This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack this log from my laptop

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've been working to get rid of a pop-up problem for a few weeks now. Any help would be appreciated. Thanks in advance. Log is as follows.

Logfile of HijackThis v1.99.1
Scan saved at 7:26:15 AM, on 1/28/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchosts.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Tim\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 166.44.41.203 securityresponse.symantec.com
O1 - Hosts: 130.142.126.183 symantec.com
O1 - Hosts: 235.11.42.128 www.sophos.com
O1 - Hosts: 30.129.139.85 sophos.com
O1 - Hosts: 226.77.165.168 www.mcafee.com
O1 - Hosts: 65.4.126.80 mcafee.com
O1 - Hosts: 169.59.89.65 liveupdate.symantecliveupdate.com
O1 - Hosts: 211.201.0.107 www.viruslist.com
O1 - Hosts: 184.32.77.125 viruslist.com
O1 - Hosts: 102.31.56.254 viruslist.com
O1 - Hosts: 31.142.0.178 f-secure.com
O1 - Hosts: 116.153.198.133 www.f-secure.com
O1 - Hosts: 211.245.175.143 kaspersky.com
O1 - Hosts: 189.146.211.122 kaspersky-labs.com
O1 - Hosts: 147.4.41.38 www.avp.com
O1 - Hosts: 47.115.35.144 www.kaspersky.com
O1 - Hosts: 204.92.170.191 avp.com
O1 - Hosts: 84.210.192.174 www.networkassociates.com
O1 - Hosts: 34.27.86.10 networkassociates.com
O1 - Hosts: 95.94.63.190 www.ca.com
O1 - Hosts: 117.171.183.143 ca.com
O1 - Hosts: 67.31.251.209 mast.mcafee.com
O1 - Hosts: 11.104.81.250 my-etrust.com
O1 - Hosts: 85.249.1.143 www.my-etrust.com
O1 - Hosts: 175.23.65.182 download.mcafee.com
O1 - Hosts: 7.25.232.243 dispatch.mcafee.com
O1 - Hosts: 130.36.246.80 secure.nai.com
O1 - Hosts: 43.13.218.101 nai.com
O1 - Hosts: 56.189.238.50 www.nai.com
O1 - Hosts: 203.81.152.143 update.symantec.com
O1 - Hosts: 1.182.140.175 updates.symantec.com
O1 - Hosts: 146.21.149.149 us.mcafee.com
O1 - Hosts: 246.57.245.86 liveupdate.symantec.com
O1 - Hosts: 188.214.35.22 customer.symantec.com
O1 - Hosts: 148.78.12.156 rads.mcafee.com
O1 - Hosts: 165.86.40.244 trendmicro.com
O1 - Hosts: 206.175.106.216 www.trendmicro.com
O1 - Hosts: 88.201.111.2 www.grisoft.com
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\oaybqyny.dll",setvm
O4 - HKCU\..\Run: [Orcl] "C:\WINDOWS\System32\CROSOF~1.NET\taskmgr.exe" -vt ndrv
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Program Files\Mozilla Firefox\plugins\GetFlash.exe -p
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132531998
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132486833
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\acs.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e mc-110-12-0000501 (file missing)
O23 - Service: winsock32 (winsock32.exe) - Unknown owner - C:\WINDOWS\winsock32.exe (file missing)
1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Post back with the combofix log and anew HijackThis log
Ok, the combo fix log is pretty long. Here goes.

ComboFix 07.02.03 - Running from: "C:\Documents and Settings\Tim\My Documents"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))

REGISTRY ENTRIES REMOVED:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\clsid\{098bb90c-d117-4d2c-a5c8-e829a6f9c815}]
@=""

[HKEY_CLASSES_ROOT\clsid\{098bb90c-d117-4d2c-a5c8-e829a6f9c815}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{098bb90c-d117-4d2c-a5c8-e829a6f9c815}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{098bb90c-d117-4d2c-a5c8-e829a6f9c815}\InprocServer32]
@="C:\\WINDOWS\\system32\\pbustab.dll"
"ThreadingModel"="Apartment"Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\clsid\{561ad330-c25c-4167-bdc4-c71cae0f5156}]
@=""

[HKEY_CLASSES_ROOT\clsid\{561ad330-c25c-4167-bdc4-c71cae0f5156}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{561ad330-c25c-4167-bdc4-c71cae0f5156}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{561ad330-c25c-4167-bdc4-c71cae0f5156}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\clsid\{a5d25f9a-5515-4438-a153-72958e087573}]
@=""

[HKEY_CLASSES_ROOT\clsid\{a5d25f9a-5515-4438-a153-72958e087573}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{a5d25f9a-5515-4438-a153-72958e087573}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{a5d25f9a-5515-4438-a153-72958e087573}\InprocServer32]
@="C:\\WINDOWS\\system32\\mipbde40.dll"
"ThreadingModel"="Apartment"Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\clsid\{b25baa41-8129-4176-9f23-b8851240a53f}]
@=""

[HKEY_CLASSES_ROOT\clsid\{b25baa41-8129-4176-9f23-b8851240a53f}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{b25baa41-8129-4176-9f23-b8851240a53f}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{b25baa41-8129-4176-9f23-b8851240a53f}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\clsid\{15c2fc15-88c7-4e3e-9e58-09c456b3bcc4}]
@=""

[HKEY_CLASSES_ROOT\clsid\{15c2fc15-88c7-4e3e-9e58-09c456b3bcc4}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{15c2fc15-88c7-4e3e-9e58-09c456b3bcc4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{15c2fc15-88c7-4e3e-9e58-09c456b3bcc4}\InprocServer32]
@="C:\\WINDOWS\\system32\\wznsta.dll"
"ThreadingModel"="Apartment"Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\clsid\{2eaece30-a3d9-4121-ac63-f9bfb964f9f4}]
@=""

[HKEY_CLASSES_ROOT\clsid\{2eaece30-a3d9-4121-ac63-f9bfb964f9f4}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{2eaece30-a3d9-4121-ac63-f9bfb964f9f4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{2eaece30-a3d9-4121-ac63-f9bfb964f9f4}\InprocServer32]
@="C:\\WINDOWS\\system32\\mclogmgr.dll"
"ThreadingModel"="Apartment"Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\clsid\{f6ff4fed-1f22-4a7e-a0e5-2683fae2ffc2}]
@=""

[HKEY_CLASSES_ROOT\clsid\{f6ff4fed-1f22-4a7e-a0e5-2683fae2ffc2}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\clsid\{f6ff4fed-1f22-4a7e-a0e5-2683fae2ffc2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\clsid\{f6ff4fed-1f22-4a7e-a0e5-2683fae2ffc2}\InprocServer32]
@="C:\\WINDOWS\\system32\\mwxdm.dll"
"ThreadingModel"="Apartment"

* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


FILES REMOVED:

C:\WINDOWS\system32\g8400ihme84a0.dll
C:\WINDOWS\system32\m4460ehseh460.dll
C:\WINDOWS\system32\mclogmgr.dll


Granting SeDebugPrivilege to Administrators … successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\cfg32.exe
C:\WINDOWS\keyboard1.dat
C:\WINDOWS\newname.dat
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\DOCUME~1\Tim\Application Data\Dxcdmns.dll
C:\DOCUME~1\Tim\Application Data\Dxcknwrd.dll
C:\DOCUME~1\Tim\Application Data\Dxcuknwrd.dll
C:\WINDOWS\system32\unsvchosts.lzma
C:\WINDOWS\system32\unsvchosts.exe
C:\DOCUME~1\LOCALS~1\Application Data\NetMon
C:\DOCUME~1\Tim\Application Data\SearchToolbarCorp
C:\Program Files\outlook
C:\Program Files\Common Files\{A05EC~1
C:\WINDOWS\system32\svchosts.exe
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\WINDOWS\RACLE~1
C:\qoobox\purity\WINDOWS\TSKS~1
C:\qoobox\purity\WINDOWS\system32\CROSOF~1.NET
C:\qoobox\purity\WINDOWS\system32\CROSOF~1.NET\??crosoft.NET


((((((((((((((((((((((((((((((( Files Created from 2006-12-28 to 2007-01-28 ))))))))))))))))))))))))))))))))))


2007-01-28 09:18 d——– C:\WINDOWS\ERDNT
2007-01-27 17:24 960,758 —hs—- C:\WINDOWS\system32\tvuvw.bak1
2007-01-27 17:24 4,666 –a—— C:\WINDOWS\winus1.exe
2007-01-27 17:22 51,201 –a—— C:\svhost.exe
2007-01-27 17:06 76,412 –a—— C:\WINDOWS\system32\kmsngulx.dll
2007-01-27 17:06 44,060 –a—— C:\WINDOWS\system32\xtpmjoll.dll
2006-12-29 10:30 1,691,153 —hs—- C:\WINDOWS\system32\tvuvw.ini2
2006-12-29 10:19 44,060 –a—— C:\WINDOWS\system32\dtwotytb.dll
2006-12-29 10:05 83,672 –a—— C:\autoexes.exe
2006-12-29 09:40 44,060 –a—— C:\WINDOWS\system32\ebyyviij.dll
2006-12-29 09:30 44,060 –a—— C:\WINDOWS\system32\fshtihuu.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-28 06:32 ——– d——– C:\Program Files\mozilla firefox
2007-01-27 17:14 45056 –a—— C:\command.exe
2007-01-27 17:06 960084 —hs—- C:\WINDOWS\system32\tvuvw.bak2
2006-12-27 02:00 44060 –a—— C:\WINDOWS\system32\fbagxsin.dll
2006-12-27 01:57 81684 –a—— C:\WINDOWS\system32\yldrqhqe.dll
2006-12-23 18:16 118804 –a—— C:\WINDOWS\system32\oaybqyny.dll
2006-12-23 18:13 44052 –a—— C:\WINDOWS\system32\jdietcsx.dll
2006-12-12 08:28 81684 –a—— C:\WINDOWS\system32\qkiwysfu.dll
2006-12-10 13:45 88340 –a—— C:\WINDOWS\system32\pgbnthbc.exe
2006-12-10 13:45 126996 –a—— C:\WINDOWS\system32\qomwlfqm.dll
2006-12-10 13:44 42516 –a—— C:\WINDOWS\system32\qgybxlii.dll
2006-12-04 19:58 ——– d——– C:\Program Files\msn gaming zone
2006-12-04 19:58 ——– d——– C:\Program Files\messenger
2006-12-04 19:21 ——– d——– C:\Program Files\grisoft
2006-10-17 16:31 0 –a—— C:\Documents and Settings\Tim\Application Data\t2.tmp


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Orcl"="\"C:\\WINDOWS\\System32\\CROSOF~1.NET\\taskmgr.exe\" -vt ndrv"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"DllRunning"="rundll32.exe \"C:\\WINDOWS\\System32\\oaybqyny.dll\",setvm"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\control panel\load]
"net_insll"=dword:45952f11
"worg"=hex:1f,a1,79,69,78,6d,50,41,7a,7e,4b,4f,a6,87,f6,d2,35,0f,75,51,a4,97,\
d6,23,71,5e,d6,f7,60,21,f4
"cmpid"=hex:23,80,3d,df,53,5d,1d,08,06,12,53,4b,a7,9f,fd,d0,34,60,02,28,a9,ff,\
d7,28,05,43,e6,98,20,0c,b1,87,30,77,c5,fa,25,6a,93,b4,75,d7,d3,7b,a0,d9,06,\
99,34,25,f1,1e,a8,ca,51,97,05,80,16,a8,28,bf,37,b7,46,b6,41,bf


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source REG_SZ C:\Program Files\Messenger\kyzeve.html

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source REG_SZ C:\Program Files\MSN Gaming Zone\howysyhu.html

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuvt

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0



********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-01-28 9:23:50

And Hijack this…

Logfile of HijackThis v1.99.1
Scan saved at 9:36:07 AM, on 1/28/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Documents and Settings\Tim\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\oaybqyny.dll",setvm
O4 - HKCU\..\Run: [Orcl] "C:\WINDOWS\System32\CROSOF~1.NET\taskmgr.exe" -vt ndrv
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132531998
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132486833
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\acs.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e mc-110-12-0000501 (file missing)
O23 - Service: winsock32 (winsock32.exe) - Unknown owner - C:\WINDOWS\winsock32.exe (file missing)


Thanks for the help.
Rename HijackThis to scanner.exe

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
Ok, got the SDfix done without problems. However, when I restarted in safe mode I can't do anything, the screen just says safe mode on all four corners and is black, there is an arrow, I can move it, but can't do anything with it. I must have done something wrong….
New log is as follows…

Logfile of HijackThis v1.99.1
Scan saved at 1:31:10 PM, on 2/3/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\Reg.exe
C:\Documents and Settings\Tim\Desktop\scanner.exe\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\oaybqyny.dll",setvm
O4 - HKCU\..\Run: [Orcl] "C:\WINDOWS\System32\CROSOF~1.NET\taskmgr.exe" -vt ndrv
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132531998
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132486833
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\acs.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e mc-110-12-0000501 (file missing)
O23 - Service: winsock32 (winsock32.exe) - Unknown owner - C:\WINDOWS\winsock32.exe (file missing)


thanks.
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Copy/paste the following quote box into a new notepad (not wordpad) document. Make sure that wordwrap is turned off.

sc stop winsock32
sc delete winsock32
sc stop "Client IP-IPX"
sc delete "Client IP-IPX"


Save it to your Desktop as cleanup.bat. Save it as:
File Type: All Files (not as a text document or it wont work).
Name: cleanup.bat

Locate cleanup.bat on your Desktop and double-click it. A DOS window will open briefly and then close, this is normal

Post abck with the vundofix log and a new HijackThis log
Ok latest scans…


VundoFix V6.3.5

Checking Java version…

Sun Java not detected
Scan started at 1:50:29 PM 2/3/2007

Listing files found while scanning….

C:\WINDOWS\System32\jdietcsx.dll
C:\WINDOWS\system32\oaybqyny.dll
C:\WINDOWS\system32\pgbnthbc.exe
C:\WINDOWS\system32\qkiwysfu.dll
C:\WINDOWS\System32\tvuvw.bak1
C:\WINDOWS\System32\tvuvw.bak2
C:\WINDOWS\System32\tvuvw.ini
C:\WINDOWS\System32\tvuvw.ini2
C:\WINDOWS\System32\tvuvw.tmp
C:\WINDOWS\system32\vmilbkeu.dll
C:\WINDOWS\System32\wvuvt.dll
C:\WINDOWS\System32\xtpmjoll.dll
C:\WINDOWS\system32\yldrqhqe.dll
C:\WINDOWS\system32\ynyqbyao.ini

Beginning removal…

Attempting to delete C:\WINDOWS\System32\jdietcsx.dll
C:\WINDOWS\System32\jdietcsx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oaybqyny.dll
C:\WINDOWS\system32\oaybqyny.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pgbnthbc.exe
C:\WINDOWS\system32\pgbnthbc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qkiwysfu.dll
C:\WINDOWS\system32\qkiwysfu.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\tvuvw.bak1
C:\WINDOWS\System32\tvuvw.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\tvuvw.bak2
C:\WINDOWS\System32\tvuvw.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\tvuvw.ini
C:\WINDOWS\System32\tvuvw.ini Has been deleted!

Attempting to delete C:\WINDOWS\System32\tvuvw.ini2
C:\WINDOWS\System32\tvuvw.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\System32\tvuvw.tmp
C:\WINDOWS\System32\tvuvw.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\vmilbkeu.dll
C:\WINDOWS\system32\vmilbkeu.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\wvuvt.dll
C:\WINDOWS\System32\wvuvt.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\xtpmjoll.dll
C:\WINDOWS\System32\xtpmjoll.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yldrqhqe.dll
C:\WINDOWS\system32\yldrqhqe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ynyqbyao.ini
C:\WINDOWS\system32\ynyqbyao.ini Has been deleted!

Performing Repairs to the registry.
Done!

and.

Logfile of HijackThis v1.99.1
Scan saved at 1:31:10 PM, on 2/3/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\Reg.exe
C:\Documents and Settings\Tim\Desktop\scanner.exe\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\oaybqyny.dll",setvm
O4 - HKCU\..\Run: [Orcl] "C:\WINDOWS\System32\CROSOF~1.NET\taskmgr.exe" -vt ndrv
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132531998
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132486833
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\acs.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e mc-110-12-0000501 (file missing)
O23 - Service: winsock32 (winsock32.exe) - Unknown owner - C:\WINDOWS\winsock32.exe
Earlier I asked you to rename HijackThis.exe to scanner.exe, you renamed the folder, please rename the file to scanner.exe

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\System32\oaybqyny.dll",setvm
O4 - HKCU\..\Run: [Orcl] "C:\WINDOWS\System32\CROSOF~1.NET\taskmgr.exe" -vt ndrv
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\System32\svchosts.exe" -e mc-110-12-0000501 (file missing)
O23 - Service: winsock32 (winsock32.exe) - Unknown owner - C:\WINDOWS\winsock32.ex

Then close all windows except HijackThis and click Fix Checked

Go here to run an online scannner from Kaspersky.
  • Click on "Kaspersky Online Scanner"
  • A new smaller window will pop up. Press on "Accept". After reading the contents.
  • Now Kaspersky will update the anti-virus database. Let it run.
  • Click on "Next">"Scan Settings", and make sure the database is set to "extended". And check both the scan options. Then click OK.
  • Then click on "My Computer", and the scan will start.
  • Once finished, save the log as "KAV.txt" to the desktop.

Post back with the Kaspersky log and a new HijackThis log
Ok, sorry I messed the renaming up. First the Kaspersky then the Hijack this.

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, February 04, 2007 8:04:23 AM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 4/02/2007
Kaspersky Anti-Virus database records: 264715
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 11574
Number of viruses found: 32
Number of infected objects: 149 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:42:46

Infected Object Name / Virus Name / Last Action
C:\autoexes.exe Infected: Trojan-Spy.Win32.BZub.gr skipped
C:\command.exe Infected: Trojan-Downloader.Win32.Agent.axh skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Tim\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Tim\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Tim\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Tim\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tim\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Tim\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Tim\ntuser.dat.LOG Object is locked skipped
C:\RECYCLER\S-1-5-18\Dc1\system.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\RECYCLER\S-1-5-18\Dc1\Update.exe Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\RECYCLER\S-1-5-18\Dc2\system.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\RECYCLER\S-1-5-18\Dc2\Update.exe Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\RECYCLER\S-1-5-18\Dc3\system.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\RECYCLER\S-1-5-18\Dc3\Update.exe Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\RECYCLER\S-1-5-18\Dc4\system.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\RECYCLER\S-1-5-18\Dc4\Update.exe Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\svhost.exe Infected: Backdoor.Win32.Agent.akj skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0008518.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0008520.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009526.exe Infected: Trojan-Downloader.Win32.Agent.axh skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009539.exe/data0002 Infected: Trojan.Win32.VB.tg skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009539.exe/data0006 Infected: Trojan.Win32.VB.tg skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009539.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009540.exe Infected: Trojan.Win32.VB.tg skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009541.exe Infected: Trojan-Downloader.Win32.Zlob.avo skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009548.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009549.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009550.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009551.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009552.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009553.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009556.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009557.ocx Infected: not-a-virus:AdWare.Win32.MediaMotor.t skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009559.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.es skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009559.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009560.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.EZula.ch skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009560.exe/stream Infected: not-a-virus:AdWare.Win32.EZula.ch skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009560.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009561.dll Infected: not-a-virus:AdWare.Win32.EZula.ci skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009562.dll Infected: not-a-virus:AdWare.Win32.EZula.ci skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009564.exe Infected: not-a-virus:AdWare.Win32.Searchcolor.a skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009566.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0009579.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0012644.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0013604.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0013608.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0013610.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0013612.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP10\A0013613.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0013625.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0013626.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0014634.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0014635.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0015634.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0016637.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0016667.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0016668.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0016669.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP11\A0016671.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0016680.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0016682.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0017685.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0018688.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0019688.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0020688.dll Infected: Trojan-Spy.Win32.BZub.hg skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0020689.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0020690.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0020691.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0020692.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0020693.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0020695.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP12\A0020696.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0020704.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0020711.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0021707.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0021711.exe Infected: Trojan-Downloader.Win32.Agent.axh skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0022711.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025717.exe Infected: Trojan-Downloader.Win32.VB.ajp skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025719.dll Infected: Trojan-Downloader.Win32.Small.dxm skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025720.exe Infected: Trojan.Win32.VB.atw skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025721.exe Infected: Trojan-PSW.Win32.LdPinch.bdf skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025722.exe Infected: Backdoor.Win32.Agent.akj skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025723.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025724.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025725.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025726.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025727.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025728.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025729.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025730.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025731.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025732.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025734.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025735.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025741.exe Infected: Trojan-Downloader.Win32.PurityScan.dc skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025757.exe Infected: not-a-virus:AdWare.Win32.Softomate.af skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025761.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025762.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0025763.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0026796.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gf skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0026797.exe Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0026798.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0026800.dll Infected: Trojan.Win32.BHO.g skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0026802.dll Infected: Trojan.Win32.BHO.g skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP13\A0026803.dll Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP14\change.log Object is locked skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007452.exe Infected: Trojan-Downloader.Win32.Dyfuca.ey skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007453.exe Infected: Trojan-Downloader.Win32.Small.cyh skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007454.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007455.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007456.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007457.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007458.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007459.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007461.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007462.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007463.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007465.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007466.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007467.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007468.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007469.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007470.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007471.dll Infected: not-a-virus:AdWare.Win32.AutoSearch.b skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007472.exe/AutoSearch.dll Infected: not-a-virus:AdWare.Win32.AutoSearch.b skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007472.exe CAB: infected - 1 skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007473.exe/data0002/stream/data0002 Infected: not-a-virus:AdWare.Win32.EZula.ch skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007473.exe/data0002/stream Infected: not-a-virus:AdWare.Win32.EZula.ch skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007473.exe/data0002 Infected: not-a-virus:AdWare.Win32.EZula.ch skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007473.exe/data0003/stream/data0001 Infected: not-a-virus:AdWare.Win32.TrafficSol.d skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007473.exe/data0003/stream Infected: not-a-virus:AdWare.Win32.TrafficSol.d skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007473.exe/data0003 Infected: not-a-virus:AdWare.Win32.TrafficSol.d skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007473.exe NSIS: infected - 6 skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007474.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.i skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007475.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.de skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007477.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP8\A0007478.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP9\A0007488.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP9\A0007489.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP9\A0007496.exe Infected: Trojan-Dropper.Win32.Agent.mu skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP9\A0007497.exe Infected: Trojan-Downloader.Win32.VB.ang skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP9\A0007501.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\System Volume Information\_restore{E8D029A7-5B4C-47F3-A932-DDABA6DB8FF3}\RP9\A0008508.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped
C:\VundoFix Backups\oaybqyny.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gf skipped
C:\VundoFix Backups\pgbnthbc.exe.bad Infected: not-a-virus:AdWare.Win32.Agent.at skipped
C:\VundoFix Backups\qkiwysfu.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\VundoFix Backups\vmilbkeu.dll.bad Infected: Trojan.Win32.BHO.g skipped
C:\VundoFix Backups\xtpmjoll.dll.bad Infected: Trojan.Win32.BHO.g skipped
C:\VundoFix Backups\yldrqhqe.dll.bad Infected: Trojan-Spy.Win32.VBStat.j skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\dtwotytb.dll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\ebyyviij.dll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\fbagxsin.dll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\fshtihuu.dll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\kmsngulx.dll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\WINDOWS\system32\qgybxlii.dll Infected: Trojan.Win32.BHO.g skipped
C:\WINDOWS\system32\qomwlfqm.dll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

Scan process completed.


Logfile of HijackThis v1.99.1
Scan saved at 8:05:42 AM, on 2/4/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Tim\Desktop\scanner.exe\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {22B9D9A8-02C6-462F-808E-0238B8D14390} - C:\WINDOWS\System32\wvuvt.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132531998
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132486833
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\acs.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: winsock32 (winsock32.exe) - Unknown owner - C:\WINDOWS\winsock32.exe (file missing)

Thanks again.
Reveal Hidden Files
  • Click Start.
  • Open My Computer.
  • SelectTools menu
  • Click Folder Options.
  • Select the View Tab.
  • Select Show hidden files and foldersin the Hidden files and folders section.
  • Uncheck Hide protected operating system files (recommended) option.
  • Uncheck the Hide file extensions for known file types option.
  • Click Yes.
  • Click OK.
Copy/paste the following quote box into a new notepad (not wordpad) document. Make sure that wordwrap is turned off.

sc stop winsock32.exe
sc delete winsock32.exe


Save it to your Desktop as cleanup2.bat. Save it as:
File Type: All Files (not as a text document or it wont work).
Name: cleanup2.bat

Locate cleanup2.bat on your Desktop and double-click it. A DOS window will open briefly and then close, this is normal

Run HijackThis
Click on do a system scan only
Place a checkmark next to these lines(if still present)

O2 - BHO: (no name) - {22B9D9A8-02C6-462F-808E-0238B8D14390} - C:\WINDOWS\System32\wvuvt.dll (file missing)
O23 - Service: winsock32 (winsock32.exe) - Unknown owner - C:\WINDOWS\winsock32.exe (file missing)

Then close all windows except HijackThis and click Fix Checked

Use windows explorer to find and delete these files, if still present:

C:\WINDOWS\system32\tvuvw.bak1
C:\WINDOWS\winus1.exe
C:\svhost.exe
C:\WINDOWS\system32\xtpmjoll.dll
C:\WINDOWS\system32\xtpmjoll.dll
C:\WINDOWS\system32\dtwotytb.dll
C:\autoexes.exe
C:\WINDOWS\system32\ebyyviij.dll
C:\WINDOWS\system32\fshtihuu.dll
C:\command.exe
C:\WINDOWS\system32\tvuvw.bak2
C:\WINDOWS\system32\fbagxsin.dll
C:\WINDOWS\system32\yldrqhqe.dll
C:\WINDOWS\system32\oaybqyny.dll
C:\WINDOWS\system32\jdietcsx.dll
C:\WINDOWS\system32\qkiwysfu.dll
C:\WINDOWS\system32\pgbnthbc.exe
C:\WINDOWS\system32\qomwlfqm.dll
C:\WINDOWS\system32\qgybxlii.dll

Restart

Post back with a new HijackThis log and let me know of any remaining problems
OK, done and here's the log..

Logfile of HijackThis v1.99.1
Scan saved at 9:46:55 AM, on 2/4/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe
C:\Documents and Settings\Tim\Desktop\scanner.exe\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ?
O4 - Global Startup: D-Link REG Utility.lnk = ?
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132531998
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161132486833
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\acs.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


Things seem to be fine, has been working well since about half way through the process. I've done most of this with the notebook off line, doing the downloading on my desktop and transferring via jump drive and vice versa. The laptop couldn't even stay plugged into my router before as it would start IE by itself, even when no browser was running at the time. Seems fine now. Two things, my daughter has a desktop that behaves about the same as the laptop did, though not as bad. Can I post a Hijack this log for it in a new thread? Also, what should I do with the programs I downloaded onto the laptop if the problem is now solved? Thanks for your assistance..

Can I post a Hijack this log for it in a new thread?



Yes

You now appear to be clean. Congratulations!

Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you do not have to be registered to post.. just find your country room and register your complaint.
The infections you had were Vundo and Look2me

Below are some steps to follow in order to dramatically lower the chances of reinfection
You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented
  • Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    Reboot.

    Turn ON System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK.
    NOTE: only do this ONCE,NOT on a regular basis
  • Use an antivirus program
    Two good free programs are
    AVG
    Avast
    Two good paid-for programs are
    NOD32
    Bitdefender

    Whichever antivirus you choose, it is essential that you keep it up to date
  • Use a firewall
    While the firewall built into windows XP will protect you from incoming attacks, it will not monitor outgoing connections
    It is therefore recommended that you install one of the following firewalls
    Sunbelt kerio personal firewall
    Zonealarm
  • Keep windows up to date with the latest patches


    IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

    If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.
  • Install spywareblaster
    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes
    kill bits
    in the registry, so that certain activex controls can't install.
    If you don't know what activex controls are, see here
    You can download SpywareBlaster here here
    Make sure to update it on a regular basis
  • Install IE-SPYAD
    Dowload and instructions located here
    Make sure to update it on a regular basis
  • Use a HOSTS file
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
    • This is why using a hosts file is optional!!
    Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
    If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button (at the lower left hand corner of your screen)
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then double-click it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click ok
  • Install and use Ad-aware & Spybot search & destroy
    Instructions are located here
    Make sure to update them on a regular basis
  • Most exploits are aimed at internet explorer, so I recommend you switch to an altenative browser
    Two good alternative browsers are
    Firefox
    Opera
    It is essential to update to the latest version of your browser, as the updates fix known security holes
  • Even if you do decide to switch to another browser, it is still a good idea to lock down Internet explorer
    This can be done by following these simple instructions:
    From within Internet Explorer click on the Tools menu and then click on Options.
    Click once on the Security tab
    Click once on the Internet icon so it becomes highlighted.
    Click once on the Custom Level button.
    Change the Download signed ActiveX controls to Prompt
    Change the Download unsigned ActiveX controls to Disable
    Change the Initialize and script ActiveX controls not marked as safe to Disable
    Change the Installation of desktop items to Prompt
    Change the Launching programs and files in an IFRAME to Prompt
    Change the Navigate sub-frames across different domains to Prompt
    Change the allow paste operations via script to Disable
    When all these settings have been made, click on the OK button.
    If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.
  • Clean out you temp file on a regular basis
    I use and recommend ATF Cleaner by Attribune
    To use it, follow these instructions
    • Double-click ATF-Cleaner.exe to run the program.
    • Click Main at the top and choose Select All from the list.
    • Click the Empty Selected button.
    If you use Firefox browser:
    • Click Firefox at the top and choose Select All from the list.
    • Click the Empty Selected button.
    • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser:
    • Click Opera at the top and choose Select All from the list.
    • Click the Empty Selected button.
    • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.
  • Finally I am trying to make one point very clear. It is absolutely essential to keep all of your security programs up to date

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI