This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected, please help...

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Dell laptop has been hit with a whammy of troubles, with popups and the like. I've tried fixing it myself following that "Before Posting A HijackThis Log "Self Help", For Windows XP" guide topic here, but there's still problems.

Here's the AVG report when I first ran it in safe mode:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:11:30 PM 11/7/2004

+ Scan result:



C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035017.exe/AutoSearch.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP352\A0036273.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP352\A0036275.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\offun.exe -> Adware.Bagon : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034954.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034997.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035027.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\temp.frDC2F -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\temp.frFCBF -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035956.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035961.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035014.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035049.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035029.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035052.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035013.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\WINDOWS\Uninstall.exe -> Adware.SearchClickAds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP352\A0036284.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034977.lnk -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034979.lnk -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP352\A0036286.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034964.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034970.inf -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034972.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034973.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034993.inf -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034994.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035042.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035043.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035046.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035002.exe -> Downloader.Adload.gt : Cleaned with backup (quarantined).
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\Program Files\Apoint\Apoint.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0033916.EXE -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0033917.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0033918.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0033919.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0033920.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0033921.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0033922.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0033942.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034976.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035021.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035010.exe -> Downloader.Dyfuca.fb : Cleaned with backup (quarantined).
C:\WINDOWS\АppPatch\javaw.exe -> Downloader.PurityScan.cx : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe -> Downloader.PurityScan.dc : Cleaned with backup (quarantined).
[680] C:\WINDOWS\system32\chktybg.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035015.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035033.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\WINDOWS\hvkxtroA.exe -> Downloader.VB.ang : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035028.exe -> Downloader.Zlob.avo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035025.exe -> Dropper.Agent.mu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034959.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035012.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035018.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035005.exe -> Trojan.Favadd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035011.exe -> Trojan.Favadd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035024.exe -> Trojan.Qoologic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035038.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\V29vbiBMdW9uZw\pZ6Sv21gxq6RtT.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034939.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0034940.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP351\A0035022.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\WINDOWS\uninst108.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\WINDOWS\uni_e6h.exe -> Trojan.YourEnhancement : Cleaned with backup (quarantined).


::Report end




And here's the AVG report after I ran it in normal mode:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:55:21 PM 11/7/2004

+ Scan result:



C:\Documents and Settings\sluong\Local Settings\Temp\stub_sca4.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\batty2.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\cmfibula.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\mmxsnet.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\NNBar_VCSetup_876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\mit7.tmp.cab/NNBar_VCSetup_876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\mit7.tmp/NNBar_VCSetup_876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\SpySheriff.dvm -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\SpySheriff.exe -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\Uninstall.exe -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\base.avd -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\base001.avd -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\base002.avd -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\found.wav -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\heur000.dll -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\heur001.dll -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\heur002.dll -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\heur003.dll -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\notfound.wav -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Program Files\SpySheriff\removed.wav -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\i80.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\i97.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\GLBBC.tmp/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\drsmartload180a.exe -> Downloader.Adload.fu : Cleaned with backup (quarantined).
C:\Program Files\QuickTime\qttask.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
[1512] C:\Program Files\QuickTime\qttask.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\bwywt.dat -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[1584] C:\WINDOWS\system32\chktybg.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[1924] C:\WINDOWS\system32\chktybg.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[224] C:\WINDOWS\system32\chktybg.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[2648] C:\WINDOWS\system32\chktybg.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[384] C:\WINDOWS\system32\chktybg.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Local Settings\Temp\pre.exe -> Hijacker.VB.pg : Cleaned with backup (quarantined).
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\sluong\Cookies\sluong@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][2].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\sluong\Cookies\sluong@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\sluong\Cookies\sluong@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\sluong\Cookies\sluong@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\sluong\Cookies\sluong@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\sluong\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\sluong\Cookies\sluong@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\sluong\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\sluong\Cookies\sluong@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end



And the HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 7:57:47 PM, on 11/7/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\vyktis.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ljbxi.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ljbxi.exe
C:\WINDOWS\system32\ljbxi.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\DOCUME~1\sluong\LOCALS~1\Temp\abc123lThVa.exe
C:\Program Files\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\ljbxi.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,weicsxv.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [zchbed92] RUNDLL32.EXE w0799c6c.dll,n 005bed8d000000120799c6c
O4 - HKLM\..\Run: [ychbed91] RUNDLL32.EXE w079a1aa.dll,n 005bed8c00000012079a1aa
O4 - HKLM\..\Run: [mmnext06] C:\WINDOWS\next06.exe
O4 - HKLM\..\Run: [sys02579811814] C:\WINDOWS\sys02579811814.exe
O4 - HKLM\..\Run: [uqoliq] C:\WINDOWS\system32\vyktis.exe reg_run
O4 - HKLM\..\Run: [{0B-B3-3E-E6-ZN}] c:\windows\system32\oqdsregm.exe GEN001
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\nwinrpes.exe GEN001
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [rnvmj] C:\WINDOWS\system32\vyktis.exe reg_run
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: nhwuo.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1160876190681
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


I'd really appreciate your help!
Hi KIRBO

Please download Qoofix by Rubber Ducky to your desktop.
  • Right click on the Qoofix folder, and choose "Extract All". Extract Qoofix to your C: drive
  • Close all windows and programs, including internet windows.
  • Go to C:\Qoofix and open the folder, then double click on Qoofix.exe
  • Click Begin Removal and wait for the scan to finish
  • If Qoofix finds an infection, select yes to restart your computer
  • You will now find a log from this tool, located at C:\Qoofix\Qoofix Logfile.txt Copy and paste the contents of that report into your next reply here.
1. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
2. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Do not do anything with these yet!

Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.


3. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
If you have any questions about the use of BFU please read here:
http://metallica.geekstogo.com/BFUinstructions.html

Then reboot and post a new HijackThis log and qoofix report.
Thanks for the quick response, Shaba!

Here is the Qoofix report you've requested:

Qoofix v1.04 by http://www.malwarebytes.org
Scan started on [11/8/2004] at [4:22:23 PM]
————————————————————-
Terminated module: chktybg.dll found in Qoofix.exe (3560)
Terminated module: chktybg.dll found in vyktis.exe (560)
Terminated module: chktybg.dll found in EXPLORER.EXE (580)
Terminated module: chktybg.dll found in ljbxi.exe (604)
Terminated module: chktybg.dll found in ljbxi.exe (676)
Terminated module: chktybg.dll found in ljbxi.exe (692)
Terminated module: chktybg.dll found in avgas.exe (1456)
Terminated module: chktybg.dll found in ctfmon.exe (1600)
Terminated module: chktybg.dll found in DLG.exe (2156)
————————————————————-
C:\WINDOWS\system32\bwywt.dat will be deleted on reboot!
C:\WINDOWS\system32\chktybg.dll will be deleted on reboot!
C:\WINDOWS\system32\ljbxi.exe will be deleted on reboot!
C:\WINDOWS\system32\vyktis.exe will be deleted on reboot!
C:\WINDOWS\system32\weicsxv.exe will be deleted on reboot!
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nhwuo.exe will be deleted on reboot!

User prompted YES to reboot, system now rebooting…
————————————————————-
Scan COMPLETED SUCCESSFULLY on [11/8/2004] at [4:23:49 PM]

Note: Some registry keys may have been removed.



And here is the new hijackthis log after rebooting into normal mode:

Logfile of HijackThis v1.99.1
Scan saved at 4:35:24 PM, on 11/8/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [zchbed92] RUNDLL32.EXE w0799c6c.dll,n 005bed8d000000120799c6c
O4 - HKLM\..\Run: [ychbed91] RUNDLL32.EXE w079a1aa.dll,n 005bed8c00000012079a1aa
O4 - HKLM\..\Run: [mmnext06] C:\WINDOWS\next06.exe
O4 - HKLM\..\Run: [sys02579811814] C:\WINDOWS\sys02579811814.exe
O4 - HKLM\..\Run: [{0B-B3-3E-E6-ZN}] c:\windows\system32\oqdsregm.exe GEN001
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1160876190681
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Hi

Looking over your log, it seems you don't have any evidence of an anti-virus software.

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

Looking over your log, it seems you don't have any evidence of a third party firewall.

As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

1) ZoneAlarm
2) Agnitum
3) Sunbelt/Kerio
4) Comodo

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

Open HijackThis, click do a system scan only and checkmark these:

R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
O4 - HKLM\..\Run: [zchbed92] RUNDLL32.EXE w0799c6c.dll,n 005bed8d000000120799c6c
O4 - HKLM\..\Run: [ychbed91] RUNDLL32.EXE w079a1aa.dll,n 005bed8c00000012079a1aa
O4 - HKLM\..\Run: [mmnext06] C:\WINDOWS\next06.exe
O4 - HKLM\..\Run: [sys02579811814] C:\WINDOWS\sys02579811814.exe
O4 - HKLM\..\Run: [{0B-B3-3E-E6-ZN}] c:\windows\system32\oqdsregm.exe GEN001


Close all windows including browser and press fix checked.

Boot in safe mode

Delete if present:

C:\WINDOWS\next06.exe
C:\WINDOWS\sys02579811814.exe
c:\windows\system32\oqdsregm.exe
w0799c6c.dll
w079a1aa.dll

Empty Recycle Bin

Reboot

Download this tool:

http://noahdfear.geekstogo.com/FindAWF.exe

Save to desktop and run. Output is to awf.txt

Post contents of awf.txt along with a fresh HijackThis log, please :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI