Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93101 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Hijack Log


  • This topic is locked This topic is locked
29 replies to this topic

#1 kshmom

kshmom

    Authentic Member

  • Authentic Member
  • PipPip
  • 25 posts

Posted 24 June 2006 - 02:03 PM

My computer freezes, my programs stop responding, I can't access microsoft for downloads, and my winantivirus 2006 can't permanently delete the malware or trojans it finds. I have spyware blaster, ccleaner, and winantivirus installed and I am afraid that I have messed up my computer worse than it was to start with. I appreciate any help or advice you can give me. Here is my Hijack log. Logfile of HijackThis v1.99.1 Scan saved at 2:58:11 PM, on 6/24/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\fxssvc.exe C:\Documents and Settings\Aarons\Desktop\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00005.exe" O4 - HKLM\..\Run: [SysTray] c:\Program Files\wkggdmyf.exe O4 - HKLM\..\Run: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe O4 - HKLM\..\Run: [rpcc] rpcc.exe O4 - HKLM\..\Run: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O4 - HKLM\..\Run: [df197d52.exe] C:\WINDOWS\System32\df197d52.exe O4 - HKLM\..\RunServices: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe O4 - HKLM\..\RunServices: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O21 - SSODL: LtDXCV - {D09360C1-7A39-CA6B-F9BC-E052B1DFB332} - C:\WINDOWS\System32\bhpu.dll (file missing) O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file) O23 - Service: Microsoft Networks DN (msndn) - Unknown owner - C:\WINDOWS\msndn.exe (file missing)

    Advertisements

Register to Remove


#2 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 26 June 2006 - 03:21 PM

Hello and welcome to the forums.

I see you have HijackThis located here:
C:\Documents and Settings\Aarons\Desktop\HijackThis.exe

Please rename HijackThis.exe to HJT.exe
by Right Clicking on HijackThis.exe and select Rename.

Restart the computer

Scan again with HJT and copy/paste" a new log file into this thread using the
Posted Image Button below to reply. Thanks.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#3 kshmom

kshmom

    Authentic Member

  • Authentic Member
  • PipPip
  • 25 posts

Posted 27 June 2006 - 06:37 PM

Hello. Thanks in advance for any help you can give me. I am totally lost. I tried to fix stuff myself and now think I am worse off. Here is the new HJT log Logfile of HijackThis v1.99.1 Scan saved at 7:29:10 PM, on 6/27/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\explorer.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\fxssvc.exe C:\Documents and Settings\Aarons\Desktop\HJT.exe.exe C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00007.exe" O2 - BHO: (no name) - {5D583DEE-98EC-448A-B56B-24A7DCF97BCB} - C:\WINDOWS\System32\vtsqq.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O4 - HKLM\..\Run: [SysTray] c:\Program Files\wkggdmyf.exe O4 - HKLM\..\Run: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe O4 - HKLM\..\Run: [rpcc] rpcc.exe O4 - HKLM\..\Run: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O4 - HKLM\..\Run: [df197d52.exe] C:\WINDOWS\System32\df197d52.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\RunServices: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe O4 - HKLM\..\RunServices: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll O20 - Winlogon Notify: pmnnk - pmnnk.dll (file missing) O20 - Winlogon Notify: se500mdm - C:\WINDOWS\SYSTEM32\se500mdm.dll O20 - Winlogon Notify: vtsqq - C:\WINDOWS\System32\vtsqq.dll O21 - SSODL: LtDXCV - {D09360C1-7A39-CA6B-F9BC-E052B1DFB332} - C:\WINDOWS\System32\bhpu.dll (file missing) O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file) O23 - Service: Microsoft Networks DN (msndn) - Unknown owner - C:\WINDOWS\msndn.exe (file missing)

#4 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 27 June 2006 - 06:43 PM

Please do not delete anything unless instructed to.

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Delete ".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.


Download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES.
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on. Please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.


While still in Safe Mode:

Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED PROFILE USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#5 kshmom

kshmom

    Authentic Member

  • Authentic Member
  • PipPip
  • 25 posts

Posted 28 June 2006 - 04:52 PM

Hello-Sorry for the delay. When I reset my internet options to default it went back to dial up so I had to reinstall the cable modem. I rcvd the error msg "The file C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83EY4C588624}\RPO\A0001017.exe\drz.exe cannot be removed because it is embedded in the archive C:Same file name Do you want to remove the whole archive? I checked no since I didn't know what else to do. Here is my Ewido log --------------------------------------------------------- ewido anti-spyware - Scan Report --------------------------------------------------------- + Created at: 11:19:11 AM 6/28/2006 + Scan result: C:\Program Files\MSN\kyhehecox..exe -> Adware.Agent : Cleaned. C:\WINDOWS\Тasks\mmc.exe -> Adware.ClickSpring : Cleaned. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned. HKU\.DEFAULT\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned. HKU\S-1-5-18\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0033618.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0034617.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0035618.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0036616.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0037618.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0038618.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0039618.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0039625.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0039631.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0040630.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0040638.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0040642.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0040646.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0041645.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0042645.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0043645.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0045642.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0045654.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0045661.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0046660.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0047659.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0048659.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0049659.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0050659.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0051659.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0051665.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0052665.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0052672.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0053672.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0054674.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0054679.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0054683.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0054687.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0054693.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0055690.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0056692.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0057692.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0058692.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0058703.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0059703.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0059709.dll -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0059715.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0060714.DLL -> Adware.Look2Me : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP8\A0061714.DLL -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\MGC71DEU.DLL -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\OSESVR32.DLL -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\c400ledm1h0a.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\d8j0li1m18.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\dn8001lme.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\e020lafm1d2a.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\en08l1du1.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\en6ml1j11.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\enpsl1771.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\fpns0357e.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\g8joli1318.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\gp2sl3f71.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\gpr8l39u1.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\h0j40a1qed.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\hrj8051ue.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\ir4ml5h11.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\ir6ql5j51.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\irrol5931.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\k0080adued080.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\k0800almedqa0.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\k2800clmefqa0.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\kt0sl7d71.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\kt2sl7f71.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\ktn4l75q1.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\l6j8lg1u16.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\l6n40g5qe6.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\l8r00i9me8.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\l8r0li9m18.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\lvnm0951e.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\lvp8097ue.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\mv26l9fs1.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\mvlsl9371.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\mvp8l97u1.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\o8480ihue8480.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\p6p6lg7s16.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\p86slij718o.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\q2680cjuefo80.dll -> Adware.Look2Me : Cleaned. C:\WINDOWS\SYSTEM32\t88u0il9e8q.dll -> Adware.Look2Me : Cleaned. C:\Documents and Settings\Aarons\Application Data\Mіcrosoft\nοtepad.exe -> Adware.PurityScan : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003394.dll -> Adware.TargetServer : Cleaned. C:\Documents and Settings\Aarons\dotrm.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001001.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001017.exe/rmz.dll -> Adware.Virtumonde : Error during cleaning. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003017.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003018.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003172.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003173.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003176.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003177.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003181.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003182.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003186.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003187.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003416.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003418.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003433.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003435.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0072764.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0089857.dll -> Adware.Virtumonde : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0013478.dll -> Adware.Virtumonde : Cleaned. C:\WINDOWS\SYSTEM32\awvvv.dll -> Adware.Virtumonde : Cleaned. C:\WINDOWS\SYSTEM32\ddayv.dll -> Adware.Virtumonde : Cleaned. C:\WINDOWS\SYSTEM32\vtsqn.dll -> Adware.Virtumonde : Cleaned. HKLM\SOFTWARE\Classes\CLSID\{2178F3FB-2560-458f-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003193.cpl -> Backdoor.Flood : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001060.exe -> Backdoor.Hupigon.hk : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001047.sys -> Backdoor.Sliv.a : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003195.cpl -> Backdoor.Sliv.a : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001017.exe/drz.exe -> Downloader.Adload.ap : Error during cleaning. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0088831.dll -> Downloader.Agent.anm : Cleaned. C:\Documents and Settings\Aarons\Local Settings\Temporary Internet Files\Content.IE5\WTAB8TYV\SysProtectScannerInstall[1].exe -> Downloader.Small : Cleaned. C:\Program Files\Common Files\svchostsys\svchostupdate.exe -> Downloader.Small : Cleaned. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OT6N85YN\runfile[1].exe -> Hijacker.Small.cc : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0089852.dll -> Logger.Goldun.kc : Cleaned. C:\WINDOWS\SYSTEM32\se500mdmd.sys -> Logger.Goldun.kc : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003421.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003441.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned. C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N822M1605NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001057.exe -> Not-A-Virus.PSWTool.Win32.PassView.162 : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0088830.exe -> Proxy.Agent.km : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0088833.exe -> Proxy.Agent.km : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0088834.exe -> Proxy.Agent.km : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0088832.exe -> Proxy.Dlena.d : Cleaned. :mozilla.26:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.27:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.310:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.126:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.142:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.170:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.171:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.172:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.173:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.174:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.175:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.176:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.226:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.227:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.228:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.273:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.274:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.286:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.304:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.305:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.306:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.307:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.43:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.234:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.268:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.270:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.311:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.210:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.211:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.28:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.29:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.30:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.31:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.6:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.7:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.8:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.96:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.97:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.9:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.308:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.309:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.178:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.179:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.50:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.51:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.52:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.53:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.19:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies-1.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.20:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies-1.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.21:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies-1.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.281:C:\Documents and Settings\Aarons\Application Data\Mozilla\Firefox\Profiles\cypx0hth.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00008.dll -> Trojan.Sinowal.aa : Cleaned. [640] C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00008.dll -> Trojan.Sinowal.aa : Error during cleaning. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ENIDAH4R\qizblv[1].txt -> Trojan.Small : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP11\A0074781.exe -> Trojan.Small : Cleaned. C:\knoy.exe -> Trojan.Small : Cleaned. C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts -> Worm.Anker.n : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003189.cpl -> Worm.Randon.a : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0001053.sys -> Worm.Randon.am : Cleaned. C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP0\A0003188.cpl -> Worm.Randon.am : Cleaned. ::Report end and my HJT log Logfile of HijackThis v1.99.1 Scan saved at 5:38:22 PM, on 6/28/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\df197d52.exe C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\ewido.exe C:\WINDOWS\System32\rundll32.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Program Files\WinAntiVirus Pro 2006\winav.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe C:\Documents and Settings\Aarons\Desktop\HJT.exe.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html R3 - URLSearchHook: (no name) - {AA713A75-F290-F849-9C4F-FFBAAF3C18C2} - C:\WINDOWS\System32\qtvyyhhq.dll R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00007.exe" O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\System32\vtsqn.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: (no name) - {AA713A75-F290-F849-9C4F-FFBAAF3C18C2} - C:\WINDOWS\System32\qtvyyhhq.dll O2 - BHO: (no name) - {BFE5E531-60B5-4540-9C05-674384FF6F78} - C:\WINDOWS\System32\vtsqq.dll O4 - HKLM\..\Run: [SysTray] c:\Program Files\wkggdmyf.exe O4 - HKLM\..\Run: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe O4 - HKLM\..\Run: [rpcc] rpcc.exe O4 - HKLM\..\Run: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O4 - HKLM\..\Run: [df197d52.exe] C:\WINDOWS\System32\df197d52.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [!ewido] "C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [xmplib] rundll32.exe C:\WINDOWS\System32\xmplib.dll,start O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [newname] C:\\nwnm.exe O4 - HKLM\..\Run: [mswap] rundll32.exe C:\WINDOWS\System32\mswap.dll,start O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [Microsoft ® Windows Update Manager Tool] C:\WINDOWS\update\updmangr.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [keyboard] C:\\kybrd.exe O4 - HKLM\..\Run: [jjhgrn] C:\WINDOWS\System32\krdorp.exe reg_run O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [fstsvc] rundll32.exe C:\WINDOWS\System32\fstsvc.dll,start O4 - HKLM\..\Run: [defender] C:\\dfndr.exe O4 - HKLM\..\Run: [ciennooA] C:\WINDOWS\ciennooA.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\RunServices: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe O4 - HKLM\..\RunServices: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O4 - HKCU\..\Run: [Zugbequa] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\APPLIC~1\WNSXS~1\RNDLL3~1.EXE O4 - HKCU\..\Run: [Woezmfms] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\APPLIC~1\WNSXS~1\RNDLL3~1.EXE O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe O4 - HKCU\..\Run: [sys_up1] C:\Program Files\Common Files\svchostsys\svchostsys.exe O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - HKCU\..\Run: [ggois] C:\WINDOWS\System32\krdorp.exe reg_run O4 - HKCU\..\Run: [df197d52.exe] C:\Documents and Settings\Aarons\Local Settings\Application Data\df197d52.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O20 - AppInit_DLLs: C:\WINDOWS\System32\wuauboot.dll O20 - Winlogon Notify: pmnnk - pmnnk.dll (file missing) O20 - Winlogon Notify: se500mdm - se500mdm.dll (file missing) O20 - Winlogon Notify: vtsqq - C:\WINDOWS\System32\vtsqq.dll O21 - SSODL: LtDXCV - {D09360C1-7A39-CA6B-F9BC-E052B1DFB332} - C:\WINDOWS\System32\bhpu.dll (file missing) O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file) O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe O23 - Service: Microsoft Networks DN (msndn) - Unknown owner - C:\WINDOWS\msndn.exe (file missing)

#6 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 28 June 2006 - 04:57 PM

Don't worry about the C:\System Volume Information\_restore right now. We'll get to that. You still have a few infections.

Please download Look2Me-Destroyer.exe to your desktop.

Close all windows before continuing.
Double-click Look2Me-Destroyer.exe to run it.
Put a check next to Run this program as a task.

You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
Once it's done scanning, click the Remove L2M button.

You will receive a Done Scanning message, click OK.
When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
Your computer will then shutdown.

Turn your computer back on.
Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive...ib/MSWINSCK.OCX[/code]

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#7 kshmom

kshmom

    Authentic Member

  • Authentic Member
  • PipPip
  • 25 posts

Posted 28 June 2006 - 10:03 PM

Hello- Here is the Look2ME.txt Look2Me-Destroyer V1.0.12 Scanning for infected files..... Scan started at 6/28/2006 10:53:04 PM Attempting to delete infected files... Making registry repairs. Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{FEFC11C3-6CDC-4BB7-A121-E6E8115293C2}" HKCR\Clsid\{FEFC11C3-6CDC-4BB7-A121-E6E8115293C2} Restoring Windows certificates. Replaced hosts file with default windows hosts file Restoring SeDebugPrivilege for Administrators - Succeeded Here is my HJT log Logfile of HijackThis v1.99.1 Scan saved at 10:57:47 PM, on 6/28/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\explorer.exe C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\fxssvc.exe C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\ewido.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Aarons\Desktop\HJT.exe.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html R3 - URLSearchHook: (no name) - {AA713A75-F290-F849-9C4F-FFBAAF3C18C2} - C:\WINDOWS\System32\qtvyyhhq.dll R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00007.exe" O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\System32\vtsqn.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: (no name) - {89975D62-9E88-4F81-A43F-7F36136E531C} - C:\WINDOWS\System32\vtsqq.dll O2 - BHO: (no name) - {AA713A75-F290-F849-9C4F-FFBAAF3C18C2} - C:\WINDOWS\System32\qtvyyhhq.dll O4 - HKLM\..\Run: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe O4 - HKLM\..\Run: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O4 - HKLM\..\Run: [xmplib] rundll32.exe C:\WINDOWS\System32\xmplib.dll,start O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe O4 - HKLM\..\Run: [SysTray] c:\Program Files\wkggdmyf.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [rpcc] rpcc.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [newname] C:\\nwnm.exe O4 - HKLM\..\Run: [mswap] rundll32.exe C:\WINDOWS\System32\mswap.dll,start O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [Microsoft ® Windows Update Manager Tool] C:\WINDOWS\update\updmangr.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [keyboard] C:\\kybrd.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [jjhgrn] C:\WINDOWS\System32\krdorp.exe reg_run O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [fstsvc] rundll32.exe C:\WINDOWS\System32\fstsvc.dll,start O4 - HKLM\..\Run: [df197d52.exe] C:\WINDOWS\System32\df197d52.exe O4 - HKLM\..\Run: [defender] C:\\dfndr.exe O4 - HKLM\..\Run: [ciennooA] C:\WINDOWS\ciennooA.exe O4 - HKLM\..\Run: [!ewido] "C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\RunServices: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe O4 - HKLM\..\RunServices: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O4 - HKCU\..\Run: [Zugbequa] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\APPLIC~1\WNSXS~1\RNDLL3~1.EXE O4 - HKCU\..\Run: [Woezmfms] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\APPLIC~1\WNSXS~1\RNDLL3~1.EXE O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe O4 - HKCU\..\Run: [sys_up1] C:\Program Files\Common Files\svchostsys\svchostsys.exe O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - HKCU\..\Run: [ggois] C:\WINDOWS\System32\krdorp.exe reg_run O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O20 - AppInit_DLLs: C:\WINDOWS\System32\wuauboot.dll O20 - Winlogon Notify: pmnnk - pmnnk.dll (file missing) O20 - Winlogon Notify: se500mdm - se500mdm.dll (file missing) O20 - Winlogon Notify: vtsqq - C:\WINDOWS\System32\vtsqq.dll O21 - SSODL: LtDXCV - {D09360C1-7A39-CA6B-F9BC-E052B1DFB332} - C:\WINDOWS\System32\bhpu.dll (file missing) O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file) O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe O23 - Service: Microsoft Networks DN (msndn) - Unknown owner - C:\WINDOWS\msndn.exe (file missing) O23 - Service: Windows Update Manager Tool (UpdateManagerTool) - Unknown owner - C:\WINDOWS\update\updmangr.exe (file missing)

#8 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 29 June 2006 - 05:19 AM

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Start>run and paste the following lines, 1 at a time, hitting enter after each.

sc stop msndn
sc delete msndn
sc stop UpdateManagerTool
sc delete UpdateManagerTool



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html

R3 - URLSearchHook: (no name) - {AA713A75-F290-F849-9C4F-FFBAAF3C18C2} - C:\WINDOWS\System32\qtvyyhhq.dll

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00007.exe"

O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - C:\WINDOWS\System32\vtsqn.dll (file missing)

O2 - BHO: (no name) - {89975D62-9E88-4F81-A43F-7F36136E531C} - C:\WINDOWS\System32\vtsqq.dll

O2 - BHO: (no name) - {AA713A75-F290-F849-9C4F-FFBAAF3C18C2} - C:\WINDOWS\System32\qtvyyhhq.dll

O4 - HKLM\..\Run: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe

O4 - HKLM\..\Run: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe

O4 - HKLM\..\Run: [xmplib] rundll32.exe C:\WINDOWS\System32\xmplib.dll,start

O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe

O4 - HKLM\..\Run: [SysTray] c:\Program Files\wkggdmyf.exe

O4 - HKLM\..\Run: [rpcc] rpcc.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [newname] C:\\nwnm.exe

O4 - HKLM\..\Run: [mswap] rundll32.exe C:\WINDOWS\System32\mswap.dll,start

O4 - HKLM\..\Run: [Microsoft ® Windows Update Manager Tool] C:\WINDOWS\update\updmangr.exe

O4 - HKLM\..\Run: [keyboard] C:\\kybrd.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [jjhgrn] C:\WINDOWS\System32\krdorp.exe reg_run

O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe

O4 - HKLM\..\Run: [df197d52.exe] C:\WINDOWS\System32\df197d52.exe

O4 - HKLM\..\Run: [defender] C:\\dfndr.exe

O4 - HKLM\..\Run: [ciennooA] C:\WINDOWS\ciennooA.exe

O4 - HKLM\..\RunServices: [˙_zskxam`b^kc_xrbmz`^40inkrwksz_] c:\windows\system32\_zskwrkni04^`zmbrx_ck^b`max.exe

O4 - HKLM\..\RunServices: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe

O4 - HKCU\..\Run: [Zugbequa] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\APPLIC~1\WNSXS~1\RNDLL3~1.EXE

O4 - HKCU\..\Run: [Woezmfms] C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\APPLIC~1\WNSXS~1\RNDLL3~1.EXE

O4 - HKCU\..\Run: [sys_up1] C:\Program Files\Common Files\svchostsys\svchostsys.exe

O4 - HKCU\..\Run: [ggois] C:\WINDOWS\System32\krdorp.exe reg_run

O20 - AppInit_DLLs: C:\WINDOWS\System32\wuauboot.dll

O20 - Winlogon Notify: pmnnk - pmnnk.dll (file missing)

O20 - Winlogon Notify: se500mdm - se500mdm.dll (file missing)

O20 - Winlogon Notify: vtsqq - C:\WINDOWS\System32\vtsqq.dll

O21 - SSODL: LtDXCV - {D09360C1-7A39-CA6B-F9BC-E052B1DFB332} - C:\WINDOWS\System32\bhpu.dll (file missing)

O23 - Service: Microsoft Networks DN (msndn) - Unknown owner - C:\WINDOWS\msndn.exe (file missing)

O23 - Service: Windows Update Manager Tool (UpdateManagerTool) - Unknown owner - C:\WINDOWS\update\updmangr.exe (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"




Delete these Files if listed:
rpcc.exe
C:\nwnm.exe
C:\dfndr.exe
c:\secure32.html
C:\WINDOWS\System32\qtvyyhhq.dll
C:\WINDOWS\System32\xmplib.dll
C:\WINDOWS\SYSC00.exe
c:\Program Files\wkggdmyf.exe
C:\WINDOWS\msndn.exe
C:\WINDOWS\update\updmangr.exe
C:\WINDOWS\System32\krdorp.exe
C:\Program Files\ipwins\ipwins.exe
C:\WINDOWS\System32\df197d52.exe
C:\WINDOWS\ciennooA.exe
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00007.exe
C:\Program Files\Common Files\svchostsys\svchostsys.exe
C:\WINDOWS\System32\krdorp.exe
C:\WINDOWS\System32\bhpu.dll


Delete these Folders if listed:
C:\Program Files\ipwins
C:\WINDOWS\update
C:\Program Files\Common Files\svchostsys



Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#9 kshmom

kshmom

    Authentic Member

  • Authentic Member
  • PipPip
  • 25 posts

Posted 29 June 2006 - 12:56 PM

My computer is doing a little better. Pop ups are down considerably and I can work on a regular boot up instead of safe boot. I still have a lot of freezes where I have to restart and it is slow to respond but it is definitely progress. On my Winantivirus the setting won't stay reset so every couple of seconds a msg pops up that I missed my scheduled scan do I want to perform it now. I click no and it just pops right back up. I have to completely disable it so it won't run. I hate this program and wish I had known more before I paid for it. I don't think it works. I also get the following error msgs. An unexpected error has occurred at procedure :modBackup_MakeBackup(sItem=20-AppInit_DLLS: C:\Windows\System32\wuauboot.dll) Error #5-Invalid procedure call or argument C:Windows\System32\lsass terminated unexpectedly with status code 128. Computer will now be shut down by NT Authority System fstsvc.dll Specefied module could not be found Also my cable internet provider called and said they detected a spamming virus Logfile of HijackThis v1.99.1 Scan saved at 1:36:04 PM, on 6/29/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\ewido.exe C:\Documents and Settings\Aarons\Desktop\HJT.exe.exe O2 - BHO: (no name) - {08928445-A8AD-4E8F-8D81-C084A2A06153} - C:\WINDOWS\System32\vtsqq.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O4 - HKLM\..\Run: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [fstsvc] rundll32.exe C:\WINDOWS\System32\fstsvc.dll,start O4 - HKLM\..\Run: [df197d52.exe] C:\WINDOWS\System32\df197d52.exe O4 - HKLM\..\RunServices: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - HKCU\..\Run: [df197d52.exe] C:\Documents and Settings\Aarons\Local Settings\Application Data\df197d52.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O20 - Winlogon Notify: vtsqq - C:\WINDOWS\System32\vtsqq.dll O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file) O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe

#10 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 29 June 2006 - 01:13 PM

They don't want to die :rant2:

[*]Double-click VundoFix.exe to run it.
[*]Click the Scan for Vundo button.
[*]Once it's done scanning, click the Remove Vundo button.
[*]You will receive a prompt asking if you want to remove the files, click YES.
[*]Once you click yes, your desktop will go blank as it starts removing Vundo.
[*]When completed, it will prompt that it will shutdown your computer, click OK.
[*]Turn your computer back on. Please reboot your computer in Safe Mode by doing the following:
[/list]1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: (no name) - {08928445-A8AD-4E8F-8D81-C084A2A06153} - C:\WINDOWS\System32\vtsqq.dll

O4 - HKLM\..\Run: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe

O4 - HKLM\..\Run: [df197d52.exe] C:\WINDOWS\System32\df197d52.exe

O4 - HKLM\..\RunServices: [˙_zskh`n_qxlqidiv]zct40inkrwksz_] c:\windows\system32\_zskwrkni04tcz]vidiqlxq_n`h.exe

O4 - HKCU\..\Run: [df197d52.exe] C:\Documents and Settings\Aarons\Local Settings\Application Data\df197d52.exe

O20 - Winlogon Notify: vtsqq - C:\WINDOWS\System32\vtsqq.dll

O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - (no file)


Close ALL windows and browsers except HijackThis and click "Fix checked"




Delete these Files if listed:
C:\WINDOWS\System32\df197d52.exe
C:\Documents and Settings\Aarons\Local Settings\Application Data\df197d52.exe



Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

    Advertisements

Register to Remove


#11 kshmom

kshmom

    Authentic Member

  • Authentic Member
  • PipPip
  • 25 posts

Posted 30 June 2006 - 07:23 PM

My computer is running fairly well right now. It is still a little slow to load and sometimes freezes but not anywhere near what it was doing. I don't spend more time rebooting than I do actually using the computer anymore. :) For a while I was a little worried. After I did what u said my modem wouldn't work. I called tech support and apparently when a file is that embedded it sometimes causes some sort of error to Winsock or something like that and so I just had to uninstall thru regedit and reinstall so everything is looking good right now I hope. I cannot tell u how much I appreciate your help. The only errors I am getting now are that fstsvc module not found and when I log on it says that I need to restore my active desktop. So here is my HJT file Logfile of HijackThis v1.99.1 Scan saved at 8:09:40 PM, on 6/30/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\System32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\ewido.exe C:\WINDOWS\System32\wuauclt.exe C:\Documents and Settings\Aarons\Desktop\HJT.exe.exe O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx (file missing) O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [fstsvc] rundll32.exe C:\WINDOWS\System32\fstsvc.dll,start O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe

#12 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 02 July 2006 - 01:11 PM

Looking alot better :thumbup:

Please do not delete anything unless instructed to.



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [fstsvc] rundll32.exe C:\WINDOWS\System32\fstsvc.dll,start
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u


Close ALL windows and browsers except HijackThis and click "Fix checked"




Delete these Files if listed:
C:\WINDOWS\System32\fstsvc.dll




Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#13 kshmom

kshmom

    Authentic Member

  • Authentic Member
  • PipPip
  • 25 posts

Posted 03 July 2006 - 04:06 PM

Computer running really good right now. I can't believe it actually. I can use the regular desktop and my programs respond when I tell them too. It is great. Here is the new file.

Logfile of HijackThis v1.99.1
Scan saved at 4:57:24 PM, on 7/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Aarons\Desktop\HJT.exe.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1151720462859
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Documents and Settings\Aarons\Desktop\ewido anti-spyware 4.0\guard.exe

#14 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 03 July 2006 - 04:09 PM

Good Job :thumbup:

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.





If you dont have these programs I would recommend that you get them. Spywareblaster, Spywareguard. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#15 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 07 July 2006 - 02:20 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users