This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Vundo

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is running v slow, and generates pop ups to porn sites, competition pages, and to 'winfix pro 2007'. i have symantec corporate av software which finds trojan.vundo, and always requires a reboot. but to no avail. i have run spybot and adaware, they always find tracking cookies and other unwanted files, but they don't seem to get rid of them. i get regular spam email which i delete, and symantec often finds viruses within these spams, but not always.
i have run hijack after rebooting, and am pasting the notebook log below as advised.
cheers
lars52

Logfile of HijackThis v1.99.1
Scan saved at 9:45:22 PM, on 6/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Creative\Launcher\CTLauncher.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://optuszoo.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\edgncfpf.dll",realset
O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\ouryprso.dll",realset
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {326A7290-FAE3-48C5-9FBA-F071633E1EB5} (VPlayer Control) - http://video.vividas.com/media/4436_hothou…/vivid_ocx.jpeg
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Hi Lars52 - welcome to TomCoyote forums.

VundoFix

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • It will create a report named vundofix.txt on your main drive (C:\vundofix.txt)
Note: It is possible that VundoFix may encounter a file it cannot remove.
In this case, VundoFix will run on reboot. Simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

—————————————————

Run HijackThis and click Scan and then check (tick) the following, if present:

O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\edgncfpf.dll",realset
O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\ouryprso.dll",realset


Close down all programs, browsers and other open windows. Make sure that only the above item is checked and then click on Fix checked.

————————————————–

Show hidden System Files:
  • Click Start
  • Open My Computer
  • Select the Tools menu and click Folder Options
  • Select the View tab
  • Advanced Settings:
    • Under Hidden files and folders, select Show hidden files and folders
    • Uncheck Hide extensions for known file types
    • Uncheck Hide protected operating system files (Recommended)
  • Click Apply to All Folders
  • Click Yes to confirm
  • Click OK
Click on Start then My Computer, find the following files (highlighted in red) and delete them, if present. Don't worry if any are missing, but please let me know.

C:\WINDOWS\system32\edgncfpf.dll <- File only
C:\WINDOWS\system32\ouryprso.dll <- File only
C:\WINDOWS\system32\WinFlyer32.dll <- File only

————————————————

Please post, as a reply to this thread:
  • The VundoFix report (C:\vundofix.txt)
  • A new HijackThis log
Gday beynac
thanx for your quick reply.
i have followed your instructions, tho every time i run vundofix after a reboot it comes up with c\windows\system32\gebcd.dll .it won't go away.
i checked the 3 files in hijack this, and 'fixed' them.
in the 'start' operation, i only found winflyer32, and deleted it. the other 2 files weren't there.
the vundofix report and new hijackthis logs follow
thanx again
cheers
lars

———–


VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:26:42 PM 6/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\dcbeg.bak1
C:\WINDOWS\system32\dcbeg.bak2
C:\WINDOWS\system32\dcbeg.ini
C:\WINDOWS\system32\dcbeg.ini2
C:\WINDOWS\system32\dcbeg.tmp
C:\WINDOWS\system32\gebcd.dll
C:\WINDOWS\system32\prktplts.dll
C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\xxyvusr.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\dcbeg.bak1
C:\WINDOWS\system32\dcbeg.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\dcbeg.bak2
C:\WINDOWS\system32\dcbeg.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\dcbeg.ini
C:\WINDOWS\system32\dcbeg.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\dcbeg.ini2
C:\WINDOWS\system32\dcbeg.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\dcbeg.tmp
C:\WINDOWS\system32\dcbeg.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\vtsqn.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xxyvusr.dll
C:\WINDOWS\system32\xxyvusr.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\vtsqn.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:44:52 PM 6/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 12:12:57 AM 7/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 12:27:11 AM 7/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 12:50:43 AM 7/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

—————–

Logfile of HijackThis v1.99.1
Scan saved at 1:07:01 AM, on 7/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Creative\Launcher\CTLauncher.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Lars\Desktop\VundoFix.exe
C:\HJT\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://optuszoo.ninemsn.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {218F75F2-F24F-4242-B045-0B28F22DC15C} - C:\WINDOWS\system32\vtsqn.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6C16DAC8-CB7F-4193-917A-F635C6550FDd} - C:\WINDOWS\system32\iogqmwou.dll
O2 - BHO: (no name) - {A2E24974-FBC2-493A-B7AC-BC589538C03B} - C:\WINDOWS\system32\gebcd.dll (file missing)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {326A7290-FAE3-48C5-9FBA-F071633E1EB5} (VPlayer Control) - http://video.vividas.com/media/4436_hothou…/vivid_ocx.jpeg
O20 - Winlogon Notify: gebcd - C:\WINDOWS\system32\gebcd.dll (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
G'day Lars52.

every time i run vundofix after a reboot it comes up with c\windows\system32\gebcd.dll

According to the HijackThis log, the file seems to have gone - very strange! Is VundoFix starting itself after each reboot? I'm also a bit worried that those other files weren't there. Did you go through the steps to show the hidden system files? Still, let's press on - we'll come back to this a bit later.

——————————————————————-

Run HijackThis and click Scan and then check (tick) the following, if present (don't worry if any are missing):

O2 - BHO: (no name) - {218F75F2-F24F-4242-B045-0B28F22DC15C} - C:\WINDOWS\system32\vtsqn.dll (file missing)
O2 - BHO: (no name) - {6C16DAC8-CB7F-4193-917A-F635C6550FDd} - C:\WINDOWS\system32\iogqmwou.dll
O2 - BHO: (no name) - {A2E24974-FBC2-493A-B7AC-BC589538C03B} - C:\WINDOWS\system32\gebcd.dll (file missing)
O20 - Winlogon Notify: gebcd - C:\WINDOWS\system32\gebcd.dll (file missing)

Close down all programs, browsers and other open windows. Make sure that only the above items are checked and then click on Fix checked.

——————————————————————–

Click on Start then My Computer, find the following files and folders (highlighted in red) and delete them, if present. Don't worry if any are missing, but please let me know.

C:\WINDOWS\system32\gebcd.dll <- File only (this is the one that VundoFix had trouble with - I just want to check that it's gone).
C:\WINDOWS\system32\iogqmwou.dll <- File only
C:\WINDOWS\system32\prktplts.dll <- File only

——————————————————————-

Reboot the computer

——————————————————————-

ComboFix by sUBs
  • Download this file - combofix.exe
  • Close all open windows.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Please split the log into separate posts to ensure that they don't get cut off. It is important that I see the full log.

——————————————————————-

Please post, as a reply to this thread (you may need more than one post):
  • The ComboFix report
  • A new HijackThis log
Please also answer my questions in the first paragraph.
gday beynac.
sorry i left this morning, i fell asleep, v late!

re vundofix, it does not start itself after reboot, i ran it to see what would happen. also, when i came home this afternoon, symantec had found 2 trojan.vundo files, and said a reboot was required. i closed the symantec box, ran vundofix, and the gebcd.dll file came up again. vundofix then rebooted the computer after prompting.

re hidden files, i did go through the steps, and i have double checked this evening.
i then followed your instructions, ran hijack, checked and fixed those 4 files.

question, when you say close all files, i close all files on the bottom bar. should i also close symantec, and other progs that may be running in background such as monitor prog and others that i don't know of?

i then searched for the 3 dll files in system32, but i couldn't find any of them.

i then rebooted, downloaded combofix, and am pasting the log below, along with the new hijack log. i have checked that both entire logs appear on this post.

thanx again
cheers
lars

"Lars" - 07-05-07 20:25:48 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\Lars\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\aefmnrob.dll
C:\WINDOWS\system32\mgbwmxel.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\Common Files\{38DC1~1\Bar888.dll
C:\Program Files\Common Files\{38DC1~1\UnInstall.exe
C:\Program Files\Common Files\{38DC1~1
C:\Program Files\Common Files\{68DC1~1


((((((((((((((((((((((((((((((( Files Created from 2007-04-07 to 2007-05-07 ))))))))))))))))))))))))))))))))))


2007-05-06 23:26 d——– C:\VundoFix Backups
2007-05-06 23:15 597,884 —hs—- C:\WINDOWS\system32\nqstv.bak2
2007-05-06 23:03 d——– C:\WINDOWS\pss
2007-05-06 21:39 d——– C:\HJT
2007-05-06 21:14 596,753 —hs—- C:\WINDOWS\system32\nqstv.bak1
2007-05-03 23:02 d——– C:\DOCUME~1\Lars\APPLIC~1\Lavasoft
2007-05-03 23:01 d——– C:\Program Files\Lavasoft
2007-05-03 23:00 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-04-30 20:47 d——– C:\DOCUME~1\Lars\APPLIC~1\Help
2007-04-28 23:20 d——– C:\Program Files\Common Files\Adobe Systems Shared
2007-04-28 23:20 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macrovision
2007-04-28 23:16 d–h—– C:\Program Files\InstallShield Installation Information
2007-04-21 18:00 d——– C:\Program Files\GuitarStar_v1
2007-04-21 17:59 d——– C:\Program Files\CopyScat
2007-04-21 17:46 110,592 –a—— C:\WINDOWS\system32\tsccvid.dll
2007-04-21 17:43 d——– C:\Program Files\Blues_PianoMC_1
2007-04-21 17:30 d——– C:\Program Files\PowerTracks DirectX Plugins


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-07 20:20 ——– d——– C:\Program Files\symantec antivirus
2007-05-07 02:34 ——– d——– C:\Program Files\limewire
2007-05-07 02:34 ——– d——– C:\Program Files\incomplete
2007-04-30 20:57 ——– d——– C:\Program Files\windows media connect 2
2007-04-30 20:57 ——– d——– C:\Program Files\Common Files\installshield
2007-04-22 21:02 ——– d——– C:\Program Files\Common Files\symantec shared
2007-04-17 01:27 ——– d——– C:\DOCUME~1\Lars\APPLIC~1\image zone express
2007-03-30 17:01 ——– d——– C:\DOCUME~1\Lars\APPLIC~1\msninstaller
2007-03-17 23:43 292864 –a—— C:\WINDOWS\system32\winsrv.dll
2007-03-09 01:36 577536 –a—— C:\WINDOWS\system32\user32.dll
2007-03-09 01:36 40960 –a—— C:\WINDOWS\system32\mf3216.dll
2007-03-09 01:36 281600 –a—— C:\WINDOWS\system32\gdi32.dll
2007-03-08 23:47 1843584 –a—— C:\WINDOWS\system32\win32k.sys
2007-03-04 20:39 117644 –a—— C:\WINDOWS\hpoins11.dat
2007-02-06 05:08 62 –ahs—- C:\DOCUME~1\Lars\APPLIC~1\desktop.ini


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_03\\bin\\jusched.exe"
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"Creative Launcher"="C:\\Program Files\\Creative\\Launcher\\CTLauncher.exe"
"AudioHQ"="C:\\Program Files\\Creative\\SBLive\\AudioHQ\\AHQTB.EXE"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{C5E02D55-E7B6-4AD1-8140-D418D409A047}"=""

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
WudfServiceGroup REG_MULTI_SZ WUDFSvc\




~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20070507-200739-347
O20 - Winlogon Notify: gebcd - C:\WINDOWS\system32\gebcd.dll (file missing)
backup-20070507-200739-952
O2 - BHO: (no name) - {A2E24974-FBC2-493A-B7AC-BC589538C03B} - C:\WINDOWS\system32\gebcd.dll (file missing)
backup-20070507-200739-297
O2 - BHO: (no name) - {6C16DAC8-CB7F-4193-917A-F635C6550FDd} - C:\WINDOWS\system32\iogqmwou.dll
backup-20070507-200739-442
O2 - BHO: (no name) - {218F75F2-F24F-4242-B045-0B28F22DC15C} - C:\WINDOWS\system32\vtsqn.dll (file missing)
backup-20070507-004108-876
O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\ouryprso.dll",realset
backup-20070507-004108-214
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\edgncfpf.dll",realset
backup-20070507-004108-434
O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-07 20:28:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 07-05-07 20:28:38
C:\ComboFix-quarantined-files.txt … 07-05-07 20:28


—————————-

Logfile of HijackThis v1.99.1
Scan saved at 8:46:04 PM, on 7/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Creative\Launcher\CTLauncher.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://optuszoo.ninemsn.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {326A7290-FAE3-48C5-9FBA-F071633E1EB5} (VPlayer Control) - http://video.vividas.com/media/4436_hothou…/vivid_ocx.jpeg
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
G'day.

That looks a lot better. :)

question, when you say close all files, i close all files on the bottom bar. should i also close symantec, and other progs that may be running in background such as monitor prog and others that i don't know of?

No, just make sure that there are no open windows (the files on the bottom bar). If any of the others need closing, I will let you know.

————————————————————

There's a couple more files to delete:

Click on Start then My Computer, find the following files and folders (highlighted in red) and delete them, if present. Don't worry if any are missing, but please let me know.

C:\WINDOWS\system32\nqstv.bak2
C:\WINDOWS\system32\nqstv.bak1

———————————————————-

ATF Cleaner by Atribune ©

Download ATF Cleaner by Atribune © from here : http://www.atribune.org/ccount/click.php?id=1
This is a stand-alone program that does not need to be installed. Save it to a convenient location and make a shortcut on your desktop. Using this program will remove temporary files, temporary internet files and cookies from your system, which will mean that any scans will run faster.
  • Make sure that all browser windows are closed
  • Double-click the shortcut on your desktop to run the program.
  • Under Main, choose Select All
  • Untick Prefetch
  • Click Empty Selected
  • If you use Firefox browser,
    • Click Firefox at the top and choose Select All
    • Click on Empty Selected
    • NOTE: If you would like to keep any saved passwords, please untick that option.
  • Click Exit to close.
  • If you use Opera browser,
    • Click Opera at the top and choose Select All
    • Click on Empty Selected
    • NOTE: If you would like to keep any saved passwords, please untick that option.
  • Click Exit to close.
—————————————————

AVG Anti-Spyware:

Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open. Do not run a scan yet.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful.
You will need to change the following settings:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Automatically generate report after every scan and uncheck Only if threats were found.
  • Under What to scan? - Select Scan every file.
You can now close AVG Anti-Spyware. Do not scan yet.

—————————————————

Boot to Safe Mode.

You will need to reboot your computer into Safe Mode for the next steps. It would be a good idea for you to print these instructions, as you will not have access to the internet.

Important: If you have an always on connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode. I suggest that you print out these instructions.
  • Restart your computer.
  • Continually tap the F8 button as your computer is booting (a menu appears).
  • Use up-arrow key to select Safe Mode and press Enter.
————————————————

Run AVG Anti-Spyware:

Close all open windows and then start AVG Anti-Spyware, which you downloaded earlier
  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
—————————————————————–

Reboot in Normal Mode.

——————————————————————-

Please post, as a reply to this thread:
  • The AVG Anti-Spyware report
  • A new HijackThis log
Please let me know how the computer is running. Do you still have any of the original symptoms?
That can happen - it usually means that the update server is busy. You can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, double-click on avgas-signatures-full-current.exe to install the database.
Thanx, i've got it now.
deleted the 2 nq files, ran atf, set up avg then ran it in safe mode.. reports following
pop ups have stopped, am moving between windows and tasks quickly and without any grief. booting up takes about 5 minutes tho.
thanks beynac
cheers
lars

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:15:34 AM 8/05/2007

+ Scan result:



C:\HJT\Hijackthis\backups\backup-20070507-200739-297.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\aefmnrob.dll.vir -> Adware.BHO : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\mgbwmxel.dll.vir -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP96\A0024986.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP96\A0025010.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP96\A0025011.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{38DC1~1\UnInstall.exe.vir -> Adware.IWantSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP96\A0025009.exe -> Adware.IWantSearch : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Common Files\{38DC1~1\Bar888.dll.vir -> Adware.Lucky : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP96\A0025008.dll -> Adware.Lucky : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP95\A0024916.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\VundoFix Backups\xxyvusr.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP95\A0024962.dll -> Dropper.Agent.bhc : Cleaned with backup (quarantined).


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 7:30:32 AM, on 8/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Creative\Launcher\CTLauncher.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://optuszoo.ninemsn.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {326A7290-FAE3-48C5-9FBA-F071633E1EB5} (VPlayer Control) - http://video.vividas.com/media/4436_hothou…/vivid_ocx.jpeg
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Well done - you're latest HijackThis log and the AVG Anti-Spyware scan are both clean. I can't see any reason for the slow startup but Symantec/Norton programs can sometimes cause this. Has this only happened since the computer became infected? In the circumstances, I think that it would be a good idea to re-run VundoFix and do an online scan to make sure that we've got everything. First, we need to update Java.

————————————————————-

Update Java Runtime:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6u1.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Click on the link named Java Runtime Environment (JRE) 6u1
  • Click on the radio button to Accept License Agreement
  • Click on Windows Offline Installation, Multi-language and save the downloaded file to your hard disk
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 2 Runtime Environment, JRE or JSE)
  • Reboot your computer
  • Delete the folder C:\Program Files\Java if present
  • Install the new version by running the newly-downloaded file, and follow the on-screen instructions.
  • Reboot your computer
———————————————————-

VundoFix

Please run VundoFix
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • It will create a report named vundofix.txt on your main drive (C:\vundofix.txt)
Note: It is possible that VundoFix may encounter a file it cannot remove.
In this case, VundoFix will run on reboot. Simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

———————————————————–

Kaspersky Online Scanner

Using Internet Explorer, go to: http://www.kaspersky.com/virusscanner
  • Click on Kaspersky Online Scanner
  • Click the Accept button
  • Follow the prompts to download and install the ActiveX component(s) and other software
    • If a yellow information bar appears at the top of the browser window, click on it and select Install ActiveX Control
    • If a message box appears, click on OK or Run as appropriate
  • Click Accept again (see the note below if using IE7)
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click 'Next'.
  • Now click on 'Scan Settings'
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
    • Scan Options: 'Scan Archives' and 'Scan Mail Bases'
  • Click 'OK'
  • Now under 'Select a target to scan' select 'My Computer'
  • The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
  • Now click on the Save as… button:
  • Save the report to your desktop (Save as type: Text document (txt))
Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

————————————————————-

Please post:
  • The VundoFix report (C:\vundofix.txt)
  • The Kaspersky report
Thankyou beynac. reboot takes over 6 minutes, i don't know since when. i usually start the puter, walk away and come back later. symantec does take ages to come on and initialise, so does avg (disabled). i have deleted old java and installed new one. i ran vundofix, it found nothing. yay! :weee: i am about to run kapersky, it says it will take a long time, so i thort i'd say g'day to you first. dum question time… i have an external hard drive which has been switched off during this entire process. should i have switched it on? should i switch it on for kapersky? also, i have a second hard drive which is the original drive from this puter. it no longer 'operates', but the data on it is accessable and to some extent, usable. this drive has been on during this entire proccess. will these two drives have any bearing on these procedures? cheers lars
G'day.

i ran vundofix, it found nothing. yay! :weee:

Excellent news! :D

I suggest that you run the Kaspersky scan on the computer as it is at the moment. Once we're happy, then I would run a separate scan on the external hard drive using your antivirus program (I'm assuming that you only use the external drive for backups of files, pictures etc.).
done the kapersky scan. wow. :blink:
why do the other virus scanners miss all these?
logs follow…
thanx beynac
cheers
lars

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:26:42 PM 6/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\dcbeg.bak1
C:\WINDOWS\system32\dcbeg.bak2
C:\WINDOWS\system32\dcbeg.ini
C:\WINDOWS\system32\dcbeg.ini2
C:\WINDOWS\system32\dcbeg.tmp
C:\WINDOWS\system32\gebcd.dll
C:\WINDOWS\system32\prktplts.dll
C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\xxyvusr.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\dcbeg.bak1
C:\WINDOWS\system32\dcbeg.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\dcbeg.bak2
C:\WINDOWS\system32\dcbeg.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\dcbeg.ini
C:\WINDOWS\system32\dcbeg.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\dcbeg.ini2
C:\WINDOWS\system32\dcbeg.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\dcbeg.tmp
C:\WINDOWS\system32\dcbeg.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\vtsqn.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xxyvusr.dll
C:\WINDOWS\system32\xxyvusr.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\vtsqn.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 11:44:52 PM 6/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 12:12:57 AM 7/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 12:27:11 AM 7/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 12:50:43 AM 7/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 7:40:53 PM 7/05/2007

Listing files found while scanning….

C:\WINDOWS\system32\gebcd.dll

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V6.3.21

Checking Java version…

Scan started at 8:29:32 PM 8/05/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…

——————
kapersky log
——————

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 09, 2007 7:36:08 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 8/05/2007
Kaspersky Anti-Virus database records: 315395
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 157795
Number of viruses found: 18
Number of infected objects: 51 / 0
Number of suspicious objects: 0
Duration of the scan process: 02:42:28

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\C00001.VBN/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\C00001.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\C00001.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine4200000.VBN/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine4200000.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine4200000.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine5E00000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ir skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine5E00001.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ir skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine9A80000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.iy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\QuarantineA140000.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\QuarantineAEC0000.VBN/Setup.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\QuarantineAEC0000.VBN ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\QuarantineAEC0000.VBN CryptZ: infected - 1 skipped
C:\Documents and Settings\Lars\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Lars\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Lars\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Lars\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lars\Local Settings\History\History.IE5\MSHist012007050820070509\index.dat Object is locked skipped
C:\Documents and Settings\Lars\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Lars\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lars\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Lars\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT121NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT731NAV~.TMP Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP97\A0025062.dll Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{178CB59C-380A-496F-BAEC-B1466C614182}\RP99\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\Documents and Settings\Carol\Desktop\Tristan\bs\Installer\BSInstall5.2.5.1.exe/WISE0026.BIN/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
E:\Documents and Settings\Carol\Desktop\Tristan\bs\Installer\BSInstall5.2.5.1.exe/WISE0026.BIN Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
E:\Documents and Settings\Carol\Desktop\Tristan\bs\Installer\BSInstall5.2.5.1.exe WiseSFX: infected - 2 skipped
E:\Documents and Settings\Carol\Desktop\Tristan\bs\Installer\BSInstall5.2.5.1.exe WiseSFX Dropper: infected - 2 skipped
E:\Documents and Settings\Carol\Desktop\Tristan\BSINSTALL.exe/WISE0023.BIN/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
E:\Documents and Settings\Carol\Desktop\Tristan\BSINSTALL.exe/WISE0023.BIN Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
E:\Documents and Settings\Carol\Desktop\Tristan\BSINSTALL.exe WiseSFX: infected - 2 skipped
E:\Documents and Settings\Carol\Desktop\Tristan\BSINSTALL.exe WiseSFX Dropper: infected - 2 skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx/[From "Returned mail" <[removed]>][Date Tue, 27 Jul 2004 08:27:03 +1000]/UNNAMED/optusnet.com.au Infected: Email-Worm.Win32.Mydoom.m skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx/[From "Returned mail" <[removed]>][Date Tue, 27 Jul 2004 08:27:03 +1000]/UNNAMED Infected: Email-Worm.Win32.Mydoom.m skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx/[From [removed]][Date Tue, 25 May 2004 15:41:52 +1000]/UNNAMED/document_4351.pif Infected: Email-Worm.Win32.NetSky.d skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx/[From [removed]][Date Tue, 25 May 2004 15:41:52 +1000]/UNNAMED Infected: Email-Worm.Win32.NetSky.d skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx/[From [removed]][Date Mon, 9 Aug 2004 00:57:04 -0700]/UNNAMED/UNNAMED/[From <[removed]>][Date Mon, 9 Aug 2004 17:31:05 +0900]/Old/Old Excel Documents.txt .scr Infected: Email-Worm.Win32.Mabutu.a skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx/[From [removed]][Date Mon, 9 Aug 2004 00:57:04 -0700]/UNNAMED/UNNAMED/[From <[removed]>][Date Mon, 9 Aug 2004 17:31:05 +0900]/Old Infected: Email-Worm.Win32.Mabutu.a skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx/[From [removed]][Date Mon, 9 Aug 2004 00:57:04 -0700]/UNNAMED/UNNAMED Infected: Email-Worm.Win32.Mabutu.a skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx/[From [removed]][Date Mon, 9 Aug 2004 00:57:04 -0700]/UNNAMED Infected: Email-Worm.Win32.Mabutu.a skipped
E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx Mail MS Outlook 5: infected - 8 skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0015.BIN/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.h skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0015.BIN/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.e skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0015.BIN/data0005 Infected: not-a-virus:AdWare.Win32.BargainBuddy.h skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.BargainBuddy.h skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.EZula.o skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0023.BIN/data0001.cab/Save.exe Infected: not-a-virus:AdWare.Win32.SaveNow.e skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0023.BIN/data0001.cab/SaveUninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0023.BIN/data0001.cab/Weather/Weather.exe Infected: not-a-virus:AdWare.Win32.SaveNow skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0023.BIN/data0001.cab/Weather/Uninst.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0023.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe/WISE0023.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.bl skipped
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe WiseSFX: infected - 11 skipped
E:\Lars\downloaded programs\wavtomp3.exe/WISE0015.BIN/wbhshare.dll Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped
E:\Lars\downloaded programs\wavtomp3.exe/WISE0015.BIN/Webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
E:\Lars\downloaded programs\wavtomp3.exe/WISE0015.BIN/WhAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped
E:\Lars\downloaded programs\wavtomp3.exe/WISE0015.BIN/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped
E:\Lars\downloaded programs\wavtomp3.exe/WISE0015.BIN/whieshm.dll Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped
E:\Lars\downloaded programs\wavtomp3.exe/WISE0015.BIN/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped
E:\Lars\downloaded programs\wavtomp3.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.WebHancer.214 skipped
E:\Lars\downloaded programs\wavtomp3.exe WiseSFX: infected - 7 skipped
E:\Program Files\Symantec AntiVirus\SAVRT789NAV~.TMP Object is locked skipped
E:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\accwiz.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\crypt32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\hh.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\html32.cnv Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\itss.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\locator.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\magnify.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\migwiz.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\msconv97.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\narrator.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\newdev.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\ntdll.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\osk.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\pchshell.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\raspptp.sys Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\shell32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\shmedia.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\srrstr.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\srv.sys Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\sysmain.sdb Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\user32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\win32k.sys Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB826939$\zipfldr.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\dao360.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\expsrv.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msexch40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msjint40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msjter40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msltus40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msrd2x40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msrd3x40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\mstext40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\mswdat10.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\mswstr10.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB837001$\vbajet32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB839645$\shell32.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB839645$\shlwapi.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB839645$\sxs.dll Object is locked skipped
E:\WINDOWS\$NtUninstallKB839645$\xpsp2res.dll Object is locked skipped
E:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
E:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll Object is locked skipped

Scan process completed.

————————-
latest hijack log, just in case…
————————-Logfile of HijackThis v1.99.1
Scan saved at 7:47:29 AM, on 9/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Creative\Launcher\CTLauncher.exe
C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://optuszoo.ninemsn.com.au/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe
O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {326A7290-FAE3-48C5-9FBA-F071633E1EB5} (VPlayer Control) - http://video.vividas.com/media/4436_hothou…/vivid_ocx.jpeg
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
ps this morning symantec said it had found and deleted trojan.vundo at 11.03 pm, this was after vundofix found nothing :scratch: avagooday lars

this morning symantec said it had found and deleted trojan.vundo at 11.03 pm, this was after vundofix found nothing

I am confident that this was not a live file. When the anti-malware tools pick up a bad file they usually quarantine it before deletion. You then scan with another program and it picks up the quarantined file. If you look at the results of the AVG scan you will see that it quarantined a file in the VundoFix backup folder. Symantec probably found something there or even in the AVG quarantine folder. If it happens again, please note the location of the file.

The HijackThis log is still clean. The Kaspersky scan found some items in your System Restore (which we will clean shortly) and quite a lot in your E drive. We'll also delete the removal tools' quarantine/backup folders.

—————————————————————-

Click on Start then My Computer, find the following files and folders (highlighted in red) and delete them, if present. Don't worry if any are missing, but please let me know.

C:\VundoFix Backups\ <- Folder
C:\QooBox\ <- Folder
E:\Documents and Settings\Carol\Desktop\Tristan\bs\ <- Folder
E:\Documents and Settings\Carol\Desktop\Tristan\BSINSTALL.exe <- File only
E:\Documents and Settings\Carol\My Documents\Downloaded Files\setupwavtomp3.exe <- File only
E:\Lars\downloaded programs\wavtomp3.exe <- File only

There are also some infected emails in a backup folder from August 2004:

E:\Documents and Settings\Carol\My Documents\Back up, Aug 04\Inbox.dbx

I suggest that you delete the whole folder, but leave it (and let me know) if you want/need to keep all but the infected items.

————————————————————–

We need to tidy up a bit. You can delete the following
  • VundoFix and its log (C:\vundofix.txt)
  • ComboFix and its log
I suggest that you keep ATF Cleaner and AVG Anti-Spyware as they are useful programs.

————————————————————–

Hide System Files:
  • Click Start
  • Open My Computer
  • Select the Tools menu and click Folder Options
  • Select the View tab
  • Advanced Settings:
    • Under Hidden files and folders, select Do not show hidden files and folders
    • Select Hide extensions for known file types
    • Select Hide protected operating system files (Recommended)
  • Click Apply to All Folders
  • Click Yes
  • Click OK
——————————————————–

Flush System Restore

We need to 'flush' your System Restore points and create a new clean one.

Turn OFF System Restore.
  • Click on Start
  • Right-click My Computer
  • Click Properties
  • Click the System Restore tab
  • Check Turn off System Restore
  • Click Apply, and then click OK
Restart your computer

Turn ON System Restore.
  • Click on Start
  • Right-click My Computer
  • Click Properties
  • Click the System Restore tab
  • Uncheck Turn off System Restore
  • Click Apply, and then click OK
———————————————————–

If you do not already use it, I suggest that you install SpywareBlaster. This program will:
  • Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.
  • Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.
  • Restrict the actions of potentially unwanted sites in Internet Explorer.
This program blocks these items but does not run in the background. It therefore does not use any resources.

I would also recommend that you have a look at Firetrust SiteHound. This gives warnings when you are about to enter a website that is on their 'block' list. An alternative is McAfee SiteAdvisor. I use SiteHound, but both have a good reputation (N.B. use only one of them, not both).

———————————————————–

Please let me know if you have any questions (or any problems with the above).

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI