This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Klone virus and Trojan Horse

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just put AVG anti-virus and anti-spywear on my computer today and it says the I have a Klone virus and a Trojan horse downloader.generic2.QJQ and a Trojan Clicker. I have also installed the hijackthis program. I hpoe that someone can help me fix this computer, it is my work computer, I have so many pop-ups, and now the Klone Virus from the anti-virus keeps popping up. It's driving me crazy!!!

(((((((((((((((((((((((((((((((((((((Here it the hijackthis log)))))))))))))))))))))))))))))))))))))))))))

Logfile of HijackThis v1.99.1
Scan saved at 2:53:13 PM, on 12/27/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\LTMSG.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\WildTangent\Apps\GameChannel.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\hp deskjet 9600 series\Toolbox\HPWITBX.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\interMute\SpamSubtract\SpamSub.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us10.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {013A653B-49A6-4f76-8B68-E4875EA6BA54} - C:\WINDOWS\System32\tmp1A.tmp.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {87529EC0-7C1B-4D60-92D2-AF8AD6227FEA} - C:\WINDOWS\system32\igf006.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [HPWITOOLBOX] C:\Program Files\Hewlett-Packard\hp deskjet 9600 series\Toolbox\HPWITBX.exe "-i"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://i.grab.com/media/d3d944/games/files/222/222.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://69.58.19.2/html/jackson/mgaxctrl.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.shockwave.com/content/dinerdash…h2.1.0.0.53.cab
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/clo/install/grab/CLOAct…tallerProj1.cab
O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://media.grab.com/media/35f4a8/games/f…1147/axhost.cab
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVC Download Control) - http://www.shockwave.com/content/davincico…d%20Control.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/f…outLauncher.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://www.playfirst.com/play/game/dinerdash/dinerdash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://i.grab.com/media/70efdf/games/files…aploader_v6.cab
O20 - Winlogon Notify: igf006 - C:\WINDOWS\SYSTEM32\igf006.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Crypkey License - Unknown owner - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe



(((((((((((((((((((((((((((((((((((((((((here is the anti-spyware log)))))))))))))))))))))))))))))))))))))))))))))

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 2:56:48 PM 12/27/2006

+ Scan result:



HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.
C:\WINDOWS\wt\updater\install\wcmdmgr.exe -> Adware.Wildtangent : Ignored.
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Ignored.
C:\WINDOWS\Downloaded Program Files\UERS_0001_N91M2007NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@247realmedia[1].txt -> TrackingCookie.247realmedia : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@cnetaustralia.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@ford.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@ldproducts.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@livedealcom.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@onetoone.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@pch.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@reunioncom.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@waterfrontmedia.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@wrigley.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@adbrite[1].txt -> TrackingCookie.Adbrite : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@admarketplace[1].txt -> TrackingCookie.Admarketplace : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[3].txt -> TrackingCookie.Adrevolver : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Adrevolver : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@adtech[2].txt -> TrackingCookie.Adtech : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@bfast[2].txt -> TrackingCookie.Bfast : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Bridgetrack : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Bridgetrack : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@burstnet[2].txt -> TrackingCookie.Burstnet : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Casalemedia : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[1].txt -> TrackingCookie.Casalemedia : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@clickbank[2].txt -> TrackingCookie.Clickbank : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@com[1].txt -> TrackingCookie.Com : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@enhance[2].txt -> TrackingCookie.Enhance : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@fastclick[1].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@findwhat[2].txt -> TrackingCookie.Findwhat : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Goclick : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@goclick[2].txt -> TrackingCookie.Goclick : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Hitslink : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@hotlog[1].txt -> TrackingCookie.Hotlog : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@kmpads[2].txt -> TrackingCookie.Kmpads : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@linksynergy[1].txt -> TrackingCookie.Linksynergy : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Myaffiliateprogram : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Onestat : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@overture[1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Planetactive : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@qksrv[2].txt -> TrackingCookie.Qksrv : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt -> TrackingCookie.Questionmarket : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Realtracker : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@revenue[1].txt -> TrackingCookie.Revenue : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[2].txt -> TrackingCookie.Ru4 : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed]-sys[2].txt -> TrackingCookie.Serving-sys : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt -> TrackingCookie.Serving-sys : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@spylog[2].txt -> TrackingCookie.Spylog : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Starware : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Starware : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt -> TrackingCookie.Statcounter : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@tacoda[2].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@targetnet[1].txt -> TrackingCookie.Targetnet : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[1].txt -> TrackingCookie.Trafficmp : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Valuead : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@valueclick[1].txt -> TrackingCookie.Valueclick : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@web-stat[1].txt -> TrackingCookie.Web-stat : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@yadro[2].txt -> TrackingCookie.Yadro : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignored.
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Zedo : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@zedo[2].txt -> TrackingCookie.Zedo : Ignored.
C:\WINDOWS\system32\tmpB0.tmp.dll -> Trojan.BHO.g : Ignored.
C:\WINDOWS\system32\drivers\etc\hosts -> Trojan.Qhost.hl : Ignored.


::Report end
Hello larakatts,

Welcome to the Tomcoyote forum! I'll be glad to help you with your computer problems.
HijackThis logs can take some time to research, so please be patient with me. I know that you need
your computer working as quickly as possible, and I will work hard to help see that happens.

In order to help me help you, please observe the following while we work:
  • If you don't know, stop and ask! Don't continue, we don't want to start all over again!
  • Understand that cleaning your computer can sometimes take multiple passes/posts,
    and it's important to follow the steps as listed including re-running scans as listed
  • Please reply to this thread, do not start another.

If you can do those three things, everything should go smoothly
Hello larakatts,

First things first from the looks of your log we have a lot to do. You said this is your work computer your OS is not up-to-date HJT Log shows Windows XP SP1 you are not protected from infections. Is there any reason you don't have SP2 installed. Please do not install it now your system has to be cleared of infections first. Installing on an infected system can cause all sorts of problems. We will have to do that last.

———————————————————————————————-

Please read this information:

I just put AVG anti-virus and anti-spywear on my computer today

This is very bad you are running two Anti-virus Programs AVG anti-virus and Norton AntiVirus
Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two or more anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash. They can conflict with each other which leaves you open to infection.
you can not have more than one antivirus program installed on the same system, you must narrow it down to only one. Please choose one that is currently capable of receiving updates of virus definitions. If you have an antivirus program that no longer has an active subscription to antivirus updates, it cannot protect your system from malware.

Choose which one you want and you must uninstall the other.
Do not uninstall AVG Anti-Spyware 7.5 this is a different program and is fine to run on the same system with Anti-virus programs and we will need it later.
————————————————————-

Now this is next you are running HiJackThis from a Temp folder if you have created a shortcut on your desktop please delete it now. Do not worry about the one in the Temp folder we will clean it out later. We are doing this to insure backups are made and not deleted
Download HijackThis and save to your Desktop. Click HERE
  • Double click on hijackthis_sfx.exe and now choose unzip button it should install to C:\Program Files\HijackThis
  • Now click start > then My Computer > then double click C drive
  • Double click Program Files folder > Then open HijackThis folder.
  • Now right-click on HijackThis.exe icon > and choose Send to > Choose Desktop( create a shortcut)
  • Done close all open windows
This is important to have done first.
—————————————————————————————-

Disable(turn off) program can interfer with removal of infection.
Open AVG Anti-Spyware 7.5
  • On the main screen under Your Computer's security.
  • Click on Change state next to Resident shield. It should now change to inactive.
  • Close AVG Anti-Spyware 7.5
  • Right-click the AVG Anti-Spyware 7.5 Tray Icon and choose Exit. Confirm by clicking Yes.
—————————————————————————————-

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
——————————————————————————————-

Please do the following:
Here we are going to clean out cookies and temp files from your computer.


*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!

Download CCleaner from here It will start to download automatically. If ask if you want to download let it. Save to your Desktop.
Note: If you get and Error page from this link.
Try again you will see this message Your download of CCleaner will automatically start in 5 seconds. Click here if it does not do not wait go ahead and click on it.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Follow prompts to install finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the Windows tab, under Internet Explorer,
  • All Boxes should have a check mark. (You will need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • On the Windows tab, under Windows Explorer,
  • All Boxes should have a check mark.
  • On the Windows tab, under System,
  • All Boxes should have a check mark.
  • On the Windows tab, under Advanced,
  • NO check marks
[*]If you use either the Firefox or Mozilla browsers, the box to put check in for "Cookies" is on the Applications tab, under Firefox/Mozilla. If already checked move to next step.

[*]Click on the "Options" icon at the left side of the window, then click on "Advanced."

deselect "Only delete files in Windows Temp folders older than 48 hours."
[*]Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.

[*]Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.

[*]After CCleaner has completed its process, click Exit.

[*]You will need to reboot here if not ask to do so.

_______________________________


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Here we are going to just make sure this tool is setup correctly. Some of the steps you did earlier but I like to recap to make sure.
Do not run scan yet.
  • Open AVG Anti-Spyware
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to the words Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
    • Click on Scanner on the toolbar at top of this screen.
    • Click on the Settings tab.
      • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Close AVG Anti-Spyware without running yet.
Now disable (turn off AVG Anti-Spyware)
  • Right-click the AVG Anti-Spyware Tray Icon (Bottom right corner of computer screen near clock) and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon again and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Note: If AVG Anti-Spyware screen does not fit your monitor screen Hold down the Alt button on keyboard then tap spacebar, menu should pop up then choose maximize. AVG Anti-Spyware screen should fix screen a little better.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
[external image: Posted Image]

IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
  • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
  • At the bottom of the window click on the Apply all Actions button.(3)
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

———————————————————–

Next do the following:
1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

———————————————————-

Run Panda's ActiveScan from here and perform a full system scan.

1. Once you are on the Panda site click the "Scan your PC" button NOTE: If you have a popblocker enable you will have to allow popup here.
2. A new window will open…click the big "Check Now" button
3. Enter your Country
4. Enter your State/Province
5. Enter your e-mail address and click send
6. Select either Home User or Company
7. Click the big Scan Now button
8. If it wants to install an ActiveX component allow it
9. It will start downloading the files it requires for the scan (Note: It will take a couple minutes. You may have to reboot here and start back with step 1. I did.)
10. Click on "Local Disks" to start the scan
11. Post Panda scan results in your next reply with others requested.
—————————————————————–

Please post these log in your next reply to this thread:
vundofix.txt
AVG Anti-Spyware
combofix's log
Panda's ActiveScan report
New HJT log
Hi larakatts, I need to know if you are still needing help. If you do I need you to post a new HiJackThis log. Infections can change in the time that has past. I will leave this topic open for another 48 hours
Due to inactivity, this topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI