This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Removing Outerinfo

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello everybody

I followed "How to remove Outerinfo pop-ups" topic by LDTate to fix problems connected to Spyware.
Now everything seems to be good.
I just would like to post logs by HJT, Combo Fix and AVG 7.5.
I followed every step advised and now Outerinfo is not there and my pc is not showing any System Alert.

HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 14.17.31, on 21/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\GSICON.EXE
C:\WINDOWS\system32\dslagent.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmi\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\utente1\Desktop\controouterinfo\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [HP Software Update] C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TZ Spyware Remover] C:\Programmi\TrackZapper.com\TZ Spyware Remover\SpyRem.exe /STARTUP
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmi\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://giavembler.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A5CBC46E-CB7A-40A2-A902-D8B0B0376739}: NameServer = 213.205.36.70 213.205.32.70
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs:
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documenti\Settings\partnership.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll (file missing)
O21 - SSODL: DCOM Server 3339 - {2C1CD3D7-86AC-4068-93BC-A02304BB3339} - C:\WINDOWS\system32\xqnle.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Programmi\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


Combo Fix Log:

"utente1" - 07-01-21 12.55.20 Service Pack 2
ComboFix 07-01-21 - Running from: "C:\Documents and Settings\utente1\Desktop\controouterinfo"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\update00822631.exe
C:\WINDOWS\system32\unsvchosts.lzma
C:\Programmi\File comuni\{3C67D~1
C:\Programmi\File comuni\{8C67D~1
C:\WINDOWS\system32\rpcc.dll
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\WINDOWS\system32\ECURIT~1


((((((((((((((((((((((((((((((( Files Created from 2006-12-21 to 2007-01-21 ))))))))))))))))))))))))))))))))))


2007-01-21 12:57 d——– C:\WINDOWS\erdnt
2007-01-19 14:53 d——– C:\WINDOWS\system32\bak
2007-01-18 23:49 d——– C:\Programmi\NoAdware5.0
2007-01-18 17:41 d——– C:\Programmi\Lavasoft
2007-01-18 17:41 d——– C:\DOCUME~1\utente1\Dati applicazioni\Lavasoft
2007-01-18 17:34 57,344 –a—— C:\WINDOWS\system32\COMMTB32.DLL
2007-01-18 17:34 28,672 –a—— C:\WINDOWS\system32\HLP95EN.DLL
2007-01-18 17:34 25,872 –a—— C:\WINDOWS\system32\FM20ENU.DLL
2007-01-18 17:34 169,984 –a—— C:\WINDOWS\system32\P2D.DLL
2007-01-18 17:34 161,552 –a—— C:\WINDOWS\system32\ASYCPICT.DLL
2007-01-18 17:33 d——– C:\Programmi\ActiveX Control Pad
2007-01-18 16:45 d——– C:\DOCUME~1\ALLUSE~1\Dati applicazioni\Spybot - Search & Destroy
2007-01-18 16:29 512,688 –a—— C:\WINDOWS\system32\XceedCry.dll
2007-01-18 16:29 423,784 –a—— C:\WINDOWS\system32\XceedBkp.dll
2007-01-18 16:29 101,888 –a—— C:\WINDOWS\system32\VB6STKIT.DLL
2007-01-18 16:28 35,999 –a—— C:\WINDOWS\system32\lsasss.exe
2007-01-18 15:33 d——– C:\WINDOWS\system32\ActiveScan
2007-01-18 15:20 d–h—– C:\Programmi\File comuni\Uninstall Information
2007-01-18 14:23 d——– C:\Programmi\Malware-Wiped
2007-01-18 14:12 115,013 –a—— C:\tdd.exe
2007-01-18 13:11 d–h—– C:\WINDOWS\PIF
2007-01-18 09:40 6,819 –a—— C:\WINDOWS\system32\update83349740.exe
2007-01-18 09:40 38,358 –a—— C:\WINDOWS\system32\update56324761.exe
2007-01-18 09:35 6,819 –a—— C:\WINDOWS\system32\update54417805.exe
2007-01-18 09:35 35,628 –a—— C:\WINDOWS\system32\update60978402.exe
2007-01-18 09:30 5,389 –a—— C:\WINDOWS\system32\update91906356.exe
2007-01-18 09:30 38,488 –a—— C:\WINDOWS\system32\update89770330.exe
2007-01-18 09:25 6,819 –a—— C:\WINDOWS\system32\update80286011.exe
2007-01-18 09:25 38,488 –a—— C:\WINDOWS\system32\update54091001.exe
2007-01-18 09:20 6,819 –a—— C:\WINDOWS\system32\update92380205.exe
2007-01-18 09:20 38,488 –a—— C:\WINDOWS\system32\update33674268.exe
2007-01-18 09:15 38,488 –a—— C:\WINDOWS\system32\update18561603.exe
2007-01-18 09:15 20,992 –a—— C:\WINDOWS\system32\gwquvw.dll
2007-01-18 09:15 2,560 –a—— C:\WINDOWS\system32\update42851695.exe
2007-01-18 09:15 17,920 –a—— C:\WINDOWS\system32\ntio256.sys
2007-01-18 09:15 dr——- C:\DOCUME~1\LOCALS~1\Preferiti
2007-01-18 09:15 d——– C:\DOCUME~1\LOCALS~1\Menu Avvio
2007-01-18 09:14 60,377 –a—— C:\WINDOWS\system32\vcodec.exe
2007-01-18 09:14 6,819 –a—— C:\WINDOWS\system32\update21677000.exe
2007-01-13 23:46 d——– C:\DOCUME~1\utente1\Dati applicazioni\InterVideo
2007-01-13 23:45 d——– C:\Programmi\InterVideo


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-21 12:57 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\skype
2007-01-18 17:41 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\lavasoft
2007-01-18 16:22 ——– d——– C:\Programmi\msn messenger
2007-01-18 15:12 ——– d—s—- C:\Documents and Settings\utente1\Dati applicazioni\microsoft
2007-01-17 15:03 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\adobe
2007-01-13 23:46 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\intervideo
2007-01-13 23:45 ——– d–h—– C:\Programmi\installshield installation information
2006-12-20 14:44 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\image zone express
2006-12-17 23:03 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\adobeum
2006-12-17 23:02 ——– d——– C:\Programmi\elcomsoft
2006-12-14 20:48 ——– d——– C:\Programmi\radvideo
2006-12-14 09:05 ——– d——– C:\Programmi\ccleaner
2006-12-11 08:21 ——– d——– C:\Programmi\hp
2006-12-11 08:21 ——– d——– C:\Programmi\File comuni\hp
2006-12-11 08:17 ——– d——– C:\Programmi\hewlett-packard
2006-12-09 16:16 ——– d——– C:\Programmi\microsoft.net
2006-12-09 15:05 ——– d——– C:\Programmi\File comuni\hewlett-packard
2006-12-07 08:15 ——– d——– C:\Programmi\File comuni\adobe
2006-12-07 08:11 ——– d——– C:\Programmi\File comuni\installshield
2006-12-06 22:20 502368 –a—— C:\WINDOWS\system32\drivers\amon.sys
2006-12-06 22:20 270336 –a—— C:\WINDOWS\system32\imon.dll
2006-12-06 17:50 ——– d——– C:\Documents and Settings\utente1\Dati applicazioni\macromedia
2006-12-06 14:46 ——– d——– C:\Programmi\skype
2006-11-02 21:28 62 –ahs—- C:\Documents and Settings\utente1\Dati applicazioni\desktop.ini
2006-11-02 20:42 0 -rahs—- C:\MSDOS.SYS
2006-11-02 20:42 0 -rahs—- C:\IO.SYS
2006-11-02 20:42 0 –a—— C:\CONFIG.SYS
2006-11-02 20:42 0 –a—— C:\AUTOEXEC.BAT


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Skype"="\"C:\\Programmi\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"TZ Spyware Remover"="C:\\Programmi\\TrackZapper.com\\TZ Spyware Remover\\SpyRem.exe /STARTUP"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIModeChange"="Ati2mdxx.exe"
"ATIPTA"="C:\\Programmi\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"SoundMan"="SOUNDMAN.EXE"
"GSICONEXE"="GSICON.EXE"
"DSLAGENTEXE"="dslagent.exe USB"
"nod32kui"="\"C:\\Programmi\\Eset\\nod32kui.exe\" /WAITSERVICE"
"HP Software Update"="C:\\Programmi\\HP\\HP Software Update\\HPWuSchd2.exe"
"Lexmark_X79-55"="C:\\WINDOWS\\system32\\lsasss.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"
"{81E38CB4-FDDF-4CCE-A729-73854CE5C8A8}"="Microsoft Printer Sheduler"
"{2C1CD3D7-86AC-4068-93BC-A02304BB3339}"="DCOM Server 3339"
"{8A5849C4-93F3-429D-FF34-660A2068897C}"="OpenGL additional"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"carbinyl"="{8d8c2387-7f80-4022-9be6-43630a969558}"
"DCOM Server 3339"="{2C1CD3D7-86AC-4068-93BC-A02304BB3339}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"none"="C:\\Programmi\\Video ActiveX Object\\pmsngr.exe"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\partnershipreg

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\HPpromotions psc 2350 series.job

Completion time: 07-01-21 12:58:42

AVG 7.5 Log:

AVG Anti-Spyware - Rapporto scansione
———————————————————

+ Creato alle: 13.30.57 21/01/2007

+ Risultato scansione:



C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014147.exe -> Adware.AntiVermins : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014096.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014101.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014102.exe -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014103.dll -> Adware.DelphinMediaViewer : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Classes\CLSID\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Classes\CLSID\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-21-507921405-484763869-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Ripulito con backup (in quarantena)
HKU\S-1-5-21-507921405-484763869-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ripulito con backup (in quarantena)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014148.dll -> Adware.Maxifiles : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014273.dll -> Adware.PurityScan : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014016.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014017.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014018.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014019.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014020.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014021.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014028.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014029.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014030.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014031.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014282.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014284.exe -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014285.dll -> Adware.Softomate : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\gwquvw.dll -> Adware.WorldSecurityOnline : Ripulito con backup (in quarantena)
[1224] C:\WINDOWS\system32\gwquvw.dll -> Adware.WorldSecurityOnline : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169214827 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169230346 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe1169295803 -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\ESET\nod32kui.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014098.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014099.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014149.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014188.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014189.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014190.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014191.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014199.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014200.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014201.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014202.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014203.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014235.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014236.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014237.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014238.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014239.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014286.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\bak\lsasss.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\lsasss.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
[1636] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Downloader.Agent.awf : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/path.exe -> Downloader.Agent.bdr : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014218.exe -> Downloader.Agent.bdr : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update42851695.exe -> Downloader.Small.ebm : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update21677000.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update54417805.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update80286011.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update83349740.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\update92380205.exe -> Downloader.Vidlo.ab : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014034.exe -> Downloader.Zlob.aon : Ripulito con backup (in quarantena)
C:\WINDOWS\system32\vcodec.exe -> Downloader.Zlob.bio : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014107.exe -> Downloader.Zlob.bjy : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013849.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013850.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013851.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014045.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014046.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014048.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014064.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014065.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014066.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014086.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014087.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014088.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014104.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014105.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014106.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014109.dll -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014110.exe -> Downloader.Zlob.bkn : Ripulito con backup (in quarantena)
C:\tdd.exe -> Dropper.Agent.bbp : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0013845.exe -> Dropper.Small.avb : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014038.dll -> Not-A-Virus.SpamTool.Win32.Agent.t : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014300.dll -> Proxy.Horst : Ripulito con backup (in quarantena)
C:\Documents and Settings\utente1\Cookies\utente1@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ripulito.
C:\Documents and Settings\utente1\Cookies\utente1@atdmt[2].txt -> TrackingCookie.Atdmt : Ripulito.
C:\Documents and Settings\utente1\Cookies\utente1@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ripulito.
C:\Documents and Settings\utente1\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Ripulito.
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014033.exe -> Trojan.Agent : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014035.exe -> Trojan.Agent.pk : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP45\A0014039.dll -> Trojan.Agent.pk : Ripulito con backup (in quarantena)
C:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP47\A0014267.exe -> Trojan.Small : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014221.exe -> Worm.Agent.v : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/crack.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014216.exe/run.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014217.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)
D:\System Volume Information\_restore{8486F73E-F840-468A-B5C2-64FE0AD62C37}\RP46\A0014219.exe -> Worm.HappyNewYear.a : Ripulito con backup (in quarantena)


::Fine rapporto


Thanks in advance anyone who will check these logs and thanks for your help!

Greetings,

Luca
Welcome to the forum.


Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O20 - AppInit_DLLs:
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll (file missing)
O21 - SSODL: DCOM Server 3339 - {2C1CD3D7-86AC-4068-93BC-A02304BB3339} - C:\WINDOWS\system32\xqnle.dll (file missing)

Click on Fix Checked and exit HijackThis.

Open up Internet Explorer , Tools, General Tab, reset your home page to what you want, now the Programs Tab, click Reset Web Settings
That will change everything back to the default settings.


——————-

Do to the amount of malware on the system, I suggest you run an additional program to clear out any left overs.

<====><====><====><====><====><====><====>

Please download SUPERAntiSpyware Home Edition (free)

Install it and double-click the icon on your desktop to run it.
It will ask if you want to update the program definitions, click "Yes",
Let it through your firewall!
Under "Configuration and Preferences", click the "Preferences" button.
Click the "Scanning Control" tab.
Under "Scanner Options" make sure the following are checked:
1>> Close browsers before scanning
2>> Scan for tracking cookies
3>> Terminate memory threats before quarantining.
4>> Ignore System Restore/Volume Information on ME and XP
5>> Please leave the others unchecked.
6>> Click the Close button to leave the control center screen.

On the main screen, under "Scan for Harmful Software" click "Scan your
computer".
On the left check "C:\Fixed Drive".
On the right, under "Complete Scan", choose "Perform Complete Scan".
Click "Next" to start the scan. Please be patient while it scans your computer.
After the scan is complete a summary box will appear. Click "OK".
Make sure everything in the white box has a check next to it, then click "Next".
It will quarantine what it found and if it asks if you want to reboot, click
"Yes".

To retrieve the removal information - please do the following:
1>> After reboot, double-click the "SUPERAntispyware icon" on your desktop.
2>> Click "Preferences". Click the "Statistics/Logs tab".
3>> Under "Scanner Logs", double-click "SUPERAntiSpyware Scan Log".
4>> It will open in your default text editor (such as Notepad/Wordpad).
5>> Please highlight everything , then right-click and choose copy.
6>> Click close and close again to exit the program.

Now please paste the "removal information" along with a fresh "HijackThis log" in your reply. If it's a large log, you may need several replies to post it.
Good Luck, MrC
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI