Thanks Micah_6:8
Look2Me-Destroyer would not close and re-open. Even the Start>Run and type in sc start schedule did not restart it. So I borrowed a page from your book and downloaded it again and saved it as Tuesday.exe
So I have the Look2Me-Destroyer.txt followed by another HijackThis log
Look2Me-Destroyer V1.0.12
Scanning for infected files…..
Scan started at 6/2/2006 7:56:07 PM
Infected! C:\WINDOWS\system32\q6rqlg9516.dll
Infected! C:\WINDOWS\system32\sJfrdm.dll
Infected! C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012948.dll
Infected! C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012956.dll
Infected! C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012960.dll
Infected! C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012963.dll
Infected! C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012971.dll
Infected! C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013969.dll
Infected! C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013973.dll
Infected! C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013976.dll
Infected! C:\WINDOWS\system32\acrsvc.dll
Infected! C:\WINDOWS\system32\alferror.dll
Infected! C:\WINDOWS\system32\axpmgr.dll
Infected! C:\WINDOWS\system32\donet.dll
Infected! C:\WINDOWS\system32\dyskmon.dll
Infected! C:\WINDOWS\system32\en8ql1l51.dll
Infected! C:\WINDOWS\system32\fOultrep.dll
Infected! C:\WINDOWS\system32\gp2ql3f51.dll
Infected! C:\WINDOWS\system32\h60q0gd5e60.dll
Infected! C:\WINDOWS\system32\hr6u05j9e.dll
Infected! C:\WINDOWS\system32\hrru0599e.dll
Infected! C:\WINDOWS\system32\ir24l5fq1.dll
Infected! C:\WINDOWS\system32\j60slgd7160.dll
Infected! C:\WINDOWS\system32\kvdlv1.dll
Infected! C:\WINDOWS\system32\l0l60a3sed.dll
Infected! C:\WINDOWS\system32\l4n40e5qeh.dll
Infected! C:\WINDOWS\system32\lv2009fme.dll
Infected! C:\WINDOWS\system32\lv4o09h3e.dll
Infected! C:\WINDOWS\system32\lvj4091qe.dll
Infected! C:\WINDOWS\system32\lvrq0995e.dll
Infected! C:\WINDOWS\system32\mvn0l95m1.dll
Infected! C:\WINDOWS\system32\mvrml9911.dll
Infected! C:\WINDOWS\system32\mzvidctl.dll
Infected! C:\WINDOWS\system32\r48s0el7ehq.dll
Infected! C:\WINDOWS\system32\rhcdll.dll
Infected! C:\WINDOWS\system32\sJfrdm.dll
Infected! C:\WINDOWS\system32\uzrvoica.dll
Infected! C:\WINDOWS\System32\guard.tmp
Attempting to delete infected files…
Attempting to delete: C:\WINDOWS\system32\sJfrdm.dll
C:\WINDOWS\system32\sJfrdm.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012948.dll
C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012948.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012956.dll
C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012956.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012960.dll
C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012960.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012963.dll
C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012963.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012971.dll
C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0012971.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013969.dll
C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013969.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013973.dll
C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013973.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013976.dll
C:\System Volume Information\_restore{A7D3969A-17E0-4085-880C-313C2F2A765D}\RP17\A0013976.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\acrsvc.dll
C:\WINDOWS\system32\acrsvc.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\alferror.dll
C:\WINDOWS\system32\alferror.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\axpmgr.dll
C:\WINDOWS\system32\axpmgr.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\donet.dll
C:\WINDOWS\system32\donet.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\dyskmon.dll
C:\WINDOWS\system32\dyskmon.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\en8ql1l51.dll
C:\WINDOWS\system32\en8ql1l51.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\fOultrep.dll
C:\WINDOWS\system32\fOultrep.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\gp2ql3f51.dll
C:\WINDOWS\system32\gp2ql3f51.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\h60q0gd5e60.dll
C:\WINDOWS\system32\h60q0gd5e60.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\hr6u05j9e.dll
C:\WINDOWS\system32\hr6u05j9e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\hrru0599e.dll
C:\WINDOWS\system32\hrru0599e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\ir24l5fq1.dll
C:\WINDOWS\system32\ir24l5fq1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\j60slgd7160.dll
C:\WINDOWS\system32\j60slgd7160.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\kvdlv1.dll
C:\WINDOWS\system32\kvdlv1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\l0l60a3sed.dll
C:\WINDOWS\system32\l0l60a3sed.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\l4n40e5qeh.dll
C:\WINDOWS\system32\l4n40e5qeh.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\lv2009fme.dll
C:\WINDOWS\system32\lv2009fme.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\lv4o09h3e.dll
C:\WINDOWS\system32\lv4o09h3e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\lvj4091qe.dll
C:\WINDOWS\system32\lvj4091qe.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\lvrq0995e.dll
C:\WINDOWS\system32\lvrq0995e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mvn0l95m1.dll
C:\WINDOWS\system32\mvn0l95m1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mvrml9911.dll
C:\WINDOWS\system32\mvrml9911.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mzvidctl.dll
C:\WINDOWS\system32\mzvidctl.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\r48s0el7ehq.dll
C:\WINDOWS\system32\r48s0el7ehq.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\rhcdll.dll
C:\WINDOWS\system32\rhcdll.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\sJfrdm.dll
C:\WINDOWS\system32\sJfrdm.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\uzrvoica.dll
C:\WINDOWS\system32\uzrvoica.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\System32\guard.tmp
C:\WINDOWS\System32\guard.tmp Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnceEx
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellCompatibility
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5C636E6E-1EA7-4728-B7B9-3C4D85990C48}"
HKCR\Clsid\{5C636E6E-1EA7-4728-B7B9-3C4D85990C48}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A9D3A63F-061C-47D7-8549-C6934A767068}"
HKCR\Clsid\{A9D3A63F-061C-47D7-8549-C6934A767068}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{489919E2-9E61-43C5-8FA6-137871DEBAFC}"
HKCR\Clsid\{489919E2-9E61-43C5-8FA6-137871DEBAFC}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5CAA5D53-98F6-404A-A2E5-81E0FEDC07E7}"
HKCR\Clsid\{5CAA5D53-98F6-404A-A2E5-81E0FEDC07E7}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{4DF55A78-AD08-4255-AC5A-0623F1DB5A33}"
HKCR\Clsid\{4DF55A78-AD08-4255-AC5A-0623F1DB5A33}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5ED71346-D822-4DEA-A4FA-7B5759256EBE}"
HKCR\Clsid\{5ED71346-D822-4DEA-A4FA-7B5759256EBE}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{C310E2B3-F520-4922-AEBB-0C9900D0E3D8}"
HKCR\Clsid\{C310E2B3-F520-4922-AEBB-0C9900D0E3D8}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E35DBF3D-9664-4B13-B610-621D224C2D58}"
HKCR\Clsid\{E35DBF3D-9664-4B13-B610-621D224C2D58}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{9BA52B8F-3376-4A3A-9E93-2E03270E40DD}"
HKCR\Clsid\{9BA52B8F-3376-4A3A-9E93-2E03270E40DD}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{23618C8D-05C8-467A-BF7C-9C2815A5C628}"
HKCR\Clsid\{23618C8D-05C8-467A-BF7C-9C2815A5C628}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AC444F57-86BB-4A14-B76C-DC99F2617A5A}"
HKCR\Clsid\{AC444F57-86BB-4A14-B76C-DC99F2617A5A}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
Logfile of HijackThis v1.99.1
Scan saved at 8:03:14 PM, on 6/2/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\smss.exe
C:\WINDOWS\TG9yaXMgSiBNYXRoZW55\command.exe
C:\WINDOWS\System32\libsys32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\yejjfyf.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\yejjfyfA.exe
C:\WINDOWS\ms075613-187714.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\defender25.exe
C:\WINDOWS\system32\owinnqez.exe
C:\Program Files\Common Files\svchostsys\svchostsys.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Loris\My Documents\HijackThis\Friday.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\escny.exe
F2 - REG:system.ini: UserInit=userinit.exe,oniqjxa.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft System Checkup] libsys32.exe
O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe
O4 - HKLM\..\Run: [keyboard] C:\\keyboard25.exe
O4 - HKLM\..\Run: [newname] C:\\newname25.exe
O4 - HKLM\..\Run: [yejjfyfA] C:\WINDOWS\yejjfyfA.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [ms075613-187714] C:\WINDOWS\ms075613-187714.exe
O4 - HKLM\..\Run: [w0989c85.dll] RUNDLL32.EXE w0989c85.dll,I2 0010750700989c85
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program Files\webHancer\Programs\whsurvey.exe
O4 - HKLM\..\Run: [defender] C:\\defender25.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\owinnqez.exe GID003
O4 - HKLM\..\RunServices: [Microsoft System Checkup] libsys32.exe
O4 - HKCU\..\Run: [sys_up1] C:\Program Files\Common Files\svchostsys\svchostsys.exe
O4 - Startup: Desktop Application Director.lnk = C:\OFFICE\SHARED\WPC20\dtwin20.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\owinnqez.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1147623380437
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1147623298920
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O23 - Service: aol software (Aol Software) - Unknown owner - C:\WINDOWS\smss.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TG9yaXMgSiBNYXRoZW55\command.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NT login service (ntlogin32) - Unknown owner - C:\WINDOWS\System32\libsys32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\yejjfyf.exe