This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Thought I had it all cleared out, but I was wrong...

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So about a week ago, I got hit with a really nasty bug. Thanks to the help I got here, I got rid of it. Well, most of it. There seems to be some remaining problems that I haven't been able to solve with Ad-Aware, Ewido, or SpyBot, so I'm guessing it's something else I'll have to take care of with HJT and/or KillBox. ——- Logfile of HijackThis v1.99.1 Scan saved at 11:26:35 AM, on 7/26/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\WINDOWS\System32\svchost.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\ps2.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\Program Files\MSN\MSNCoreFiles\msn.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\MSNAccel.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Spyware Tools\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022 O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\fgiebar.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_link.htm O8 - Extra context menu item: Update Page Content - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\refreshpage.htm O8 - Extra context menu item: View All Originals On Page - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\getoriginal.htm O8 - Extra context menu item: View Original Image - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\getoriginal.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{1006A85C-A17F-4643-8C98-6A3ECD2D22EB}: NameServer = 209.244.0.3 209.244.0.4 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hello :) There are a couple problems. I'm still getting random IE pop-ups, despite using Firefox as my browser. Also, I keep getting "warnings" that state my computer is infected, and to "click here for a free scan." Funnily enough, these "warnings" are actually pop-ups as well, and, when clicked, a browser window opens to some random website for very generic sounding anti-virus/spyware programs. Obviously, it's not my anti-virus or spyware software "warning" me, but some sort of spyware. Ewido has also detected some stuff that I haven't been able to remove. When it's open, it keeps detecting some sort of malicious program/file, and gives the option to clean, quarantine, etc. However, no matter what option I choose, after the warning closes, it simply opens back up, with the same exact problem. Also, when running an ewido scan in safe mode, it detects several problems that it seems to be unable to fix. Every time I run Ad-Aware and clean all the spyware out that it finds, it all seems to come back as soon as I reboot.
Only for Windows XP and Windows 2000

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named:

c:\rapport.txt

Open that file with Notepad, and "copy/paste" the ENTIRE CONTENTS of it into this thread.
Okay, here's the log from that program: Scan done at 5:53:52.20, Thu 07/27/2006 Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\keyboard1.dat FOUND ! C:\WINDOWS\newname.dat FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ixt?.dll FOUND ! C:\WINDOWS\system32\ixt??.dll FOUND ! C:\WINDOWS\system32\ot.ico FOUND ! C:\WINDOWS\system32\ts.ico FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1 C:\DOCUME~1\Owner\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="C:\\Program Files\\Common Files\\kyzep.html" "SubscribedURL"="" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="C:\\Program Files\\WindowsUpdate\\howymym.html" "SubscribedURL"="" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "cinnamomum"="{93ac7c30-3878-4eaa-9420-7977285df5b1}" »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Clean

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • Click on Scanner
  • Click on Settings
    • Under How to scan all boxes should be checked
    • Under Unwanted Software all boxes should be checked
    • Under What to scan select Scan every file
    • Click on Ok
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put a checkmark in the box next to Create encrypted backup, then choose clean and click Ok.

Once the scan has completed, there will be a button located on the bottom of the screen named Save Report.
  • Click Save Report button
  • Save the report to your Desktop
Close Ewido and Reboot in Normal Mode.
______________________________

Please post:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Alright, thanks for the help! Here are the logs you requested: SmitFraudFix v2.75b Scan done at 7:48:33.89, Thu 07/27/2006 Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "cinnamomum"="{93ac7c30-3878-4eaa-9420-7977285df5b1}" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\keyboard1.dat Deleted C:\WINDOWS\newname.dat Deleted C:\WINDOWS\system32\ixt?.dll Deleted C:\WINDOWS\system32\ot.ico Deleted C:\WINDOWS\system32\ts.ico Deleted C:\DOCUME~1\Owner\FAVORI~1\Antivirus Test Online.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End — ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 11:06:03 AM 7/27/2006 + Scan result: C:\WINDOWS\system32\ddaba.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\ar3.jar-7429efec-2b21974f.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Ignored. :mozilla.30:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.31:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.36:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.38:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.39:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.149:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Adviva : Cleaned. :mozilla.16:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.134:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.135:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.136:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.174:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.13:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.128:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.129:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.130:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.131:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.94:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.95:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.96:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.66:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.6:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.7:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.139:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.140:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.167:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.168:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.169:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.170:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.120:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.121:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.122:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.123:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.124:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.125:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.126:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.127:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.61:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.63:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.64:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.160:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.161:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.162:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\xrkt6mox.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. ::Report end — Logfile of HijackThis v1.99.1 Scan saved at 11:10:57 AM, on 7/27/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\WINDOWS\System32\svchost.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\ps2.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Spyware Tools\HijackThis\HijackThis.exe C:\Program Files\MSN\MSNCoreFiles\msn.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022 O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\fgiebar.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_link.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
The log is free of any "malware". :thumbup:

I do see "Viewpoint Manager" in there.

Some consider it to be "spyware".

There's a post somewhere on this site about their announcement to gather more information about the machines the software is installed on, I beleieve. I can check that if you want.

"Viewpoint Manager" can be uninstalled via "Add/Remove Programs" (reboot afterwards to complete the uninstall). It's not a "fundamental" program required for the operation of your machine.

How's the machine running?
:unsure:
Great, I appreciate the help :) I guess somewhere along the line, I got rid of it. I have yet to see any pop-ups or "warnings" since I completed all the steps you gave me, so it looks like I'm in the clear. Everything seems to be running fine, as of now. The first time you helped me out, the really bad problems, like getting booted off the internet frequently, and everything slowing to a crawl while two dozen IE windows popping up one after another, were cleared. Now it looks like you've helped me get rid of the supremely annoying remnants. Thanks again for all your help, it's much appreciated! EDIT: Nevermind… see below.
Ah carp**, hold the presses. Ironically enough, immediately after closing the window in which I posted my last reply, about 20 IE pop-ups slammed my computer. I tried closing them, then CTRL-ALT-DEL to close IE, but I couldn't, they just kept opening. I really don't know what is going on, everything had seemed fine up until that point.

Upon restarting, also, the following came up:
[external image: Posted Image]

This has come up before, and when I click "clean," and the ewido window closes, it immediately pops back up. I'm stumped.
Rename this file (HijackThis):

C:\Program Files\Spyware Tools\HijackThis\HijackThis.exe

to

C:\Program Files\Spyware Tools\HijackThis\letmebe.exe

Reboot.

Run it and post another log file, into this thread.

"Virtumonde" isn't showing in your present log.

You must have the variant that "hides" from HijackThis!

Renaming it, and rebooting should make it reveal itself.

:)
Alright, here goes: Logfile of HijackThis v1.99.1 Scan saved at 3:21:44 PM, on 7/27/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\WINDOWS\System32\svchost.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\ps2.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Spyware Tools\HijackThis\letmebe.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022 O2 - BHO: (no name) - {7BDE2364-3236-4E06-9015-8E1A3C5285F2} - C:\WINDOWS\system32\ddaba.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\jccatch.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\fgiebar.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_link.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: ddaba - C:\WINDOWS\system32\ddaba.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
And Virtumonde rears it's ugly head:

O2 - BHO: (no name) - {7BDE2364-3236-4E06-9015-8E1A3C5285F2} - C:\WINDOWS\system32\ddaba.dll

O20 - Winlogon Notify: ddaba - C:\WINDOWS\system32\ddaba.dll

Download VundoFix.exe to your desktop from here:

VundoFix.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

1. Double-click VundoFix.exe to run it.
2. Click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. You will receive a prompt asking if you want to remove the files, click YES.
5. Once you click yes, your desktop will go blank as it starts removing Vundo.
6. When completed, it will prompt that it will shutdown your computer, click OK.
7. Turn your computer back on.

Post a new HijackThis! log, along with the contents of this file:

C:\vundofix.txt


into this thread.
:)
Man, this is a sutbborn little bugger! Logfile of HijackThis v1.99.1 Scan saved at 4:13:10 PM, on 7/27/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Softex\OmniPass\Omniserv.exe C:\WINDOWS\System32\svchost.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\ps2.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\MSN\MSNCoreFiles\msn.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\logonmgr.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\msncc.exe C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\MSNAccel.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Spyware Tools\HijackThis\letmebe.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9022 O2 - BHO: (no name) - {069EF646-B3A1-4134-B7C4-6535727DCDBC} - C:\WINDOWS\system32\ddaba.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\jccatch.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\fgiebar.dll O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\Mozilla Firefox\extensions\FlashGet\jc_link.htm O8 - Extra context menu item: Update Page Content - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\refreshpage.htm O8 - Extra context menu item: View All Originals On Page - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\getoriginal.htm O8 - Extra context menu item: View Original Image - C:\Program Files\MSN\MSNIA\CC\MSNCC\WA\getoriginal.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\MOZILL~1\EXTENS~1\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{1006A85C-A17F-4643-8C98-6A3ECD2D22EB}: NameServer = 209.244.0.3 209.244.0.4 O20 - Winlogon Notify: ddaba - C:\WINDOWS\system32\ddaba.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe — VundoFix V5.1.5 Checking Java version… Scan started at 3:59:21 PM 7/27/2006 Listing files found while scanning…. C:\windows\system32\ddaba.dll C:\windows\system32\abadd.ini C:\windows\system32\abadd.bak1 C:\windows\system32\abadd.bak2 C:\windows\system32\abadd.ini2 Beginning removal… The process smss.exe could not be stopped Vundofix may not be able to delete some files that were found. The process winlogon.exe could not be stopped Vundofix may not be able to delete some files that were found. The process explorer.exe was successfully stopped The process iexplore.exe was successfully stopped The process rundll32.exe was successfully stopped Attempting to delete C:\windows\system32\ddaba.dll C:\windows\system32\ddaba.dll Could not be deleted. Attempting to delete C:\windows\system32\abadd.ini C:\windows\system32\abadd.ini Has been deleted! Attempting to delete C:\windows\system32\abadd.bak1 C:\windows\system32\abadd.bak1 Has been deleted! Attempting to delete C:\windows\system32\abadd.bak2 C:\windows\system32\abadd.bak2 Has been deleted! Attempting to delete C:\windows\system32\abadd.ini2 C:\windows\system32\abadd.ini2 Has been deleted! Performing Repairs to the registry. Done!

Attempting to delete C:\windows\system32\ddaba.dll
C:\windows\system32\ddaba.dll Could not be deleted.

A stubborn little bugger, indeed!!!
:rant:

Download this file:

Combofix.exe

And save it to your desktop. <– VERY IMPORTANT!!!

Go to Start –> Run and copy/paste in the following:

"%userprofile%\desktop\combofix.exe" /v ddaba

Then hit or click OK.

When finished, it shall produce a log for you. Post that log in your next reply, along with a new HijackThis! log.
:)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI