This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HiJack issue

41 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

splat

Looking better

Please go here to upload a
suspicious file for analysis.
  • Enter your username from this forum
  • Copy and paste the link to this thread
  • Browse for this filename: C:\WINDOWS\System32\drivers\spoolsv.dll
  • In the comments, please mention that I asked you to upload this file
  • Click on Send File
Thanks

Next Re Run Hijackthis and place checks beside the following entriesR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
O2 - BHO: Spoolsv Class - {9C363D55-07D7-433d-A13E-D9C105202F6F} - C:\WINDOWS\System32\drivers\spoolsv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE2\Update.exe

Close all other open windows except Hijackthis and Select "Fix checked"

Next Using Windows Explorer(Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate and delete the following folderC:\Program Files\Common Files\UPDATE2
Locate and delete the following fileC:\WINDOWS\System32\drivers\spoolsv.dll
Close Windows explorer ->> Reboot your PC
Next Run an online virus scan called Kaspersky from HERE.1. Click on "Kaspersky Online Scanner"
2. A new smaller window will pop up. Press on "Accept". After reading the contents.
3. Now Kaspersky will update the anti-virus database. Let it run.
4. Click on "Next"->>"Scan Settings", and make sure the database is set to "extended". And check both the scan options. Then click OK.
5. Then click on "My Computer". And the scan will start.
6. Once finished, save a log as ".txt" to the desktop.
Copy and post the results of the Kaspersky Online scan

thanks
Sorry it took so long to reply, i've been caught us with alot of work. But here's the Kaspersky report: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Friday, September 29, 2006 9:56:56 AM Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 28/09/2006 Kaspersky Anti-Virus database records: 227072 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 26888 Number of viruses found: 25 Number of infected objects: 63 / 0 Number of suspicious objects: 0 Duration of the scan process: 00:29:18 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\IEHelper\IEHelper_5104.dll Infected: not-a-virus:AdWare.Win32.IEHlpr.q skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02680001.VBN Infected: Worm.Win32.Viking.ae skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\030C0000.VBN Infected: Worm.Win32.Viking.ae skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\036C0000.VBN Infected: Worm.Win32.Viking.ae skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0000.VBN/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0000.VBN/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0000.VBN ZIP: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0000.VBN CryptZ: infected - 2 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0002.VBN/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0002.VBN/Counter.class Infected: Trojan.Java.ClassLoader.h skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0002.VBN/Parser.class Infected: Trojan.Java.ClassLoader.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0002.VBN ZIP: infected - 3 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\045C0002.VBN CryptZ: infected - 3 skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04780000.VBN Infected: Virus.Win32.Parite.a skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04980000.VBN Infected: Virus.Win32.Parite.a skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\070C0000.VBN Infected: Worm.Win32.Viking.ae skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07300000.VBN Infected: Worm.Win32.Viking.j skipped C:\Documents and Settings\All Users\Templates\temp.exe/data0003 Infected: Trojan-Downloader.Win32.QQHelper.km skipped C:\Documents and Settings\All Users\Templates\temp.exe/data0004 Infected: Trojan-Downloader.Win32.QQHelper.km skipped C:\Documents and Settings\All Users\Templates\temp.exe NSIS: infected - 2 skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\1001hkcmd[2].txt Infected: Trojan-Downloader.Win32.Agent.ayd skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\1001hkcmd[3].txt Infected: Trojan-Downloader.Win32.Agent.ayd skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\bizG2[2].txt/data0004 Infected: not-a-virus:AdWare.Win32.BHO.ag skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\01234567\bizG2[2].txt NSIS: infected - 1 skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\43242new[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\bizG2[2].txt/data0004 Infected: not-a-virus:AdWare.Win32.BHO.ag skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\bizG2[2].txt NSIS: infected - 1 skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\89ABCDEF\GIMM1091[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\1018[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\2014hkcmd[1].txt Infected: Trojan-Downloader.Win32.Agent.ayd skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\ads[1].htm Infected: Trojan-Downloader.VBS.Psyme.cl skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\counter[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\searchcar[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\Setup5018[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\13663[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\2006[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\bind_40123[1].txt Infected: Trojan-Downloader.Win32.Small.duy skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OPQRSTUV\in[1].htm Infected: Trojan-Downloader.VBS.Psyme.cm skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Templates\5fbcb5c\2.exe Infected: not-a-virus:AdWare.Win32.Dm.q skipped C:\Documents and Settings\LocalService\Templates\5fbcb5c\3.dll Infected: not-a-virus:AdWare.Win32.Dm.s skipped C:\Documents and Settings\LocalService\Templates\5fbcb5c\4.dll Infected: not-a-virus:AdWare.Win32.Dm.t skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\history.dat Object is locked skipped C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\parent.lock Object is locked skipped C:\Documents and Settings\Patrick\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms0311.jar-72fd87ac-4bfe71df.zip/Installer.class Infected: Trojan-Downloader.Java.Agent.a skipped C:\Documents and Settings\Patrick\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ms0311.jar-72fd87ac-4bfe71df.zip ZIP: infected - 1 skipped C:\Documents and Settings\Patrick\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Patrick\Desktop\Hihack this\backups\backup-20060928-213558-747.dll Infected: not-a-virus:AdWare.Win32.BHO.ag skipped C:\Documents and Settings\Patrick\Desktop\programs\bsplayer210[1].939_clip.exe/data0011 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped C:\Documents and Settings\Patrick\Desktop\programs\bsplayer210[1].939_clip.exe NSIS: infected - 1 skipped C:\Documents and Settings\Patrick\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\Application Data\Mozilla\Firefox\Profiles\22sxn025.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\History\History.IE5\MSHist012006092920060930\index.dat Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\ILBCXCZ2\mr[1] Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\ILBCXCZ2\mr[2] Object is locked skipped C:\Documents and Settings\Patrick\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Patrick\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Patrick\NTUSER.DAT.LOG Object is locked skipped C:\Documents and Settings\Patrick\Templates\5fbcb5c\4.dll Infected: not-a-virus:AdWare.Win32.Dm.t skipped C:\Program Files\Internet Explorer\hmmapi.exe Infected: Trojan.Win32.Agent.zl skipped C:\Program Files\Internet Explorer\iedw.dll Infected: Trojan.Win32.Agent.zl skipped C:\Program Files\Windows Media Player\iedw.exe Infected: Trojan.Win32.Agent.zl skipped C:\Program Files\Windows Media Player\setup_wm.dll Infected: Trojan.Win32.Agent.zl skipped C:\WINDOWS\daemon.exe Infected: Trojan-Downloader.Win32.Agent.ayd skipped C:\WINDOWS\Debug\oakley.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\WINDOWS\system32\inetsrv\csrss.exe Infected: Backdoor.Win32.Delf.auu skipped C:\WINDOWS\system32\inetsrv\Update\BoExplorer.rar/csrss.exe Infected: Backdoor.Win32.Delf.auu skipped C:\WINDOWS\system32\inetsrv\Update\BoExplorer.rar ZIP: infected - 1 skipped C:\WINDOWS\system32\mssapi.dll Infected: Trojan-Downloader.Win32.QQHelper.km skipped C:\WINDOWS\system32\mysvcc.exe Infected: Backdoor.Win32.Rbot.bjp skipped C:\WINDOWS\system32\oobe\data\dbisam.lck Object is locked skipped C:\WINDOWS\system32\oobe\data\DownFileList.blb Object is locked skipped C:\WINDOWS\system32\oobe\data\DownFileList.dat Object is locked skipped C:\WINDOWS\system32\oobe\data\DownFileList.idx Object is locked skipped C:\WINDOWS\system32\oobe\data\ShareFileList.dat Object is locked skipped C:\WINDOWS\system32\oobe\data\ShareFileList.idx Object is locked skipped C:\WINDOWS\system32\oobe\data\Users.dat Object is locked skipped C:\WINDOWS\system32\oobe\data\Users.idx Object is locked skipped C:\WINDOWS\system32\repair\IECWM\hkcmd.exe Infected: Trojan-Downloader.Win32.Agent.ayd skipped C:\WINDOWS\system32\repair\IECWM\nerochk.exe Infected: Trojan.Win32.Agent.tl skipped C:\WINDOWS\system32\repair\IECWM\update\hkcmd.exe Infected: Trojan-Downloader.Win32.Agent.ayd skipped C:\WINDOWS\system32\Setup_silent_mms_ad.exe/data0003 Infected: not-a-virus:AdWare.Win32.Boran.o skipped C:\WINDOWS\system32\Setup_silent_mms_ad.exe/data0009 Infected: not-a-virus:AdWare.Win32.Boran.c skipped C:\WINDOWS\system32\Setup_silent_mms_ad.exe NSIS: infected - 2 skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped Scan process completed.
Bamajim i'm a bit curious… i've been using spybot for ages and it picks things up really good as far as i know. In your opinion is it enough to just have that as a scanner for spywares? you've shown me ewido and tat seems to pick alot more than spybot…is that because it's a licensed program? Splat
splat

To answer your question, SpybotSD is a great program, remember to update it before you use it each time as infection definitions change daily.
But it is only one tool, and there are a couple of others that need to be used in conjunction with SpybotSD for total protection. We will make recommendations in closing.

Now You need to Open Norton AV and empty the quarantine folder.

Next Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

This will remove all files from the items that are checked so if you have some cookies you'd like to save. please move them to a different directory first.

Next Download win32delfkil.exe.
Save it on your desktop. Close all windows.
Double click on win32delfkil.exe to start the removaltool.
The computer will reboot automatically.
After reboot a logfile will open: c:\windelf.txt
Post the contents of the logfile, along with a new HijackThislog
thanks bamajim
WIN32DELFKIL LOGFILE - by Marckie version 3.04 Fri 29/09/2006 23:25:29.37 running from: "C:\Documents and Settings\Patrick\Desktop" — File(s) found in Windows directory — — File(s) found in system32 folder — — Export SharedTaskScheduler key — REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" — Notify key — — rebooting the computer — — File(s) found in Windows directory — — File(s) found in system32 folder — — Export SharedTaskSchedulerkey — REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" — Notify key — Finished!
Logfile of HijackThis v1.99.1
Scan saved at 11:29:04 PM, on 29/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\System32\Svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\SYSTEM32\RUNDLL.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\WINDOWS\System32\svchost.exe
c:\windows\system32\wbem\smss.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\mysvcc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe
C:\WINDOWS\system32\net.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7322.com/
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [mysvcig38] mysvcc.exe
O4 - HKLM\..\RunServices: [mysvcig38] mysvcc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
splat

Good Job so far :)

1) Please download the Killbox.
Save it to the desktop and run it.

2) Select "Delete on Reboot", and then select "All files".

3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:C:\WINDOWS\System32\mysvcc.exe
4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

5) Click the red-and-white "Delete File" button.  Click "Yes" at the Delete on Reboot prompt.  Click "No" at the Pending Operations prompt.

Next Re Run Hijackthis and place checks beside the following entriesO2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O4 - HKLM\..\Run: [mysvcig38] mysvcc.exe
O4 - HKLM\..\RunServices: [mysvcig38] mysvcc.exe

Close all other open windows except Hijackthis and Select "Fix checked"

Next Using Windows Explorer

Locate and delete the following foldersC:\Documents and Settings\All Users\Templates\temp.exe
C:\Documents and Settings\LocalService\Templates\5fbcb5c
C:\Documents and Settings\Patrick\Desktop\programs\bsplayer210[1].939_clip.exe

Locate and delete the following filesC:\Program Files\Internet Explorer\hmmapi.exe
C:\Program Files\Internet Explorer\iedw.dll
C:\WINDOWS\system32\mssapi.dll

Close Windows explorer->>Reboot your PC->>Re run Hijackthis and post a fresh Hijackthis log

thanks bamajim
here's the new hjt log:::


Logfile of HijackThis v1.99.1
Scan saved at 6:27:40 PM, on 30/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\System32\Svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\SYSTEM32\RUNDLL.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsgSys.EXE
c:\windows\system32\wbem\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\WordWeb\wweb32.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7322.com/
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: BHOImp Class - {70AFF2CB-9DA2-499C-8D15-900729FCE83D} - C:\WINDOWS\system32\YHBO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: PestPatrol Remote - Computer Associates International, Inc. - C:\Program Files\Common Files\PestPatrol\ppRemoteService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
splat

Well done, now let's see if we can get rid of that stubborn 02

Go HERE and Download System Repair Engine by small frogSave it to your Desktop
Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
Open the sreng folder
Double click SREng->>Click Run
At the main Window, in the left Pane,Select Smart Scan
At the next window make sure all of the boxes are checked and Select Scan
When the scan is complete Select Save reports
Save it to your desktop and Close the tool
Double Click SREngLog.txt copy and paste that log as a reply to this thread
Do not run any other options with this tool unless instructed to do so.

Thanks bamjaim
hope this helps. 2006-10-02,01:56:41 System Repair Engineer 2.2.6.605 Smallfrogs (http://www.KZTechs.com) Windows XP Professional Service Pack 1 (Build 2600) - Administrative User - Completed Functions Allowed Follow item(s) have been choosed: All Boot Items (Including Registry, Startup Folders, Services and so on) Browser Add-ons Runing Processes (Including process model information) File Associations Winsock Provider Autorun.Inf HOSTS File Boot Items Registry [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] [(Verified)Microsoft Corporation] <"C:\Program Files\MSN Messenger\msnmsgr.exe" /background> [Microsoft Corporation] [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [N/A] <"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.] <"C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized> [Anti-Malware Development a.s.] [N/A] [N/A] [N/A] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices] [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Corporation] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] <> [N/A] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] <{57B86673-276A-48B2-BAE7-C6DBB3020EB8}> [Anti-Malware Development a.s.] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] [MSWebwork Cop.] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon] [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; C:\Program Files\CNNIC\Cdn\cdnup.exe> [N/A] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; C:\Program Files\HP\HP Software Update\HPWuSchd2.exe> [Hewlett-Packard Co.] <; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32> [(Verified)Microsoft Corporation] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; C:\Program Files\IDA\ida.exe -autorun> [N/A] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; mssvcc.exe> [N/A] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [Microsoft Corporation] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] <; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC> [(Verified)N/A] <; mysvcc.exe> [N/A] <; C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh] <; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName> [(Verified)Microsoft Corporation] <; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC> [(Verified)Microsoft Corporation] <; "C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.] <; "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"> [Sun Microsystems, Inc.] <; C:\Program Files\NavNT\vptray.exe> [Symantec Corporation] <; VTTimer.exe> [(Verified)S3 Graphics, Inc.] <; winystems.exe> [N/A] <; C:\WINDOWS\system32\ymssmsgs.exe> [N/A] ================================== Startup Folders [WordWeb] C:\PROGRA~1\WordWeb\wweb32.exe [Antony Lewis]> ================================== Services [ASP.NET Work State Service / aspwstate] c:\windows\system32\aspwswin.dll> [Remote Route Service / AtWork] C:\WINDOWS\System32\mssapi.dll> [CA License Client / CA_LIC_CLNT] [COM+ Event System Helper / COMEventHelper] c:\windows\system32\comeventhelper.dll> [DefWatch / DefWatch] [Distributed Logical Disks Manager / DistriDiskMan] c:\windows\system32\wuwebldsv.dll> [ewido anti-spyware 4.0 guard / ewido anti-spyware 4.0 guard] [Human Interface Device Access / HidServ] %SystemRoot%\System32\hidserv.dll> [JMediaService / JMediaService] [Event Log Watch / LogWatch] [MessageService / MessageService] C:\WINDOWS\System32\MsServices\svchost.dll> [WinDDE Service / NetDisDDE] c:\windows\system32\netwindde.dll> [NetFrame Wireless Configuration / NFSWZCSVC] c:\windows\system32\nfswzwin32.dll> [Norton AntiVirus Client / Norton AntiVirus Server] [Pml Driver HPZ12 / Pml Driver HPZ12] ================================== Drivers [Albus / Albus] <\SystemRoot\System32\drivers\Albus.SYS> [ewido anti-spyware 4.0 driver / ewido anti-spyware 4.0 driver] <\??\C:\Program Files\ewido anti-spyware 4.0\guard.sys> [GMSIPCI / GMSIPCI] <\??\D:\INSTALL\GMSIPCI.SYS> [IEEE-1284.4 Driver HPZid412 / HPZid412] [Print Class Driver for IEEE-1284.4 HPZipr12 / HPZipr12] [USB to IEEE-1284.4 Translation Driver HPZius12 / HPZius12] [NAVAP / NAVAP] <\??\C:\Program Files\NavNT\NAVAP.sys> [NAVAPEL / NAVAPEL] <\??\C:\Program Files\NavNT\NAVAPEL.SYS> [NAVENG / NAVENG] <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060927.018\NAVENG.sys> [NAVEX15 / NAVEX15] <\??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060927.018\NAVEX15.sys> [nwlnksipx / nwlnksipx] <\??\C:\WINDOWS\System32\drivers\nwlnksipx.sys> [nwupspx / nwupspx] <\SystemRoot\System32\drivers\nwupspx.sys> [ProcServ / ProcServ] <\??\C:\WINDOWS\System32\drivers\ProcServ.sys> [Direct Parallel Link Driver / Ptilink] [PxHelp20 / PxHelp20] <\SystemRoot\System32\Drivers\PxHelp20.sys> [RegGuard / RegGuard] <\??\C:\WINDOWS\System32\Drivers\regguard.sys> [Realtek RTL8139/810x/8169/8110 all in one NDIS XP Driver / RTL8023xp] [Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139] [Secdrv / Secdrv] [SymEvent / SymEvent] <\??\C:\Program Files\Symantec\SYMEVENT.SYS> [VIA AGP Filter / viaagp1] <\SystemRoot\System32\DRIVERS\viaagp1.sys> [viagfx / viagfx] ================================== Browser Add-ons [HelperObject Class] {00C6482D-C502-44C8-8409-FCE54AD9C208} [Adobe PDF Reader Link Helper] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [SYM] {36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} [] {53707962-6F74-2D53-2644-206D7942484F} [CdnForIE Class] {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} [Vision] {6671A431-5C3D-463d-A7CF-5587F9B7E191} [SSVHelper Class] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [DDOC] {A64E86D2-203D-4145-AA9B-2425BAF568E9} [Java Plug-in 1.5.0_08] {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [] {1D901067-2529-4A9B-9B6B-7A1DB3A44CB5} [CdnForIE Class] {5C3853CF-C7E0-4946-B3FA-1ABDB6F48108} [MMSAssistMenu] {6671A433-5C3D-463d-A7CF-5587F9B7E191} [&Research] {92780B25-18CC-41C8-B9BE-3C9C571A8263} [@shdoclc.dll,-866] {c95fe080-8f5d-11d2-a20b-00aa003c157a} <, N/A> [&Radio] {8E718888-423F-11D2-876E-00A0C9082467} [FlashGet Bar] {E0E899AB-F487-11D5-8D29-0050BA6940E3} [SnagIt] {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} [QuickTime Object] {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [CKAVWebScan Object] {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} [Shockwave ActiveX Control] {166B1BCA-3F9C-11CF-8075-444553540000} [Windows Genuine Advantage Validation Tool] {17492023-C23A-453E-A040-C7C580BBF700} [Java Plug-in 1.5.0_08] {8AD9C840-044E-11D1-B3E9-00805F499D93} [Java Plug-in 1.5.0_08] {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} [Java Plug-in 1.5.0_08] {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [Shockwave Flash Object] {D27CDB6E-AE6D-11CF-96B8-444553540000} [>>²ÊÐÅ·¢ËÍ<<] [Download All by FlashGet] [Download using FlashGet] ================================== Running Processes [PID: 432][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)] [PID: 488][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 512][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)] [C:\WINDOWS\System32\NavLogon.dll] [N/A, N/A] [PID: 564][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 576][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)] [PID: 752][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 804][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 908][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 992][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1108][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)] [C:\WINDOWS\system32\HpTcpMon.dll] [Hewlett Packard, 5.01.00.011] [C:\WINDOWS\system32\hpzjrd01.dll] [Hewlett Packard, 2.01.00.001] [C:\WINDOWS\system32\HPTcpMUI.dll] [Microsoft Corporation, 5.01.00.011] [C:\WINDOWS\system32\hptcpmib.dll] [Hewlett Packard, 5.01.00.011] [C:\WINDOWS\system32\hpz3l3xu.dll] [Hewlett-Packard Company, 60.051.644.00] [C:\WINDOWS\System32\spool\PRTPROCS\W32X86\hpzpp3xu.dll] [Hewlett-Packard Corporation, 60.051.644.00] [PID: 1220][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1236][C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe] [Computer Associates International Inc., 0, 1, 3, 1] [C:\Program Files\CA\SharedComponents\CA_LIC\licdscvr.dll] [Computer Associates International Inc., 0, 0, 1, 7] [C:\Program Files\CA\SharedComponents\CA_LIC\licencrypt.dll] [Computer Associates International Inc., 0, 0, 1, 7] [C:\Program Files\CA\SharedComponents\CA_LIC\lic98.dll] [Computer Associates, 01.61.0] [PID: 1264][C:\Program Files\NavNT\defwatch.exe] [Symantec Corporation, 7.60.00.926] [PID: 1308][C:\Program Files\ewido anti-spyware 4.0\guard.exe] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\Program Files\ewido anti-spyware 4.0\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [PID: 1324][C:\WINDOWS\System32\rundll32.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [C:\PROGRA~1\MMSASS~1\MMSSVER.DLL] [, 1, 2, 0, 6] [PID: 1360][C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe] [Computer Associates, 1.52] [C:\Program Files\CA\SharedComponents\CA_LIC\lic98.dll] [Computer Associates, 01.61.0] [PID: 1380][C:\WINDOWS\System32\Svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [c:\windows\system32\msservices\svchost.dll] [N/A, N/A] [c:\windows\system32\msservices\MsService.dll] [, 1, 0, 0, 1] [c:\windows\system32\msservices\unreg1.dll] [N/A, N/A] [c:\windows\system32\msservices\OldUnReg.dll] [N/A, N/A] [PID: 1504][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1516][C:\Program Files\NavNT\rtvscan.exe] [Symantec Corporation, 7.60.00.926] [C:\Program Files\NavNT\Dec2.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2ARJ.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2ID.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2LHA.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\SymLHA.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2LZ.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2MIME.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2Zip.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2AMG.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\SYMAMG32.DLL] [Symantec Corporation with portions by FUJITSU DEVICES INC., 2.50.31.52] [C:\Program Files\NavNT\Dec2UUE.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2SS.dll] [Symantec Corporation, 2.50.31.52] [C:\Program Files\NavNT\Dec2RTF.dll] [Symantec Corporation, 2.50.31.52] [C:\WINDOWS\System32\CBA.DLL] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\MsgSys.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\NTS.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\PDS.DLL] [Intel Corporation, 6.0.201.0940 E] [C:\Program Files\NavNT\NAVLU.dll] [Symantec Corporation, 7.60.00.926] [C:\Program Files\NavNT\NAVNTUTL.DLL] [Symantec/Peter Norton Group, 1, 0, 0, 1] [C:\Program Files\NavNT\i2ldvp3.dll] [Symantec Corporation, 7.60.00.926] [C:\Program Files\NavNT\NAVAPI32.DLL] [Symantec Corp., 4.1.0.15] [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060927.018\NAVEX32a.DLL] [Symantec Corporation, 20061.2.0.26] [C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060927.018\NAVENG32.DLL] [Symantec Corporation, 20061.2.0.26] [C:\Program Files\NavNT\NAVAP32.DLL] [Symantec Corporation, 5.3.1.39] [C:\WINDOWS\System32\amslib.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\loc32vc0.dll] [Intel, 3, 0, 0, 2] [PID: 1548][C:\WINDOWS\system32\HPZipm12.exe] [HP, 9, 0, 0, 0] [PID: 1588][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)] [PID: 1808][C:\WINDOWS\System32\MsgSys.EXE] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\NTS.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\CBA.DLL] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\MsgSys.dll] [Intel Corporation, 6.0.201.0940 E] [C:\WINDOWS\System32\PDS.DLL] [Intel Corporation, 6.0.201.0940 E] [PID: 1876][c:\windows\system32\wbem\winlogon.exe] [Microsoft, 1.0.0.0] [PID: 684][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)] [C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [C:\WINDOWS\webwork\webwork.nls] [MSWebwork Cop., 1, 0, 0, 1] [C:\Program Files\Unlocker\UnlockerCOM.dll] [N/A, N/A] [C:\Program Files\WinRAR\rarext.dll] [N/A, N/A] [C:\Program Files\TechSmith\SnagIt 8\SnagItShellExt.dll] [TechSmith Corporation, 1.0.2.0] [C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll] [Symantec Corporation, 7.60.00.926] [C:\Program Files\ewido anti-spyware 4.0\context.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\WINDOWS\System32\usercrd.dll] [, 1, 0, 0, 1] [C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 7.0.0.0] [PID: 1252][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)] [PID: 1576][C:\Program Files\Unlocker\UnlockerAssistant.exe] [N/A, N/A] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [PID: 1568][C:\Program Files\QuickTime\qttask.exe] [Apple Computer, Inc., 7.1] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [C:\WINDOWS\System32\QuickTime.qts] [Apple Computer, Inc., 5.0.2] [C:\WINDOWS\system32\QuickTime\QuickTimeEssentials.qtx] [Apple Computer, Inc., 5.0.2] [C:\WINDOWS\system32\QuickTime\QuickTimeInternetExtras.qtx] [Apple Computer, Inc., 5.0.1] [C:\WINDOWS\system32\QuickTime\QuickTimeStreaming.qtx] [Apple Computer, Inc., 5.0.2] [C:\WINDOWS\system32\QuickTime\QuickTimeStreamingExtras.qtx] [Apple Computer, Inc., 5.0.1] [C:\WINDOWS\system32\QuickTimeVR.qtx] [Apple Computer, Inc, 5.0.2] [PID: 1580][C:\Program Files\ewido anti-spyware 4.0\ewido.exe] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\Program Files\ewido anti-spyware 4.0\engine.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [PID: 1640][C:\Program Files\Winamp\winampa.exe] [N/A, N/A] [C:\Program Files\Winamp\NSCRT.dll] [Nullsoft, Inc., 7.10.0000] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [PID: 1748][C:\Program Files\CNNIC\Cdn\cdnup.exe] [, 2, 4, 0, 3] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [PID: 1780][C:\Program Files\Common Files\UPDATE2\Update.exe] [N/A, N/A] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [PID: 1804][C:\Program Files\MSN Messenger\msnmsgr.exe] [Microsoft Corporation, 8.0.0812.00] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [C:\WINDOWS\System32\devenum.dll] [N/A, N/A] [C:\WINDOWS\System32\msdmo.dll] [N/A, N/A] [PID: 1044][C:\Program Files\WordWeb\wweb32.exe] [Antony Lewis, 4.0.0.0] [C:\WINDOWS\wweb32.dll] [Antony Lewis, 4.0.0.0] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [PID: 188][C:\Program Files\BitComet\BitComet.exe] [www.BitComet.com, 0.56.] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [PID: 2196][C:\Program Files\Azureus\Azureus.exe] [Aelitis, 1.0.0.0] [c:\program files\java\jre1.5.0_08\bin\client\jvm.dll] [Sun Microsystems, Inc., 5.0.80.3] [c:\program files\java\jre1.5.0_08\bin\hpi.dll] [Sun Microsystems, Inc., 5.0.80.3] [c:\program files\java\jre1.5.0_08\bin\verify.dll] [Sun Microsystems, Inc., 5.0.80.3] [c:\program files\java\jre1.5.0_08\bin\java.dll] [Sun Microsystems, Inc., 5.0.80.3] [c:\program files\java\jre1.5.0_08\bin\zip.dll] [Sun Microsystems, Inc., 5.0.80.3] [C:\Program Files\Java\jre1.5.0_08\bin\net.dll] [Sun Microsystems, Inc., 5.0.80.3] [C:\Program Files\Azureus\aereg.dll] [N/A, N/A] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [C:\Program Files\Java\jre1.5.0_08\bin\management.dll] [Sun Microsystems, Inc., 5.0.80.3] [C:\Program Files\Java\jre1.5.0_08\bin\nio.dll] [Sun Microsystems, Inc., 5.0.80.3] [C:\Program Files\Azureus\swt-win32-3232.dll] [Eclipse Foundation, 3.232] [C:\Program Files\Java\jre1.5.0_08\bin\awt.dll] [Sun Microsystems, Inc., 5.0.80.3] [C:\Program Files\Java\jre1.5.0_08\bin\jpeg.dll] [Sun Microsystems, Inc., 5.0.80.3] [C:\Program Files\Java\jre1.5.0_08\bin\cmm.dll] [Eastman Kodak Company, 1.1.0] [PID: 2096][C:\WINDOWS\System32\mysvcc.exe] [N/A, N/A] [PID: 2448][C:\Program Files\Mozilla Firefox\firefox.exe] [Mozilla Corporation, 1.8.0.7: 2006090918] [C:\Program Files\Mozilla Firefox\js3250.dll] [Netscape Communications Corporation, 4.0] [C:\Program Files\Mozilla Firefox\nspr4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\Mozilla Firefox\xpcom_core.dll] [Mozilla Foundation, 1.8.0.7: 2006090918] [C:\Program Files\Mozilla Firefox\plc4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\Mozilla Firefox\plds4.dll] [Netscape Communications Corporation, 4.6.1] [C:\Program Files\Mozilla Firefox\smime3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\Mozilla Firefox\nss3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\Mozilla Firefox\softokn3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\Mozilla Firefox\ssl3.dll] [Netscape Communications Corporation, 3.10.2] [C:\Program Files\Mozilla Firefox\xpcom_compat.dll] [Mozilla Foundation, 1.8.0.7: 2006090918] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] [C:\Program Files\Mozilla Firefox\components\jar50.dll] [Mozilla Foundation, 1.8.0.7: 2006090918] [C:\Program Files\Mozilla Firefox\nssckbi.dll] [Netscape Communications Corporation, 1.53] [C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll] [Anti-Malware Development a.s., 4, 0, 0, 172] [PID: 2592][C:\Documents and Settings\Patrick\Desktop\SREng\SREng.exe] [Smallfrogs Studio, 2.2.6.605] [C:\Program Files\Unlocker\UnlockerHook.dll] [N/A, N/A] ================================== File Associations .TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1] .EXE OK. ["%1" %*] .COM OK. ["%1" %*] .PIF OK. ["%1" %*] .REG OK. [regedit.exe "%1"] .BAT OK. ["%1" %*] .SCR OK. ["%1" /S] .CHM OK. ["C:\WINDOWS\hh.exe" %1] .HLP OK. [%SystemRoot%\System32\winhlp32.exe %1] .INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1] .VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*] .LNK OK. [{00021401-0000-0000-C000-000000000046}] ================================== Winsock Provider N/A ================================== Autorun.Inf N/A ================================== HOSTS File 127.0.0.1 localhost ==================================
splat

Sorry for the delay I had to do some research. The infection that you have is of Chinese origin. Good job so far

You should print out these instructions for reference

We Need to make another batch file

First Copy and paste the following into NotePad (Not Wordpad)sc stop JMediaService
sc stop MessageService

Click File ->>Save as ->>type in 023.batUnder "Save as type" Select "all files" ->>Save it to your Desktop
Close Notepad
The 023.bat file should now appear on your Desktop
Double Click that file (It will appear that nothing has happened, but that's o.k.)
We are going to delete files and folders, some of these we have deleted before, and some are new. But go through the whole list to make sure they have not reloaded.

Next Using Windows Search (Click Start->>Search) Making sure your search includes looking in hidden files and Folders)
Locate and delete the following Folders (if found)C:\WINDOWS\System32\MsServices
C:\Program Files\CNNIC
C:\Program Files\Common Files\UPDATE2
C:\PROGRA~1\MMSASS~1
<<-The folder will start with MMSASS->>
C:\Program Files\coolsign
Locate and delete the following files (if found)c:\windows\system32\netwindde.dll
C:\WINDOWS\System32\usercrd.dll
C:\WINDOWS\System32\xenroer.dll
mysvcc.exe
mssvcc.exe
winystems.exe

Next Rerun SREng2At the main Window and in the Left pane Select "Boot Items"
In the Right pane Click the registry tab
In the List of items listed
Locate the items listed below->>Hilite the items one at a time->>Then Select the Delete Button
CdnCtr->>C:\Program Files\CNNIC\Cdn\cdnup.exe><<-There will be 2 of these->>
Update->>C:\Program Files\Common Files\UPDATE2\Update.exe>
mysvcig38->>mysvcc.exe><<-There will be 3 of these->>
msconfig38->>; mssvcc.exe>
winystems25->>; winystems.exe>
Then In the left Pane Select System repair
In the right pane Click the Browser Add-ons Tab
Locate the CLSID Numbers below->>Hilite the items one at a time_>>Select the Delete Selected Button
(Note: if you cannot see enough of the CLSID number, place your mouse between CLSID and CLSID1, a divider bar will appear, left click and slide the columb over untill the CLSID is visable){36BF6929-DCBC-4CCD-A620-C5E3BBA77B95}->>C:\WINDOWS\System32\usercrd.dll,
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}->>C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll, CNNIC
{6671A431-5C3D-463d-A7CF-5587F9B7E191}->>C:\PROGRA~1\MMSASS~1\mmsass~1.dll,
{A64E86D2-203D-4145-AA9B-2425BAF568E9}->>C:\WINDOWS\System32\xenroer.dll,
{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5}->>C:\Program Files\coolsign\coolsign.dll
{5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}->>C:\PROGRA~1\CNNIC\Cdn\cdnforie.dll,
{6671A433-5C3D-463d-A7CF-5587F9B7E191}->>C:\PROGRA~1\MMSASS~1\mmsass~1.dll,

Close SREng->>Reboot your pc->>Rerun Hijackthis and post a fresh log

thanks bamajim
Bamajim,
There were a few problems with the deletion process.
The following folder reappears :huh: after deletion:
C:\Program Files\MMSAssist

The following file reappears :huh: after deletion:
C:\WINDOWS\System32\usercrd.dll

In SREng2
I am unable to permanently delete these following keys as they reappear after deletion :( :
{36BF6929-DCBC-4CCD-A620-C5E3BBA77B95}->>C:\WINDOWS\System32\usercrd.dll,
{6671A431-5C3D-463d-A7CF-5587F9B7E191}->>C:\PROGRA~1\MMSASS~1\mmsass~1.dll,
{6671A433-5C3D-463d-A7CF-5587F9B7E191}->>C:\PROGRA~1\MMSASS~1\mmsass~1.dll,
{A64E86D2-203D-4145-AA9B-2425BAF568E9}->>C:\WINDOWS\System32\xenroer.dll


Anyways here's the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 11:22:20 AM, on 2/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsgSys.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\WordWeb\wweb32.exe
c:\windows\system32\wbem\winlogon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Patrick\Desktop\SREng\SREng.exe
C:\WINDOWS\System32\rundll32.exe
C:\Documents and Settings\Patrick\Desktop\Hihack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.7322.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://client.jogo.cn/cdn/browser/sidesear…esearch-en.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://client.jogo.cn/cdn/browser/customse…msearch-en.html
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SYM - {36BF6929-DCBC-4CCD-A620-C5E3BBA77B95} - C:\WINDOWS\System32\usercrd.dll
O2 - BHO: (no name) - {3D898C55-74CC-4B7C-B5F1-45913F368388} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Vision - {6671A431-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: DDOC - {A64E86D2-203D-4145-AA9B-2425BAF568E9} - C:\WINDOWS\System32\xenroer.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [UnlockerAssistant] ; C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKLM\..\Run: [QuickTime Task] ; "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [WinampAgent] ; C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] ; C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] ; "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] ; C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [NeroFilterCheck] ; C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PHIME2002A] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PHIME2002ASync] ; C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [SunJavaUpdateSched] ; "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [vptray] ; C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [VTTimer] ; VTTimer.exe
O4 - HKLM\..\Run: [YhooUapdates] ; C:\WINDOWS\system32\ymssmsgs.exe
O4 - HKCU\..\Run: [ctfmon.exe] ; C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] ; "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Internet Download Accelerator] ; C:\Program Files\IDA\ida.exe -autorun
O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
O8 - Extra context menu item: >>²ÊÐÅ·¢ËÍ<< - res://C:\PROGRA~1\MMSASS~1\mmsass~1.dll/mms.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra 'Tools' menuitem: ²ÊE¾«ÁéÉèÖà - {6671A433-5C3D-463d-A7CF-5587F9B7E191} - C:\PROGRA~1\MMSASS~1\mmsass~1.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O21 - SSODL: webwork - {4C611512-2C1D-44b2-A044-872AD2AD5A61} - C:\WINDOWS\webwork\webwork.dll
O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates International Inc. - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
splat

Don't get discouraged, sometimes these infections can be difficult, please hang in there with me. I haven't had one beat me yet. I will reply tommorrow, have some more research to do. In the mean time I have a question or 2

1. Did you find these folders again C:\Program Files\CNNIC
C:\Program Files\Common Files\UPDATE2
And did you find these filesc:\windows\system32\netwindde.dll
C:\WINDOWS\System32\usercrd.dll
C:\WINDOWS\System32\xenroer.dll
mysvcc.exe
mssvcc.exe
winystems.exe
thanks bamajim
I was able to delete the folders without them coming back: C:\Program Files\CNNIC C:\Program Files\Common Files\UPDATE2 And also these files: C:\WINDOWS\System32\xenroer.dll mysvcc.exe mssvcc.exe winystems.exe Splat
splat

Thanks for the information. What I would like you to do is to follow the instructions in the previous post, but I would like you to Reboot your PC into SafeMode before you do the fix

And then reply with the results

thanks bamajim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI