This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

hijackthis log

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

one of you guys helped me out a while back with a messed up comp. need some more help.

here's my current HJT log. I've already run CWShredder, downloaded AVG antivirus, ran Trendmicro House call, downloaded Adaware and Spybot as well.

I think i'm almost there and need a little more to finish. please help.

Logfile of HijackThis v1.99.1
Scan saved at 7:15:08 PM, on 10/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Toshiba_User\My Documents\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

http://www.mrfindalot.com/search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer =

84.54.134.215:3128
R3 - URLSearchHook: (no name) - _{855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program

Files\ICQToolbar\toolbaru.dll (file missing)
O3 - Toolbar: SearchHelper - {B6A5B638-6025-4C2C-A899-867B416453D2} - C:\Program

Files\SearchHelper\SearchHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [tyylafg.dll] C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\tyylafg.dll,zriqmtc
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKCU\..\Run: [swg] C:\Program

Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program

Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.adsextend.net
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.adsextend.net (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} -

http://cabs.media-motor.net/cabs/joysavsht.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsupdate/…ab?116121129037

6
O16 - DPF: {886DDE35-E955-11D0-A707-000000881958} - http://69.56.176.75/webplugin.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} -

http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\azaul7d91.dll
O21 - SSODL: bsZdVcHSraP - {7C54AAC1-D6FE-006B-BCDF-945287C05832} - C:\WINDOWS\system32\xlj.dll

(file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. -

C:\WINDOWS\system32\DVDRAMSV.exe
Please download Look2Me-Destroyer.exe to your desktop.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank

R3 - URLSearchHook: (no name) - _{855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)

O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll (file missing)

O3 - Toolbar: SearchHelper - {B6A5B638-6025-4C2C-A899-867B416453D2} - C:\Program Files\SearchHelper\SearchHelper.dll

O4 - HKLM\..\Run: [tyylafg.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\tyylafg.dll,zriqmtc

O4 - HKLM\..\RunServices: [stonedrv] c:\windows\system32\stonedrv.exe

O15 - Trusted Zone: *.adgate.info

O15 - Trusted Zone: *.adsextend.net

O15 - Trusted Zone: *.dollarrevenue.com

O15 - Trusted Zone: *.elitemediagroup.net

O15 - Trusted Zone: *.errorsafe.com

O15 - Trusted Zone: *.imagesrvr.com

O15 - Trusted Zone: *.matcash.com

O15 - Trusted Zone: *.media-motor.com

O15 - Trusted Zone: *.mediatickets.net

O15 - Trusted Zone: *.snipernet.biz

O15 - Trusted Zone: *.systemdoctor.com

O15 - Trusted Zone: *.winantivirus.com

O15 - Trusted Zone: *.winfixer.com

O15 - Trusted Zone: *.adgate.info (HKLM)

O15 - Trusted Zone: *.adsextend.net (HKLM)

O15 - Trusted Zone: *.dollarrevenue.com (HKLM)

O15 - Trusted Zone: *.elitemediagroup.net (HKLM)

O15 - Trusted Zone: *.errorsafe.com (HKLM)

O15 - Trusted Zone: *.imagesrvr.com (HKLM)

O15 - Trusted Zone: *.matcash.com (HKLM)

O15 - Trusted Zone: *.media-motor.com (HKLM)

O15 - Trusted Zone: *.media-motor.net (HKLM)

O15 - Trusted Zone: *.mediatickets.net (HKLM)

O15 - Trusted Zone: *.snipernet.biz (HKLM)

O15 - Trusted Zone: *.systemdoctor.com (HKLM)

O15 - Trusted Zone: *.winantivirus.com (HKLM)

O15 - Trusted Zone: *.winfixer.com (HKLM)

O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/joysavsht.cab

O16 - DPF: {886DDE35-E955-11D0-A707-000000881958} - http://69.56.176.75/webplugin.cab

O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab

O21 - SSODL: bsZdVcHSraP - {7C54AAC1-D6FE-006B-BCDF-945287C05832} - C:\WINDOWS\system32\xlj.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\windows\system32\tyylafg.dll <— file

c:\windows\system32\stonedrv.exe <— file

C:\Program Files\SearchHelper <— FOLDER

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task .
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button .
  • You will receive a Done Scanning message, click OK .
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK .
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory

MSWINSCK.OCX


Please turn wordwrap OFF in Notepad before posting any more logs.
:)
1. Here's the Look2Me .txt :


Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 10/28/2006 10:43:06 AM

Infected! C:\WINDOWS\system32\azaul7d91.dll

Attempting to delete infected files…

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ShellServiceObjectDelayLoad

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5581DC89-2141-468D-950B-8C4EEE062360}"
HKCR\Clsid\{5581DC89-2141-468D-950B-8C4EEE062360}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{303A2CC5-F7E3-4683-845C-F62AE27BF416}"
HKCR\Clsid\{303A2CC5-F7E3-4683-845C-F62AE27BF416}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{507AB728-F93B-422A-98EF-D51443AC6CB2}"
HKCR\Clsid\{507AB728-F93B-422A-98EF-D51443AC6CB2}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{1ABC006C-2AFE-471A-B1EC-097F9821A5A6}"
HKCR\Clsid\{1ABC006C-2AFE-471A-B1EC-097F9821A5A6}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{16880876-E38E-4753-92FA-CAFE04BF8FD3}"
HKCR\Clsid\{16880876-E38E-4753-92FA-CAFE04BF8FD3}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{F6BF7A0E-21CC-4869-99E5-3831A529460D}"
HKCR\Clsid\{F6BF7A0E-21CC-4869-99E5-3831A529460D}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{F09FE329-5456-45E8-947E-39C7BCA7FF51}"
HKCR\Clsid\{F09FE329-5456-45E8-947E-39C7BCA7FF51}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{EB4E6078-F2BB-4123-927B-3738B2B854A2}"
HKCR\Clsid\{EB4E6078-F2BB-4123-927B-3738B2B854A2}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{16F8BC61-98CD-43F0-98DB-E68038FB6794}"
HKCR\Clsid\{16F8BC61-98CD-43F0-98DB-E68038FB6794}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{31467C90-BFC1-4302-A3FF-E00016AC0C99}"
HKCR\Clsid\{31467C90-BFC1-4302-A3FF-E00016AC0C99}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A509D120-AA0C-4460-B014-88EE0BBE92AA}"
HKCR\Clsid\{A509D120-AA0C-4460-B014-88EE0BBE92AA}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

2. Here's the updated HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 10:52:47 AM, on 10/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\AOL\1161388852\ee\AOLSoftware.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Toshiba_User\My Documents\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 84.54.134.215:3128
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161388852\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [zbXb] C:\WINDOWS\system32\ekuxpv3.exe
O4 - HKLM\..\Run: [win32082020859235] C:\WINDOWS\win32082020859235.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [webHancer Agent] "C:\Program Files\webHancer\Programs\whAgent.exe"
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\testtestt.exe
O4 - HKLM\..\Run: [sys010859235202] C:\WINDOWS\sys010859235202.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Rdcqwi] C:\Program Files\Koncv\Griqji.exe
O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_11.exe
O4 - HKLM\..\Run: [ms063520208592] C:\WINDOWS\ms063520208592.exe
O4 - HKLM\..\Run: [mgwoqksA] C:\WINDOWS\mgwoqksA.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_11a.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_11a.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [PSLister] "C:\Program Files\PSLister\PSLister.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [BraveSentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [BPS Security Console] C:\Program Files\BulletProofSoft.com\BPS Security Console\SecCon.exe
O4 - HKCU\..\Run: [505aa858.exe] C:\Documents and Settings\Toshiba_User\Local Settings\Application Data\505aa858.exe
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1161211290376
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161218843808
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi198458.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
Many new malware items are present.
:(

Download combofix.exe from the link below:

Combofix.exe

Save it to your desktop.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run combofix.

When finished, it will produce a log for you.

Post that log in your next reply, along with a new HijackThis! log.
:)

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
FYI - my dad had lent this computer to someone before and i only got it back recently after sending it away to to the manufacturer to fix what was physically wrong with it. thanks for your help now and in the future.

1. - combofix log

Toshiba_User - 06-10-28 17:37:18.78 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Toshiba_User\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\acl71.dll
C:\WINDOWS\system32\ayvapi32.dll
C:\WINDOWS\system32\azaulc591f.dll
C:\WINDOWS\system32\c0002admgd0a2.dll
C:\WINDOWS\system32\c2002cdmgf0a2.dll
C:\WINDOWS\system32\cmmmdlg.dll
C:\WINDOWS\system32\cQtsrvut.dll
C:\WINDOWS\system32\d00mlad11d0.dll
C:\WINDOWS\system32\d4j00e1meh.dll
C:\WINDOWS\system32\eipsrv.dll
C:\WINDOWS\system32\en02l1do1.dll
C:\WINDOWS\system32\en2ol1f31.dll
C:\WINDOWS\system32\enp2l17o1.dll
C:\WINDOWS\system32\enpol1731.dll
C:\WINDOWS\system32\enr4l19q1.dll
C:\WINDOWS\system32\enr6l19s1.dll
C:\WINDOWS\system32\f4j20e1oeh.dll
C:\WINDOWS\system32\g422lefo1h2c.dll
C:\WINDOWS\system32\g4400ehmeh4a0.dll
C:\WINDOWS\system32\g440lehm1h4a.dll
C:\WINDOWS\system32\g6jolg1316.dll
C:\WINDOWS\system32\h42o0ef3eh2.dll
C:\WINDOWS\system32\hHl.dll
C:\WINDOWS\system32\hr0u05d9e.dll
C:\WINDOWS\system32\hr6u05j9e.dll
C:\WINDOWS\system32\i6lo0g33e6.dll
C:\WINDOWS\system32\i842liho184c.dll
C:\WINDOWS\system32\iLspolcy.dll
C:\WINDOWS\system32\imign32.dll
C:\WINDOWS\system32\inssuba.dll
C:\WINDOWS\system32\ir0ol5d31.dll
C:\WINDOWS\system32\irr0l59m1.dll
C:\WINDOWS\system32\izetmib1.dll
C:\WINDOWS\system32\j64olgh3164.dll
C:\WINDOWS\system32\k662lgjo16oc.dll
C:\WINDOWS\system32\k6jslg1716.dll
C:\WINDOWS\system32\k6lqlg3516.dll
C:\WINDOWS\system32\kjdfr.dll
C:\WINDOWS\system32\kjdinmal.dll
C:\WINDOWS\system32\kml8l73u1.dll
C:\WINDOWS\system32\krdinmal.dll
C:\WINDOWS\system32\krdru1.dll
C:\WINDOWS\system32\kRlqlg3516.dll
C:\WINDOWS\system32\ktpul7791.dll
C:\WINDOWS\system32\kUjs0a17ed.dll
C:\WINDOWS\system32\lvpm0971e.dll
C:\WINDOWS\system32\lyasrv.dll
C:\WINDOWS\system32\lyr4099qe.dll
C:\WINDOWS\system32\m4rm0e91eh.dll
C:\WINDOWS\system32\mEg_hook.dll
C:\WINDOWS\system32\mmdex.dll
C:\WINDOWS\system32\mpn.dll
C:\WINDOWS\system32\mqc71.dll
C:\WINDOWS\system32\mywstr10.dll
C:\WINDOWS\system32\o0ns0a57ed.dll
C:\WINDOWS\system32\o6pqlg7516.dll
C:\WINDOWS\system32\ocecli32.dll
C:\WINDOWS\system32\p0n80a5ued.dll
C:\WINDOWS\system32\q686lgls16q6.dll
C:\WINDOWS\system32\qA86lgls16q6.dll
C:\WINDOWS\system32\r06u0aj9edo.dll
C:\WINDOWS\system32\r0p80a7ued.dll
C:\WINDOWS\system32\r26ulcj91fo.dll
C:\WINDOWS\system32\rOsmontr.dll
C:\WINDOWS\system32\tppmib.dll
C:\WINDOWS\system32\tQpiui.dll
C:\WINDOWS\system32\wgavideo.dll
C:\WINDOWS\system32\whdmtpdr.dll
C:\WINDOWS\system32\wicsvc.dll
C:\WINDOWS\system32\wkhnetbs.dll
C:\WINDOWS\system32\wvpencen.dll


Granting sedebugprivilege to Administrators … successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\WinNB58.dll
C:\Program Files\PSLister
C:\Program Files\System Files
C:\Program Files\System Icons
C:\Program Files\Common Files\{7C54AAC0-06C1-1033-0117-060913200001}


((((((((((((((((((((((((((((((( Files Created from 2006-09-28 to 2006-10-28 ))))))))))))))))))))))))))))))))))


2006-10-18 22:03 127,208 –a—— C:\WINDOWS\system32\mucltui.dll
2006-10-18 20:38 18,200 –a—— C:\WINDOWS\system32\wups2.dll
2006-10-18 20:25 24,072 –a—— C:\WINDOWS\system32\uxtuneup.dll
2006-10-18 18:48 816,288 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2006-10-18 18:48 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-10-18 18:48 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2006-10-18 18:48 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-10-18 17:30 157,184 –a—— C:\WINDOWS\system32\symsr.dll
2006-10-18 17:10 72,704 –a—— C:\WINDOWS\system32\odvhzsf.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-28 17:37 ——– d——– C:\Program Files\Common Files
2006-10-28 11:00 ——– d——– C:\Program Files\Messenger
2006-10-28 11:00 ——– d——– C:\Program Files\Internet Explorer
2006-10-28 10:56 ——– d——– C:\Program Files\Outlook Express
2006-10-28 10:56 ——– d——– C:\Program Files\Common Files\System
2006-10-28 10:12 ——– d——– C:\Documents and Settings\Toshiba_User\Application Data\AVG7
2006-10-26 23:24 ——– d——– C:\Program Files\Ringz Studio
2006-10-20 20:01 ——– d——– C:\Program Files\Common Files\Nullsoft
2006-10-20 20:01 ——– d——– C:\Program Files\Common Files\AOL
2006-10-20 20:01 ——– d——– C:\Program Files\AOL
2006-10-20 20:01 ——– d——– C:\Program Files\AOD
2006-10-20 20:01 ——– d——– C:\Documents and Settings\Toshiba_User\Application Data\acccore
2006-10-20 20:00 ——– d——– C:\Program Files\Common Files\aolshare
2006-10-20 19:59 ——– d——– C:\Documents and Settings\Toshiba_User\Application Data\Mozilla
2006-10-18 20:57 ——– d——– C:\Documents and Settings\Toshiba_User\Application Data\Help
2006-10-18 20:25 ——– d——– C:\Program Files\TuneUp Utilities 2006
2006-10-18 20:25 ——– d——– C:\Program Files\Common Files\Wise Installation Wizard
2006-10-18 20:25 ——– d——– C:\Documents and Settings\Toshiba_User\Application Data\TuneUp Software
2006-10-18 20:21 ——– d——– C:\Program Files\BitComet
2006-10-18 19:57 ——– d——– C:\Program Files\Lavasoft
2006-10-18 19:57 ——– d——– C:\Documents and Settings\Toshiba_User\Application Data\Lavasoft
2006-10-18 19:46 ——– d——– C:\Program Files\WinRAR
2006-10-18 19:45 ——– d——– C:\Program Files\Google
2006-10-18 19:07 ——– d——– C:\Program Files\Koncv
2006-10-18 18:48 ——– d——– C:\Program Files\Grisoft
2006-10-18 18:47 ——– d—s—- C:\Documents and Settings\Toshiba_User\Application Data\Microsoft
2006-10-18 18:39 ——– d——– C:\Program Files\Windows Plus
2006-10-18 18:07 ——– d——– C:\Documents and Settings\Toshiba_User\Application Data\Google
2006-10-18 18:05 ——– d——– C:\Program Files\Mozilla Firefox
2006-10-18 17:53 ——– d——– C:\Documents and Settings\Toshiba_User\Application Data\Sun
2006-10-18 17:52 ——– d——– C:\Program Files\Java
2006-10-18 17:48 ——– d——– C:\Program Files\Common Files\Java
2006-09-13 01:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll
2006-08-25 11:45 617472 –a—— C:\WINDOWS\system32\comctl32.dll
2006-08-23 01:49 234203 -r–s—- C:\WINDOWS\system32\k4js0e17eh.dll
2006-08-21 08:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 05:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-19 08:10 517 –a—— C:\Program Files\Common Files\niwyq
2006-08-16 07:58 100352 –a—— C:\WINDOWS\system32\6to4svc.dll
2006-08-05 13:53 45056 –a—— C:\WINDOWS\system32zkdmg.exe
2006-08-05 13:53 28672 –a—— C:\WINDOWS\system32tpsd.exe
2006-08-05 13:53 28672 –a—— C:\WINDOWS\system32\tpsd.exe
2006-07-31 16:03 1163264 –a—— C:\WINDOWS\system32\riwzkn.exe
2006-07-31 16:02 36864 –a—— C:\WINDOWS\system32\hauc.exe
2006-07-20 18:48 62 –ahs—- C:\Documents and Settings\Toshiba_User\Application Data\desktop.ini


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
"Aim6"="\"C:\\Program Files\\Common Files\\AOL\\Launch\\AOLLaunch.exe\" /d locale=en-US ee://aol/imApp"
"PSLister"="\"C:\\Program Files\\PSLister\\PSLister.exe\""
"BraveSentry"="C:\\Program Files\\BraveSentry\\BraveSentry.exe"
"BPS Security Console"="C:\\Program Files\\BulletProofSoft.com\\BPS Security Console\\SecCon.exe"
"505aa858.exe"="C:\\Documents and Settings\\Toshiba_User\\Local Settings\\Application Data\\505aa858.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1161388852\\ee\\AOLSoftware.exe"
"IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"zbXb"="C:\\WINDOWS\\system32\\ekuxpv3.exe"
"win32082020859235"="C:\\WINDOWS\\win32082020859235.exe"
"sys010859235202"="C:\\WINDOWS\\sys010859235202.exe"
"StormCodec_Helper"="\"C:\\Program Files\\Ringz Studio\\Storm Codec\\StormSet.exe\" /S /opti"
"stonedrv"="c:\\windows\\system32\\stonedrv.exe"
"RTHDCPL"="RTHDCPL.EXE"
"Rdcqwi"="C:\\Program Files\\Koncv\\Griqji.exe"
"pop06ap"="C:\\WINDOWS\\pop06ap2.exe"
"Persistence"="C:\\WINDOWS\\system32\\igfxpers.exe"
"ms063520208592"="C:\\WINDOWS\\ms063520208592.exe"
"mgwoqksA"="C:\\WINDOWS\\mgwoqksA.exe"
"k6mmN5IOU"="\"C:\\WINDOWS\\system32\\wfxqhv.exe\""
"Internet Optimizer"="\"C:\\Program Files\\Internet Optimizer\\optimize.exe\""
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"ICQ Lite"="\"C:\\Program Files\\ICQLite\\ICQLite.exe\" -minimize"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"Alcmtr"="ALCMTR.EXE"
"ad8rIU3s"="C:\\WINDOWS\\system32\\cvn0.exe"
"ACTX1"="C:\\WINDOWS\\v1201.exe"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\Windows Plus\\qufyduxyx.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="C:\\Program Files\\Messenger\\nicob.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,ea,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,fe,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,02,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,02,03,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"ClassicShell"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Windows Overlay Components"=dword:00000002

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\At1.job

Completion time: 06-10-28 17:39:34.97
C:\ComboFix.txt … 06-10-28 17:39

2. HJT log

Logfile of HijackThis v1.99.1
Scan saved at 5:43:01 PM, on 10/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\AOL\1161388852\ee\AOLSoftware.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Toshiba_User\My Documents\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 84.54.134.215:3128
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161388852\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [zbXb] C:\WINDOWS\system32\ekuxpv3.exe
O4 - HKLM\..\Run: [win32082020859235] C:\WINDOWS\win32082020859235.exe
O4 - HKLM\..\Run: [sys010859235202] C:\WINDOWS\sys010859235202.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Rdcqwi] C:\Program Files\Koncv\Griqji.exe
O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ms063520208592] C:\WINDOWS\ms063520208592.exe
O4 - HKLM\..\Run: [mgwoqksA] C:\WINDOWS\mgwoqksA.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [PSLister] "C:\Program Files\PSLister\PSLister.exe"
O4 - HKCU\..\Run: [BraveSentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [BPS Security Console] C:\Program Files\BulletProofSoft.com\BPS Security Console\SecCon.exe
O4 - HKCU\..\Run: [505aa858.exe] C:\Documents and Settings\Toshiba_User\Local Settings\Application Data\505aa858.exe
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1161211290376
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161218843808
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi198458.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [zbXb] C:\WINDOWS\system32\ekuxpv3.exe

O4 - HKLM\..\Run: [win32082020859235] C:\WINDOWS\win32082020859235.exe

O4 - HKLM\..\Run: [sys010859235202] C:\WINDOWS\sys010859235202.exe

O4 - HKLM\..\Run: [stonedrv] c:\windows\system32\stonedrv.exe

O4 - HKLM\..\Run: [Rdcqwi] C:\Program Files\Koncv\Griqji.exe

O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe

O4 - HKLM\..\Run: [ms063520208592] C:\WINDOWS\ms063520208592.exe

O4 - HKLM\..\Run: [mgwoqksA] C:\WINDOWS\mgwoqksA.exe

O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"

O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe

O4 - HKLM\..\Run: [ACTX1] C:\WINDOWS\v1201.exe

O4 - HKCU\..\Run: [PSLister] "C:\Program Files\PSLister\PSLister.exe"

O4 - HKCU\..\Run: [505aa858.exe] C:\Documents and Settings\Toshiba_User\Local Settings\Application Data\505aa858.exe

O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi198458.exe (file missing)

Then click "Fix checked" and close Hijack This!.

Now, please go to:

Start –> Run

In the box type in services.msc then hit < Enter > (or click OK)

In the Name column look for:

Microsoft ASPI Manager

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\WINDOWS\system32\aspi198458.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\documents and settings\toshiba_user\local settings\application data\505aa858.exe <— file

c:\program files\internet optimizer <— FOLDER

c:\program files\koncv <— FOLDER

c:\program files\pslister <— FOLDER

c:\windows\mgwoqksa.exe <— file

c:\windows\ms063520208592.exe <— file

c:\windows\pop06ap2.exe <— file

c:\windows\sys010859235202.exe <— file

c:\windows\system32\cvn0.exe <— file

c:\windows\system32\ekuxpv3.exe <— file

c:\windows\system32\stonedrv.exe <— file

c:\windows\system32\wfxqhv.exe <— file

c:\windows\v1201.exe <— file

c:\windows\win32082020859235.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread. :)
i couldn't find and do the requisite actions on a majority of the malware you indicated.
i'm pretty sure they got zapped by some a different recovery / antivirus program.
though perhaps i just screwed up.

here's the latest HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 11:38:38 PM, on 10/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Common Files\AOL\1161388852\ee\aolsoftware.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Toshiba_User\My Documents\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 84.54.134.215:3128
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1161388852\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1161211290376
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161218843808
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
Look in these two folders:

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

C:\Documents and Settings\\Start Menu\Programs\Startup

In each, you'll find a "hidden" file named ".protected".

Delete it from each folder.

Be sure to show hidden files when looking for these files.

Reboot after, and post a new HijackThis! log.

That should do it. :thumbup:

How are things running now?
:unsure:

Securing Your PC After An Attack
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI