This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

amaena and other pop-ups- can't get rid of...

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I hve the Amaena and winfixer pop-ups on a laptop that I can't get rid off.. Any help is appreciate. Below is the HijackThis Log. I also ran L2Me Destroyer program and the log is also below. After I ran those I undid and then redid system restore. I still get the pop-ups. Any help is appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 6:36:13 PM, on 7/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\759e86fa.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\John\APPLIC~1\ASKS~1\javaw.exe
C:\WINDOWS\system32\services.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\l?gonui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\John\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rd.yahoo.com/customize/sbcydsl/defa…hoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.yahoo.com/customize/sbcydsl/defa…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.station.sony.com/
R3 - URLSearchHook: (no name) - {43046950-FEE5-F561-90AE-F78AD9A7ACBB} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINDOWS\System32\hggfc.dll
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [759e86fa.exe] C:\WINDOWS\system32\759e86fa.exe
O4 - HKLM\..\Run: [ÿ_zskBKNJMDQ^]EFZRK] C:\WINDOWS\System32\_zskwrkni05T\KRZFE]^QDMJNKB.exe
O4 - HKLM\..\RunServices: [ÿ_zskBKNJMDQ^]EFZRK] C:\WINDOWS\System32\_zskwrkni05T\KRZFE]^QDMJNKB.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Mgn] C:\WINDOWS\System32\LGONUI~1.EXE
O4 - HKCU\..\Run: [759e86fa.exe] C:\Documents and Settings\John\Local Settings\Application Data\759e86fa.exe
O4 - HKCU\..\Run: [ÿ_zskBKNJMDQ^]EFZRK] C:\WINDOWS\System32\_zskwrkni05T\KRZFE]^QDMJNKB.exe
O4 - HKCU\..\Run: [WinMedia] C:\DOCUME~1\John\LOCALS~1\Temp\4A.tmp3072.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00004.exe"
O4 - HKCU\..\Run: [Iinl] "C:\DOCUME~1\John\APPLIC~1\ASKS~1\javaw.exe" -vt rbnd
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1153026783213
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1153026678502
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O20 - AppInit_DLLs: lsass.dll C:\WINDOWS\System32\lsass.dll
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\lv0q09d5e.dll
O20 - Winlogon Notify: hggfc - C:\WINDOWS\System32\hggfc.dll
O20 - Winlogon Notify: mmx4xt - C:\WINDOWS\SYSTEM32\mmx4xt.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: njbzFVJolOYPS - {6087541F-CA2D-FEB5-5ED5-3F6E79D9ACE1} - C:\WINDOWS\System32\wrv.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_26.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\ati2evxx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 7/17/2006 6:38:07 PM

Infected! C:\WINDOWS\system32\lv0q09d5e.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP230\A0062173.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP230\A0062537.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP231\A0062649.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP231\A0062650.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP232\A0062806.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP232\A0062815.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP233\A0062853.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP233\A0062854.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP234\A0062987.dll
Infected! C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP234\A0062988.dll
Infected! C:\WINDOWS\system32\azas0al7edq.dll
Infected! C:\WINDOWS\system32\befxdial.dll
Infected! C:\WINDOWS\system32\bzowselc.dll
Infected! C:\WINDOWS\system32\c6002gdmg60a2.dll
Infected! C:\WINDOWS\system32\cwetcfg.dll
Infected! C:\WINDOWS\system32\dbsec.dll
Infected! C:\WINDOWS\system32\dJnim.dll
Infected! C:\WINDOWS\system32\en2ul1f91.dll
Infected! C:\WINDOWS\system32\en4ul1h91.dll
Infected! C:\WINDOWS\system32\enjol1131.dll
Infected! C:\WINDOWS\system32\enn6l15s1.dll
Infected! C:\WINDOWS\system32\ennul1591.dll
Infected! C:\WINDOWS\system32\enp4l17q1.dll
Infected! C:\WINDOWS\system32\f00olad31d0.dll
Infected! C:\WINDOWS\system32\hr6u05j9e.dll
Infected! C:\WINDOWS\system32\hr8u05l9e.dll
Infected! C:\WINDOWS\system32\hrlu0539e.dll
Infected! C:\WINDOWS\system32\hrnq0555e.dll
Infected! C:\WINDOWS\system32\hrr8059ue.dll
Infected! C:\WINDOWS\system32\i060lajm1doa.dll
Infected! C:\WINDOWS\system32\i4240efqeh2e0.dll
Infected! C:\WINDOWS\system32\iinathlp.dll
Infected! C:\WINDOWS\system32\ir4ol5h31.dll
Infected! C:\WINDOWS\system32\irp0l57m1.dll
Infected! C:\WINDOWS\system32\iulogmsg.dll
Infected! C:\WINDOWS\system32\j64olgh3164.dll
Infected! C:\WINDOWS\system32\jft.dll
Infected! C:\WINDOWS\system32\jQvacypt.dll
Infected! C:\WINDOWS\system32\k4no0e53eh.dll
Infected! C:\WINDOWS\system32\k6lqlg3516.dll
Infected! C:\WINDOWS\system32\l64qlgh5164.dll
Infected! C:\WINDOWS\system32\ldnq0955e.dll
Infected! C:\WINDOWS\system32\lv0609dse.dll
Infected! C:\WINDOWS\system32\guard.tmp

Attempting to delete infected files…

Attempting to delete: C:\WINDOWS\system32\lv0q09d5e.dll
C:\WINDOWS\system32\lv0q09d5e.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP230\A0062173.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP230\A0062173.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP230\A0062537.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP230\A0062537.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP231\A0062649.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP231\A0062649.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP231\A0062650.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP231\A0062650.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP232\A0062806.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP232\A0062806.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP232\A0062815.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP232\A0062815.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP233\A0062853.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP233\A0062853.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP233\A0062854.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP233\A0062854.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP234\A0062987.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP234\A0062987.dll could not be deleted!

Attempting to delete: C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP234\A0062988.dll
C:\System Volume Information\_restore{B0BEA88A-6491-4653-8138-16C48361FE45}\RP234\A0062988.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\azas0al7edq.dll
C:\WINDOWS\system32\azas0al7edq.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\befxdial.dll
C:\WINDOWS\system32\befxdial.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\bzowselc.dll
C:\WINDOWS\system32\bzowselc.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\c6002gdmg60a2.dll
C:\WINDOWS\system32\c6002gdmg60a2.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\cwetcfg.dll
C:\WINDOWS\system32\cwetcfg.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\dbsec.dll
C:\WINDOWS\system32\dbsec.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\dJnim.dll
C:\WINDOWS\system32\dJnim.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\en2ul1f91.dll
C:\WINDOWS\system32\en2ul1f91.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\en4ul1h91.dll
C:\WINDOWS\system32\en4ul1h91.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\enjol1131.dll
C:\WINDOWS\system32\enjol1131.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\enn6l15s1.dll
C:\WINDOWS\system32\enn6l15s1.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\ennul1591.dll
C:\WINDOWS\system32\ennul1591.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\enp4l17q1.dll
C:\WINDOWS\system32\enp4l17q1.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\f00olad31d0.dll
C:\WINDOWS\system32\f00olad31d0.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\hr6u05j9e.dll
C:\WINDOWS\system32\hr6u05j9e.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\hr8u05l9e.dll
C:\WINDOWS\system32\hr8u05l9e.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\hrlu0539e.dll
C:\WINDOWS\system32\hrlu0539e.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\hrnq0555e.dll
C:\WINDOWS\system32\hrnq0555e.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\hrr8059ue.dll
C:\WINDOWS\system32\hrr8059ue.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\i060lajm1doa.dll
C:\WINDOWS\system32\i060lajm1doa.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\i4240efqeh2e0.dll
C:\WINDOWS\system32\i4240efqeh2e0.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\iinathlp.dll
C:\WINDOWS\system32\iinathlp.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\ir4ol5h31.dll
C:\WINDOWS\system32\ir4ol5h31.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\irp0l57m1.dll
C:\WINDOWS\system32\irp0l57m1.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\iulogmsg.dll
C:\WINDOWS\system32\iulogmsg.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\j64olgh3164.dll
C:\WINDOWS\system32\j64olgh3164.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\jft.dll
C:\WINDOWS\system32\jft.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\jQvacypt.dll
C:\WINDOWS\system32\jQvacypt.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\k4no0e53eh.dll
C:\WINDOWS\system32\k4no0e53eh.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\k6lqlg3516.dll
C:\WINDOWS\system32\k6lqlg3516.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\l64qlgh5164.dll
C:\WINDOWS\system32\l64qlgh5164.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\ldnq0955e.dll
C:\WINDOWS\system32\ldnq0955e.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\lv0609dse.dll
C:\WINDOWS\system32\lv0609dse.dll could not be deleted!

Attempting to delete: C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\guard.tmp could not be deleted!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\BITS

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AE16E468-F122-4D93-8F00-3C306BCE31CB}"
HKCR\Clsid\{AE16E468-F122-4D93-8F00-3C306BCE31CB}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded
Sorry for the delay, our helpers have been very busy. Your log is showing the contemptible Trojan Torpig, which can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs. I would advise for you to disconnect this PC from the Internet, and then go to a known clean computer and change any passwords or security information held on the infected computer. In particular, check whatever relates to online banking financial transactions, shopping, credit cards, or sensitive personal information. It is also wise to contact your financial institutions to apprise them of your situation. I will do our best to clean the computer of any infections seen on the log. However, because of the nature of this Trojan, cannot offer a total guarantee that there are no remnants left in the system, or that the computer will be trustworthy. Many security experts believe that once infected with this type of Trojan, the best course of action is to reformat and reinstall the Operating System. Making this decision is based on what the computer is used for, and what information can be accessed from it. Knowing the above, let us know if you wish to proceed.
Thank You for getting back to me. No need to try to clean system. I will re-format laptop from ground up. It is a second laptop, not essential. Just pictures and stuff like that and games, movies…… Thank You!
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI