here is my hijackthis log
Logfile of HijackThis v1.99.1
Scan saved at 9:57:48 AM, on 5/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Please post vundofix.txt and a new HJT log in your next post.
Thanks dan
thank you, i have been up all night trying to fix my computer… took a nap and replied, thank you again! here is my VBG.TXT notepad and HIJACKTHIS.log. please advise.. once again thank you
[05/19/2007, 9:51:39] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Moyo\Desktop\VirtumundoBeGone.exe" )
[05/19/2007, 9:51:47] - Detected System Information:
[05/19/2007, 9:51:47] - Windows Version: 5.1.2600, Service Pack 2
[05/19/2007, 9:51:47] - Current Username: Moyo (Admin)
[05/19/2007, 9:51:47] - Windows is in NORMAL mode.
[05/19/2007, 9:51:47] - Searching for Browser Helper Objects:
[05/19/2007, 9:51:47] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/19/2007, 9:51:47] - BHO 2: {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} ()
[05/19/2007, 9:51:47] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:51:47] - Checking for HKLM\…\Winlogon\Notify\urqppmj
[05/19/2007, 9:51:47] - Found: HKLM\…\Winlogon\Notify\urqppmj - This is probably Virtumundo.
[05/19/2007, 9:51:47] - Assigning {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} MSEvents Object
[05/19/2007, 9:51:47] - BHO list has been changed! Starting over…
[05/19/2007, 9:51:47] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/19/2007, 9:51:47] - BHO 2: {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} (MSEvents Object)
[05/19/2007, 9:51:47] - ALERT: Found MSEvents Object!
[05/19/2007, 9:51:47] - BHO 3: {429ADE89-8151-4C05-858E-1F2E8112A3FF} ()
[05/19/2007, 9:51:47] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:51:47] - Checking for HKLM\…\Winlogon\Notify\awtst
[05/19/2007, 9:51:47] - Found: HKLM\…\Winlogon\Notify\awtst - This is probably Virtumundo.
[05/19/2007, 9:51:47] - Assigning {429ADE89-8151-4C05-858E-1F2E8112A3FF} MSEvents Object
[05/19/2007, 9:51:48] - BHO list has been changed! Starting over…
[05/19/2007, 9:51:48] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/19/2007, 9:51:48] - BHO 2: {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} (MSEvents Object)
[05/19/2007, 9:51:48] - ALERT: Found MSEvents Object!
[05/19/2007, 9:51:48] - BHO 3: {429ADE89-8151-4C05-858E-1F2E8112A3FF} (MSEvents Object)
[05/19/2007, 9:51:48] - ALERT: Found MSEvents Object!
[05/19/2007, 9:51:48] - BHO 4: {53707962-6F74-2D53-2644-206D7942484F} ()
[05/19/2007, 9:51:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:51:48] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[05/19/2007, 9:51:48] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[05/19/2007, 9:51:48] - BHO 5: {55DB983C-BDBF-426f-86F0-187B02DDA39B} ()
[05/19/2007, 9:51:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:51:48] - Checking for HKLM\…\Winlogon\Notify\udhsmtjo
[05/19/2007, 9:51:48] - Key not found: HKLM\…\Winlogon\Notify\udhsmtjo, continuing.
[05/19/2007, 9:51:48] - BHO 6: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[05/19/2007, 9:51:48] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[05/19/2007, 9:51:48] - Finished Searching Browser Helper Objects
[05/19/2007, 9:51:48] - *** Detected MSEvents Object
[05/19/2007, 9:51:48] - Trying to remove MSEvents Object…
[05/19/2007, 9:51:49] - Terminating Process: IEXPLORE.EXE
[05/19/2007, 9:51:50] - Terminating Process: RUNDLL32.EXE
[05/19/2007, 9:51:50] - Disabling Automatic Shell Restart
[05/19/2007, 9:51:50] - Terminating Process: EXPLORER.EXE
[05/19/2007, 9:51:50] - Suspending the NT Session Manager System Service
[05/19/2007, 9:51:50] - Terminating Windows NT Logon/Logoff Manager
[05/19/2007, 9:51:51] - Re-enabling Automatic Shell Restart
[05/19/2007, 9:51:51] - File to disable: C:\WINDOWS\system32\urqppmj.dll
[05/19/2007, 9:51:51] - Removing HKLM\…\Browser Helper Objects\{3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5}
[05/19/2007, 9:51:51] - Removing HKCR\CLSID\{3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5}
[05/19/2007, 9:51:51] - Adding Kill Bit for ActiveX for GUID: {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5}
[05/19/2007, 9:51:51] - Deleting ATLEvents/MSEvents Registry entries
[05/19/2007, 9:51:51] - Removing HKLM\…\Winlogon\Notify\urqppmj
[05/19/2007, 9:51:51] - Searching for Browser Helper Objects:
[05/19/2007, 9:51:51] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/19/2007, 9:51:51] - BHO 2: {429ADE89-8151-4C05-858E-1F2E8112A3FF} (MSEvents Object)
[05/19/2007, 9:51:51] - ALERT: Found MSEvents Object!
[05/19/2007, 9:51:51] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[05/19/2007, 9:51:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:51:51] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[05/19/2007, 9:51:51] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[05/19/2007, 9:51:51] - BHO 4: {55DB983C-BDBF-426f-86F0-187B02DDA39B} ()
[05/19/2007, 9:51:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:51:51] - Checking for HKLM\…\Winlogon\Notify\udhsmtjo
[05/19/2007, 9:51:51] - Key not found: HKLM\…\Winlogon\Notify\udhsmtjo, continuing.
[05/19/2007, 9:51:51] - BHO 5: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[05/19/2007, 9:51:51] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[05/19/2007, 9:51:51] - Finished Searching Browser Helper Objects
[05/19/2007, 9:51:51] - *** Detected MSEvents Object
[05/19/2007, 9:51:51] - Trying to remove MSEvents Object…
[05/19/2007, 9:51:52] - Terminating Process: IEXPLORE.EXE
[05/19/2007, 9:51:52] - Terminating Process: RUNDLL32.EXE
[05/19/2007, 9:51:52] - Disabling Automatic Shell Restart
[05/19/2007, 9:51:52] - Terminating Process: EXPLORER.EXE
[05/19/2007, 9:51:52] - Suspending the NT Session Manager System Service
[05/19/2007, 9:51:52] - Terminating Windows NT Logon/Logoff Manager
[05/19/2007, 9:51:53] - Re-enabling Automatic Shell Restart
[05/19/2007, 9:51:53] - File to disable: C:\WINDOWS\system32\awtst.dll
[05/19/2007, 9:51:53] - Renaming C:\WINDOWS\system32\awtst.dll -> C:\WINDOWS\system32\awtst.dll.vir
[05/19/2007, 9:51:53] - File successfully renamed!
[05/19/2007, 9:51:53] - Removing HKLM\…\Browser Helper Objects\{429ADE89-8151-4C05-858E-1F2E8112A3FF}
[05/19/2007, 9:51:53] - Removing HKCR\CLSID\{429ADE89-8151-4C05-858E-1F2E8112A3FF}
[05/19/2007, 9:51:53] - Adding Kill Bit for ActiveX for GUID: {429ADE89-8151-4C05-858E-1F2E8112A3FF}
[05/19/2007, 9:51:53] - Deleting ATLEvents/MSEvents Registry entries
[05/19/2007, 9:51:53] - Removing HKLM\…\Winlogon\Notify\awtst
[05/19/2007, 9:51:53] - Searching for Browser Helper Objects:
[05/19/2007, 9:51:53] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/19/2007, 9:51:53] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[05/19/2007, 9:51:53] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:51:53] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[05/19/2007, 9:51:53] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[05/19/2007, 9:51:53] - BHO 3: {55DB983C-BDBF-426f-86F0-187B02DDA39B} ()
[05/19/2007, 9:51:53] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:51:53] - Checking for HKLM\…\Winlogon\Notify\udhsmtjo
[05/19/2007, 9:51:53] - Key not found: HKLM\…\Winlogon\Notify\udhsmtjo, continuing.
[05/19/2007, 9:51:53] - BHO 4: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[05/19/2007, 9:51:53] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[05/19/2007, 9:51:53] - Finished Searching Browser Helper Objects
[05/19/2007, 9:51:53] - Finishing up…
[05/19/2007, 9:51:53] - A restart is needed.
[05/19/2007, 9:51:53] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[05/19/2007, 9:52:03] - Attempting to Restart via STOP error (Blue Screen!)
[05/19/2007, 9:54:45] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Moyo\Desktop\VirtumundoBeGone.exe" )
[05/19/2007, 9:54:52] - Detected System Information:
[05/19/2007, 9:54:52] - Windows Version: 5.1.2600, Service Pack 2
[05/19/2007, 9:54:52] - Current Username: Moyo (Admin)
[05/19/2007, 9:54:52] - Windows is in NORMAL mode.
[05/19/2007, 9:54:52] - Searching for Browser Helper Objects:
[05/19/2007, 9:54:52] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/19/2007, 9:54:52] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[05/19/2007, 9:54:53] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:54:53] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[05/19/2007, 9:54:53] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[05/19/2007, 9:54:53] - BHO 3: {55DB983C-BDBF-426f-86F0-187B02DDA39B} ()
[05/19/2007, 9:54:53] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 9:54:53] - Checking for HKLM\…\Winlogon\Notify\udhsmtjo
[05/19/2007, 9:54:53] - Key not found: HKLM\…\Winlogon\Notify\udhsmtjo, continuing.
[05/19/2007, 9:54:53] - BHO 4: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[05/19/2007, 9:54:53] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[05/19/2007, 9:54:53] - Finished Searching Browser Helper Objects
[05/19/2007, 9:54:53] - Finishing up…
[05/19/2007, 9:54:53] - Nothing found! Exiting…
[05/19/2007, 14:48:29] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Moyo\Desktop\VirtumundoBeGone.exe" )
[05/19/2007, 14:48:33] - User choose NOT to continue. Exiting…
[05/19/2007, 14:49:08] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Moyo\Desktop\VirtumundoBeGone.exe" )
[05/19/2007, 14:49:11] - Detected System Information:
[05/19/2007, 14:49:11] - Windows Version: 5.1.2600, Service Pack 2
[05/19/2007, 14:49:11] - Current Username: Moyo (Admin)
[05/19/2007, 14:49:11] - Windows is in NORMAL mode.
[05/19/2007, 14:49:11] - Searching for Browser Helper Objects:
[05/19/2007, 14:49:11] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[05/19/2007, 14:49:11] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[05/19/2007, 14:49:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 14:49:11] - Checking for HKLM\…\Winlogon\Notify\SDHelper
[05/19/2007, 14:49:11] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing.
[05/19/2007, 14:49:11] - BHO 3: {55DB983C-BDBF-426f-86F0-187B02DDA39B} ()
[05/19/2007, 14:49:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/19/2007, 14:49:11] - Checking for HKLM\…\Winlogon\Notify\udhsmtjo
[05/19/2007, 14:49:11] - Key not found: HKLM\…\Winlogon\Notify\udhsmtjo, continuing.
[05/19/2007, 14:49:11] - BHO 4: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[05/19/2007, 14:49:11] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[05/19/2007, 14:49:11] - Finished Searching Browser Helper Objects
[05/19/2007, 14:49:11] - Finishing up…
[05/19/2007, 14:49:11] - Nothing found! Exiting…
and HIJACKTHIS.log
Logfile of HijackThis v1.99.1
Scan saved at 2:49:47 PM, on 5/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Hi, moyo, did you run vundo fix as I gave you the link in the post? this is not a vundo log.
Please only down load the links I provide whilst we are working on your pc.
Thanks dan
sorry ran another… downloaded vundofix, ran it, my computer rebooted. there is no log to post but it removed (2) files. also here is my hijackthis log
Logfile of HijackThis v1.99.1
Scan saved at 4:51:13 PM, on 5/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
sorry to be bothersome, please understand that i have been trying to fix this problem for multiple days now… i have been reading everything on this matter. should i only have (1) antivirus running? i now have AVG, spyhunter, spybot, and avast
Hi, It's important for the duration of the fix to download the tools I give you links for.
I need to see the log from my first Instruction which you will find in this location C:\vundofix.txt.
If your going to be doing your own thing we are going to be going round in circles and I will be wondering why my fixes are not going as I would like.
As for your a\v you only want one a\v and one firewall active on your machine running more than one you are asking for trouble, not only that they fight for resources and fall out with each other.
Can you run the vundo fix and post me the text
in your next post
Thanks dan
Attempting to delete C:\WINDOWS\system32\uykobydy.ini
C:\WINDOWS\system32\uykobydy.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ydybokyu.dll
C:\WINDOWS\system32\ydybokyu.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.3.23
Checking Java version…
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Scan started at 4:50:27 PM 5/19/2007
Listing files found while scanning….
No infected files were found.
Beginning removal…
VundoFix V6.3.23
Checking Java version…
Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.
Scan started at 7:55:50 PM 5/19/2007
Listing files found while scanning….
No infected files were found.
Beginning removal…
here is also my hijack this log
Logfile of HijackThis v1.99.1
Scan saved at 8:08:22 PM, on 5/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Your log shows that you have two different antivirus programs installed and running side-by-side ( avast and AVG7 ).
Do not attempt to run two entirely different 'on-access' resident scanner anti-virus products simultaneously. It is simply an accident waiting to happen. Having more than one antivirus program running and "active in memory" will most definitely use far more additional resources, adversely affecting your access to files and causing overall system slowdowns.
Most of the popular anti-virus products (when running together) will "fight for control" over the user's machine, and it is this conflict that will create slowing the system speed as well as other serious compatibility problems. This can also create registry conflicts as well as causing false virus alerts - or worse, missing alerts entirely!
Additionally, many of these types of programs simply do not "play nice" or work well with each other. Unfortunately, the only thing many of these types of security applications seem to detest more than potentially harmful viruses - is other antivirus applications running simultaneously together with them. Also, not all AV programs can be installed as secondary scanners, and sometimes installing separate AV programs will cause a conflict or the program's installer will even try to 'uninstall' any other anti-virus programs during the installation.
Therefore, my advice would be to pick one (or the other) of your antivrius programs to use and then use Windows Add/Remove Programs to uninstall the one that you do not want to use anymore.
___________________
Download ATF Cleaner by Atribune and save it to your Desktop. Do not use yet!
Ewido is now known as ( AVG Anti-Spyware.)
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
Install AVG Anti-Spyware by double clicking the installer.
Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
On the main screen under Your Computer's security.
Click on Change state next to Resident shield. It should now change to inactive.
Click on Change state next to Automatic updates. It should now change to inactive.
Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
Wait until you see the Update succesfull message.
Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido. AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
Dont use yet!
__________________________
Next we need to stop a couple of processes that are running on your computer
To do this…
Startup HJT and select the 4th button entitled
Open the misc tools section
Under where it says system tools click on
Open process manager
Now look for the following processes one by one in the list below, once you find them highlight them then click on the
killl process
button
C:\WINDOWS\svhost.exe <=== Note the spelling! In the legitimate file there is a "c" ( "svchost.exe" ..This is legitimate so dont stop this process )
Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\udhsmtjo.dll (file missing)
O4 - HKLM\..\Run: [svhost] "C:\WINDOWS\svhost.exe"
O4 - HKLM\..\Run: [setup] rundll32.exe "C:\WINDOWS\system32\ydybokyu.dll",realset
WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit
_______________________
We need to reveal system folders
Close all programs so that you are at your desktop.
Double-click on the My Computer icon.
Select the Tools menu and click Folder Options
After the new window appears select the View tab.
Place a checkmark in the checkbox labeled Display the contents of system folders
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
Remove the checkmark from the checkbox labeled Hide file extensions for known file types
Remove the checkmark from the checkbox labeled Hide protected operating system files
Press the Apply and then the ok button and shut down my computer
Now your computer is configured to show all hidden files.
For you and the tools to be able to see appropriate files we need to Show Hidden Files
Re-boot into safe mode
Next, please reboot your computer in Safe Mode by doing the following:
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
Instead of Windows loading as normal, a menu should appear use arrow up to highlight
Select the first option, to run Windows in Safe Mode hit enter.
For additional help in booting into Safe Mode, see the following site:HERE
Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:
C:\WINDOWS\system32\ydybokyu.dll << This file
C:\WINDOWS\svhost.exe << This file <======= Note the spelling as explained above!
C:\WINDOWS\system32\udhsmtjo.dll << This file
Run ATF cleaner
Double click ATF-Cleaner.exe to run the program.
Check the following boxes:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch
Recycle Bin
Java Cache
The rest are optional - if you want to remove the lot, check Select All.
Now click Empty Selected.
When you get the Done Cleaning message, click OK.
If you use Firefox browser.
Click Firefox at the top and choose: Select All
If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button.
If you use Opera browser.
Click Opera at the top and choose: Select All
If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button.
Run AVG Anti-Spyware
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act?
Click on Recommended Action and choose Quarantine from the popup menu.
Under How to scan?
All checkboxes should be ticked.
Under Possibly unwanted software:
All checkboxes should be ticked.
Under Reports:
Select Automatically generate report after every scan and uncheck Only if threats were found.
Under What to scan?
Select Scan every file.
Click on the Scan tab.
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
When the scan has finished, follow the instructions below. IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
Make sure that Set all elements to: shows Quarantine(1), if not click on the link and choose Quarantine from the popup menu. (2)
At the bottom of the window click on the Apply all Actions button. (3)
[external image: Posted Image]
When done, click the Save Scan Report button. (4)
Click the Save Report as button.
Save the report to your Desktop.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
Please include new HJT log, AVG Anti-Spyware log and kaspersky log
in your next post
Thanks dan
dan, thanx for all your help.
here is my hijackthis log, my AVG log, and vundofix log
Logfile of HijackThis v1.99.1
Scan saved at 2:01:52 PM, on 5/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
The Microsoft Java Virtual Machine (MS-JVM) is installed on the computer. This is now a security risk and we need to remove it and install Sun's Java in its place. If you have any problems with this, or if you have any questions, then stop and let me know.
1. Click on Start then Run. Copy/paste the following into the Run: text box:
3. You will see a confirmation prompt which says "If this component is uninstalled, Microsoft Internet Explorer will not be able to download files from the World Wide Web. Do you want to uninstall the MicrosoftVM?". Don't worry about this message!
4. Click the Yes button to start the uninstall process of the MS-JVM.
Windows will uninstall the files and then give you a prompt asking whether or not you want to restart the computer. You should press the Yes button to allow it to do so.
When the computer has restarted, click on Start then My Computer, find the following files and folders (highlighted in red) and delete them, if present. Please let me know if there are any problems with this.
c:\windows\inf\java.pnf <- File only
c:\windows\java <- Folder
c:\windows\system32\wjview.exe <- File only
c:\windows\system32\jview.exe <- File only
Make sure there are NO blank lines before REGEDIT4
Make sure there is one blank line at the end of the file
Make sure that you have copied all of the text (e.g. don't miss the first 'R')
Then double-click on the fix.reg file, and when it prompts to merge say Yes.
Install Java Runtime:
The most current version is: Java Runtime Environment Version 6u1.
Go to http://java.sun.com/javase/downloads/index.jsp
Click on the link named Java Runtime Environment (JRE) 6u1
Click on the radio button to Accept License Agreement
Click on Windows Offline Installation, Multi-language and save the downloaded file to your hard disk
Go to Start => Control Panel => Add or Remove Programs
Uninstall all old versions of Java (Java 2 Runtime Environment, JRE or JSE)
Reboot your computer
Delete the folder C:\Program Files\Java if present
Install the new version by running the newly-downloaded file, and follow the on-screen instructions.
Reboot your computer
_______________________________
please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan select My Computer
The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Please include new HJT log, kaspersky log, and let me know how things are at this point in time!
in your next post
Thanks dan