This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help to analyse this HJT log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help me to analyse the following HJT log: Logfile of HijackThis v1.99.1 Scan saved at 5:31:23 PM, on 10/19/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINNT\SmFtZXM\command.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Network Monitor\netmon.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\slserv.exe C:\WINNT\oswinupdate.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\Program Files\WinPoET Broadband Connection\WrOS.EXE C:\WINNT\System32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\WINNT\system32\rundll32.exe C:\WINNT\system32\ctfmon.exe C:\WINNT\system32\conime.exe C:\Documents and Settings\Administrator\My Documents\HijackThis.exe O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINNT\system32\geebc.dll O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINNT\system32\mlljg.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - HKCU\..\Run: [ntdll.dll] ctfmon.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O20 - Winlogon Notify: App Management - C:\WINNT\system32\j20slcd71f0.dll (file missing) O20 - Winlogon Notify: geebc - C:\WINNT\SYSTEM32\geebc.dll O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: IntlRun - C:\WINNT\system32\guard.tmp O20 - Winlogon Notify: mlljg - C:\WINNT\system32\mlljg.dll O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\SmFtZXM\command.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINNT\system32\hwclock.exe O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe O23 - Service: Windows Vista/NT Runtime Compatibility Service (ntrcs) - Unknown owner - C:\WINNT\NT\nrcs.exe (file missing) O23 - Service: SmartLinkService (SLService) - - C:\WINNT\SYSTEM32\slserv.exe O23 - Service: Win32 Update (Win32Update) - Unknown owner - C:\WINNT\oswinupdate.exe O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
Hi. Welcome to TomCoyote. I need to take some time to look over your Hijack This log to come up with a fix. Please remember that I am an undergraduate which means I need to have my posts to you checked by a teacher or moderator to make sure I'm giving you the proper instructions. This process won't take long and I thank you for your patience. I'll be back with you soon.
Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
I feel I'm obligated to let you know that your system could be very compomised and the dangers are great. Your banking information and passwords are at risk of being stolen. You might want to remove any banking information/passwords you have stored on your system until we get this fixed. You also might want to check your bank account (not from your PC) for fraudulent charges/purchases to your bank account or credit cards and do not use your PC for banking activity until you're clean.
This is the Report.txt generated: SDFix: Version 1.30 ——————- Scan run on: Fri 10/20/2006 Time: 9:12a Microsoft Windows 2000 [Version 5.00.2195] Running from: C:\Documents and Settings\[removed]\Desktop\SDFix Stage One… Checking Services… Name: —– DP1112 hwclock ntrcs Win32Update Path: —- \??\C:\WINNT\system32\Drivers\DP.sys C:\WINNT\system32\hwclock.exe C:\WINNT\NT\nrcs.exe "C:\WINNT\oswinupdate.exe" DP1112 … deleted hwclock … deleted ntrcs … deleted Win32Update … deleted Repairing Registry… Restoring Default Hosts File… Stage One Complete Rebooting! Stage Two… Checking For Malware Files: ————————– C:\DRSMAR~1.EXE C:\DRSMAR~2.EXE C:\DRSMAR~3.EXE C:\KEYBOA~1.EXE C:\KYBRDE~1.EXE C:\MOUSEP~1.EXE C:\NEWNAM~1.EXE C:\WINNT\system32\eraseme_66220.exe C:\iexplorer.exe C:\WINNT\oswinupdate.exe C:\WINNT\system32\drivers\DP.sys C:\WINNT\system32\hwclock.exe C:\WINNT\system32\i Backing Up and Removing any Files Found… Final Check: Services: ——— Files: —— *Any removed Files are saved in the SDFix\backups Folder* *FINISHED* ********************************************************** This is the new HJT log: Logfile of HijackThis v1.99.1 Scan saved at 9:18:20 AM, on 10/20/2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\AVPersonal\AVGUARD.EXE C:\Program Files\AVPersonal\AVWUPSRV.EXE C:\WINNT\SmFtZXM\command.exe C:\WINNT\System32\svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Network Monitor\netmon.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\slserv.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\Program Files\WinPoET Broadband Connection\WrOS.EXE C:\WINNT\System32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\WINNT\system32\conime.exe C:\WINNT\system32\notepad.exe C:\WINNT\system32\ctfmon.exe C:\Documents and Settings\Administrator\My Documents\HijackThis.exe O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINNT\system32\geebc.dll O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINNT\system32\mlljg.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - HKCU\..\Run: [ntdll.dll] ctfmon.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O20 - Winlogon Notify: App Management - C:\WINNT\system32\j20slcd71f0.dll (file missing) O20 - Winlogon Notify: geebc - C:\WINNT\SYSTEM32\geebc.dll O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: IntlRun - C:\WINNT\system32\guard.tmp (file missing) O20 - Winlogon Notify: mlljg - C:\WINNT\system32\mlljg.dll O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\SmFtZXM\command.exe O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe O23 - Service: SmartLinkService (SLService) - - C:\WINNT\SYSTEM32\slserv.exe O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
OK. That looks much better. Please download and run these three programs in the order shown here.
  • Download this file - combofix.exe
  • [Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window while it's running. That may cause it to stall
After running combofix please continue with this fix:

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Finally, do this fix:

Please download delcmdservice (by Marckie), and save it to your Desktop.
  • Unzip the content to your Desktop (a folder named delcmdservice)
  • Double-click on the delcmdservice folder
  • Double-click on delreg.bat to launch the tool
  • When the tool has finished, please reboot your computer.
Post back with the ComboFix log, the Vundofix.txt log and a fresh Hijack This log.
Here is the combofix.exe log:

Administrator - Wed 10/25/2006 11:27:38.34 Service Pack 4
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Administrator\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:

[HKEY_CLASSES_ROOT\clsid\{4D98B0DA-588D-4132-B59C-AFDCB5007A31}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\clsid\{4D98B0DA-588D-4132-B59C-AFDCB5007A31}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{4D98B0DA-588D-4132-B59C-AFDCB5007A31}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{4D98B0DA-588D-4132-B59C-AFDCB5007A31}\InprocServer32]
@="C:\\WINNT\\system32\\rFssauth.dll"
"ThreadingModel"="Apartment"

[HKEY_CLASSES_ROOT\clsid\{DB09FA6A-A4AB-4AE4-8702-555AF6DAA1D1}]
@=""

[HKEY_CLASSES_ROOT\clsid\{DB09FA6A-A4AB-4AE4-8702-555AF6DAA1D1}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{DB09FA6A-A4AB-4AE4-8702-555AF6DAA1D1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{DB09FA6A-A4AB-4AE4-8702-555AF6DAA1D1}\InprocServer32]
@="C:\\WINNT\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINNT\system32\azwav.dll
C:\WINNT\system32\caadmin.dll
C:\WINNT\system32\dgnet.dll
C:\WINNT\system32\dnocx.dll
C:\WINNT\system32\e4202efmgh2a2.dll
C:\WINNT\system32\fp4203hoe.dll
C:\WINNT\system32\fXxocm.dll
C:\WINNT\system32\g204lcdq1f0e.dll
C:\WINNT\system32\g822lifo182c.dll
C:\WINNT\system32\hr2005fme.dll
C:\WINNT\system32\hyink.dll
C:\WINNT\system32\i224lcfq1f2e.dll
C:\WINNT\system32\i260lcjm1foa.dll
C:\WINNT\system32\i824lifq182e.dll
C:\WINNT\system32\iyxrtmgr.dll
C:\WINNT\system32\j0j6la1s1d.dll
C:\WINNT\system32\j0n20a5oed.dll
C:\WINNT\system32\jt0807due.dll
C:\WINNT\system32\jtl6073se.dll
C:\WINNT\system32\jtp0077me.dll
C:\WINNT\system32\k4jsle171h.dll
C:\WINNT\system32\l2j8lc1u1f.dll
C:\WINNT\system32\lfcalsec.dll
C:\WINNT\system32\m046lahs1d46.dll
C:\WINNT\system32\mcrddm.dll
C:\WINNT\system32\mcxml3r.dll
C:\WINNT\system32\MDRDO20.DLL
C:\WINNT\system32\mvr6l99s1.dll
C:\WINNT\system32\mzl_qic.dll
C:\WINNT\system32\nhdenb32.dll
C:\WINNT\system32\NHLANMAN.DLL
C:\WINNT\system32\NOTAPI32.DLL
C:\WINNT\system32\o8ns0i57e8.dll
C:\WINNT\system32\ogcache.dll
C:\WINNT\system32\palstore.dll
C:\WINNT\system32\r26ulcj91fo.dll
C:\WINNT\system32\spbkygen.dll
C:\WINNT\system32\ssripto.dll
C:\WINNT\system32\syoolss.dll
C:\WINNT\system32\t08u0al9edq.dll
C:\WINNT\system32\whadmoe.dll


Granting sedebugprivilege to Administrators … successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\sk02.exe
C:\WINNT\dh.ini
C:\WINNT\uninstall_nmon.vbs
C:\WINNT\system32\atmtd.dll
C:\WINNT\system32\atmtd.dll._
C:\Documents and Settings\Default User\Application Data\NetMon
C:\Program Files\network monitor
C:\WINNT\SmFtZXM


((((((((((((((((((((((((((((((( Files Created from 2006-09-25 to 2006-10-25 ))))))))))))))))))))))))))))))))))


2006-10-20 01:27 17,680 –a—— C:\WINNT\system32\userinit.exe
2006-10-19 13:44 21,552 –a—— C:\WINNT\system32\drivers\USBSTOR.SYS


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-25 11:29 ——– d——– C:\Program Files\WinPoET Broadband Connection
2006-10-20 15:20 ——– d——– C:\Program Files\AVPersonal
2006-10-20 14:43 ——– d-a—— C:\Program Files\Common Files\GMT
2006-10-19 15:39 ——– d——– C:\Program Files\microsoft frontpage
2006-10-19 15:37 ——– d-a—— C:\Program Files\Common Files\CMEII
2006-10-19 14:33 ——– d-a—— C:\Program Files\Common Files\Microsoft Shared
2006-10-19 14:33 ——– d-a—— C:\Program Files\Common Files
2006-10-19 14:33 ——– d——– C:\Program Files\Windows Media Player
2006-10-19 14:33 ——– d——– C:\Program Files\Winamp
2006-10-19 14:33 ——– d——– C:\Program Files\Common Files\Symantec Shared
2006-10-19 14:14 ——– d——– C:\Program Files\Error Safe Free


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="ctfmon.exe"
"ntdll.dll"="ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Synchronization Manager"="mobsync.exe /logon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000003
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3c,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f0,01,00,00,1f,00,00,00,80,00,00,00,76,00,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{20D57A66-F7DF-467d-907B-9B7F4A118AB7}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095
"CDRAutoRun"=dword:00000000
"Btn_Back"=dword:00000000
"Btn_Forward"=dword:00000000
"Btn_Stop"=dword:00000000
"Btn_Refresh"=dword:00000000
"Btn_Home"=dword:00000000
"Btn_Search"=dword:00000000
"Btn_History"=dword:00000000
"Btn_Favorites"=dword:00000000
"Btn_Folders"=dword:00000000
"Btn_Fullscreen"=dword:00000000
"Btn_Tools"=dword:00000000
"Btn_MailNews"=dword:00000000
"Btn_Size"=dword:00000000
"Btn_Print"=dword:00000000
"Btn_Edit"=dword:00000000
"Btn_Discussions"=dword:00000000
"Btn_Cut"=dword:00000000
"Btn_Copy"=dword:00000000
"Btn_Paste"=dword:00000000
"Btn_Encoding"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000095

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"Network.ConnectionTray"="{7007ACCF-3202-11D1-AAD2-00805FC1270E}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlljg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINNT\tasks\Symantec NetDetect.job

Completion time: Wed 2006-10-25 11:30:37.34
C:\ComboFix.txt … 06-10-25 11:30

**************************************************************************
Here is the vundofix.exe log:
(there is an error of "Cannot import c:\winnt\vundo.reg file)


VundoFix V6.2.6

Checking Java version…

Sun Java not detected
Scan started at 11:32:18 AM 10/25/2006

Listing files found while scanning….

C:\WINNT\system32\mlljg.dll
C:\WINNT\system32\gjllm.ini
C:\WINNT\system32\gjllm.bak1
C:\WINNT\system32\gjllm.bak2
C:\WINNT\system32\mlljg.dll
C:\WINNT\system32\gjllm.ini
C:\WINNT\system32\gjllm.bak1
C:\WINNT\system32\gjllm.bak2
C:\WINNT\system32\gjllm.ini
C:\WINNT\system32\gjllm.bak1
C:\WINNT\system32\gjllm.bak2

Beginning removal…

Attempting to delete C:\WINNT\system32\mlljg.dll
C:\WINNT\system32\mlljg.dll Has been deleted!

Attempting to delete C:\WINNT\system32\gjllm.ini
C:\WINNT\system32\gjllm.ini Has been deleted!

Attempting to delete C:\WINNT\system32\gjllm.bak1
C:\WINNT\system32\gjllm.bak1 Has been deleted!

Attempting to delete C:\WINNT\system32\gjllm.bak2
C:\WINNT\system32\gjllm.bak2 Has been deleted!

Performing Repairs to the registry.
Done!

***************************************************************************
Here is the new Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:42:45 AM, on 10/25/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\slserv.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\ctfmon.exe
C:\Documents and Settings\Administrator\My Documents\HijackThis.exe

O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINNT\system32\geebc.dll
O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINNT\system32\mlljg.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [ntdll.dll] ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O20 - Winlogon Notify: geebc - C:\WINNT\SYSTEM32\geebc.dll
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINNT\SYSTEM32\slserv.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
Hi. The log is looking much better! Good job!
:D

I need you to follow the instructions below:

I need you to run VundoFix again but follow the instructions below.
  • Double-click VundoFix.exe to run it.
  • Right Click inside the listbox (white box) and click Add more file?
  • Copy & Paste the 2 entries below into the top 2 boxes

    • C:\WINDOWS\System32\geebc.dll
    • C:\WINDOWS\system32\cbeeg.*
  • Click Add Files and click Close Window
  • Click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJack This log.
This is the new Vundofix log (There is an error message on the screen at the point when the desktop blank out. It says: Cannot import c:\winnt\vundofix.reg: error opening the file. There may be a disk or file system error.):


VundoFix V6.2.6

Checking Java version…

Sun Java not detected
Scan started at 11:32:18 AM 10/25/2006

Listing files found while scanning….

C:\WINNT\system32\mlljg.dll
C:\WINNT\system32\gjllm.ini
C:\WINNT\system32\gjllm.bak1
C:\WINNT\system32\gjllm.bak2
C:\WINNT\system32\mlljg.dll
C:\WINNT\system32\gjllm.ini
C:\WINNT\system32\gjllm.bak1
C:\WINNT\system32\gjllm.bak2
C:\WINNT\system32\gjllm.ini
C:\WINNT\system32\gjllm.bak1
C:\WINNT\system32\gjllm.bak2

Beginning removal…

Attempting to delete C:\WINNT\system32\mlljg.dll
C:\WINNT\system32\mlljg.dll Has been deleted!

Attempting to delete C:\WINNT\system32\gjllm.ini
C:\WINNT\system32\gjllm.ini Has been deleted!

Attempting to delete C:\WINNT\system32\gjllm.bak1
C:\WINNT\system32\gjllm.bak1 Has been deleted!

Attempting to delete C:\WINNT\system32\gjllm.bak2
C:\WINNT\system32\gjllm.bak2 Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Performing Repairs to the registry.
Done!

**************************************************************
This is the new Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 8:48:23 AM, on 10/27/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\slserv.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\ctfmon.exe
C:\WINNT\slrundll.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\My Documents\HijackThis.exe

O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - C:\WINNT\system32\geebc.dll
O2 - BHO: InfoDocReader Object - {295BA105-3506-4D25-B0DD-54346320BDC5} - C:\WINNT\system32\mlljg.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [ntdll.dll] ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{772E478D-5568-4B45-B0C3-52A42621281B}: NameServer = 203.120.90.40 192.169.34.181
O20 - Winlogon Notify: geebc - C:\WINNT\SYSTEM32\geebc.dll
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxsrvc.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINNT\SYSTEM32\slserv.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
Hi. Sorry it took so long to get back with you.
:)

Please follow the below instructions:
  • Download this file and save it to your desktop - combofix.exe
  • Next please click Start—>Run
  • In the run box please copy and paste the text below.

    %userprofile%\desktop\combofix.exe /v geebc

  • Allow Combofix to run (follow any prompts). At the end it will produce a log for you. Post that log in your next reply. If the log does not open automatically it can be found in C:\combofix.txt

    Note: Do not mouseclick combofix's window while it's running. That may cause it to stall.
Please post back with the Combofix log and a fresh Hijack This log.
Due to lack of feedback, this topic has been closed. If you need this topic reopened, please contact a moderator with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI