Logfile of HijackThis v1.99.1
Scan saved at 11:35:53 pm, on 21/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Tried to remove entries:
O2 - BHO: (no name) - {0233D1D6-E00D-4C45-BF14-485759765168} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {102701FA-B29F-46FB-94BC-6251B31E804D} - (no file)
O2 - BHO: (no name) - {CCB579E0-321E-4DD7-9BCF-50E33A65F7C0} - (no file)
(both with Hijack and deleting them from registry)
as well as
O20 - Winlogon Notify: hggecbx - C:\WINDOWS\
O20 - Winlogon Notify: mljge - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
also tried to erase them while in safe mode.
but on reboot and rescan the entries reappeared. Help, because i'm not sure what is going on.
Your TeaTimer is going to interfere with what we are trying to do. I need you to disable it.
Disable Spybot's TeaTimer. This is a two step process. First:
- Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
- Choose Exit Spybot S&D Resident Second:
- Open Spybot S&D
- Click Mode, check Advanced Mode
- Go To Left Panel, Click Tools, then also in left panel, click Resident
- If your firewall raises a question, say OK
- Uncheck the box labeled Resident Tea-Timer and OK any prompts.
- Use File, Exit to terminate Spybot
- Reboot your machine for the changes to take effect.
Leave it disabled till I tell you it's ok to turn it back on.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Please post vundofix.txt and a new HJT log in your next post.
Thanks dan
Attempting to delete C:\WINDOWS\system32\gvtcdgww.dll
C:\WINDOWS\system32\gvtcdgww.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\wwgdctvg.ini
C:\WINDOWS\system32\wwgdctvg.ini Has been deleted!
Performing Repairs to the registry.
Done!
HJT log however hasn't changed at all
Logfile of HijackThis v1.99.1
Scan saved at 2:49:34 am, on 22/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You may want to print these instructions for reference
Download ATF Cleaner by Atribune and save it to your Desktop. Do not use yet!
Ewido is now known as ( AVG Anti-Spyware.)
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
Install AVG Anti-Spyware by double clicking the installer.
Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
On the main screen under Your Computer's security.
Click on Change state next to Resident shield. It should now change to inactive.
Click on Change state next to Automatic updates. It should now change to inactive.
Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
Wait until you see the Update succesfull message.
Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido. AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
Dont use yet!
__________________________
We need to reveal system folders
Close all programs so that you are at your desktop.
Double-click on the My Computer icon.
Select the Tools menu and click Folder Options
After the new window appears select the View tab.
Place a checkmark in the checkbox labeled Display the contents of system folders
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
Remove the checkmark from the checkbox labeled Hide file extensions for known file types
Remove the checkmark from the checkbox labeled Hide protected operating system files
Press the Apply and then the ok button and shut down my computer
Now your computer is configured to show all hidden files.
For you and the tools to be able to see appropriate files we need to Show Hidden Files
Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
O2 - BHO: (no name) - {0233D1D6-E00D-4C45-BF14-485759765168} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {102701FA-B29F-46FB-94BC-6251B31E804D} - (no file)
O2 - BHO: (no name) - {CCB579E0-321E-4DD7-9BCF-50E33A65F7C0} - (no file)
O20 - Winlogon Notify: hggecbx - C:\WINDOWS\
O20 - Winlogon Notify: mljge - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit
Re-boot into safe mode
Next, please reboot your computer in Safe Mode by doing the following:
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
Instead of Windows loading as normal, a menu should appear use arrow up to highlight
Select the first option, to run Windows in Safe Mode hit enter.
For additional help in booting into Safe Mode, see the following site:HERE
Run ATF cleaner
Double click ATF-Cleaner.exe to run the program.
Check the following boxes:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch
Recycle Bin
Java Cache
The rest are optional - if you want to remove the lot, check Select All.
Now click Empty Selected.
When you get the Done Cleaning message, click OK.
If you use Firefox browser.
Click Firefox at the top and choose: Select All
If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button.
If you use Opera browser.
Click Opera at the top and choose: Select All
If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button.
Run AVG Anti-Spyware
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act?
Click on Recommended Action and choose Quarantine from the popup menu.
Under How to scan?
All checkboxes should be ticked.
Under Possibly unwanted software:
All checkboxes should be ticked.
Under Reports:
Select Automatically generate report after every scan and uncheck Only if threats were found.
Under What to scan?
Select Scan every file.
Click on the Scan tab.
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
When the scan has finished, follow the instructions below. IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
Make sure that Set all elements to: shows Quarantine(1), if not click on the link and choose Quarantine from the popup menu. (2)
At the bottom of the window click on the Apply all Actions button. (3)
[external image: Posted Image]
When done, click the Save Scan Report button. (4)
Click the Save Report as button.
Save the report to your Desktop.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
_____________________________
Can you change browser to "Internet explorer" for this next scan.
please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan select My Computer
The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Please include new HJT log, AVG Anti-Spyware log and kaspersky log
in your next post
Thanks dan
Logfile of HijackThis v1.99.1
Scan saved at 8:37:38 pm, on 23/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 23, 2007 8:33:17 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 23/05/2007
Kaspersky Anti-Virus database records: 328226
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 96717
Number of viruses found: 2
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 00:32:44
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Akida\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Akida\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Akida\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Akida\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Akida\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Akida\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Akida\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\sysreset\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.614 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\jkkjj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Also I haven't enable spybot yet as you told me not to, but while looking up in spybot i noticed that under tools -> startup
Essentially the reason mirc is flagged is because it is somewhat of a risk-ware…its a chat system that can be exploited to transfer viruses…but people who use it wisely and correctly can have no problem with it.
Double-click VundoFix.exe to run it again.
Right Click inside the listbox (white box) and click add more files
Copy&Paste the entries below into the open boxes C:\WINDOWS\system32\jkkjj.dll
Click Add Files and Click Close Window
Click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot,allow the computer to reboot and VundoFix to load.
Just add the very same files as before and Click Remove Vundo.
Your log doesn't appear to show a third-party software firewall installed.
If you are relying the firewall that comes with Service Pack 2, then you need to install one. While the SP2 firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will.
It is important to note that you should only have one firewall installed at a time, but you can download them all to your Desktop and install each in turn to see which one you prefer.
Understanding and Using Firewalls: http://www.bleepingcomputer.com/tutorials/tutorial60.html
Once installed reboot and post a further HJT log
Thanks dan
ok, chose the outpost one, however i'm a bit skeptical as far as how capable i'm with recognizing which changes to allow and which not (not saying that windows firewall is any good)
hjt log as requested
Logfile of HijackThis v1.99.1
Scan saved at 12:15:43 pm, on 24/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
As you had done quite a bit of cleaning before hand, I can only guess and say they are leftovers.
You need to be very carefull of what you delete in registery unless you are confident that you know what your doing.
Create a folder in your C: drive C:\Regsearch, and extract all the files from the zip archive into that folder.
Double click regsearch.exe to launch the programme.
Copy/Paste the following into the Search Box {0233D1D6-E00D-4C45-BF14-485759765168}
On the next line Copy/Paste {02478D38-C3F9-4EFB-9B51-7695ECA05670}
On the next line Copy/Paste {102701FA-B29F-46FB-94BC-6251B31E804D}
On the next line Copy/Paste {CCB579E0-321E-4DD7-9BCF-50E33A65F7C0}
Click OK.
Regsearch will now search your Registry for the required strings, when it is finished it will open a Notepad file RegSearch.txt, saved to the Regsearch folder.
Save it to your desktop. Run and install this program.
In the box that opens only choose System registry
Then click OK.
Click save and then go to File > Exit.
This is so the registry can be restored to this point if we need it. It may take a minute. Just let it go until it's done.
Copy/paste the following text into a new Notepad document. (You must use Notepad, NOT Wordpad). Make sure that you have NO blank lines at the beginning of the document before REGEDIT4, and ONE blank line at the end of the document as shown in the quoted text:
Save it to your desktop as Fixme.reg. Save it as follows…
File Type: "All Files" (not as a text document or it wont work).
Name: Fixme.reg
Locate Fixme.reg on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the merged successfully prompt.
post me another HJT log and let me know how things are?
Thanks dan
Logfile of HijackThis v1.99.1
Scan saved at 11:27:20 am, on 26/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
seems clean to me, the registry entries have been removed as well. Things look normal minus one "surprise" reboot my machine did yesterday and then froze on restart until i completely turn off the computer and started it over. I think this one was due to the firewall as it's the only one reporting error after the machine got to normal. However i have slight suspicion that if i was to re-enable spybot the registry entries as well as WgaLogon entry would return, because they are still marked to run on start up along with that program.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI