This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis Logfile: browser hijacked and frequent pop ups

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi everybody (again)
This is a scan of my sister's PC. She doesn't usually perform spyware scans and only recently switched over to Firefox, so I'm afraid she probably has numerous problems with *ware. Also, she is running Windows XP Home, but SP1. I've gone on Windows Update to download SP2, but strangely, it locks while searching for required updates. :rant2: Help necessary and GREATLY appreciated. Thanks in advance :D

Logfile of HijackThis v1.99.1
Scan saved at 4:03:38 PM, on 7/6/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Vanita\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.eoemtuhlholmfof.uk/jS0xbcBvzxL5…gd_PDNO51F.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {D482D5C4-CCC1-294F-68A8-297642BA5CF1} - C:\DOCUME~1\Owner\APPLIC~1\ERRORC~1\Hold this.exe (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Savenurbsitetitle] C:\Documents and Settings\All Users\Application Data\CORNWIPESAVENURB\FordWay.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145576942453
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\wmfhotfix.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Hello legendarysoc, and welcome to TomCoyote forums. I'm dak, and I'll be helping you to fix your computer. I'm sorry for the delay in replying to your log. If you still require assistance, please do the following: Firstly, HijackThis needs to be in its own folder so that it will correctly make backup copies of anything that we use it to fix. Please right-click on an empty area of your desktop and select new > folder. Then, drag the HijackThis icon into the folder. Next, run HijackThis and click on the "Open the misc tools section". Click on "open uninstall manager" Then Click "save list". This should create a log called "uninstall_list.txt". Please post the contents of "uninstall_list.txt", along with a new HijackThis log, as a reply to this thread.
Ad-Aware SE Personal Adobe Acrobat 5.0 Avira AntiVir PersonalEdition Classic CNET Download Manager Compaq Connections FaxTools foobar2000 v0.9.1 HijackThis 1.99.1 HP Deskjet printer preloaded drivers Instant Support Intel® Extreme Graphics Driver IntelliMover Data Transfer Demo iTunes J2SE Runtime Environment 5.0 Update 4 Java 2 Runtime Environment Standard Edition v1.3.1_04 KBD Lexmark X74-X75 LimeWire MA111 Configuration Utility Microsoft .NET Framework (English) v1.0.3705 Microsoft .NET Framework 1.1 Microsoft Money 2003 System Pack Microsoft Office Professional Edition 2003 Microsoft Works 7.0 Monkey's Audio Mozilla Firefox (1.5.0.4) MSN Messenger 7.0 MUSICMATCH® Jukebox NVIDIA Windows 2000/XP Display Drivers OmniPass OpenOffice.org 1.9.125 PC MightyMax v9 PC-Doctor for Windows PCFriendly PS2 Python 2.2 combined Win32 extensions Python 2.4.1 Quicken 2003 New User Edition QuickTime RealOne Player RecordNow S3Display S3Gamma2 S3Info2 S3Overlay Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905495) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Simple Installer - Multilanguage Version Sonic Update Manager SpamSubtract Spybot - Search & Destroy 1.4 Startnow Navigation Helper (v1.0.1.1) Sure Delete 5.1.1 The Compressonator The GIMP 2.2.8 TuneUp Utilities 2006 Update for Windows XP (KB835409) Update for Windows XP (KB898461) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Weblink Winamp (remove only) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows WMF Metafile Vulnerability HotFix 1.4 Windows XP Hotfix - KB833407 Windows XP Hotfix - KB835732 Windows XP Hotfix - KB842773 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB911567 Windows XP Hotfix - KB916281 Windows XP Hotfix - KB918439 Windows XP Hotfix (SP2) [See q329256 for more information] Windows XP Hotfix (SP2) Q327979 Windows XP Hotfix (SP2) Q329909 Windows XP Hotfix (SP2) Q331958 Windows XP Hotfix (SP2) Q811789 WinPcap 3.1 beta4 WinRAR archiver ZIP Reader 8.00.0018 ZoneAlarm
Very sorry, I haven't had access to my sister's pc in a while. I'll post another log as soon as I have the oppurtunity.
Thanks for being so patient Dak, here's a new log file and a new uninstall list

Logfile of HijackThis v1.99.1
Scan saved at 4:34:20 PM, on 7/18/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://web.cvjemccicdbmnequblaytlcn.com/JS…J4cDxgrq5m.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ipnbpmawjwlypoetpcpngfef.com/JS…rmujI3Thqbw.php
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qca8.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {D482D5C4-CCC1-294F-68A8-297642BA5CF1} - C:\DOCUME~1\Owner\APPLIC~1\ERRORC~1\Hold this.exe (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Savenurbsitetitle] C:\Documents and Settings\All Users\Application Data\CORNWIPESAVENURB\FordWay.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Audio Noun] C:\DOCUME~1\Owner\APPLIC~1\OPENDO~1\Info Platform First.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145576942453
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\wmfhotfix.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: hpdj00 - HP - C:\DOCUME~1\Owner\LOCALS~1\Temp\hpdj00.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



Ad-Aware SE Personal
Adobe Acrobat 5.0
Avira AntiVir PersonalEdition Classic
Ch2r
CNET Download Manager
Compaq Connections
FaxTools
foobar2000 v0.9.1
HijackThis 1.99.1
HP Deskjet printer preloaded drivers
Instant Support
Intel® Extreme Graphics Driver
IntelliMover Data Transfer Demo
iTunes
J2SE Runtime Environment 5.0 Update 4
Java 2 Runtime Environment Standard Edition v1.3.1_04
KBD
Lexmark X74-X75
LimeWire
MA111 Configuration Utility
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.1
Microsoft Money 2003 System Pack
Microsoft Office Professional Edition 2003
Microsoft Works 7.0
Monkey's Audio
Mozilla Firefox (1.5.0.4)
MSN Messenger 7.0
MSN Music Assistant
MUSICMATCH® Jukebox
NVIDIA Windows 2000/XP Display Drivers
OmniPass
OpenOffice.org 1.9.125
PC MightyMax v9
PC-Doctor for Windows
PCFriendly
PS2
Python 2.2 combined Win32 extensions
Python 2.4.1
Quicken 2003 New User Edition
QuickTime
RealOne Player
RecordNow
S3Display
S3Gamma2
S3Info2
S3Overlay
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905495)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Simple Installer - Multilanguage Version
Sonic Update Manager
SpamSubtract
Spybot - Search & Destroy 1.4
Startnow Navigation Helper (v1.0.1.1)
Sure Delete 5.1.1
The Compressonator
The GIMP 2.2.8
TuneUp Utilities 2006
Update for Windows XP (KB835409)
Update for Windows XP (KB898461)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Weblink
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows WMF Metafile Vulnerability HotFix 1.4
Windows XP Hotfix - KB833407
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB911567
Windows XP Hotfix - KB916281
Windows XP Hotfix - KB918439
Windows XP Hotfix (SP2) [See q329256 for more information]
Windows XP Hotfix (SP2) Q327979
Windows XP Hotfix (SP2) Q329909
Windows XP Hotfix (SP2) Q331958
Windows XP Hotfix (SP2) Q811789
WinPcap 3.1 beta4
WinRAR archiver
ZIP Reader 8.00.0018
ZoneAlarm
First download ewido anti-spyware from hereand save that file to your desktop.

This is a 30 day trial of the program

  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.

1) Fixing with HijackThis

Please scan with HijackThis, and put a check-mark next to the following entries:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://web.cvjemccicdbmnequblaytlcn.com/JS…J4cDxgrq5m.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ipnbpmawjwlypoetpcpngfef.com/JS…rmujI3Thqbw.php

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {D482D5C4-CCC1-294F-68A8-297642BA5CF1} - C:\DOCUME~1\Owner\APPLIC~1\ERRORC~1\Hold this.exe (file missing)

O4 - HKLM\..\Run: [Savenurbsitetitle] C:\Documents and Settings\All Users\Application Data\CORNWIPESAVENURB\FordWay.exe

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

O4 - HKCU\..\Run: [Audio Noun] C:\DOCUME~1\Owner\APPLIC~1\OPENDO~1\Info Platform First.exe

O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab



Then, with all other windows and browsers closed (including this one), please click on the "fix checked" button.

———-

2) Show hidden files

Please set your computer to show hidden files, by doing this:
  • Click Start.
  • Open "My Computer"
  • Select the "Tools" menu and click "Folder Options"
  • Select the "View" Tab
  • Under the "Hidden files and folders" heading select "Show hidden files and folders"
  • Uncheck the "Hide protected operating system files (recommended)" option
  • Click "Yes" to confirm
  • Click "OK".
———-

3) Reboot into safe-mode

Please reboot into safe-mode by restarting your computer, and continually poking the F8 button whilst it is loading up.

In the menu that appears, use the arrows on your keyboard to select "safe mode" and press enter.

———-

4) Delete files and folders

Please delete any of the following files and folders, if they still exist:

C:\Documents and Settings\All Users\Application Data\CORNWIPESAVENURB<–foler

C:\DOCUME~1\Owner\APPLIC~1\OPENDO~1\<–folder (the folder will be called something like opendocuments, or opendoor, and will contain the file Info Platform First.exe)

———-

5) Scan with ewido

Whilst still in safe mode,
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.

    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode
———-

6) Online antivirus scan

Please do an online scan with Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
———-

Finally, please scan with HijackThis and make a new log. Post the new log, along with the ewido and kaspersky logs, as a reply to this thread :)
Alright, I did everything you said here are the results:

HijackThis Logfile
Logfile of HijackThis v1.99.1
Scan saved at 4:42:01 PM, on 7/19/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://xkhmujqahnan.com/JSIcYVRqWejQivYFBP…J4cDxgrq5m.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ipnbpmawjwlypoetpcpngfef.com/JS…rmujI3Thqbw.php
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qca8.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145576942453
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\wmfhotfix.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: hpdj00 - HP - C:\DOCUME~1\Owner\LOCALS~1\Temp\hpdj00.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Ewido Anti-Spyware Logfile
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 12:14:44 PM 7/19/2006

+ Scan result:



C:\Documents and Settings\Owner\Local Settings\Temp\__unin__.exe -> Adware.Altnet : No action taken.
C:\Program Files\Screensavers.com\Installer\bin\ScreensaversInst.dll -> Adware.Comet : No action taken.
HKU\S-1-5-21-3982506024-1423630766-570624250-1003\Software\Igor V. Gunko -> Adware.HyperBar : No action taken.
C:\Documents and Settings\All Users\Application Data\Starware -> Adware.Starware : No action taken.
C:\Documents and Settings\Owner\Cookies\owner@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Vanita\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Vanita\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Vanita\Cookies\vanita@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : No action taken.


::Report end


Kaspersky Online Antivirus Scan Logfile
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, July 19, 2006 4:39:05 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 19/07/2006
Kaspersky Anti-Virus database records: 208465


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 144446
Number of viruses found 15
Number of infected objects 95
Number of suspicious objects 0
Duration of the scan process 03:18:50

Infected Object Name Virus Name Last Action
C:\Documents and Settings\Owner\Local Settings\Temp\10bed98.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\1371571.exe Infected: Trojan-Downloader.Win32.Swizzor.dv skipped

C:\Documents and Settings\Owner\Local Settings\Temp\13e6c2a.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\1417805.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\1884ec6.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\188d2d1.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\1d356df.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\1d3a123.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\22d8aaa.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\274654a.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\407afdc0.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\40caabe7.exe Infected: Trojan-Downloader.Win32.Swizzor.eu skipped

C:\Documents and Settings\Owner\Local Settings\Temp\40fa811b.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\41262a.exe Infected: Trojan-Downloader.Win32.Swizzor.eu skipped

C:\Documents and Settings\Owner\Local Settings\Temp\42040967.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\420cd996.exe Infected: not-a-virus:AdWare.Win32.Lop.o skipped

C:\Documents and Settings\Owner\Local Settings\Temp\4238fce1.exe Infected: Trojan-Downloader.Win32.Swizzor.dj skipped

C:\Documents and Settings\Owner\Local Settings\Temp\423ff896.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\4295df43.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\429ff364.exe Infected: Trojan-Downloader.Win32.Swizzor.dv skipped

C:\Documents and Settings\Owner\Local Settings\Temp\42aac5e4.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\42b42169.exe Infected: Trojan-Downloader.Win32.Swizzor.dv skipped

C:\Documents and Settings\Owner\Local Settings\Temp\42d307d0.exe Infected: Trojan-Downloader.Win32.Swizzor.ca skipped

C:\Documents and Settings\Owner\Local Settings\Temp\42dfbcf5.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\42e33afd.exe Infected: Trojan-Downloader.Win32.Swizzor.eu skipped

C:\Documents and Settings\Owner\Local Settings\Temp\42e55524.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\4316dfc9.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\43399435.exe Infected: Trojan-Downloader.Win32.Swizzor.cs skipped

C:\Documents and Settings\Owner\Local Settings\Temp\4f8a60.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped

C:\Documents and Settings\Owner\Local Settings\Temp\9fe75b.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\adc4c.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\b90e88.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\c01cc9.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\c5a6e1ca.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\c5ac66ba.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\c5adf009.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\db0319.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\e2eff4.exe Infected: Trojan-Downloader.Win32.Swizzor.cc skipped

C:\Documents and Settings\Owner\Local Settings\Temp\e56e9.exe Infected: Trojan-Downloader.Win32.Swizzor.dv skipped

C:\Documents and Settings\Owner\Local Settings\Temp\fd7381.exe Infected: Trojan-Downloader.Win32.Swizzor.eu skipped

C:\Documents and Settings\Owner\Local Settings\Temp\Inside Program.exe Infected: Trojan-Downloader.Win32.Swizzor.dr skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sta21.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped

C:\Documents and Settings\Owner\Local Settings\Temp\sta39.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr7E0C Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped

C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\aqrbaesh.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\augtfmhj.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\bfulcnil.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\djgmyavx.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\drtkqfaf.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\dtlswhvr.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\fpuhkkyh.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\hqztwiou.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\ihyecbhb.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\Info Platform First.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\jfzmzyzp.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\jmnsmcsb.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\jqjadcxa.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\kmfdsfiv.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\mblfjprt.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\mkpnkkoi.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\nftswaon.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\ofdhnzhf.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\pagbtihp.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\qnzraluc.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\softacewaveslow.exe Infected: Trojan-Downloader.Win32.Swizzor.dv skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\tbuvjykl.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\udkhbqls.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\umykjwlg.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\uwybmwol.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\VcAmenDownload.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\venpayoj.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\vmqjfghz.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\yivlinbx.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\zktvpyjg.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc72\zpedlvic.exe Infected: Trojan-Downloader.Win32.Swizzor.de skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc73\FordWay.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc73\grey dash.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\RECYCLER\S-1-5-21-3982506024-1423630766-570624250-1003\Dc73\Team bits.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP483\A0109220.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP483\A0109221.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP483\A0109222.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP483\A0109223.exe Infected: not-a-virus:AdWare.Win32.Lop.ag skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP492\A0110045.exe Infected: Trojan-Downloader.Win32.Swizzor.eu skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP492\A0110046.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP493\A0110092.exe Infected: Trojan-Downloader.Win32.Swizzor.eu skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP493\A0110093.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP493\A0110094.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP493\A0110259.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP493\A0110260.exe Infected: not-a-virus:AdWare.Win32.Lop.bb skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP493\A0110261.exe Infected: Trojan-Downloader.Win32.Swizzor.dv skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP493\A0110262.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP493\A0110263.exe Infected: Trojan-Downloader.Win32.Swizzor.fg skipped

C:\System Volume Information\_restore{E0C22EC0-D318-4D95-967D-A5C2B4653ED0}\RP553\A0115581.dll Infected: not-a-virus:AdWare.Win32.Comet.c skipped

Scan process completed.
You've got a few stragglers, but your log looks pretty clean. How's your computer behaving?

1/

Download and install CCleaner (make sure to deselect 'install yahoo/CCleaner toolbar for internet explorer' unless you want it)

Double click the CCleaner icon, and make sure only the following are checked under the "windows" tab:

temporary internet files

empty recycle bin

temporary files

old prefetch data


Then click the 'applications' tab, and uncheck everything.


Now, click on "run cleaner" to clean out your temp files.

2/

Delete the following folders:

C:\Program Files\Screensavers.com


C:\Documents and Settings\All Users\Application Data\Starware

3/

Run HijackThis, and place a check-mark next to the following entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://xkhmujqahnan.com/JSIcYVRqWejQivYFBP…J4cDxgrq5m.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ipnbpmawjwlypoetpcpngfef.com/JS…rmujI3Thqbw.php


Then, with all other windows closed, click 'fix selected'

4/

Finally, reboot and post up a new hijack this log please.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI