This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Yeah, I Got Big Problems....

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Oh Boy,

You really had everything I could imagine present - what a huge amount of malware… :blink:
From your log you uploaded (Avira log), I see it already removed A LOT!!!

Let's deal with the rest now, because there's still an infection active and running..

Please perform my next steps in the right order without missing any step..

* Go to start > control panel > Display properties > Desktop > Customize Desktop… > Web tab
Select everything you find in there (except for "My current home page") and press the delete button on the right.
Hit ok below > apply in previous window.

Then, * Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Where it says: "Paste List of Files/Folders to be Moved", copy and paste next bold part into that Window:

    C:\WINDOWS\xsgiq.dll
    C:\Program Files\Common Files\qwmk
    C:\Program Files\Ultimate Cleaner
    C:\DOCUME~1\MIKE~1.FUC\APPLIC~1\Ultimate Cleaner
    C:\Program Files\Uninstall Information\memehozet.html
    C:\Program Files\XEROX\popokyc.html
    C:\WINDOWS\SYSTEM32\vmntsdwo.exe



  • Then click the red Moveit! button below.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.. Then it will reboot your computer.

Then, after reboot (in case it asked to reboot)…

Open notepad and copy and paste next present in the quotebox below in it:
(don't forget to copy and paste REGEDIT4)

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{9ae613a2-a13b-4379-8d0e-86a1a78476ec}"=-

[-HKEY_CLASSES_ROOT\CLSID\{9ae613a2-a13b-4379-8d0e-86a1a78476ec}]

[-HKEY_USERS\.default\software\microsoft\windows\currentversion\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11B9AB3F-A91E-4F86-B21C-7ECEF54C5623}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{16D06D3E-2A5B-E9C9-F07C-0B9D099A71D0}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{45B6AD15-60F9-4854-F63D-69E34F97AFBF}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{515B087E-08BF-1665-8CCF-0868A01116CD}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60D0CF58-AFF4-1BD7-9033-059ED7FE9ADC}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F446A814-8EF9-4554-A201-8747C82043BB}]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\barolg]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\RunOnceEx]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxmetwbf]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=""

Save this as fix.reg Choose to save as *all files and place it on your desktop.
It should look like this: [external image: Posted Image]
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
(In case you are unsure how to create a reg file, take a look here with screenshots.)

* Open notepad and copy and paste next present in the quotebox in it:

copy /y "C:\Program Files\iTunes\bak\iTunesHelper.exe" "C:\Program Files\iTunes"
copy /y "C:\Program Files\QuickTime\bak\qttask.exe" "C:\Program Files\QuickTime"

Save this as replace.bat , choose to save as *all files and place it on your desktop.
It should look like this: [external image: Posted Image]
(In case you are unsure how to create a bat file, take a look here with screenshots.)

Doubleclick replace.bat you created previously.

* Clean your Cache and Cookies in IE:
  • Close all instances of Outlook Express and Internet Explorer
  • Go to Control Panel > Internet Options > General tab
  • Under Browsing History, click "Delete".
  • Click "Delete Files", "Delete cookies" and "Delete history"
  • Click Close below.
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu..
  • Click the Clear now button below.. A new window will popup what to clear.
  • Select all and click the Clear button again.
  • Click OK to close the Options window
* Clean other Temporary files + Recycle bin
  • Go to start > run and type: cleanmgr and click ok.
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Press OK to remove them.
* download http://www.mvps.org/winhelp2002/DelDomains.inf and place it on desktop
right click the file and select install, that will reset the zone settings that have been altered

and also

* Download: ResetProtocolDefaults.reg
http://www.mvps.org/winhelp2002/ResetProtocolDefaults.reg

Locate "ResetProtocolDefaults.reg"
Right-click and select: Merge (Ok the prompt)

Go to start > run and copy and paste next command in the field:

"C:\Program Files\Mozilla Firefox\ComboFix.exe" /v barolg

Hit enter. This should start Combofix again in another way.
Then it will reboot.
After reboot, post the new log combofix created (combofix.txt) in your next reply together with a new HijackThislog.
I just took a look at your Avira-log again. That was before you ran Combofix and AVG Antispyware:

1460 viruses and/or unwanted programs were found
1 classified as suspicious:
1459 files were deleted

:blink:
No wonder you started your thread with: "Yeah, I Got Big Problems…."

And it seems like your system was already infected for over 2 years.. since a LOT of older malware was flagged/deleted as well :blink:
This means that - all this time you were surfing without ANY protection present…. You really really have to change your surfing habits though. I'll give you some tips afterwards.
Ok, almost done, except for that last command…

Go to start > run and copy and paste next command in the field:

"C:\Program Files\Mozilla Firefox\ComboFix.exe" /v barolg


It says windows can't find that executable file, and it may be typed wrong.
Hi,

Well it showed in your previous Combofixlog that you were running Combofix.exe from the Mozilla Firefox folder even though I asked you to save it on your desktop.
Anyway, make sure Combofix.exe is present on your desktop. Then copy and paste next command in start > run:

"%userprofile%\desktop\ComboFix.exe" /v barolg

Please make sure you also copy and paste the quotes present in above command.

I just took a look at your Avira-log again. That was before you ran Combofix and AVG Antispyware:

1460 viruses and/or unwanted programs were found
1 classified as suspicious:
1459 files were deleted

:blink:
No wonder you started your thread with: "Yeah, I Got Big Problems…."

And it seems like your system was already infected for over 2 years.. since a LOT of older malware was flagged/deleted as well :blink:
This means that - all this time you were surfing without ANY protection present…. You really really have to change your surfing habits though. I'll give you some tips afterwards.


Yeah, I'm into planes and race cars. Computers have never really been my thing. Thanks for all you've done.

Why do you do this? Just to help people out, you really like computers, or hate people that write viruses? Or is it all of it?

Why do you do this? Just to help people out, you really like computers, or hate people that write viruses? Or is it all of it?

I love to help people and I hate malware and the malware writers. :)
I am doing this mainly because I want to teach people how to keep their system clean, because malware is lurking everywhere unfortunately. :(

Anyway, does it work with Combofix now? (not sure if you read my previous post)
Ok, Combofix report

"Mike" - 2007-05-16 16:47:11 Service Pack 1
ComboFix 07-05.17.V - Running from: "C:\Documents and Settings\Mike.FUCKSTICK\Desktop\"
Command switches used :: "/v barolg"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\vsadd-in
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\C\DOCUME~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\PPPATC~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\STEM~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\WNSXS~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0000
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0001
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0002
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0003
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\APPLIC~1\ASEMBL~1\ASEMBL~1\ctxad-465.0004
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\ASKS~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\ECURIT~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\MANTEC~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSEMBL~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\STEM32~1
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1\bak
C:\qoobox\purity\C\DOCUME~1\MIKE~1.FUC\MYDOCU~1\SSTEM~1\SSTEM~1
C:\qoobox\purity\C\Program Files\MCROSO~1.NET
C:\qoobox\purity\C\Program Files\TSKS~1
C:\qoobox\purity\C\Program Files\YMBOLS~1
C:\qoobox\purity\C\Program Files\YSTEM~1
C:\qoobox\purity\C\Program Files\Common Files\ASEMBL~1
C:\qoobox\purity\C\Program Files\Common Files\MBOLS~1
C:\qoobox\purity\C\Program Files\Common Files\RACLE~1
C:\qoobox\purity\C\Program Files\Common Files\SCURIT~1
C:\qoobox\purity\C\Program Files\Common Files\YSTEM~1
C:\qoobox\purity\C\WINDOWS\FNTS~1
C:\qoobox\purity\C\WINDOWS\RACLE~1
C:\qoobox\purity\C\WINDOWS\SCURIT~1
C:\qoobox\purity\C\WINDOWS\SYSTEM32\FNTS~1
C:\qoobox\purity\C\WINDOWS\SYSTEM32\ICROSO~1


((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-16 ))))))))))))))))))))))))))))))))))


2007-05-16 16:30 88,340 –a—— C:\WINDOWS\SYSTEM32\uifefkjj.exe
2007-05-16 16:15 88,340 –a—— C:\WINDOWS\SYSTEM32\gsvkqooe.exe
2007-05-16 15:30 88,340 –a—— C:\WINDOWS\SYSTEM32\hacfsljt.exe
2007-05-16 15:23 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-05-16 11:49 3,968 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-05-16 10:07 43,584 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avipbb.sys
2007-05-16 10:07 28,352 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ssmdrv.sys
2007-05-16 10:07 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\AntiVir PersonalEdition Classic
2007-05-16 09:50 d——– C:\DOCUME~1\MIKE~1.FUC\APPLIC~1\Comodo
2007-05-16 09:50 d——– C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Comodo
2007-05-16 09:48 d——– C:\Program Files\Comodo


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-16 21:22:49 ——– d—–w C:\Program Files\QuickTime
2007-05-16 21:22:49 ——– d—–w C:\Program Files\iTunes
2007-02-23 17:50:58 0 —-a-w C:\DOCUME~1\MIKE~1.FUC\APPLIC~1\amlistx.dat


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{DDBC7F87-0FA0-405D-8EB9-50925D2722DC}=C:\WINDOWS\MICROS~1.NET\barolg.dll [2006-11-09 08:58]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 02:00]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe" [2004-12-06 22:31]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"Logitech Utility"="Logi_MwX.Exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-09-12 01:58]
"Dell AIO Printer A920"="C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 13:25]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" []
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2007-05-16 09:48]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2006-10-07 07:20]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sonic RecordNow!"="" []
"MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" []

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source REG_SZ C:\Program Files\XEROX\popokyc.html

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 09:13]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\barolg]
C:\WINDOWS\MICROS~1.NET\barolg.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0
Security Packages kerberos msv1_0 schannel wdigest
Notification Packages scecli

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
NetworkService DnsCache
rpcss RpcSs
imgsvc StiSvc
termsvcs TermService

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E]
Shell\AutoRun\command E:\ctrun\ctcdrun.exe


********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-16 16:49:11
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0


********************************************************************

Completion time: 2007-05-16 16:49:52
C:\ComboFix-quarantined-files.txt … 2007-05-16 16:49
C:\ComboFix2.txt … 2007-05-16 15:23


— E O F —
New HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 4:58:34 PM, on 5/16/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Duh, now I see why Combofix didn't remove it - the /v switch only works for files in the system32 folder and in your case, it's in another folder..

Do next please..

* Download VundoFix.exe to your C:\.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, Right click the list box (white box) in the main VundoFix window.
  • Select “Add More Files?” from the menu that comes up. This will open a new VundoFix window.
  • In the Window: copy and paste next in the first field: C:\WINDOWS\MICROS~1.NET\barolg.dll
  • Click the “Add Files” button.
  • Click the "Close Window" button.
  • Click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

After reboot,

Use OTMoveIt again, the same way you did before and copy and paste next in the left field ( Where it says: "Paste List of Files/Folders to be Moved ):

C:\WINDOWS\SYSTEM32\uifefkjj.exe
C:\WINDOWS\SYSTEM32\gsvkqooe.exe
C:\WINDOWS\SYSTEM32\hacfsljt.exe


Then click the red Moveit! button below.
Close OTMoveIt

Post a new hijackthislog and the contents of C:\vundofix.txt in your next reply.
Extra addition…

Do you know how to remove files manually?
Please remove next file:

C:\Documents and Settings\Mike.FUCKSTICK\APPLICATION DATA\amlistx.dat

edit, can you also tell me what is currently plugged in in your E-drive?

No, I don't know how to remove files manually.

In that case, also paste it in the left field in OTMoveIT:

C:\Documents and Settings\Mike.FUCKSTICK\APPLICATION DATA\amlistx.dat

But do this AFTERWARDS, after your computer has rebooted because of the Vundofix.

Also, I edited my previous post where I asked:

edit, can you also tell me what is currently plugged in in your E-drive?

edit, can you also tell me what is currently plugged in in your E-drive? Nothing is plugged into it. I had a "Sound Blaster Live" cd in either the D: or E: earlier in an attempt to restore sound, but nothing came of it. Is that possibly what you saw?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI