This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please review HijackThis log

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The following is my log. You guys saved me once before, I'm hoping you can do it again. (Note to parents, even if you have your screen saver on pass protect, make sure your kids don't get up and get on your computer before it kicks on!!!) :unsure:
I've ran through several scans for more then the last 24 hours, including; AVG (Says it deletes/removes, but perhaps something is 'piggy backed') Mirco trend's House Call (says it cannot delete remove, I assume this is because it's something 'active') Adaware (removed approximatley 181 'threats') Spybot Search & Destroy (removed additional threats) I can provide those logs if you need.
If I can one more porn pop up, I'm going to cry, then scream, and throw my computer out the window - perhaps not in those orders. Generally, when I close one, two more open. Sometimes I'm lucky and it stops for 3 minutes. (they're not always porn, but 1 out of 15 is enough for me)
I *should* currently have open, MSN, mIRC, HijackThis, Winzip, note pad, 3 IE windows and NoAds.

I have no issues with batting my eyes if it'll help any ;)

Thanks in advance for your help. I won't be opening any more IE's until I have this resolved.


Logfile of HijackThis v1.99.1
Scan saved at 1:00:35 AM, on 3/21/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
d:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\NoAds\NoAds.exe
D:\Program Files\mIRC\mirc.exe
D:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\Jessica\LOCALS~1\Temp\HijackThis.exe

O2 - BHO: Shell Doc Object and Control Helper Class - {00009E9F-DDD7-AA59-AA7D-AA4B7D6BE000} - C:\WINDOWS\System32\shdocvs.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13FDF1AF-E272-4FA2-9E74-09B5137E5179} - (no file)
O2 - BHO: (no name) - {1585F596-020C-492F-A806-C6E0A40709FF} - C:\WINDOWS\System32\ddccc.dll (file missing)
O2 - BHO: (no name) - {3B35D985-7648-4521-83BE-1E16AE5CD05F} - C:\WINDOWS\system32\driverb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {a82e2904-dd27-4fe9-82a0-d3879a985a86} - C:\WINDOWS\system32\fsuther.dll
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\System32\tmp5C.tmp.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - https://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O20 - Winlogon Notify: ddccc - C:\WINDOWS\System32\ddccc.dll (file missing)
O20 - Winlogon Notify: fsuther - C:\WINDOWS\SYSTEM32\fsuther.dll
O20 - Winlogon Notify: winkku32 - winkku32.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
Alas, I was so hoping to see something here when I woke up. Maybe I'll be lucky enough to see something in a few hours when I return ?
The crying has started. This is getting worse and worse. Any kind of help would be so very much apprecaited. I see all of these threads being replied to - and I get pushed to the 4th page. I won't bat my eyes anymore, I promise !!! Help me =\
Hi :) Can't offer you a solution, just a helpful reminder.

Sometimes it takes the volunteers a while to get around to helping us. Too many problems, not enough volunteers.

Unfortunately, by adding messages to your own thread, it may appear to them that some other volunteer has already replied to your message … so chances are they'll move on to some other thread that has zero responses.

Please check the following links for more info:

What to do if you have no response in 5 days
http://forums.tomcoyote.org/index.php?showtopic=65180

Tips to getting a faster response
http://forums.tomcoyote.org/index.php?showtopic=76234

Hope you get your problem solved soon :)
Download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Put a check next to Run VundoFix as a task.
  • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
  • When VundoFix re-opens, click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Post the contents of C:\vundofix.txt and a new HiJackThis log.
I did everything you said, except for, this step was missing, as there was no suck thing to check -

"Put a check next to Run VundoFix as a task."

I ran it regardless - Following is the Vundo anfter that is the Hijackthis log.
Thank you soooo very much for your assistance.



VundoFix V6.3.17

Checking Java version…

Sun Java not detected
Scan started at 12:31:18 AM 3/24/2007

Listing files found while scanning….

C:\Documents and settings\Jessica\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Jessica\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\Program Files\VSAdd-in\VSAdd-in.dll
C:\WINDOWS\System32\cccdd.bak1
C:\WINDOWS\System32\cccdd.ini
C:\WINDOWS\system32\cfbctnyq.exe
C:\WINDOWS\System32\ddccc.dll
C:\WINDOWS\system32\fafffwkf.exe
C:\WINDOWS\system32\orbmsuav.exe
C:\WINDOWS\System32\qomlj.dll
C:\WINDOWS\system32\qwfklnuo.exe
C:\WINDOWS\System32\tmp32.tmp.dll
C:\WINDOWS\system32\vhfejjql.exe
C:\WINDOWS\system32\wrkhmidc.exe
C:\WINDOWS\system32\yepsgimx.exe

Beginning removal…

Attempting to delete C:\Documents and settings\Jessica\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Jessica\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!

Attempting to delete C:\Documents and settings\Jessica\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\Documents and settings\Jessica\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!

Attempting to delete C:\Program Files\VSAdd-in\VSAdd-in.dll
C:\Program Files\VSAdd-in\VSAdd-in.dll Has been deleted!

Attempting to delete C:\WINDOWS\System32\cccdd.bak1
C:\WINDOWS\System32\cccdd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\System32\cccdd.ini
C:\WINDOWS\System32\cccdd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\cfbctnyq.exe
C:\WINDOWS\system32\cfbctnyq.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\fafffwkf.exe
C:\WINDOWS\system32\fafffwkf.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\orbmsuav.exe
C:\WINDOWS\system32\orbmsuav.exe Has been deleted!

Attempting to delete C:\WINDOWS\System32\qomlj.dll
C:\WINDOWS\System32\qomlj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qwfklnuo.exe
C:\WINDOWS\system32\qwfklnuo.exe Has been deleted!

Attempting to delete C:\WINDOWS\System32\tmp32.tmp.dll
C:\WINDOWS\System32\tmp32.tmp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vhfejjql.exe
C:\WINDOWS\system32\vhfejjql.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wrkhmidc.exe
C:\WINDOWS\system32\wrkhmidc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\yepsgimx.exe
C:\WINDOWS\system32\yepsgimx.exe Has been deleted!

Performing Repairs to the registry.
Done!


While runing Hijackthis - I had 4 addidtional pop ups as well.

Logfile of HijackThis v1.99.1
Scan saved at 1:00:02 AM, on 3/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\Explorer.exe
C:\Documents and Settings\Jessica\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Shell Doc Object and Control Helper Class - {00009E9F-DDD7-AA59-AA7D-AA4B7D6BE000} - C:\WINDOWS\System32\shdocvs.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {13FDF1AF-E272-4FA2-9E74-09B5137E5179} - (no file)
O2 - BHO: (no name) - {1585F596-020C-492F-A806-C6E0A40709FF} - C:\WINDOWS\System32\ddccc.dll (file missing)
O2 - BHO: (no name) - {3B35D985-7648-4521-83BE-1E16AE5CD05F} - C:\WINDOWS\system32\driverb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {800A0C44-E788-419C-B8B5-1B4964C56785} - C:\WINDOWS\System32\nnnmklm.dll
O2 - BHO: (no name) - {a82e2904-dd27-4fe9-82a0-d3879a985a86} - C:\WINDOWS\system32\fsuther.dll
O2 - BHO: (no name) - {EBB9045D-9133-4998-887B-773404449DDE} - C:\WINDOWS\System32\qomlj.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\System32\ahtqfaeo.dll",setvm
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\System32\eccsjnmk.dll",setvm
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - https://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O20 - Winlogon Notify: ddccc - C:\WINDOWS\System32\ddccc.dll (file missing)
O20 - Winlogon Notify: fsuther - C:\WINDOWS\SYSTEM32\fsuther.dll
O20 - Winlogon Notify: nnnmklm - C:\WINDOWS\SYSTEM32\nnnmklm.dll
O20 - Winlogon Notify: winkku32 - winkku32.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE




I'll be holding my breath for a responce. Thank you again !!! :wavey:
Download The Avenger Copyright © Swandog46
You must extract avenger.exe to your desktop, before you run it.
The Avenger must be run from a user account with administrator privileges,
and ONLY works on Windows 2000 and XP, and only on 32-bit versions!

Copy all the text contained in the code box below to your Clipboard.

Files to delete:
C:\WINDOWS\system32\driverb.dll
C:\WINDOWS\System32\nnnmklm.dll
C:\WINDOWS\system32\fsuther.dll
C:\WINDOWS\System32\qomlj.dll
C:\WINDOWS\System32\ddccc.dll


The above script is for this user only, if you need help please start your own thread.


Start the Avenger.
Under "Script file to execute" choose "Input Script Manually".
Click on the Magnifying Glass icon which will open a new window titled "View/edit script".
Paste the entire text in into this window.
Click done, now click on the Green Light
Answer "Yes" twice when prompted.
Your computer shoud reboot, and briefly open a black command window on your desktop, this is normal.

After the restart, it will create a log file that should open.
This log file will be located at C:\avenger.txt
Paste the contents of the file into your reply along with a fresh HJT log.

Also: Avenger has made backups of all the files, etc., that you asked it to delete, located at C:\avenger\backup.zip.

___________________________________________________________

Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

O2 - BHO: Shell Doc Object and Control Helper Class - {00009E9F-DDD7-AA59-AA7D-AA4B7D6BE000} - C:\WINDOWS\System32\shdocvs.dll (file missing)
O2 - BHO: (no name) - {13FDF1AF-E272-4FA2-9E74-09B5137E5179} - (no file)
O2 - BHO: (no name) - {1585F596-020C-492F-A806-C6E0A40709FF} - C:\WINDOWS\System32\ddccc.dll (file missing)
O2 - BHO: (no name) - {3B35D985-7648-4521-83BE-1E16AE5CD05F} - C:\WINDOWS\system32\driverb.dll
O2 - BHO: (no name) - {800A0C44-E788-419C-B8B5-1B4964C56785} - C:\WINDOWS\System32\nnnmklm.dll
O2 - BHO: (no name) - {a82e2904-dd27-4fe9-82a0-d3879a985a86} - C:\WINDOWS\system32\fsuther.dll
O2 - BHO: (no name) - {EBB9045D-9133-4998-887B-773404449DDE} - C:\WINDOWS\System32\qomlj.dll (file missing)
O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
O4 - HKLM\..\Run: [IESet] IExplorer.dll .dbt
O4 - HKLM\..\RunServices: [IESet] IExplorer.dll .dbt
O4 - HKCU\..\Run: [IESet] IExplorer.dll .dbt
O20 - Winlogon Notify: ddccc - C:\WINDOWS\System32\ddccc.dll (file missing)
O20 - Winlogon Notify: fsuther - C:\WINDOWS\SYSTEM32\fsuther.dll
O20 - Winlogon Notify: nnnmklm - C:\WINDOWS\SYSTEM32\nnnmklm.dll
O20 - Winlogon Notify: winkku32 - winkku32.dll (file missing)


Reboot in safe mode, instructions here.
Some of these files my have hidden atributes.
Click Here Should you need instructions for Showing hidden files and folders in Windows.
Once in safe mode, using Windows Explorer, locate the first file right click then select delete.

Delete the following file(s) listed in bold.
IExplorer.dll
winkku32.dll


___________________________________________________________

Run this online scan and post the results here.
I think I got it - Well, the directions anyways. When I did the step for Hijackthis again, Only 4 things were found - I removed them, and see something similar or the same is there again (I ran Hijack after all of the rest of the steps again. I'm still having pops ups. Here's the Info -

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\djlvepob

*******************

Script file located at: \??\C:\Documents and Settings\lvfoyjpd.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\driverb.dll deleted successfully.
File C:\WINDOWS\System32\nnnmklm.dll deleted successfully.
File C:\WINDOWS\system32\fsuther.dll deleted successfully.


File C:\WINDOWS\System32\qomlj.dll not found!
Deletion of file C:\WINDOWS\System32\qomlj.dll failed!

Could not process line:
C:\WINDOWS\System32\qomlj.dll
Status: 0xc0000034



File C:\WINDOWS\System32\ddccc.dll not found!
Deletion of file C:\WINDOWS\System32\ddccc.dll failed!

Could not process line:
C:\WINDOWS\System32\ddccc.dll
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.


——————————————–


Incident Status Location

Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\System32\eccsjnmk.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\System32\ahtqfaeo.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Program Files\VSAdd-in\VSAdd-in.dll
Virus:trj/abwiz.a Disinfected Operating system
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\SYSTEM32\VYFWWISN.EXE
Virus:Trj/KillAV.FG Disinfected C:\WINDOWS\Temp\SVCIPA.EXE
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Dream Weaver\Cookies\dream weaver@burstnet[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Dream Weaver\Cookies\dream weaver@atwola[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Dream Weaver\Cookies\dream [removed][1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Dream Weaver\Cookies\dream weaver@burstnet[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Kids\Cookies\kids@com[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Kids\Cookies\kids@burstnet[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Kids\Cookies\[removed][2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Kids\Cookies\kids@belnk[1].txt
Spyware:Cookie/DelfinMedia Not disinfected C:\Documents and Settings\Kids\Cookies\kids@delfinproject[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Kids\Cookies\[removed][1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Kids\Cookies\kids@burstnet[2].txt
Virus:Trj/BHO.C Disinfected C:\Documents and Settings\Jessica\Local Settings\Temp\SPOOLEW.EXE
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\Jessica\Local Settings\Temp\tmp5D.tmp.exe
Adware:Adware/WinAntivirus2006 Not disinfected C:\Documents and Settings\Jessica\Local Settings\Temp\FHSSEPQM.DLL
Adware:Adware/WinAntivirus2006 Not disinfected C:\Documents and Settings\Jessica\Local Settings\Temp\AODOMGSP.DLL
Virus:Trj/BHO.A Disinfected C:\Documents and Settings\Jessica\Local Settings\Temp\KURLBLDM.DLL
Adware:Adware/WinAntivirus2006 Not disinfected C:\Documents and Settings\Jessica\Local Settings\Temp\JVOHTAYQ.DLL
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Documents and Settings\Jessica\Local Settings\Temporary Internet Files\Content.IE5\0NNBMSDP\WinAntiVirusPro2007FreeInstall[1].cab[UWA7P_0001_N91M0809NetInstaller.exe]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@questionmarket[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@mediaplex[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@advertising[2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@azjmp[2].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@findwhat[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@overture[1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@atwola[1].txt
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@targetnet[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@atdmt[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][1].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@clickbank[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@tribalfusion[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@com[1].txt
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@bfast[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@statcounter[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@doubleclick[1].txt
Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@linksynergy[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@realmedia[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@zedo[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][2].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@cgi-bin[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@fastclick[2].txt
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@adrevolver[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@trafficmp[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@hitbox[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@casalemedia[2].txt
Spyware:Cookie/7search Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@7search[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@drivecleaner[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@winantivirus[2].txt
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][2].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][2].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Jessica\Cookies\jessica@revenue[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Jessica\Cookies\[removed][2].txt
Adware:Adware/DeluxeComunications Not disinfected C:\SVHOST.EXE
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\VSAdd-in.dll.bad
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\cfbctnyq.exe.bad
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\VundoFix Backups\fafffwkf.exe.bad
Adware:Adware/SystemDoctor Not disinfected C:\VundoFix Backups\orbmsuav.exe.bad
Adware:Adware/SystemDoctor Not disinfected C:\VundoFix Backups\qwfklnuo.exe.bad
Adware:Adware/SystemDoctor Not disinfected C:\VundoFix Backups\vhfejjql.exe.bad
Adware:Adware/SystemDoctor Not disinfected C:\VundoFix Backups\wrkhmidc.exe.bad
Adware:Adware/SystemDoctor Not disinfected C:\VundoFix Backups\yepsgimx.exe.bad
————————————————


Logfile of HijackThis v1.99.1
Scan saved at 11:14:14 PM, on 3/24/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
d:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\lexpps.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Documents and Settings\Jessica\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\System32\ahtqfaeo.dll",setvm
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\System32\eccsjnmk.dll",setvm
O4 - HKLM\..\RunOnce: [Panda_cleaner] C:\WINDOWS\System32\ACTIVE~1\pavdr.exe C:\WINDOWS\System32\pavdr_actions.sys
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - https://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - D:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - d:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
Download ATF Cleaner instructions here.

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works.
It will create a file named: c:\rapport.txt
Please post the C:\rapport.txt in your next reply

IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
I cleared everything with ATF per the instructions on the site given. Following is the log for Rapport.txt SmitFraudFix v2.155 Scan done at 1:15:10.15, Mon 03/26/2007 Run from C:\Documents and Settings\Jessica\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is FAT32 Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Jessica »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Jessica\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JESSICA\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
I've just had something very disturbing happen. I had no other windows other then this open, and appoximatley 50 new windows opened. They were all from this address - http://89.188.16.10/trafc-2/rfe.php?cmp=vm…311db9a090015c5 - Microsoft Internet Explorer

I had No Ads block it - but - Obviously something is very very wrong. This did not happen "right" after doing what you asked me to, but as you can see from the post times, a bit later.
Thanks once again in advance.
When I bring up AVG Anti-Spyware, a window pops up that says "Malware Found" - Name Trojan.Agent.acl - Location C:/Program Files\VSAdd-in\VSAdd-in.dll - Risk High Although it gives me options to clean & remove, Clean, Ignore, Ignore and add to exceptions, It does not seem to actually DO any of these options - The pop up keeps returning, not allowing me to even run the program. When I go to the file in Program files, the only file that's there is "__delete_on_reboot__V_S_A_d_d_-_i_n_._d_l_l_" and I'm unable to delete that as well. I"ll wait for further instructions.
Download VundoFix.exe to your desktop.

* Double-click VundoFix.exe to run it.
* When VundoFix re-opens, click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will reboot your computer, click OK.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the
Scan for Vundo button.
" when VundoFix appears at reboot. Post the text file when done.

Post the text file when done.


Forgive my sounding stupid, but what text shall I post ? I've only ran VundoFix.exe and I see no file or log for it ? It's saved to my desktop. I believe there were 5- 7 things found before my computer rebooted.
I am to be running the AVG Spy again after running Vundo ? Sorry for slowing up the process here, I just don't want to run anything until I know for sure.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI