This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My hijack log

59 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello Booberry,

I need to know if you have a firewall program installed here because AVG Anti-Virus FREE for home use only does not come with a firewall.
If you do not have a firewall installed I have listed a couple free for personal home use only.
And some information never install more than one firewall one the same computer that causes all sorts of problems they conflict with each other and computer with not be protected. Please run this fix I posted before installing firewall if you do not have one.

Here are some you can choose from
Firewall protection programs: (free for personal use only available)

ZoneAlarm: http://www.zonelabs.com/store/content/cata….jsp?lid=nav_za
Comodo http://www.personalfirewall.comodo.com/


You must install ASAP!!

————————————————-

regfix to clear that entry: .

1. Please do this:
  • Copy the contents of the Quote Box below to Notepad make sure to just copy what is inside box nothing outside of box. (not Wordpad)
  • On file menu click Save as
  • Name the file as fix.reg
  • Change the Save as Type to All Files (NOT as a txt file)
  • and Save it on the desktop
Quote:

REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers]
"VDD"=-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\VirtualDeviceDrivers]
"VDD"=hex(7):00,00

[-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Symantec NetDriver Monitor]

Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

2. Then double-click on the fix.reg file, that is on your desktop and when it prompts to merge say yes.

————————————————————————-

Next do the following:

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
———————————————————–

To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon (or click Start, then select My Computer)
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
    Now your computer is configured to show all hidden files.
—————————————————–

Just download this tool but Do not run yet I will let you know when.
Download killbox and click the Save button and save to your deskstop here > : KillBox
Unzip the folder to your desktop:
Now Right-click on the KillBox.zip icon and choose Extract to here from menu.

Now move to next step without running this tool yet.

———————————————————–

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.
————————————————————————–

Open Killbox.exe
  • When it is open Place the following line (complete path) that is in bold red color below in the "Full Path of File to Delete" box in Killbox:

    C:\WINDOWS\TEMP\69366A23.exe
  • Select the Delete on reboot option.
  • Then press the button that looks like a red circle with a white X in it.
You will then get this prompt:

files will be removed on reboot. Do you want to reboot now?


CLICK NO

Then, repeat the process..
  • Place the following line (complete path) that is in bold red color below in the "Full Path of File to Delete" box in Killbox:

    C:\Program Files\PartyPoker.net
  • Select the Delete on reboot option.
  • Then press the button that looks like a red circle with a white X in it.
You will then get this prompt:

files will be removed on reboot. Do you want to reboot now?



On the last one, click YES to the last question.

Your computer will reboot and check to see if the file is gone.

——————————————————————–

Now rerun combofix like you did before and post log

——————————————————————–

Please post in your next reply to this thread these logs
vundofix.txt
combofix
New HJT log
i have a firewall through my router for internet it's a Dlink 1 with Nvidia Firewall. Should i just skip the download and proceed with regfix? and the others?
I was trying to find out about my ip address and i ended up with the same thing as before and im not sure we fixed it, C: WINDOWS\System32\command.com C:\PROGRA~1\Symantec\S32EVNT1.DLL. An installable virtual device driver failed DLL initialization. choose close to terminate the application.
Hi I am looking into this will post back as soon as I get a reply back from Admin/Mod on this. Did that last reply mean you had already ran fix that was posted?
i didn't do anything yet i wanted to know if i should with my firewall would you like me to start? or wait untill you hear back from admin??
after i did killbox and said yes to reboot this popped up and my computer did not reboot? should i manually reboot? pendingfilerenameoperations registry data has been removed by external process
Xodice - 07-01-05 19:06:03.03 Service Pack 2 ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Xodice\NetHood\Desktop\Tom Coyote fixers" ((((((((((((((((((((((((((((((( Files Created from 2006-12-05 to 2007-01-05 )))))))))))))))))))))))))))))))))) 2007-01-05 18:49 d——– C:\!KillBox 2007-01-05 18:30 d——– C:\VundoFix Backups 2007-01-04 19:41 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-01-03 22:49 d——– C:\Program Files\WON 2007-01-03 22:28 d——– C:\avenger 2007-01-03 22:24 60,416 –a—— C:\WINDOWS\system32\drivers\ev^gnmmn.sys 2007-01-03 22:24 d——– C:\Rustbfix 2007-01-03 19:05 2,506 –a—— C:\WINDOWS\system32\tmp.reg 2007-01-03 19:05 d——– C:\Documents and Settings\Xodice\SmitfraudFix 2007-01-03 14:00 dr-h—– C:\Documents and Settings\Xodice\Recent 2007-01-02 12:33 d——– C:\Program Files\CCleaner 2007-01-01 22:30 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe 2007-01-01 22:30 7,483 –a—— C:\clean.bat 2007-01-01 22:30 4,096 –a—— C:\WINDOWS\system32\reboot.exe 2007-01-01 22:30 38,400 –a—— C:\WINDOWS\system32\moveex.exe 2007-01-01 22:29 d——– C:\Program Files\HaxFix 2006-12-27 00:48 dr-h—– C:\$VAULT$.AVG 2006-12-19 23:52 816,672 –a—— C:\WINDOWS\system32\drivers\avg7core.sys 2006-12-19 23:52 4,960 –a—— C:\WINDOWS\system32\drivers\avgtdi.sys 2006-12-19 23:52 4,224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys 2006-12-19 23:52 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys 2006-12-19 23:52 28,416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys 2006-12-19 23:52 18,240 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys 2006-12-19 23:52 d——– C:\Program Files\Grisoft 2006-12-19 23:52 d——– C:\Documents and Settings\Xodice\Application Data\AVG7 2006-12-19 23:52 d——– C:\Documents and Settings\All Users\Application Data\Grisoft 2006-12-19 23:52 d——– C:\Documents and Settings\All Users\Application Data\avg7 2006-12-19 12:41 d——– C:\Documents and Settings\Xodice\Application Data\Real 2006-12-10 00:03 d——– C:\Program Files\Winamp (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-05 19:05 ——– d——– C:\Program Files\Mozilla Firefox 2007-01-05 18:48 ——– d——– C:\Program Files\hijack this 2007-01-04 00:26 ——– d–h—– C:\Program Files\InstallShield Installation Information 2007-01-02 21:43 ——– d——– C:\Program Files\Common Files\Symantec Shared 2006-12-27 01:24 ——– d——– C:\Documents and Settings\Xodice\Application Data\Azureus 2006-12-19 23:52 ——– d—s—- C:\Documents and Settings\Xodice\Application Data\Microsoft 2006-12-19 23:25 ——– d-a—— C:\Program Files\Common Files 2006-12-17 23:17 ——– d——– C:\Program Files\Jasc Software Inc 2006-12-14 03:02 ——– d——– C:\Program Files\Internet Explorer 2006-12-14 03:01 ——– d——– C:\Program Files\Outlook Express 2006-12-14 03:01 ——– d——– C:\Program Files\Common Files\System 2006-12-06 22:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-11-07 22:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll 2006-11-06 12:05 ——– d——– C:\Program Files\MSN Messenger 2006-11-06 12:04 ——– d——– C:\Program Files\Common Files\Microsoft Shared 2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll 2006-10-19 06:56 713216 –a—— C:\WINDOWS\system32\sxs.dll 2006-10-13 05:35 142336 –a—— C:\WINDOWS\system32\nwprovau.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "BTCLiveUpdate"="\"C:\\Program Files\\LiveUpdate\\LiveUpdate.exe\" /autostart" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "NVRaidService"="C:\\WINDOWS\\System32\\nvraidservice.exe" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\"" "NVMixerTray"="\"C:\\Program Files\\NVIDIA Corporation\\NvMixer\\NVMixerTray.exe\"" "iRiver Updater"="\\Updater.exe" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe" "nwiz"="nwiz.exe /install" "ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe" "UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00 "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033 -noicon" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" "winconf"="C:\\WINDOWS\\TEMP\\69366A23.exe" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000000 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\ATI CATALYST System Tray.lnk" "backup"="C:\\WINDOWS\\pss\\ATI CATALYST System Tray.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\ATITEC~1\\ATI.ACE\\CLI.exe SystemTray" "item"="ATI CATALYST System Tray" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\HP Digital Imaging Monitor.lnk" "backup"="C:\\WINDOWS\\pss\\HP Digital Imaging Monitor.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\HP\\DIGITA~1\\bin\\hpqtra08.exe " "item"="HP Digital Imaging Monitor" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinCinema Manager.lnk" "backup"="C:\\WINDOWS\\pss\\InterVideo WinCinema Manager.lnkCommon Startup" "location"="Common Startup" "command"="G:\\PROGRA~1\\INTERV~1\\Common\\Bin\\WINCIN~1.EXE " "item"="InterVideo WinCinema Manager" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinScheduler.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\InterVideo WinScheduler.lnk" "backup"="C:\\WINDOWS\\pss\\InterVideo WinScheduler.lnkCommon Startup" "location"="Common Startup" "command"="G:\\PROGRA~1\\INTERV~1\\MSIPVS\\WINSCH~1.EXE " "item"="InterVideo WinScheduler" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -h" "item"="Kodak EasyShare software" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak software updater.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak software updater.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE " "item"="Kodak software updater" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Xodice^Start Menu^Programs^Startup^Desperate Housewives Registration.lnk] "path"="C:\\Documents and Settings\\Xodice\\Start Menu\\Programs\\Startup\\Desperate Housewives Registration.lnk" "backup"="C:\\WINDOWS\\pss\\Desperate Housewives Registration.lnkStartup" "location"="Startup" "command"="D:\\PROGRA~1\\BUENAV~1\\DESPER~1\\eReg\\DSN1.exe /remind /language=ENU /PRNM=\"Desperate Housewives\"" "item"="Desperate Housewives Registration" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\6JceYY45c] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="websk" "hkey"="HKLM" "command"="C:\\WINDOWS\\websk.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASDPLUGIN] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="canada" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\canada.exe -N" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="cli" "hkey"="HKLM" "command"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="atiptaxx" "hkey"="HKLM" "command"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="CTDetect" "hkey"="HKCU" "command"="C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe /R" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CU1] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCClient" "hkey"="HKCU" "command"="C:\\Program Files\\Common Files\\VCClient\\VCClient.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CU2] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="VCMain" "hkey"="HKCU" "command"="C:\\Program Files\\Common Files\\VCClient\\VCMain.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="daemon" "hkey"="HKLM" "command"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dinst" "hkey"="HKLM" "command"="C:\\WINDOWS\\dinst.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dljgmqgA] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dljgmqgA" "hkey"="HKLM" "command"="C:\\WINDOWS\\dljgmqgA.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\etbrun] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="elitehof32" "hkey"="HKLM" "command"="C:\\windows\\system32\\elitehof32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FLMOFFICE4DMOUSE] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="moffice" "hkey"="HKLM" "command"="C:\\Program Files\\Labtec\\moffice.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gimmygames] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="gimmygames11" "hkey"="HKLM" "command"="C:\\\\gimmygames11.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="HPWuSchd2" "hkey"="HKLM" "command"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ib35jrtp] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ib35jrtp" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\ib35jrtp.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\klop] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="30" "hkey"="HKCU" "command"="C:\\WINDOWS\\30.tmp" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load] "key"="SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows" "item"="??¯ ?" "hkey"="HKCU" "command"="??¯ ?" "inimapping"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Access] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MediaAccK" "hkey"="HKLM" "command"="C:\\Program Files\\Media Access\\MediaAccK.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mhav] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mhav" "hkey"="HKLM" "command"="C:\\WINDOWS\\mhav.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="msmsgs" "hkey"="HKCU" "command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="MWSBAR" "hkey"="HKLM" "command"="rundll32 C:\\PROGRA~1\\MYWEBS~1\\bar\\2.bin\\MWSBAR.DLL,S" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mwsoemon" "hkey"="HKLM" "command"="C:\\PROGRA~1\\MYWEBS~1\\bar\\2.bin\\mwsoemon.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="nwiz" "hkey"="HKLM" "command"="nwiz.exe /install" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ongsnah] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="bdkybh" "hkey"="HKLM" "command"="c:\\windows\\system32\\bdkybh.exe r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="mssysmgr" "hkey"="HKCU" "command"="C:\\PROGRA~1\\Ahead\\NEROPH~2\\data\\Xtras\\mssysmgr.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POINTER] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="point32" "hkey"="HKLM" "command"="C:\\Program Files\\Microsoft Hardware\\Mouse\\point32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pop-Up Stopper] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dpps2" "hkey"="HKLM" "command"="\"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\dpps2.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QD FastAndSafe] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="point32" "hkey"="HKLM" "command"="C:\\Program Files\\Microsoft Hardware\\Mouse\\point32.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="qttask" "hkey"="HKLM" "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="RealPlay" "hkey"="HKLM" "command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="PDVDServ" "hkey"="HKLM" "command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roii] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="roiim" "hkey"="HKCU" "command"="C:\\PROGRA~1\\COMMON~1\\roii\\roiim.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shell] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ibm00001" "hkey"="HKCU" "command"="\"C:\\Program Files\\Common Files\\Microsoft Shared\\Web Folders\\ibm00001.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="TeaTimer" "hkey"="HKCU" "command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="" "hkey"="HKCU" "command"="" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="jusched" "hkey"="HKLM" "command"="C:\\Program Files\\Java\\jre1.5.0_01\\bin\\jusched.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SurfSideKick 3] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="Ssk" "hkey"="HKLM" "command"="C:\\Program Files\\SurfSideKick 3\\Ssk.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svgbwr] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ggkgwm" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\ggkgwm.exe r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SNDMon" "hkey"="HKLM" "command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TheMonitor] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="SYSC00" "hkey"="HKLM" "command"="C:\\WINDOWS\\SYSC00.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="dumprep 0 -u" "hkey"="HKLM" "command"="%systemroot%\\system32\\dumprep 0 -u" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeirdOnTheWeb] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="WeirdOnTheWeb" "hkey"="HKLM" "command"="\"C:\\Program Files\\WeirdOnTheWeb\\WeirdOnTheWeb.exe\"" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\win32073991086372] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="win32073991086372" "hkey"="HKLM" "command"="C:\\WINDOWS\\win32073991086372.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winampa" "hkey"="HKLM" "command"="C:\\Program Files\\Winamp\\winampa.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysban] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winsysban11" "hkey"="HKLM" "command"="C:\\\\winsysban11.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winsysupd] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="winsysupd11" "hkey"="HKLM" "command"="C:\\\\winsysupd11.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\xwrrakq] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="izopei" "hkey"="HKLM" "command"="c:\\windows\\system32\\izopei.exe r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ydcbyf] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="ydcbyf" "hkey"="HKLM" "command"="C:\\WINDOWS\\ydcbyf.exe" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yjdtsar] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="zmppnu" "hkey"="HKLM" "command"="C:\\WINDOWS\\system32\\zmppnu.exe r" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "FreezeScreenSaver"=dword:00000002 HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwil32 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Completion time: 07-01-05 19:06:58.93 C:\ComboFix.txt … 07-01-05 19:06 C:\ComboFix2.txt … 07-01-03 19:00 C:\ComboFix3.txt … 07-01-03 14:04
VundoFix V6.2.13 Checking Java version… Scan started at 6:30:08 PM 1/5/2007 Listing files found while scanning…. No infected files were found. Beginning removal…
Logfile of HijackThis v1.99.1
Scan saved at 7:09:12 PM, on 1/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Updater.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\LiveUpdate\LiveUpdate.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: CleanMyPC Toolbar - {04164EC4-1E48-4279-818E-3721931E7636} - C:\Program Files\CleanMyPC Popup Blocker\CleanBar.dll (file missing)
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [winconf] C:\WINDOWS\TEMP\69366A23.exe
O4 - HKCU\..\Run: [BTCLiveUpdate] "C:\Program Files\LiveUpdate\LiveUpdate.exe" /autostart
O4 - Global Startup: D-Link AirPlus.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: winwil32 - winwil32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
Hi Booberry,

Ok now I need you do the following:

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
—————————————————————————

In this part you need to be in safe mode.
Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
———————————————————————

Before you run this part of fix read the following if you have uninstalled and no longer have these on your system they can be fixed to removed.

O3 - Toolbar: CleanMyPC Toolbar - {04164EC4-1E48-4279-818E-3721931E7636} - C:\Program Files\CleanMyPC Popup Blocker\CleanBar.dll (file missing)

The following entry is related to Webroot's SpySweeper. If it is no longer installed, this entry should be fixed..

O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

Now they are include here to be fix and removed do not put a checkmark in box and fix if you are using them. From looks of HJT log they look like they have been uninstalled.

Now continue with fix: .

—————————————————————
Computer still in safe mode

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O3 - Toolbar: CleanMyPC Toolbar - {04164EC4-1E48-4279-818E-3721931E7636} - C:\Program Files\CleanMyPC Popup Blocker\CleanBar.dll (file missing)
O4 - HKLM\..\Run: [winconf] C:\WINDOWS\TEMP\69366A23.exe
O20 - Winlogon Notify: winwil32 - winwil32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.

—————————————————————————


Use Explorer to navigate to and delete the following file (if it is present) just what is in red:

Files:
  • C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe <<<< Maybe C:\ProgramFiles\SYMNET << Folder Starting with these letters.

If you can not find SNDMon.exe move to next step.

—————————————————————————–

Start Killbox place a tick next to [x]Delete on reboot
Copy this file path into the windows clipboard, all the bold below…

C:\WINDOWS\TEMP\69366A23.exe

Back in Killbox go to > file > paste from clipboard.
Next, click the red highlighted X button and say NO to the prompt to restart the pc.
Now, exit Killbox and restart Your PC.

——————————————————————————

Now you sould be back to running in normal mode.
Rerun Ccleaner and it should still be set like it was before have relisted settings.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the Windows tab, under Internet Explorer,
  • All Boxes should have a check mark. (You will need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • On the Windows tab, under Windows Explorer,
  • All Boxes should have a check mark.
  • On the Windows tab, under System,
  • All Boxes should have a check mark.
  • On the Windows tab, under Advanced,
  • NO check marks
[*]If you use either the Firefox or Mozilla browsers, the box to put check in for "Cookies" is on the Applications tab, under Firefox/Mozilla. If already checked move to next step.

[*]Click on the "Options" icon at the left side of the window, then click on "Advanced."

deselect "Only delete files in Windows Temp folders older than 48 hours."
[*]Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.

[*]Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.

[*]After CCleaner has completed its process, click Exit.

[*]You will need to reboot to normal mode here if not ask to do so.

_______________________________

Please do the following online scan
Run Panda's ActiveScan from here and perform a full system scan.

1. Once you are on the Panda site click the "Scan your PC" button NOTE: If you have a popblocker enable you will have to allow popup here.
2. A new window will open…click the big "Check Now" button
3. Enter your Country
4. Enter your State/Province
5. Enter your e-mail address and click send
6. Select either Home User or Company
7. Click the big Scan Now button
8. If it wants to install an ActiveX component allow it
9. It will start downloading the files it requires for the scan (Note: It will take a couple minutes. You may have to reboot here and start back with step 1. I did.)
10. Click on "Local Disks" to start the scan
11. Post Panda scan results in your next reply with others requested.

———————————————————

Next rerun combfix same as before.

————————————————————

Please post these logs in your next reply:
SDFix Report.txt
Panda's report
combofix's log
New HJT log
SDFix: Version 1.55 **************** Sat 01/06/2007 - 20:04:45.35 Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Stage One - Safe Mode Checking Services… Service Name: File Path: Starting Registry Repairs… Restoring Default Hosts File… Stage One Complete Rebooting… Stage Two - Normal Mode Checking For Malware: ——————– C:\WINDOWS\system32\TFTP1432 C:\WINDOWS\system32\TFTP1508 Backing Up and Removing any Files Found… Alternate Stream Check: C:\WINDOWS\system32 No streams found. Final Check: Remaining Services: —————— Authorized Application Key Export: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0" "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0" "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" Remaining Files: ————— Backups Folder: - C:\SDFix\backups\backups.zip Checking for files with Hidden Attributes: C:\NTDETECT.COM C:\Program Files\Ahead\Nero PhotoShow\data\Nero PhotoShow Express.exe C:\WINDOWS\system32\cdplayer.exe.manifest C:\WINDOWS\system32\logonui.exe.manifest C:\WINDOWS\system32\YSB.exe C:\IO.SYS C:\MSDOS.SYS C:\pagefile.sys FINISHED!
after my computer restarted and i copied the txt from sdfix this popped up Services and Controller app encountered a problem and needed to close. I have left this wihtout pressing the don't send button what should i do and what does this mean??

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI