This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack this log

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Before we get to "Part 2", can you delete this folder?

C:\QooBox

If not, let me know which files in it cannot be removed.

If it was successfully removed, please let me know that as well.
:)
Well done. :thumbup:

Download Killbox from here:

Killbox.zip © Option^Explicit

Unzip it, but don't run it yet.

Copy the file names in the quote box below to the clipboard by highlighting them and pressing
C (hold the key down, then press C):

C:\WINDOWS\system32\tbyhr.exe
C:\WINDOWS\system32\fvglchk.exe


CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\tbyhr.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,fvglchk.exe

Then click "Fix checked", and close Hijack This!

Run Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new HijackThis! log file into this thread. :)
Don't think this is good news :( but I followed your instructions to the letter and when I enter both files in Killbox it came back saying "This file could not be deleted."

I rebooted and ran HJT again.

Logfile of HijackThis v1.99.1
Scan saved at 2:56:12 PM, on 7/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\hkcmd.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\dlbxcoms.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HJT.exe\HijackThis.exe
C:\WINDOWS\System32\msiexec.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\tbyhr.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,fvglchk.exe
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://whackdown.pogo.com/applet-6.0.0.25/…n-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…oad/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://netscape.musicnotes.com/download/mnviewer.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/bestfriends/miniclipGameLoader.dll
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://www.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…90/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/PearsonInstallAsst.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs7b.instantservice.com/jars/customerxsigned35.cab
O16 - DPF: {98BFD494-F6AD-4794-9038-832C0654CC43} - http://pak02.pictures.aol.com/ygp/aol/plug…-US.9.2.3.0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.filelodge.com/ImageUploader3.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O16 - DPF: {C4DD6732-1E82-4AE7-BD94-180331B84082} (DeltaCVX Control) - http://www.mathxl.com/applets/DeltaCVX.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…5/installer.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…aploader_v7.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: dlbx_device - Dell - C:\WINDOWS\System32\dlbxcoms.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


All I can say is you have the patients of JOB!! Have I said thank you recently??
Copy the text in the following quote box into Notepad:

echo ——— delqoo ————————————— > files.txt
echo ———————————————— >> files.txt
type c:\BFU\delqoo.bfu >> files.txt
echo ———————————————— >> files.txt
echo ——— regfix ————————————— >> files.txt
echo ———————————————— >> files.txt
type c:\BFU\regfix.reg >> files.txt
echo ———————————————— >> files.txt
echo ——— onreboot.bfu ————————————— >> files.txt
echo ———————————————— >> files.txt
type c:\BFU\onreboot.bfu >> files.txt
notepad files.txt


Save it to your desktop as qq.bat.

CLOSE NOTEPAD!!!

Now, the qq.bat file on the desktop. A Notepad window will open up.

Please paste it's contents into your next post.
:)
Here it is… ——— delqoo ————————————— ———————————————— OptionOnDeleteFailUseReboot OptionPauseBetweenCmds 1000 FileDeleteOnReboot %ALLUSERSSTARTUP%\*.exe FileDeleteIfMD5Match %SYSDIR%\*.exe|5B38FED0E73F6CA2A2AD2D8B5A974284 FileDeleteIfMD5Match %SYSDIR%\*.exe|4FA859B376E1CD68B6606BD7F103D6A6 OptionPauseNow 1000 FileDeleteIfMD5Match %SYSDIR%\*.exe|C250650AD39185F4467AD91D4CAEECA6 FileDeleteIfMD5Match %SYSDIR%\*.dll|B2020A73799934ACA889C4515089AA92 OptionPauseNow 1000 FileDeleteIfMD5Match %SYSDIR%\*.dat|5B38FED0E73F6CA2A2AD2D8B5A974284 FileDeleteIfMD5Match %SYSDIR%\*.dat|C250650AD39185F4467AD91D4CAEECA6 OptionPauseNow 1000 FileDeleteIfMD5Match %SYSDIR%\*.exe|34927EFD7594648462BB18E713ADA55F FileDeleteIfMD5Match %SYSDIR%\*.exe|1DCDAF76521850F8A8980249BA098CF8 OptionPauseNow 1000 FileDeleteIfMD5Match %SYSDIR%\*.exe|272E1D5EB4E85C4E03633F7D431FD6BE FileDeleteIfMD5Match %SYSDIR%\*.dll|EB881D123AF640B6C6BEAC76DF6F45DD OptionPauseNow 1000 FileDeleteIfMD5Match %SYSDIR%\*.exe|C39CF3F7A081542C3A541642CA37EFC2 FileDeleteIfMD5Match %SYSDIR%\*.dll|4156D29B461F25955B45B32D834D4E54 OptionPauseNow 1000 FileDeleteIfMD5Match %SYSDIR%\*.exe|ADF22E6BD68DF549BA48E01210415700 FileDeleteIfMD5Match %SYSDIR%\*.dat|C39CF3F7A081542C3A541642CA37EFC2 FileDeleteIfMD5Match %SYSDIR%\*.dat|1DCDAF76521850F8A8980249BA098CF8 OptionPauseNow 1000 FileDeleteOnReboot %SYSDIR%\resmm.cpl FileDeleteOnReboot %SYSDIR%\conres.cpl FileDeleteOnReboot %SYSDIR%\redit.cpl FileDeleteOnReboot %SYSDIR%\sskdsfk.dll FileDeleteOnReboot %SYSDIR%\bubhw.dll FileDeleteOnReboot %windir%\unwn.exe FileDeleteOnReboot %SYSDIR%\fwrgm.dll FileDeleteOnReboot %SYSDIR%\vgactl.cpl FileDeleteOnReboot %SYSDIR%\wuauclt.dll FileDeleteOnReboot %SYSDIR%\wmconfig.cpl FileDeleteOnReboot %SYSDIR%\dmonwv.dll FileDeleteOnReboot %ALLUSERSSTARTUP%\*.exe OptionSetBFURunOnReboot %systemdrive%\BFU\onreboot.bfu SystemRestart Let your PC be restarted please!|1 OptionBFUExit ———————————————— ——— regfix ————————————— ———————————————— REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "djmuqy"=- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "aftvs"=- ———————————————— ——— onreboot.bfu ————————————— ———————————————— OptionPauseBetweenCmds 500 SystemEmptyInternetCache SystemEmptyTempFolder RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winsync RegSetStringValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell|Explorer.exe RegSetStringValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit|%Sysdir%\Userinit.exe, RegDeleteKey HKLM\SOFTWARE\Microsoft\qopwad RegDeleteKey HKLM\Software\Microsoft\lodwqu RegDeleteKey HKLM\Software\Microsoft\wlwtdw RegDeleteKey HKLM\SOFTWARE\qstat RegDeleteKey HKCR\CLSID\{CE3A44D8-BC88-4D62-A890-42D96245F8D6} RegDeleteKey HKCR\Folder\shellex\ColumnHandlers\{CE3A44D8-BC88-4D62-A890-42D96245F8D6} RegDeleteKey HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{4ABF810A-F11D-4169-9D5F-7D274F2270A1} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebNexus systemrun regedit.exe| /s %systemdrive%\bfu\regfix.reg||1 OptionBFUExit
Lets try it this way:

Download FindQoologic.zip save it to your root folder (C:\) from the following link:

FindQool.zip

Extract (unzip) the files inside into their own folder called FindQool.
Read here how to unzip/extract properly:

How to zip and unzip files with XP

This folder should be present on your root folder (C:\)
In case it's not present there, move the FindQool folder to your root folder (C:\) otherwise it won't work.
Then open the FindQool folder.
Locate and the Qlocate.bat file to run it.

This will scan your system.

Wait until a text opens.

Post this in your next reply
:)
When you click on the link to download the zip, a dialogue box will open up asking you what you want to do with the file.

Click "Save".

Then another dialogue window will open up, wanting you to choose where you want to save it.

Click on "My Computer" (on the left side), then on "Local Disk (C:)", then click "Save".

That should put it in the root folder.
:)
This is what came up… Sat 07/01/2006 Running from: C:\FindQool\FindQool PLEASE NOTE: LEGIT FILES MIGHT BE LISTED. IF YOU ARE UNSURE OF WHAT IS LISTED LEAVE THEM ALONE. Known file names MD5 Check…. C:\WINDOWS\system32\jowgd.dat C:\WINDOWS\system32\eridrb.exe C:\WINDOWS\system32\tbyhr.exe C:\WINDOWS\system32\kyidijv.dll C:\WINDOWS\system32\fvglchk.exe Files found with locate com. C:\WINDOWS\SYSTEM32\FVGLCHK.EXE C:\WINDOWS\SYSTEM32\KYIDIJV.DLL C:\WINDOWS\SYSTEM32\JOWGD.DAT C:\WINDOWS\SYSTEM32\ERIDRB.EXE C:\WINDOWS\SYSTEM32\TBYHR.EXE C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS\STARTUP\VYTEX.EXE Re-check using dir /a:-d C:\Documents and Settings\All Users\Start Menu\Programs\Startup 07/01/2006 08:51 AM 127,488 vytex.exe … … Runs, Listed here as a Doublecheck for the locate com results HKLM "djmuqy"="C:\\WINDOWS\\system32\\eridrb.exe reg_run" HKCU "aftvs"="C:\\WINDOWS\\system32\\eridrb.exe reg_run" … Files In Winlogon shell and userinit Listed here as a Doublecheck for the locate com results shell REG_SZ Explorer.exe, C:\WINDOWS\system32\tbyhr.exe userinit REG_SZ C:\WINDOWS\SYSTEM32\Userinit.exe,fvglchk.exe … SWReg utility Written by Bobbi Flekman © 2005 Findqool edited 17/05/2006

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI