This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

need help with trojans

140 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

StartupList report, 7/25/2006, 5:21:01 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Owner\Desktop\hjt.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\hjt.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
CallWave.lnk = C:\Program Files\CallWave\IAM.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

MSConfig = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
!ewido = "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

RegisterDropHandler = C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=explorer.exe
SCRNSAVE.EXE=
drivers=

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Browser Helper Objects:

(no name) - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Yahoo!\Common\yiesrvc.dll - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
(no name) - C:\Program Files\Yahoo!\Common\YIeTagBm.dll - {65D886A2-7CA7-479B-BB95-14D1EFB7946A}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - c:\Program Files\Microsoft Money\System\mnyviewer.dll - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC}

————————————————–

Enumerating Download Program Files:

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock…director/sw.cab

[YInstStarter Class]
InProcServer32 = C:\Program Files\Yahoo!\Common\yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\yinsthelper.dll

[WUWebControl Class]
InProcServer32 = C:\WINDOWS\System32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/…b?1122319668671

[Wwlaunch Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\wwlaunch.ocx
CODEBASE = http://www.worldwinner.com/games/shared/wwlaunch.cab

[WebLine Browser Integration Classes]
InProcServer32 = C:\WINDOWS\System32\MSJAVA.DLL
CODEBASE = http://198.207.241.9/webline/applets/msie40x.cab

[WoF Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\wof.ocx
CODEBASE = http://www.worldwinner.com/games/v46/wof/wof.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab

[H2hPool Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\h2hpool.ocx
CODEBASE = http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

{B08E8A4B-05FC-1033-1216-021113020001} = "C:\Program Files\Common Files\{B08E8A4B-05FC-1033-1216-021113020001}\Update.exe" mc-110-12-0000137

————————————————–

End of report, 6,209 bytes
Report generated in 1.985 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
That test was inconclusive.

This will get us what we need to know.

Please download/unzip this:

Registry Search by Bobbi Flekman

on regsearch.exe, and search for these:

GEDZAC
regedit.exe

Copy/paste them into the search box.

One item per search line.

Make sure all the little boxes are checked, under "Search".

It may take a while to run, so be patient. When finished, the search results will appear in your text editor,

Paste the contents of the search results into your next post.
:)
REGEDIT4 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.1.0 ; Results at 7/25/2006 11:03:51 PM for strings: ; 'regedit.exe' ; 'gedzac' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\regedit.exe] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\regedit\shell\open\command] @="regedit.exe %1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\regfile\DefaultIcon] ; Contents of value: ; %systemroot%\regedit.exe,1 @=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,72,65,67,65,64,69,74,2e,65,78,\ 65,2c,31,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\regfile\shell\open\command] @="regedit.exe \"%1\"" [HKEY_LOCAL_MACHINE\SOFTWARE\GEDZAC LABS] [HKEY_LOCAL_MACHINE\SOFTWARE\GEDZAC LABS\Israfel] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\regedit.exe] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Nls\MUILanguages\RCV2\regedit.exe] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\regedit.exe] [HKEY_USERS\S-1-5-21-2131481779-646246649-3316934815-1003\Software\Microsoft\Search Assistant\ACMru\5603] "008"="gedzac.vbs" [HKEY_USERS\S-1-5-21-2131481779-646246649-3316934815-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache] "C:\\WINDOWS\\regedit.exe"="Registry Editor" ; End Of The Log…
Copy and paste the contents of the quote box below into notepad.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: *All files* and save it on your Desktop.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\GEDZAC LABS]


Then, locate fixme.reg on your desktop and it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

Copy the text in the following quote box into Notepad:

dir c:\WINDOWS\regedit.* /s > files.txt
notepad files.txt


Save it to your desktop as ff.bat.

CLOSE NOTEPAD!!!

Now, the ff.bat file on the desktop. A Notepad window will open up.

Please paste it's contents into your next post.
:)
In addition to this popping up another window popped up with C:\WINDOWS|system\cmd.exe and in the box was c:\documents and settings\owner\desktop>dir c:\windows\regedit.*/s 1>files.txt c:\documents and settings\owner\desktop>notepad files.txt. didn't know if normal or not so thought I would share it with you. :) Volume in drive C is PRESARIO Volume Serial Number is B08E-8A4B Directory of c:\WINDOWS 08/04/2004 12:56 AM 146,432 regedit.exe 1 File(s) 146,432 bytes Directory of c:\WINDOWS\$NtServicePackUninstall$ 08/29/2002 02:00 PM 134,144 regedit.exe 1 File(s) 134,144 bytes Directory of c:\WINDOWS\Help 08/29/2002 07:00 AM 46,684 regedit.chm 08/29/2002 07:00 AM 12,886 regedit.hlp 2 File(s) 59,570 bytes Directory of c:\WINDOWS\I386 08/29/2002 02:00 PM 39,702 REGEDIT.CH_ 08/29/2002 02:00 PM 134,144 REGEDIT.EXE 08/29/2002 02:00 PM 2,512 REGEDIT.HL_ 3 File(s) 176,358 bytes Directory of c:\WINDOWS\Prefetch 07/26/2006 07:51 AM 12,328 REGEDIT.EXE-2AE3423E.pf 1 File(s) 12,328 bytes Directory of c:\WINDOWS\ServicePackFiles\i386 08/04/2004 12:56 AM 146,432 regedit.exe 1 File(s) 146,432 bytes Directory of c:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\8b5e9cdb91dddbb342695fbdc36fe0e4\backup 08/29/2002 02:00 PM 134,144 regedit.exe 1 File(s) 134,144 bytes Total Files Listed: 10 File(s) 809,408 bytes 0 Dir(s) 27,687,571,456 bytes free
one more thing my AVG won't let me scan and hasn't since this started but I have it set up to automatically scan everyday and it was not doing that until this morning. I am thinking this is a good sign but it is finding that nasty little booger VBS/GEDZAC.A still everywhere. and just something to keep in mind is I still have 176 files in quarentine in my vault and will add the ones its finding now until you advise me what to do with them. thanks so much for your time I feel like this is taking forever but only because I get so little free time to pop on to check the forum and what to do next. JULIE
:scratch:

Everything looks like it should work….

Let's try this:

Rename this file:

c:\WINDOWS\regedit.exe

To:

c:\WINDOWS\regedit.old

Copy this file:

c:\WINDOWS\ServicePackFiles\i386\regedit.exe

to:

c:\WINDOWS\regedit.exe

Reboot.

Try regedit once more, and let me know the results.

I don't know why your still getting "infected" file being found
:scratch:

Please post a new HijackThis! log.

Where are the new infected files being found at (what folder are they in)?
:unsure:
okay before I go any further there is a couple things. I ran a search for regedit.exe found it clicked on open containing folder clicked on it and chose rename to regedit.old. then ran a search for regedit.exe again and found the service pack files file right clicked copy then right clicked and pasted the file to regedit.exe I did choose the right one. was that the right way to do it? when I tried to restart the computer a nonresponsive program box came up for the program control.exe, I was not sure what that was so chose cancel. Do I choose end now and reboot anyway? Want to be sure I don't make this situation any worse than it is. also here are the infected files AVG found this morning. In the info it says all are back-up files. Oh yeah one more thing everytime i click to open anything from notepad to a program to my connection an installer window pops up one says windows installer preparing to install and as soon I click cancel the second one pops up saying it is configuring microsoft money. Forgive me but I am almost ready to throw this box of electronics out the window. That is probably why you do what you do and I don't. :wacko: "","","Virus identified VBS/Gedza.A","C:\Compaq\Broadband\EarthLink\earthlink.html","7/26/2006 9:08:10 AM","earthlink.html","285.95 KB" "","","Virus identified VBS/Gedza.A","C:\Compaq\cpqOfferZone\hotdeals_consumer.html","7/26/2006 9:08:10 AM","hotdeals_consumer.html","289.11 KB" "","","Virus identified VBS/Gedza.A","C:\Compaq\cpqOfferZone\hotdeals_isp.html","7/26/2006 9:08:10 AM","hotdeals_isp.html","283.6 KB" "","","Virus identified VBS/Gedza.A","C:\Compaq\cpqOfferZone\hotdeals_smb.html","7/26/2006 9:08:10 AM","hotdeals_smb.html","290.13 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\All Users\Application Data\Microsoft\Money\10.0\Webcache\getting started.htm","7/26/2006 9:08:11 AM","getting started.htm","308.21 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\All Users\Application Data\Microsoft\Money\10.0\Webcache\privacy.htm","7/26/2006 9:08:11 AM","privacy.htm","283.76 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Application Data\HP\CRMLogs\SolutionCenter.htm","7/26/2006 9:08:12 AM","SolutionCenter.htm","539.82 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Application Data\HP\Install\LaunchPad.htm","7/26/2006 9:08:12 AM","LaunchPad.htm","300.18 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Application Data\HP\ScLogs\SolutionCenter.htm","7/26/2006 9:08:12 AM","SolutionCenter.htm","282.47 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\1P0Q4B3C\intuit[1].htm","7/26/2006 9:08:12 AM","intuit[1].htm","313.72 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\1P0Q4B3C\item[2].html","7/26/2006 9:08:13 AM","item[2].html","266.83 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\1P0Q4B3C\playmessenger[1].htm","7/26/2006 9:08:13 AM","playmessenger[1].htm","288.76 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\1P0Q4B3C\wtt_ie5[1].htm","7/26/2006 9:08:13 AM","wtt_ie5[1].htm","367.64 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8N4HYRW9\allthecowgirl62[1].htm","7/26/2006 9:08:13 AM","allthecowgirl62[1].htm","286 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8N4HYRW9\defaultoff[1].htm","7/26/2006 9:08:14 AM","defaultoff[1].htm","282.79 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8N4HYRW9\medicinewoman92[1].htm","7/26/2006 9:08:14 AM","medicinewoman92[1].htm","288.31 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8N4HYRW9\query[1].html","7/26/2006 9:08:14 AM","query[1].html","305.48 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8N4HYRW9\trexxone[1].htm","7/26/2006 9:08:14 AM","trexxone[1].htm","286.63 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\URXGVL2S\admsg[1].html","7/26/2006 9:08:14 AM","admsg[1].html","266.64 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\URXGVL2S\defaultoff[1].htm","7/26/2006 9:08:15 AM","defaultoff[1].htm","282.8 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\URXGVL2S\defaultoff[2].htm","7/26/2006 9:08:15 AM","defaultoff[2].htm","283.27 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\XMH9NCKP\admsg[1].html","7/26/2006 9:08:15 AM","admsg[1].html","266.69 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\XMH9NCKP\daisy_2039[1].htm","7/26/2006 9:08:15 AM","daisy_2039[1].htm","285.85 KB" "","","Virus identified VBS/Gedza.A","C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\XMH9NCKP\home-pogop[1].htm","7/26/2006 9:08:16 AM","home-pogop[1].htm","311.65 KB" "","","Virus identified VBS/Gedza.A","C:\GRAPHPAP\FAQ.htm","7/26/2006 9:08:16 AM","FAQ.htm","286.35 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Adobe\Acrobat 7.0\Reader\ReadMe.htm","7/26/2006 9:08:16 AM","ReadMe.htm","305.5 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\en_US\license.html","7/26/2006 9:08:17 AM","license.html","301.42 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\CenturyTel FastLine Accelerator\docroot\help\help.html","7/26/2006 9:08:17 AM","help.html","374.88 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\CenturyTel FastLine Accelerator\docroot\help\readme.html","7/26/2006 9:08:18 AM","readme.html","287.61 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Common Files\Microsoft Shared\Works Shared\Mny10Warr.htm","7/26/2006 9:08:18 AM","Mny10Warr.htm","479.59 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Common Files\Microsoft Shared\Works Shared\wks7warr.htm","7/26/2006 9:08:19 AM","wks7warr.htm","292.63 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\HighMAT CD Writing Wizard\1033\HighMAT_readme.htm","7/26/2006 9:08:20 AM","HighMAT_readme.htm","282.52 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\readme.htm","7/26/2006 9:08:21 AM","readme.htm","356.62 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Individual Software\Professor Answers\index.htm","7/26/2006 9:08:22 AM","index.htm","297 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Individual Software\Professor Answers\Help\index.htm","7/26/2006 9:08:22 AM","index.htm","297 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Java Web Start\Readme_de.html","7/26/2006 9:08:23 AM","Readme_de.html","280.94 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Java Web Start\Readme_es.html","7/26/2006 9:08:23 AM","Readme_es.html","281.19 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Java Web Start\Readme_fr.html","7/26/2006 9:08:24 AM","Readme_fr.html","282.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Ligos\Indeo\Release notes\INDEO4.HTM","7/26/2006 9:08:24 AM","INDEO4.HTM","297.66 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Ligos\Indeo\Release notes\INDEO5.HTM","7/26/2006 9:08:25 AM","INDEO5.HTM","344.25 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\MGI\MGI PhotoSuite II\ReadMe.HTM","7/26/2006 9:08:26 AM","ReadMe.HTM","301.3 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\MGI\MGI PhotoSuite II\TempPSII\Common\ActivityList.html","7/26/2006 9:08:27 AM","ActivityList.html","289.35 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\MGI\MGI PhotoSuite II\TempPSII\Guides\B_Publish.html","7/26/2006 9:08:27 AM","B_Publish.html","285.72 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\MGI\MGI PhotoSuite II\TempPSII\Publish\BuddyTools.html","7/26/2006 9:08:27 AM","BuddyTools.html","282.65 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Microsoft Money\Calcs\C_Erorg\data.htm","7/26/2006 9:08:28 AM","data.htm","284.97 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Microsoft Money\Calcs\C_Erorg\pg_2.htm","7/26/2006 9:08:28 AM","pg_2.htm","281.12 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Microsoft Money\Calcs\C_Erorg\pg_3.htm","7/26/2006 9:08:29 AM","pg_3.htm","283.11 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Microsoft Money\Calcs\C_Erorg\pg_5.htm","7/26/2006 9:08:29 AM","pg_5.htm","281.48 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Microsoft Money\Calcs\C_Erorg\pg_6.htm","7/26/2006 9:08:29 AM","pg_6.htm","281.9 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Microsoft Money\Calcs\C_Erorg\pg_8.htm","7/26/2006 9:08:30 AM","pg_8.htm","286.74 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\NetMeeting\netmeet.htm","7/26/2006 9:08:30 AM","netmeet.htm","294.44 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\NewSoft\Presto! Mr.Photo 3\CardExpr\index3.htm","7/26/2006 9:08:30 AM","index3.htm","307.33 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\OEMLink\content\SV\recovery.htm","7/26/2006 9:08:31 AM","recovery.htm","267.77 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\de\System_Information.htm","7/26/2006 9:08:32 AM","System_Information.htm","299.39 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\es\System_Information.htm","7/26/2006 9:08:33 AM","System_Information.htm","299.49 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\it\System_Information.htm","7/26/2006 9:08:34 AM","System_Information.htm","301.13 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\ja\System_Information.htm","7/26/2006 9:08:34 AM","System_Information.htm","300.21 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\ko\System_Information.htm","7/26/2006 9:08:35 AM","System_Information.htm","299.59 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\nl\System_Information.htm","7/26/2006 9:08:35 AM","System_Information.htm","300.83 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\pt\System_Information.htm","7/26/2006 9:08:36 AM","System_Information.htm","302.16 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\zh\System_Information.htm","7/26/2006 9:08:36 AM","System_Information.htm","298.81 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\PC-Doctor\Java\CUI Help\zh_tw\System_Information.htm","7/26/2006 9:08:37 AM","System_Information.htm","298.92 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\localweb\mms\signup_quicken.htm","7/26/2006 9:08:37 AM","signup_quicken.htm","299.76 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\localweb\privacy\privacy.htm","7/26/2006 9:08:38 AM","privacy.htm","281.78 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\cir\cir.htm","7/26/2006 9:08:38 AM","cir.htm","283.79 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\05b1.htm","7/26/2006 9:08:39 AM","05b1.htm","281.59 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\51.htm","7/26/2006 9:08:39 AM","51.htm","288.58 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Quicken\inet\common\pnf\quicken\index_parent.htm","7/26/2006 9:08:39 AM","index_parent.htm","285.46 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\playrlic.html","7/26/2006 9:08:40 AM","playrlic.html","324.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\RealNetworks License.html","7/26/2006 9:08:40 AM","RealNetworks License.html","324.37 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\active.html","7/26/2006 9:08:41 AM","active.html","289.61 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Real\RealOne Player\DataCache\embedded.html","7/26/2006 9:08:41 AM","embedded.html","288.51 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Trend Micro\TIS11_1131\Setup\program files\Trend Micro\PC-cillin\Http.htm","7/26/2006 9:08:42 AM","Http.htm","272.34 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Trend Micro\TIS11_1131\Setup\program files\Trend Micro\PC-cillin\HttpPrivacy.htm","7/26/2006 9:08:42 AM","HttpPrivacy.htm","272.5 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Trend Micro\TIS11_1131\Setup\program files\Trend Micro\PC-cillin\Pop3.htm","7/26/2006 9:08:43 AM","Pop3.htm","272.59 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Trend Micro\TIS11_1131\Setup\program files\Trend Micro\PC-cillin\Realtime.htm","7/26/2006 9:08:43 AM","Realtime.htm","273.28 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Trend Micro\TIS11_1131\Setup\program files\Trend Micro\PC-cillin\Smtp.htm","7/26/2006 9:08:44 AM","Smtp.htm","272.6 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Trend Micro\TIS11_1131\Setup\program files\Trend Micro\PC-cillin\SmtpPrivacy.htm","7/26/2006 9:08:44 AM","SmtpPrivacy.htm","272.72 KB" "","","Virus identified VBS/Gedza.A","C:\Program Files\Trend Micro\TIS11_1131\Setup\program files\Trend Micro\PC-cillin\Tsc.htm","7/26/2006 9:08:45 AM","Tsc.htm","271.68 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP400\A0024250.VBS","7/26/2006 9:08:46 AM","A0024250.VBS","265.97 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP401\A0025222.vbs","7/26/2006 9:08:46 AM","A0025222.vbs","265.97 KB" "","","Trojan horse IRC/BackDoor.SdBot.LNB","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP401\A0025234.exe","7/26/2006 9:08:47 AM","A0025234.exe","176 KB" "","","Trojan horse IRC/BackDoor.SdBot.LNB","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP401\A0025235.exe","7/26/2006 9:08:47 AM","A0025235.exe","176 KB" "","","Trojan horse Generic.EUC","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP402\A0025243.exe","7/26/2006 9:08:47 AM","A0025243.exe","17 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP402\A0025317.VBS","7/26/2006 9:08:48 AM","A0025317.VBS","265.97 KB" "","","Virus identified Worm/VB.FL","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP402\A0025318.exe","7/26/2006 9:08:48 AM","A0025318.exe","960 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP402\A0025324.vbs","7/26/2006 9:08:49 AM","A0025324.vbs","265.97 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP402\A0025325.vbs","7/26/2006 9:08:50 AM","A0025325.vbs","265.97 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025391.hta","7/26/2006 9:08:50 AM","A0025391.hta","267.29 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025392.hta","7/26/2006 9:08:51 AM","A0025392.hta","266.56 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025393.vbs","7/26/2006 9:08:51 AM","A0025393.vbs","265.97 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025394.vbs","7/26/2006 9:08:52 AM","A0025394.vbs","265.97 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025395.hta","7/26/2006 9:08:52 AM","A0025395.hta","276.22 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025418.hta","7/26/2006 9:08:53 AM","A0025418.hta","267.29 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025419.hta","7/26/2006 9:08:54 AM","A0025419.hta","266.56 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025424.hta","7/26/2006 9:08:54 AM","A0025424.hta","267.29 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025425.hta","7/26/2006 9:08:55 AM","A0025425.hta","266.56 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025426.vbs","7/26/2006 9:08:56 AM","A0025426.vbs","265.97 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025427.vbs","7/26/2006 9:08:56 AM","A0025427.vbs","265.97 KB" "","","Virus identified VBS/Gedza.A","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025428.hta","7/26/2006 9:08:57 AM","A0025428.hta","276.22 KB" "","","Virus identified Worm/VB.FL","C:\System Volume Information\_restore{FDF7E1BD-3514-4652-A0DC-09D8FF2520E1}\RP403\A0025432.exe","7/26/2006 9:08:58 AM","A0025432.exe","960 KB" "","","Virus identified VBS/Gedza.A","C:\WINDOWS\$NtServicePackUninstall$\actshell.htm","7/26/2006 9:09:00 AM","actshell.htm","353.9 KB" "","","Virus identified VBS/Gedza.A","C:\WINDOWS\$NtServicePackUninstall$\dtsgnup.htm","7/26/2006 9:09:01 AM","dtsgnup.htm","307.97 KB" "","","Virus identified VBS/Gedza.A","C:\WINDOWS\$NtServicePackUninstall$\msobshel.htm","7/26/2006 9:09:01 AM","msobshel.htm","432.33 KB" "","","Virus identified VBS/Gedza.A","C:\WINDOWS\$NtServicePackUninstall$\netmeet.htm","7/26/2006 9:09:02 AM","netmeet.htm","294.76 KB" "","","Virus identified VBS/Gedza.A","C:\WINDOWS\$NtServicePackUninstall$\welcome.htm","7/26/2006 9:09:03 AM","welcome.htm","281.75 KB" "","","Virus identified VBS/Gedza.A","C:\WINDOWS\Help\ciquery.htm","7/26/2006 9:09:03 AM","ciquery.htm","286.86 KB" "","","Virus identified VBS/Gedza.A","C:\WINDOWS\Help\starter\welcome.htm","7/26/2006 9:09:04 AM","welcome.htm","282.9 KB"
no still can't open regedit


Logfile of HijackThis v1.99.1
Scan saved at 2:30:56 PM, on 7/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\CallWave\IAM.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\regedit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Owner\Desktop\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus7.hpwis.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.4.3.28/aces…s-ob-assets.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.3.0.53/blac…k-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.4.2.30/harv…t-ob-assets.cab
O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.4.2.30/pool…l-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.2.30/mahj…g-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.5.1.24/mlsl…slots-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.4.2.30/hots…k-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.3.1.26/spid…r-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.4.3.28/peak…s-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.4.4.34/word…2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.4.3.28/whac…n-ob-assets.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122319668671
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://198.207.241.9/webline/applets/msie40x.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v46/wof/wof.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98B1C8ED-1091-4B97-8F08-1C006A6248E1}: NameServer = 208.54.220.20 64.91.3.46
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
:scratch:

Reboot in "safe" mode.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All. Click the Empty Selected button.
If you have Firefox, Under Firefox choose: Firefox cookies and Firefox cache. Click the Empty Selected button.
Close the program.

Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds.
Save the logfile from the scan.

Reboot in normal mode.

Post:

1. A new HijackThis! log.

2. The report from Ewido.

into this thread.
:)
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 4:44:07 PM 7/26/2006

+ Scan result:



Nothing found.


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 5:00:29 PM, on 7/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\CallWave\IAM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\Owner\Desktop\coyote forum\hjt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pogo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus7.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus7.hpwis.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - Global Startup: CallWave.lnk = C:\Program Files\CallWave\IAM.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.4.3.28/aces…s-ob-assets.cab
O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.3.0.53/blac…k-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.4.2.30/harv…t-ob-assets.cab
O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.4.2.30/pool…l-ob-assets.cab
O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.4.2.30/mahj…g-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.com/applet-6.5.1.24/mlsl…slots-en_US.cab
O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.4.2.30/popp…a-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.4.2.30/hots…k-ob-assets.cab
O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.3.1.26/spid…r-ob-assets.cab
O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.4.3.28/peak…s-ob-assets.cab
O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.4.4.34/word…2-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.4.3.28/whac…n-ob-assets.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122319668671
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8D83D301-E841-11D1-B155-00600823BCF9} (WebLine Browser Integration Classes) - http://198.207.241.9/webline/applets/msie40x.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v46/wof/wof.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v51/h2hpool/h2hpool.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{98B1C8ED-1091-4B97-8F08-1C006A6248E1}: NameServer = 208.54.220.20 64.91.3.46
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Content Monitoring Tool (msCMTSrvc) - Unknown owner - C:\WINDOWS\system32\msCMTSrvc.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

I think I am trying to run REGEDIT the correct way but tell me again to be sure. I truly apprieciate your time, I know you are trying to help other peeps as well. JULIE
Ewido found no infections. :thumbup:

I assume AVG is quiet now as well.
:unsure:

I was afraid you still had an active infection, but it appears not.

Go to:

Start –> Run

In the box, type regedit, then press or click OK

Alternately, navigate and on:

c:\WINDOWS\regedit.exe

Please run the ff.bat file and post the results again.
:)
Volume in drive C is PRESARIO Volume Serial Number is B08E-8A4B Directory of c:\WINDOWS 08/04/2004 12:56 AM 146,432 regedit.exe 08/04/2004 12:56 AM 146,432 regedit.old.exe 2 File(s) 292,864 bytes Directory of c:\WINDOWS\$NtServicePackUninstall$ 08/29/2002 02:00 PM 134,144 regedit.exe 1 File(s) 134,144 bytes Directory of c:\WINDOWS\Help 08/29/2002 07:00 AM 46,684 regedit.chm 08/29/2002 07:00 AM 12,886 regedit.hlp 2 File(s) 59,570 bytes Directory of c:\WINDOWS\I386 08/29/2002 02:00 PM 39,702 REGEDIT.CH_ 08/29/2002 02:00 PM 134,144 REGEDIT.EXE 08/29/2002 02:00 PM 2,512 REGEDIT.HL_ 3 File(s) 176,358 bytes Directory of c:\WINDOWS\Prefetch 07/26/2006 05:45 PM 15,238 REGEDIT.EXE-2AE3423E.pf 1 File(s) 15,238 bytes Directory of c:\WINDOWS\ServicePackFiles\i386 08/04/2004 12:56 AM 146,432 regedit.exe 1 File(s) 146,432 bytes Directory of c:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\8b5e9cdb91dddbb342695fbdc36fe0e4\backup 08/29/2002 02:00 PM 134,144 regedit.exe 1 File(s) 134,144 bytes Directory of c:\WINDOWS\system32\dllcache 08/04/2004 12:56 AM 146,432 regedit.exe 1 File(s) 146,432 bytes Total Files Listed: 12 File(s) 1,105,182 bytes 0 Dir(s) 27,712,446,464 bytes free
I'd say you copied the right one (from my instructions in a previous post). And I also must assume that neither way of running regedit was successful, or you'd be dancing across the screen about now? :unsure: You don't get any "specific" error messages when trying to run regedit? :scratch:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI