s) 303 bytes 0 Dir(s) 25,751,683,072 bytes free Volume in drive C is DSK2_VOL1 Volume Serial Number is 0000-0E72 Directory of C:\WINDOWS\msagent\Intl 09/07/2005 08:23 PM 303 nuniw.ini 09/10/2005 09:16 PM 303 cfmagv.ini 2 File(s) 606 bytes 0 Dir(s) 25,751,683,072 bytes free
Please print these instructions out for use in Safe Mode.

Download Killbox from here:

Killbox.zip

Unzip it, but don't run it yet.

Copy/paste the text in the Quote box below into Notepad, and save it on the desktop as "killme.txt"

C:\WINDOWS\Help\bdtac.ini
C:\WINDOWS\Help\bdtac.bak2
C:\WINDOWS\AppPatch\lrutnof.ini
C:\WINDOWS\AppPatch\taclld.ini
C:\WINDOWS\Web\Wallpaper\splld.ini
C:\WINDOWS\repair\Backup\dmcsod.ini
C:\WINDOWS\repair\Backup\pisod.ini
C:\WINDOWS\Cursors\bvtun.ini
C:\WINDOWS\Cursors\avajsod.ini
C:\WINDOWS\Help\mail\evawsod.ini
C:\WINDOWS\ServicePackFiles\i386\xafpxe.ini
C:\WINDOWS\ServicePackFiles\i386\xafpxe.bak1
C:\WINDOWS\ServicePackFiles\i386\xafpxe.bak2
C:\WINDOWS\ServicePackFiles\i386\ssvagv.ini
C:\WINDOWS\ServicePackFiles\i386\pxeavaj.ini
C:\WINDOWS\ServicePackFiles\i386\ccavrs.ini
C:\WINDOWS\ServicePackFiles\i386\ccaelo.ini
C:\WINDOWS\Fonts\AdvUninstal\daofni.ini
C:\WINDOWS\java\smavaj.ini
C:\WINDOWS\msagent\chars\tenilitu.ini
C:\WINDOWS\msagent\chars\sod.ini
C:\WINDOWS\java\Packages\sabagv.ini
C:\WINDOWS\msagent\Intl\nuniw.ini
C:\WINDOWS\msagent\Intl\cfmagv.ini


Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to extract the files
  • This will create a VundoFix folder on your desktop.
  • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
  • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
  • You will first be presented with a warning that should look like this

    VundoFix V2.15 by Atri
    By using VundoFix you agree that you are doing so at your own risk
    Press enter to continue….

  • At this point press enter one time.
  • Next you will see:

    Type in the filepath as instructed by the forum staff
    Then Press Enter:

  • At this point please type the following file path (make sure to enter it exactly as below!):
    • C:\WINDOWS\msagent\abrdos.dll
  • Press Enter to continue with the fix.
  • Next you will see:

    Please type in the second filepath as instructed by the forum staff
    Then Press Enter to continue with the fix.

  • At this point please type the following file path (make sure to enter it exactly as below!):C:\WINDOWS\msagent\sodrba.*
  • Press Enter to continue with the fix.
  • The fix will run then HijackThis will open, if it does not open automatically please open it manually.
  • In HijackThis, please place a check next to the following items and click FIX CHECKED:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm

    R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)

    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\msagent\abrdos.dll

    O20 - Winlogon Notify: abrdos - C:\WINDOWS\msagent\abrdos.dll

    O20 - Winlogon Notify: catdb - C:\WINDOWS\Help\catdb.dll (file missing)

    O20 - Winlogon Notify: dllcat - C:\WINDOWS\AppPatch\dllcat.dll (file missing)

    O20 - Winlogon Notify: dllps - C:\WINDOWS\Web\Wallpaper\dllps.dll (file missing)

    O20 - Winlogon Notify: dos - C:\WINDOWS\msagent\chars\dos.dll (file missing)

    O20 - Winlogon Notify: doscmd - C:\WINDOWS\repair\Backup\doscmd.dll (file missing)

    O20 - Winlogon Notify: dosip - C:\WINDOWS\repair\Backup\dosip.dll (file missing)

    O20 - Winlogon Notify: dosjava - C:\WINDOWS\Cursors\dosjava.dll (file missing)

    O20 - Winlogon Notify: doswave - C:\WINDOWS\Help\mail\doswave.dll (file missing)

    O20 - Winlogon Notify: expfax - C:\WINDOWS\ServicePackFiles\i386\expfax.dll (file missing)

    O20 - Winlogon Notify: fonturl - C:\WINDOWS\AppPatch\fonturl.dll (file missing)

    O20 - Winlogon Notify: infoad - C:\WINDOWS\Fonts\AdvUninstal\infoad.dll (file missing)

    O20 - Winlogon Notify: javaexp - C:\WINDOWS\ServicePackFiles\i386\javaexp.dll (file missing)

    O20 - Winlogon Notify: javams - C:\WINDOWS\java\javams.dll (file missing)

    O20 - Winlogon Notify: mlllm - mlllm.dll (file missing)

    O20 - Winlogon Notify: nutvb - C:\WINDOWS\Cursors\nutvb.dll (file missing)

    O20 - Winlogon Notify: oleacc - C:\WINDOWS\ServicePackFiles\i386\oleacc.dll (file missing)

    O20 - Winlogon Notify: srvacc - C:\WINDOWS\ServicePackFiles\i386\srvacc.dll (file missing)

    O20 - Winlogon Notify: utilinet - C:\WINDOWS\msagent\chars\utilinet.dll (file missing)

    O20 - Winlogon Notify: vgabas - C:\WINDOWS\java\Packages\vgabas.dll (file missing)

    O20 - Winlogon Notify: vgamfc - C:\WINDOWS\msagent\Intl\vgamfc.dll (file missing)

    O20 - Winlogon Notify: vgavss - C:\WINDOWS\ServicePackFiles\i386\vgavss.dll (file missing)

    O20 - Winlogon Notify: winun - C:\WINDOWS\msagent\Intl\winun.dll (file missing)
  • After you have fixed these items, close Hijackthis.
  • Press enter to exit the program
  • On the desktop, open the "killme.txt" file with Notepad.
  • copy the all file names in the "killme.txt" to the clipboard by highlighting them and pressing C (hold the key down, then press C)
  • Close Notepad.
  • Double click on Killbox.exe and then check the Delete on reboot button.
  • In Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".
  • Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.
  • Once your machine reboots please continue with the instructions below.
Copy a new HijackThis log and the vundofix.txt file from the vundofix folder into this topic.
Here are the new logs:

Logfile of HijackThis v1.99.1
Scan saved at 11:23:41 PM, on 10/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\SuperFlexible\ExtremeSyncService.exe
C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\HP Web Jetadmin\hpwebjetd.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Hmonitor\hmonitor.exe
C:\WINDOWS\SYSTEM\atiptaxx.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\WINDOWS\Logi_MwX.Exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Program Files\StarOffice7\program\soffice.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Documents and Settings\joe\Desktop\virus programs\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adb…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adb…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bellsouth.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe
O4 - HKLM\..\Run: [ATIPTA] C:\WINDOWS\SYSTEM\atiptaxx.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: StarOffice 8.lnk = C:\Program Files\Sun\StarOffice 8\program\quickstart.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Global Startup: StarOffice 7.lnk = C:\Program Files\StarOffice7\program\quickstart.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\spool\drivers\w32x86\3\E_SRCV02.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Open PDF in Word - res://C:\Program Files\ScanSoft\OmniPagePro14.0\PdfCnv\IEShellExt.dll /100
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fastaccess.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121826124081
O16 - DPF: {7876E4A5-78B7-4020-B08F-C960A1ED54C9} (WebWatch Class) - http://tlcwatch1.homeip.net/WinWebPush.cab
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - http://transfers.one.microsoft.com/FTM/Tra…ransferCtrl.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://camiwe.brett-robinson.com/activex/AxisCamControl.cab
O20 - Winlogon Notify: abrdos - C:\WINDOWS\msagent\abrdos.dll (file missing)
O20 - Winlogon Notify: catdb - C:\WINDOWS\Help\catdb.dll (file missing)
O20 - Winlogon Notify: dllcat - C:\WINDOWS\AppPatch\dllcat.dll (file missing)
O20 - Winlogon Notify: dllps - C:\WINDOWS\Web\Wallpaper\dllps.dll (file missing)
O20 - Winlogon Notify: dos - C:\WINDOWS\msagent\chars\dos.dll (file missing)
O20 - Winlogon Notify: doscmd - C:\WINDOWS\repair\Backup\doscmd.dll (file missing)
O20 - Winlogon Notify: dosip - C:\WINDOWS\repair\Backup\dosip.dll (file missing)
O20 - Winlogon Notify: dosjava - C:\WINDOWS\Cursors\dosjava.dll (file missing)
O20 - Winlogon Notify: doswave - C:\WINDOWS\Help\mail\doswave.dll (file missing)
O20 - Winlogon Notify: expfax - C:\WINDOWS\ServicePackFiles\i386\expfax.dll (file missing)
O20 - Winlogon Notify: fonturl - C:\WINDOWS\AppPatch\fonturl.dll (file missing)
O20 - Winlogon Notify: infoad - C:\WINDOWS\Fonts\AdvUninstal\infoad.dll (file missing)
O20 - Winlogon Notify: javaexp - C:\WINDOWS\ServicePackFiles\i386\javaexp.dll (file missing)
O20 - Winlogon Notify: javams - C:\WINDOWS\java\javams.dll (file missing)
O20 - Winlogon Notify: mlllm - mlllm.dll (file missing)
O20 - Winlogon Notify: nutvb - C:\WINDOWS\Cursors\nutvb.dll (file missing)
O20 - Winlogon Notify: oleacc - C:\WINDOWS\ServicePackFiles\i386\oleacc.dll (file missing)
O20 - Winlogon Notify: srvacc - C:\WINDOWS\ServicePackFiles\i386\srvacc.dll (file missing)
O20 - Winlogon Notify: utilinet - C:\WINDOWS\msagent\chars\utilinet.dll (file missing)
O20 - Winlogon Notify: vgabas - C:\WINDOWS\java\Packages\vgabas.dll (file missing)
O20 - Winlogon Notify: vgamfc - C:\WINDOWS\msagent\Intl\vgamfc.dll (file missing)
O20 - Winlogon Notify: vgavss - C:\WINDOWS\ServicePackFiles\i386\vgavss.dll (file missing)
O20 - Winlogon Notify: winun - C:\WINDOWS\msagent\Intl\winun.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ExtremeSync Service (ExtremeSync_Service) - Unknown owner - C:\Program Files\SuperFlexible\ExtremeSyncService.exe
O23 - Service: HP Web Jetadmin (HPWebJetadmin) - Unknown owner - C:\Program Files\HP Web Jetadmin\hpwebjetd.exe" -k runservice (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: Network Time Protocol Daemon (NTP) - Unknown owner - C:\Program Files\NTP\bin\ntpd.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe



VundoFix V2.15 by Atri
————————————————————————————–

Listing files contained in the vundofix folder.
————————————————————————————–

ReadMe.txt
killvundo.bat
process.exe
vundo.reg
vundofix.txt

————————————————————————————–

Filepaths entered
————————————————————————————–

The filepath entered was C:\WINDOWS\msagent\abrdos.dll

The second filepath entered was C:\WINDOWS\msagent\sodrba.*

————————————————————————————–

Log from Process
————————————————————————————–


Killing PID 212 'smss.exe'

Killing PID 1540 'explorer.exe'


Killing PID 332 'winlogon.exe'
Killing PID 332 'winlogon.exe'
Killing PID 332 'winlogon.exe'
Killing PID 332 'winlogon.exe'
Killing PID 332 'winlogon.exe'
————————————————————————————–

C:\WINDOWS\msagent\abrdos.dll Deleted sucessfully.
C:\WINDOWS\msagent\sodrba.* Deleted sucessfully.

Fixing Registry
————————————————————————————–
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)

O20 - Winlogon Notify: abrdos - C:\WINDOWS\msagent\abrdos.dll (file missing)

O20 - Winlogon Notify: catdb - C:\WINDOWS\Help\catdb.dll (file missing)

O20 - Winlogon Notify: dllcat - C:\WINDOWS\AppPatch\dllcat.dll (file missing)

O20 - Winlogon Notify: dllps - C:\WINDOWS\Web\Wallpaper\dllps.dll (file missing)

O20 - Winlogon Notify: dos - C:\WINDOWS\msagent\chars\dos.dll (file missing)

O20 - Winlogon Notify: doscmd - C:\WINDOWS\repair\Backup\doscmd.dll (file missing)

O20 - Winlogon Notify: dosip - C:\WINDOWS\repair\Backup\dosip.dll (file missing)

O20 - Winlogon Notify: dosjava - C:\WINDOWS\Cursors\dosjava.dll (file missing)

O20 - Winlogon Notify: doswave - C:\WINDOWS\Help\mail\doswave.dll (file missing)

O20 - Winlogon Notify: expfax - C:\WINDOWS\ServicePackFiles\i386\expfax.dll (file missing)

O20 - Winlogon Notify: fonturl - C:\WINDOWS\AppPatch\fonturl.dll (file missing)

O20 - Winlogon Notify: infoad - C:\WINDOWS\Fonts\AdvUninstal\infoad.dll (file missing)

O20 - Winlogon Notify: javaexp - C:\WINDOWS\ServicePackFiles\i386\javaexp.dll (file missing)

O20 - Winlogon Notify: javams - C:\WINDOWS\java\javams.dll (file missing)

O20 - Winlogon Notify: mlllm - mlllm.dll (file missing)

O20 - Winlogon Notify: nutvb - C:\WINDOWS\Cursors\nutvb.dll (file missing)

O20 - Winlogon Notify: oleacc - C:\WINDOWS\ServicePackFiles\i386\oleacc.dll (file missing)

O20 - Winlogon Notify: srvacc - C:\WINDOWS\ServicePackFiles\i386\srvacc.dll (file missing)

O20 - Winlogon Notify: utilinet - C:\WINDOWS\msagent\chars\utilinet.dll (file missing)

O20 - Winlogon Notify: vgabas - C:\WINDOWS\java\Packages\vgabas.dll (file missing)

O20 - Winlogon Notify: vgamfc - C:\WINDOWS\msagent\Intl\vgamfc.dll (file missing)

O20 - Winlogon Notify: vgavss - C:\WINDOWS\ServicePackFiles\i386\vgavss.dll (file missing)

O20 - Winlogon Notify: winun - C:\WINDOWS\msagent\Intl\winun.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot, and you're "good to go"

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI