This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Computer shuts off without warning, i think it's a virus:

here's the hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 11:58:57 PM, on 11/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\regscan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\common files\aol\1162953580\ee\aim6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\WINDOWS\system32\wuauclt.exe
c:\program files\common files\aol\1162953580\ee\aolsoftware.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\program files\aol\aol toolbar 3.1\aoltbhelper.exe
C:\Documents and Settings\Owner.BOB.000\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\lixaj.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,vefetdk.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [tqlnju] C:\WINDOWS\System32\uyhvjw.exe reg_run
O4 - HKLM\..\Run: [xFXMixer] C:\PROGRA~1\xFXMixer\xfxmixer.exe /min
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1162953580\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [qnsok] C:\WINDOWS\System32\uyhvjw.exe reg_run
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\System32\regscan.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: customize__IE.lnk = C:\hp\region\customizeIe.wsf
O4 - Global Startup: MsnFixer.lnk = ?
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1148445894859
O16 - DPF: {CE74A05D-ED12-473A-97F8-85FB0E2F479F} (dlControl.UserControl1) - http://www.livemetallica.com/nugster/dlControl.CAB
O20 - AppInit_DLLs:
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Tomorrowsnightmarefrank

Welcome to Tom Coyote

Sorry for the delay

1. Please download the Killbox. Save it to the desktop.

2. Reboot into Safe Mode
This can be done byRestart your PC, and after it starts, but before you see the Windows Splash screen
Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
Use your arrow keys and select Safe Mode and then Enter
3.1) Run Killbox
2) Select "Delete on Reboot", and then select "All files".
3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:
C:\WINDOWS\System32\lixaj.exe
C:\WINDOWS\System32\uyhvjw.exe

4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
5) Click the red-and-white "Delete File" button.  Click "Yes" at the Delete on Reboot prompt.  Click "No" at the Pending Operations prompt.
4. Using Windows Search (Click Start->>Search)
Locate and Delete the following fileALCXMNTR.EXE
Close Windows Search->>Reboot your PC

5.1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

thanks bamajim
Thank You for your help so far. Here's the combofix log: Owner - 06-12-02 22:05:15.10 Service Pack 2 ComboFix 06.11.27W - Running from: "C:\Documents and Settings\Owner.BOB.000\Desktop" ((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log ))))))))))))))))))))))))))))))))))))))))))))))))))) * * * POST-RUN - Files in the Quarantine folder * * * * * * * * * * * * * * * * * * * * * * * * * DO NOT DELETE ANY FILES FROM THIS DIRECTORY UNLESS INSTRUCTED TO (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\wnsintsv.exe C:\Program Files\Common Files\Yazzle1122OinAdmin.exe C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe C:\WINDOWS\uninstall_nmon.vbs C:\WINDOWS\system32\atmtd.dll C:\WINDOWS\system32\atmtd.dll._ C:\Documents and Settings\LocalService\Application Data\NetMon C:\Program Files\Common Files\download C:\Program Files\Cowabanga C:\Program Files\Inetget2 C:\Program Files\network monitor C:\Program Files\ql C:\Program Files\Common Files\{3868A95C-09BA-1033-1016-030224200001} C:\Program Files\Common Files\{8868A95C-09BA-1033-1016-030224200001} C:\Program Files\Common Files\{8868A95C-09BA-1033-1016-030224200001} C:\WINDOWS\RmVsaWNlIFByaWFtbw ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: C:\QooBox\Purity\Program Files\SEMBLY~1 C:\QooBox\Purity\Program Files\SMBOLS~1 C:\QooBox\Purity\Program Files\Common Files\CROSOF~1.NET C:\QooBox\Purity\Program Files\Common Files\FNTS~1 C:\QooBox\Purity\Program Files\Common Files\STEM~1 C:\QooBox\Purity\Program Files\Common Files\YSTEM~1 C:\QooBox\Purity\Program Files\SMBOLS~1\r?gsvr32.exe C:\QooBox\Purity\WINDOWS\RACLE~1 C:\QooBox\Purity\WINDOWS\SEMBLY~1 C:\QooBox\Purity\WINDOWS\RACLE~1\RACLE~1 C:\QooBox\Purity\WINDOWS\RACLE~1\winword.exe C:\QooBox\Purity\WINDOWS\system32\SMANTE~1 ((((((((((((((((((((((((((((((( Files Created from 2006-11-02 to 2006-12-02 )))))))))))))))))))))))))))))))))) 2006-12-02 21:13 d——– C:\!KillBox 2006-11-30 00:18 56,320 –a—— C:\WINDOWS\system32\rgbcly.dll 2006-11-23 22:46 d——– C:\Documents and Settings\Owner.BOB.000\Application Data\Motive 2006-11-23 08:53 145 –a-s—- C:\WINDOWS\test.bat 2006-11-23 00:04 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys 2006-11-18 00:00 d——– C:\Program Files\Apple Software Update 2006-11-05 18:18 d——– C:\Program Files\SpacialAudio 2006-11-05 18:05 737,280 –a—— C:\WINDOWS\iun6002.exe (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-12-02 22:07 ——– d——– C:\Program Files\Common Files 2006-11-22 23:05 ——– d——– C:\Program Files\VirtualDJ 2006-11-18 03:00 ——– d——– C:\Program Files\Internet Explorer 2006-11-18 00:03 ——– d——– C:\Program Files\iTunes 2006-11-18 00:03 ——– d——– C:\Program Files\iPod 2006-11-18 00:02 ——– d——– C:\Program Files\QuickTime 2006-11-07 21:40 ——– d——– C:\Program Files\Common Files\AOL 2006-11-07 21:40 ——– d——– C:\Program Files\AOL 2006-11-07 21:40 ——– d——– C:\Program Files\AOD 2006-11-05 18:00 ——– d——– C:\Program Files\MixVibes6 2006-10-30 20:35 ——– d——– C:\Documents and Settings\Owner.BOB.000\Application Data\Atari 2006-10-30 20:28 ——– d–h—– C:\Program Files\InstallShield Installation Information 2006-10-30 20:28 ——– d——– C:\Program Files\Atari 2006-10-25 00:48 ——– d——– C:\Program Files\Common Files\Microsoft Shared 2006-10-18 12:40 ——– d——– C:\Program Files\Google 2006-10-15 23:35 ——– d——– C:\Documents and Settings\Owner.BOB.000\Application Data\Google 2006-10-15 21:06 ——– d——– C:\Program Files\MtStudio 2006-10-15 19:45 ——– d——– C:\Program Files\Image-Line 2006-10-15 19:44 ——– d——– C:\Program Files\AtomixMP3 2006-10-13 07:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll 2006-10-10 21:17 ——– d——– C:\Program Files\REGSHAVE 2006-10-10 21:17 ——– d——– C:\Program Files\Common Files\Symantec Shared 2006-10-10 21:17 ——– d——– C:\Program Files\AIM 2006-10-10 21:11 25600 –a—— C:\WINDOWS\system32\ps2.exe 2006-10-10 21:11 25600 –a—— C:\WINDOWS\system32\igfxtray.exe 2006-10-10 21:11 25600 –a—— C:\WINDOWS\system32\hkcmd.exe 2006-10-09 20:08 ——– d——– C:\Program Files\MixVibesFREE5 2006-10-08 12:44 ——– d——– C:\Program Files\Visiosonic 2006-10-08 12:20 ——– d——– C:\Program Files\SoftJock 2006-10-06 22:55 56 -r-hs—- C:\WINDOWS\system32\C5E2E194A4.sys 2006-10-05 19:51 ——– d——– C:\Documents and Settings\Owner.BOB.000\Application Data\LimeWire 2006-10-03 00:06 ——– d——– C:\Documents and Settings\Owner.BOB.000\Application Data\AdobeUM 2006-09-20 20:11 61678 –a—— C:\Documents and Settings\Owner.BOB.000\Application Data\PFP110JPR.{PB 2006-09-20 20:11 12358 –a—— C:\Documents and Settings\Owner.BOB.000\Application Data\PFP110JCM.{PB 2006-09-19 15:43 109360 –a—— C:\WINDOWS\system32\GEARAspi.dll 2006-09-13 00:01 1084416 –a—— C:\WINDOWS\system32\msxml3.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "NVIEW"="rundll32.exe nview.dll,nViewLoadHook" "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "RealPlayer"="\"C:\\Program Files\\Real\\RealOne Player\\realplay.exe\" /RunUPGToolCommandReBoot" "AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl" "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.0.720.3640\\GoogleToolbarNotifier.exe" "Regscan"="C:\\WINDOWS\\System32\\regscan.exe" "Aim6"="\"C:\\Program Files\\Common Files\\AOL\\Launch\\AOLLaunch.exe\" /d locale=en-US ee://aol/imApp" "Notn"="\"C:\\WINDOWS\\RACLE~1\\winword.exe\" -vt yazr" "Twm"="C:\\Program Files\\s?mbols\\r?gsvr32.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "hpsysdrv"="c:\\windows\\system\\hpsysdrv.exe" "HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe" "KBD"="C:\\HP\\KBD\\KBD.EXE" "StorageGuard"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup" "nwiz"="nwiz.exe /installquiet /keeploaded /nodetect" "ccApp"="\"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "ccRegVfy"="\"c:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\"" "PS2"="C:\\WINDOWS\\system32\\ps2.exe" "HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb08.exe" "ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe" "REGSHAVE"="C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE /AUTORUN" "AlcxMonitor"="ALCXMNTR.EXE" "IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_03\\bin\\jusched.exe" "mmtask"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mmtask.exe" "ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNOTIFY.EXE" "QuickFinder Scheduler"="\"c:\\Program Files\\WordPerfect Office 11\\Programs\\QFSCHD110.EXE\"" "xFXMixer"="C:\\PROGRA~1\\xFXMixer\\xfxmixer.exe /min" "HostManager"="C:\\Program Files\\Common Files\\AOL\\1162953580\\ee\\AOLSoftware.exe" "IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="ewido shell guard" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job Completion time: 06-12-02 22:14:26.20 C:\ComboFix.txt … 06-12-02 22:14 C:\ComboFix2.txt … 06-12-02 21:36
Tomorrowsnightmarefrank

First We need to make sure we can see hidden files and folders:

To enable the viewing of Hidden and System files follow these steps: Right click on Start and select Explore.
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Put a checkmark in the checkbox labeled Display the contents of system folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.
Click Yes To confirm
Press the Apply button and then the OK button.
Next You have a suspicious file I need some more info on

Please upload this file to Jotti's Online Virus Scan C:\WINDOWS\system32\C5E2E194A4.sys
Click "Browse" at the top of the page
- Navigate to (Locate)C:\WINDOWS\system32\C5E2E194A4.sys
- Click "Open" Then the "Submit" and let the scan finish
- Scroll down to the bottom of the page to find the results
- Copy/paste the results in your next reply.
thanks bamajim
Sorry, for the delay, I still have the same problem, and once again thanks for your help. THis is what was yielded by the scan: Service load: 0% 100% File: C5E2E194A4.sys Status: OK MD5 5d993a7eecdc9625d104c3e958590518 Packers detected: - Scanner results AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing VirusBuster Found nothing VBA32 Found nothing Powered by Disclaimer This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER EVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service. Also, we are aware of the implications of a setup like this. We are sure this whole thing is by no means scientifically correct, since this is a fully automated service (although manual correction is possible). We are aware, in spite of efforts to proactively counter these, false positives might occur, for example. We do not consider this a very big issue, so please do not e-mail us about it. This is a simple online scan service, not the university of Wichita. Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Another note: some scanners will only report one virus when scanning archives with multiple pieces of malware. Virus definitions are updated every hour. There is a 15Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample. Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception. Read more about this in our privacy policy. If you do not want your files to be distributed, please do not send them at all. Sponsored by donations (in random order) from: Stormbyte Technologies LLC, The ClamAV project, Steve S., Eric Johansen, Eric Schechter, Paul Bokel, Wilders Security, Wilfried Lilie, Prevx, SonicWALL, Lance Mueller, Ewido networks, HotelScraper.com, people who donated in the past, and some people who prefer to remain anonymous… many thanks to all! Statistics Last file scanned at least one scanner reported something about: netmng.exe (MD5: 727c2b3fffd2c077f5afb736802c331c), detected by: Scanner Malware name AntiVir Heuristic/Crypted ArcaVir X Avast X AVG Antivirus X BitDefender MemScan:Backdoor.Eggdrop.1.7 ClamAV X Dr.Web BackDoor.EggDrop.17 F-Prot Antivirus X F-Secure Anti-Virus X Fortinet X Kaspersky Anti-Virus X NOD32 X Norman Virus Control X VirusBuster X VBA32 Backdoor.EggDrop.17 You're free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives We are not affiliated with any third parties that conduct tests using this service.
Tomorrowsnightmarefrank

O.k. that file seems o.k.

1. Open Notepad (Not Wordpad)
Copy and paste the following into notepad
(Making sure there is no space between the top of the window and the first line)

REGEDIT4

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Notn"=-
"Regscan"=-
"Twm"=-

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AlcxMonitor"=-

After you copy and paste it your cursor should be at the end of the first line
Hit Enter so your cursor is under the last lineClick File->>Save as->>type in fix.reg->>
Under "Save as type" Select "All Files"->> save it to your Desktop
Close Notepad
The fix.reg file should now appear on your Desktop

Rt Click and Select merge->>If prompted to merge with registry Select Yes (it will appear that nothing has happened but that's o.k.)

2. Using Windows Explorer(Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate and Delete the following filesC:\WINDOWS\system32\rgbcly.dll
C:\WINDOWS\iun6002.exe

Close Windows Explorer->>Reboot your PC

3. Please perform an Ewido Online Malware Scan
  • When a dialog box appears asking you if you would like to download and install the ewido anti-spyware online scanner please click Yes to allow the download.
  • Click on Start Scan.
  • after the scan completes i twill produce a log for you, copy and paste the results of that scan as a reply to this thread
  • If any infections are found, (After you save the logfile), Click on Remove Infections.
thanks bamajim

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI