This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Random internet related issues

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 22:12:14, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\WINDOWS\system32\Weather.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Stephen\Desktop\HijackThis.exe
C:\Documents and Settings\Stephen\Desktop\EN CounterSpyConsumer.2.1.854.0.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {7191BA0E-7C17-AAA7-981B-05C0166B055B} - C:\WINDOWS\system32\qfipplj.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\msvrl.dll
O12 - Plugin for .hlq: C:\Program Files\Internet Explorer\PLUGINS\NpHcd32.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: instcat - instcat.dll (file missing)
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
Reveal Hidden Files
  • Click Start.
  • Open My Computer.
  • SelectTools menu
  • Click Folder Options.
  • Select the View Tab.
  • Select Show hidden files and foldersin the Hidden files and folders section.
  • Uncheck Hide protected operating system files (recommended) option.
  • Uncheck the Hide file extensions for known file types option.
  • Click Yes.
  • Click OK.
Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

O20 - Winlogon Notify: instcat - instcat.dll (file missing)
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\System32\vbsys2.dll (file missing)

Then close all windows except Hijackthis and click Fix Checked

Now please Download LSPFix from http://www.cexx.org/lspfix.htm and Run the Program. Disconnect from the Internet and close all Internet Explorer Windows. Check the "I know what I'm doing" Button and place all listings of msvrl.dll into the remove section by clicking on the button that points to the right. When all instances of this dll are in the Remove section. Press the finish button.

Restart

Use windows explorer to find and delete these files:

C:\WINDOWS\system32\rpcc.dll
C:\WINDOWS\System32\vbsys2.dll
C:\WINDOWS\System32\instcat.dll

Go here to run an online scannner from Kaspersky.
  • Click on "Kaspersky Online Scanner"
  • A new smaller window will pop up. Press on "Accept". After reading the contents.
  • Now Kaspersky will update the anti-virus database. Let it run.
  • Click on "Next">"Scan Settings", and make sure the database is set to "extended". And check both the scan options. Then click OK.
  • Then click on "My Computer", and the scan will start.
  • Once finished, save the log as "KAV.txt" to the desktop.
Post back with the Kaspersky log, a new HijackThis log and let me know if your problems still persist.
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, January 21, 2007 12:06:26 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 21/01/2007
Kaspersky Anti-Virus database records: 260491
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 60812
Number of viruses found: 41
Number of infected objects: 150 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:44:16

Infected Object Name / Virus Name / Last Action
C:\bak\dfndrff_e19.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\bak\kybrdff_e19.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Stephen\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Stephen\Desktop\backups\backup-20070120-163456-843.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\Documents and Settings\Stephen\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Stephen\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Stephen\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\246.tmp Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\h91746.exe Infected: Trojan-Downloader.Win32.Busky.gen skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\qvxt42.game Infected: Trojan-Downloader.Win32.Small.eci skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Internet Files\Content.IE5\32HINTUK\w[1].exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Internet Files\Content.IE5\8JZMTYSB\popup[1].htm Infected: Trojan-Clicker.HTML.Agent.a skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Internet Files\Content.IE5\8JZMTYSB\popup[2].htm Infected: Trojan-Clicker.HTML.Agent.a skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Internet Files\Content.IE5\8JZMTYSB\ss[1].exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Internet Files\Content.IE5\N22A7Q89\checkin[1].htm Infected: Trojan-Downloader.VBS.Small.co skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Internet Files\Content.IE5\N22A7Q89\popup[1].htm Infected: Trojan-Clicker.HTML.Agent.a skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\Temporary Internet Files\Content.IE5\VICZ6MVF\se[1].exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\uninstall.exe Infected: Trojan-Clicker.Win32.Small.iz skipped
C:\Documents and Settings\Stephen\Local Settings\Temp\v4x3.ga2me Infected: Trojan-Proxy.Win32.Dlena.ax skipped
C:\Documents and Settings\Stephen\Local Settings\Temporary Internet Files\Content.IE5\05VFG6DP\sltchyod.t Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\Documents and Settings\Stephen\Local Settings\Temporary Internet Files\Content.IE5\05VFG6DP\vrsteduj.t Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\Documents and Settings\Stephen\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Stephen\My Documents\IMNames.exe/data.rar/1.exe Infected: Trojan.Win32.KillFW.a skipped
C:\Documents and Settings\Stephen\My Documents\IMNames.exe/data.rar/IM-svr.exe Infected: not-a-virus:AdWare.Win32.2Search.i skipped
C:\Documents and Settings\Stephen\My Documents\IMNames.exe/data.rar/IMNames.exe Infected: not-a-virus:AdWare.Win32.2Search.h skipped
C:\Documents and Settings\Stephen\My Documents\IMNames.exe/data.rar/main.exe Infected: not-a-virus:AdWare.Win32.2Search.i skipped
C:\Documents and Settings\Stephen\My Documents\IMNames.exe/data.rar Infected: not-a-virus:AdWare.Win32.2Search.i skipped
C:\Documents and Settings\Stephen\My Documents\IMNames.exe RarSFX: infected - 5 skipped
C:\Documents and Settings\Stephen\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Stephen\ntuser.dat.LOG Object is locked skipped
C:\eied_s7.cab/eied_s7_c_7.exe Infected: Trojan-Downloader.Win32.Mediket.c skipped
C:\eied_s7.cab CAB: infected - 1 skipped
C:\mcydp.exe Infected: Trojan.Win32.Agent.aai skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\InstallShield Installation Information\{576E71DA-3000-48F6-9B21-B9A70D47DFCF}\setup.ilg Object is locked skipped
C:\Program Files\MyWay\bar\1.bin\F3HTMLMU.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.d skipped
C:\Program Files\MyWay\bar\1.bin\MWSBAR.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\MyWay\bar\1.bin\MWSOEMON.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Program Files\MyWay\bar\1.bin\MWSOEPLG.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP723\A0648388.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP723\A0648389.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP730\A0655388.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP730\A0655389.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP731\A0655397.exe Infected: Trojan-Proxy.Win32.Dlena.bd skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP731\A0656385.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP731\A0656386.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP732\A0656392.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP732\A0657392.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP732\A0657393.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP732\A0657398.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP732\A0657401.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP733\A0657402.exe Infected: Trojan-Proxy.Win32.Dlena.bd skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP733\A0658392.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP733\A0658393.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP733\A0658400.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP734\A0659392.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP734\A0659393.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP734\A0659399.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP735\A0660395.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP735\A0660396.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP736\A0661398.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP736\A0661399.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP736\A0661401.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP736\A0662398.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP736\A0662399.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP736\A0662404.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP737\A0663398.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP737\A0663399.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP738\A0663404.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP738\A0664398.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP738\A0664399.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP738\A0664404.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP739\A0666403.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP739\A0666404.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP739\A0666414.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP740\A0667403.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP740\A0667404.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP740\A0667410.exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP741\A0674413.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP741\A0674414.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP742\A0675413.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP742\A0675414.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP743\A0676608.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP743\A0676622.EXE Infected: not-a-virus:AdWare.Win32.2Search.i skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP743\A0676624.exe Infected: not-a-virus:AdWare.Win32.2Search.h skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP743\A0676625.exe Infected: not-a-virus:AdWare.Win32.2Search.i skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP743\A0676630.exe Infected: Trojan-Downloader.Win32.Tiny.et skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP743\A0676631.exe Infected: Email-Worm.Win32.Glowa.n skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP743\A0676632.exe Infected: Trojan-Downloader.Win32.Tiny.et skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP745\A0676804.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP745\A0676805.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP745\A0677787.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP745\A0677788.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP746\A0678814.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP746\A0678815.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP746\A0678905.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP746\A0678906.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP746\A0679031.exe Infected: Trojan.Win32.Agent.aai skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP750\A0679390.exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP750\A0679409.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP750\A0679410.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679708.exe Infected: Trojan.Win32.LipGame.i skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679709.exe Infected: IM-Worm.Win32.VB.ao skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679710.exe Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679711.exe Infected: Trojan-Downloader.Win32.Adload.fu skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679712.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679713.exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679714.dll Infected: Email-Worm.Win32.Locksky.au skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679715.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679716.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679717.sys Infected: Trojan-Clicker.Win32.Costrat.l skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679718.exe Infected: Trojan-Downloader.Win32.Tiny.bw skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679719.exe Infected: Trojan-Downloader.Win32.Mediket.br skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679720.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679721.exe Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679722.exe Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679723.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679724.exe Infected: Trojan-Proxy.Win32.Agent.ji skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679725.exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679726.dll Infected: Trojan-Clicker.Win32.Agent.ac skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679727.exe Infected: Email-Worm.Win32.Banwarum.f skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679728.exe Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679729.exe Infected: Trojan-Proxy.Win32.Agent.ji skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679730.exe Infected: Trojan.Win32.Agent.oh skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679731.exe Infected: Trojan-Downloader.Win32.Small.cxx skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679732.dll Infected: not-a-virus:AdWare.Win32.NetNucleus skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679733.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679734.exe Infected: Trojan-Proxy.Win32.Small.bo skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679735.exe Infected: Trojan-Downloader.Win32.Harnig.cu skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679752.exe Infected: Trojan-Clicker.Win32.VB.ly skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP751\A0679753.exe Infected: Trojan-Downloader.Win32.Adload.fk skipped
C:\System Volume Information\_restore{E466FB10-B916-475D-B108-80AEF1C6A536}\RP756\change.log Object is locked skipped
C:\tidyfck.exe Infected: Trojan.Win32.Agent.aai skipped
C:\WINDOWS\$NtUninstallQ307274$\shgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ307274$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ307274$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\guitrn.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\guitrn_a.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\migapp.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\migwiz.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\migwiz_a.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\script.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\script_a.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\sysmod.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ307869$\sysmod_a.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ308210$\rdchost.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ308210$\sessmgr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ308210$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ308210$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ308276$\smlogsvc.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ308276$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ308276$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ309376$\rdbss.sys Object is locked skipped
C:\WINDOWS\$NtUninstallQ309376$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ309376$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ309495$\msi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309495$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ309495$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\dxmasf.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\msdxm.ocx Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\sfcfiles.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\ssdpapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ309521$\ssdpsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ310437$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ310437$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ310437$\ups.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ311542$\pci.sys Object is locked skipped
C:\WINDOWS\$NtUninstallQ311542$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ311542$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ314862$\qmgr.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ314862$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ314862$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\netsetup.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\spuninst\spuninst.inf Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\ssdpapi.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\ssdpsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ315000$\upnp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ318966$\spuninst\Q318966.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UERS_9999_N91S2507NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UERS_9999_N91S2507NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UERS_9999_N91S2507NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\UERS_9999_N91S2507NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\UERS_9999_N91S2507NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\WINDOWS\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\11292052ld.exe Infected: Trojan-Proxy.Win32.Dlena.bd skipped
C:\WINDOWS\system32\37372702ld.exe Infected: Trojan-Proxy.Win32.Dlena.bd skipped
C:\WINDOWS\system32\54543122ld.exe Infected: Trojan-Proxy.Win32.Dlena.bd skipped
C:\WINDOWS\system32\abiabni.dll Infected: Trojan-Downloader.Win32.Busky.gen skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\game0.exe.exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\WINDOWS\system32\google.png.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\inet.exe Infected: Trojan-Downloader.Win32.Small.eci skipped
C:\WINDOWS\system32\lsasac6.exe Infected: Trojan.Win32.Pakes skipped
C:\WINDOWS\system32\messenger.lib.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\WINDOWS\system32\MZU_DRV.sys Infected: Trojan-Proxy.Win32.Small.bo skipped
C:\WINDOWS\system32\ppl.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\WINDOWS\system32\qfipplj.dll Infected: Trojan-Downloader.Win32.Busky.gen skipped
C:\WINDOWS\system32\qvx5gamet2.exe Infected: Trojan-Downloader.Win32.Small.eci skipped
C:\WINDOWS\system32\rpcc.dll Object is locked skipped
C:\WINDOWS\system32\se.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\WINDOWS\system32\ss.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\WINDOWS\system32\syspools.exe Infected: Trojan-Downloader.Win32.Small.dam skipped
C:\WINDOWS\system32\vxga5me3.exe Infected: Trojan-Proxy.Win32.Dlena.ax skipped
C:\WINDOWS\system32\w.exe Infected: Email-Worm.Win32.Luder.a skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\win_b.exe Infected: Trojan-Downloader.Win32.Small.cyn skipped
C:\WINDOWS\Temp\Perflib_Perfdata_4bc.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\ydiegyf.exe Infected: Trojan.Win32.Pakes skipped
C:\ywen.exe Infected: Trojan-Downloader.Win32.Small.ctf skipped

Scan process completed.



Logfile of HijackThis v1.99.1
Scan saved at 00:07:05, on 21/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Stephen\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {7191BA0E-7C17-AAA7-981B-05C0166B055B} - C:\WINDOWS\system32\qfipplj.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O12 - Plugin for .hlq: C:\Program Files\Internet Explorer\PLUGINS\NpHcd32.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)



Those 3 files

Use windows explorer to find and delete these files:

C:\WINDOWS\system32\rpcc.dll
C:\WINDOWS\System32\vbsys2.dll
C:\WINDOWS\System32\instcat.dll

The last 2 were not there, it would not let me delete rpcc.dll.

Thanks :-)
Go to Start> Control Panel> Add or Remove Programs.

Remove the following programs, if they are present.
MyWay
MyWebsearch
Please download the Killbox.
Unzip it to the desktop but do NOT run it yet.

Copy the text to a Notepad file and save it to your desktop! We will need the file later.

Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.

Once in Safe Mode, please run Killbox.

Select "Delete on Reboot".

Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\bak\dfndrff_e19.exe
C:\bak\kybrdff_e19.exe
C:\Documents and Settings\Stephen\My Documents\IMNames.exe
C:\eied_s7.cab
C:\WINDOWS\system32\game0.exe.exe
C:\WINDOWS\system32\google.png.exe
C:\WINDOWS\system32\inet.exe
C:\WINDOWS\system32\lsasac6.exe
C:\WINDOWS\system32\messenger.lib.exe
C:\WINDOWS\system32\MZU_DRV.sys
C:\WINDOWS\system32\ppl.exe
C:\WINDOWS\system32\qfipplj.dll
C:\WINDOWS\system32\qvx5gamet2.exe
C:\WINDOWS\system32\rpcc.dll
C:\WINDOWS\system32\se.exe
C:\WINDOWS\system32\ss.exe
C:\WINDOWS\system32\syspools.exe
C:\WINDOWS\system32\vxga5me3.exe
C:\WINDOWS\system32\w.exe
C:\WINDOWS\system32\win_b.exe
C:\ydiegyf.exe
C:\ywen.exe

Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

O2 - BHO: (no name) - {7191BA0E-7C17-AAA7-981B-05C0166B055B} - C:\WINDOWS\system32\qfipplj.dll
O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll

Then close all windows except Hijackthis and click Fix Checked

Use windows explorer to find and delete this folder:

C:\Program Files\MyWay\

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG anti-spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

Post back with the AVG-antispyware log and a new HijackThis log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI