This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can Someone Take A Look Plz?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my bf doesnt listen to me very well and got more carp** on the pc





Logfile of HijackThis v1.99.1
Scan saved at 9:39:51 AM, on 6/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ResChanger XP\ResChangerXP.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O4 - HKLM\..\Run: [ResChangerXP] C:\Program Files\ResChanger XP\ResChangerXP.exe
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Rcca] "C:\PROGRA~1\ASEMBL~1\notepad.exe" -vt yazb
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!



1. Download Combo fix from one of these locations.
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

________________________________




Panda
Run Panda's ActiveScan from here and perform a full system scan.
- Once you are on the Panda site click the "Scan your PC" button
- A new window will open…click the big "Check Now" button
- Enter your Country
- Enter your State/Province
- Enter your Valid Email
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
- Click on "Local Disks" to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
- Post Panda scan results in your next reply

____________________________________


In your next reply I would like to see:
  • A new HJT log
  • The report from Pandas online scan
  • The report from Comboscan
the panda scan kept freezing and my internet kept diconnecting so i couldnt do that one but heres the rest


"chad1" - 2007-06-09 7:58:27 Service Pack 2 NTFS
ComboFix 07-06-3B - Running from: "C:\Documents and Settings\chad1\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\llkkj.bak1
C:\WINDOWS\system32\llkkj.ini
C:\WINDOWS\system32\llkkj.bak1
C:\WINDOWS\system32\llkkj.ini
C:\WINDOWS\system32\llkkj.tmp
C:\WINDOWS\system32\jkkll.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))



– Purity Folders:
C:\DOCUME~1\chad1\APPLIC~1\Microsoft\25319.dat
C:\DOCUME~1\chad1\Desktop\internet.lnk
C:\Documents and Settings\All Users.\documents\settings
C:\Documents and Settings\All Users.\documents\settings\desktop.ini
C:\Documents and Settings\All Users.\documents\settings\partnership.dll
C:\Program Files\ASEMBL~1
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\WINDOWS\cs_cache.ini
C:\WINDOWS\ICROSO~1.NET
C:\WINDOWS\system32\5_exception.nls
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\drivers\runtime2.sys
C:\WINDOWS\system32\KB18561603.exe
C:\WINDOWS\system32\KB96926207.exe
C:\WINDOWS\system32\KB98879216.exe
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\kprof
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\pog
C:\WINDOWS\system32\poof
C:\WINDOWS\system32\RunOnce2.t__
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T4
C:\WINDOWS\system32\T4\amst5.exe
C:\WINDOWS\system32RunOnce2.t__
C:\WINDOWS\system32RunOnce2.tm_
C:\WINDOWS\wr.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_CORE
——-\LEGACY_POOF
——-\LEGACY_RUNTIME
——-\LEGACY_RUNTIME2
——-\core
——-\Runtime
——-\Windows Overlay Components


((((((((((((((((((((((((( Files Created from 2007-05-09 to 2007-06-09 )))))))))))))))))))))))))))))))


2007-06-09 08:05 d——– C:\Avenger
2007-06-08 22:50 75,792 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2007-06-08 22:50 32,528 –a—— C:\WINDOWS\system32\drivers\tmpreflt.sys
2007-06-08 22:50 300,816 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2007-06-08 22:50 199,440 –a—— C:\WINDOWS\system32\drivers\tmxpflt.sys
2007-06-08 22:50 112,400 –a—— C:\WINDOWS\system32\drivers\tm_mbd_c.sys
2007-06-08 22:50 1,052,472 –a—— C:\WINDOWS\system32\drivers\vsapint.sys
2007-06-08 22:49 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trend Micro
2007-06-08 22:48 d——– C:\Program Files\Trend Micro
2007-06-08 22:37 d——– C:\DOCUME~1\chad1\.housecall6.6
2007-06-08 10:35 164 –a—— C:\install.dat
2007-06-08 10:32 d——– C:\DOCUME~1\chad1\APPLIC~1\GetRightToGo
2007-06-08 09:21 193,536 –a—— C:\WINDOWS\system32\scchk32.exe
2007-06-08 06:26 58,420 –a—— C:\WINDOWS\system32\kamdpqaw.dll
2007-06-08 06:26 131,124 –a—— C:\WINDOWS\system32\rsjoctoi.dll
2007-06-08 02:58 33,302 –a—— C:\WINDOWS\system32\vtustsq.dll
2007-06-08 02:54 33,302 –a—— C:\WINDOWS\system32\urqrqop.dll
2007-06-08 02:50 928 –a—— C:\WINDOWS\system32\winpfz32.sys
2007-06-08 02:50 1,036,352 -r-hs—- C:\WINDOWS\jybvrwzA.exe
2007-06-08 02:49 102,400 –a—— C:\WINDOWS\MBDownloader_876916.exe
2007-06-08 02:49 d——– C:\WINDOWS\system32\TQ0
2007-06-08 02:49 d——– C:\WINDOWS\system32\T7
2007-06-08 02:49 d——– C:\WINDOWS\system32\T6
2007-06-08 02:49 d——– C:\WINDOWS\system32\T5
2007-06-08 02:49 d——– C:\WINDOWS\system32\T1QaSQ
2007-06-08 02:49 d——– C:\Temp
2007-06-08 02:48 33,302 –a—— C:\WINDOWS\system32\ddcyxwv.dll
2007-06-07 14:27 d–h—– C:\WINDOWS\PIF
2007-06-07 14:17 19,520 –a—— C:\WINDOWS\system32\pCHOH3PJ.exe
2007-06-07 12:42 d——– C:\WINDOWS\pss
2007-06-07 11:51 d——– C:\DOCUME~1\chad1\APPLIC~1\Ahead
2007-06-07 11:48 d——– C:\Program Files\Nero
2007-06-07 11:48 d——– C:\Program Files\Common Files\Ahead
2007-06-07 11:48 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
2007-06-07 08:26 d—s—- C:\DOCUME~1\chad1\UserData
2007-06-07 07:09 d——– C:\Program Files\ReflexiveArcade
2007-06-07 07:09 d——– C:\Program Files\Gemsweeper
2007-06-07 07:09 d——– C:\DOCUME~1\chad1\APPLIC~1\gemsweeperextractedgfx
2007-06-07 07:09 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\My Games
2007-06-07 04:15 d——– C:\DOCUME~1\chad1\APPLIC~1\vlc
2007-06-07 02:49 d——– C:\Program Files\mIRC
2007-06-07 02:37 402,944 -ra—— C:\WINDOWS\system32\drivers\BLKWGU.sys
2007-06-07 02:36 d——– C:\Program Files\Belkin
2007-06-07 02:29 d——– C:\WINDOWS\RegisteredPackages
2007-06-07 02:20 d——– C:\Program Files\VideoLAN
2007-06-07 02:19 118,784 –a—— C:\WINDOWS\system32\MSSTDFMT.DLL
2007-06-07 02:19 d——– C:\Program Files\SpywareBlaster
2007-06-07 02:18 87,608 –a—— C:\DOCUME~1\chad1\APPLIC~1\inst.exe
2007-06-07 02:18 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-06-07 02:18 47,360 –a—— C:\DOCUME~1\chad1\APPLIC~1\pcouffin.sys
2007-06-07 02:18 217,127 –a—— C:\WINDOWS\system32\drv43260.dll
2007-06-07 02:18 208,935 –a—— C:\WINDOWS\system32\drv33260.dll
2007-06-07 02:18 176,165 –a—— C:\WINDOWS\system32\drv23260.dll
2007-06-07 02:18 d——– C:\Program Files\vso
2007-06-07 02:18 d——– C:\DOCUME~1\chad1\APPLIC~1\Vso
2007-06-07 02:17 d——– C:\Program Files\videofixer
2007-06-07 02:16 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-07 02:15 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2007-06-07 02:15 62,744 –a—— C:\WINDOWS\system32\xinput1_2.dll
2007-06-07 02:15 3,426,072 –a—— C:\WINDOWS\system32\d3dx9_32.dll
2007-06-07 02:15 255,848 –a—— C:\WINDOWS\system32\xactengine2_6.dll
2007-06-07 02:15 251,672 –a—— C:\WINDOWS\system32\xactengine2_5.dll
2007-06-07 02:15 237,848 –a—— C:\WINDOWS\system32\xactengine2_4.dll
2007-06-07 02:15 236,824 –a—— C:\WINDOWS\system32\xactengine2_3.dll
2007-06-07 02:15 2,414,360 –a—— C:\WINDOWS\system32\d3dx9_31.dll
2007-06-07 02:15 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2007-06-07 02:15 15,128 –a—— C:\WINDOWS\system32\x3daudio1_1.dll
2007-06-07 02:15 d——– C:\Program Files\XviD
2007-06-07 02:15 d——– C:\Program Files\Gabest
2007-06-07 02:14 90,112 –a—— C:\WINDOWS\system32\LMISOMux.dll
2007-06-07 02:14 53,248 –a—— C:\WINDOWS\system32\ltserial.dll
2007-06-07 02:14 487,424 –a—— C:\WINDOWS\system32\LtAct14n.dll
2007-06-07 02:14 425,984 –a—— C:\WINDOWS\system32\LENCMPG4.dll
2007-06-07 02:14 405,504 –a—— C:\WINDOWS\system32\LEncMPG4Krn.dll
2007-06-07 02:14 36,734 –a—— C:\WINDOWS\system32\OggDSuninst.exe
2007-06-07 02:14 184,320 –a—— C:\WINDOWS\system32\LEncAAC.dll
2007-06-07 02:14 180,224 –a—— C:\WINDOWS\system32\DSKernel2.dll
2007-06-07 02:14 172,032 –a—— C:\WINDOWS\system32\LMOggMux.dll
2007-06-07 02:14 135,168 –a—— C:\WINDOWS\system32\ltact.dll
2007-06-07 02:14 131,072 –a—— C:\WINDOWS\system32\LMVYUVxf.dll
2007-06-07 02:14 122,880 –a—— C:\WINDOWS\system32\LEncAACKrn.dll
2007-06-07 02:14 d——– C:\Program Files\LEAD Technologies, Inc
2007-06-07 02:13 5,248 –a—— C:\WINDOWS\system32\drivers\a347scsi.sys
2007-06-07 02:13 160,640 –a—— C:\WINDOWS\system32\drivers\a347bus.sys
2007-06-07 02:13 d——– C:\WINDOWS\system32\QuickTime
2007-06-07 02:13 d——– C:\Program Files\Alcohol Soft
2007-06-07 02:13 d——– C:\Program Files\3ivx
2007-06-07 02:09 6,942 –a—— C:\WINDOWS\system32\drivers\Msikbd2k.sys
2007-06-07 02:09 28,672 –a—— C:\WINDOWS\system32\msiosd32.dll
2007-06-07 02:09 d–h—– C:\Program Files\InstallShield Installation Information
2007-06-07 02:09 d——– C:\Program Files\Netropa
2007-06-07 02:09 d——– C:\Program Files\Common Files\InstallShield
2007-06-07 02:08 286,720 –a—— C:\WINDOWS\iun506.exe
2007-06-07 02:08 d——– C:\Program Files\ResChanger XP
2007-06-07 02:05 82,944 –a—— C:\WINDOWS\system32\drivers\wdmaud.sys
2007-06-07 02:05 6,400 –a—— C:\WINDOWS\system32\drivers\splitter.sys
2007-06-07 02:04 7,552 –a—— C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-06-07 02:04 60,800 –a—— C:\WINDOWS\system32\drivers\sysaudio.sys
2007-06-07 02:04 60,288 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-06-07 02:04 54,272 –a—— C:\WINDOWS\system32\drivers\swmidi.sys


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-03-14 23:27:58 972,336 —-a-w C:\WINDOWS\UNRecode.exe
2007-03-14 23:19:56 95,864 —-a-w C:\WINDOWS\system32\NeroCo.dll
2007-03-14 23:19:26 972,336 —-a-w C:\WINDOWS\UNNeroBackItUp.exe
2007-03-12 17:51:08 972,336 —-a-w C:\WINDOWS\UNNeroMediaHome.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{272b88a1-0d6d-4a18-85d7-5e55baaa3a18}=C:\WINDOWS\system32\klroqok.dll []
{2A1A336F-30E9-43D0-68A5-34DF9BB000DD}=C:\Program Files\Windows NT\lazuqoh.dll []
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{8A61098D-612B-4EF2-943D-64E920684061}=C:\WINDOWS\system32\ddcyxwv.dll [2007-06-08 02:48]
{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E}=C:\WINDOWS\system32\WinNB58.dll []
{CE0A4C3F-F4D8-8971-DF0B-89ADDBE8289B}=C:\WINDOWS\system32\hblmlo.dll []
{DE1EBFCE-310C-4707-B0DB-FB229430226F}=C:\Program Files\MSN Gaming Zone\honew.dll []
{E12BFF69-38A7-406e-A8EF-2738107A7831}=C:\WINDOWS\system32\kamdpqaw.dll [2007-06-08 06:26]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ResChangerXP"="C:\Program Files\ResChanger XP\ResChangerXP.exe" [2002-02-14 14:33]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2000-11-29 00:10]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2006-10-07 08:20]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2007-04-12 06:58]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 13:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13]
"{8A61098D-612B-4EF2-943D-64E920684061}"="C:\WINDOWS\system32\ddcyxwv.dll" [2007-06-08 02:48]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyxwv]
ddcyxwv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rcca]
"C:\PROGRA~1\ASEMBL~1\notepad.exe" -vt ndrv

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"ERSvc"=2 (0x2)

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


Contents of the 'Scheduled Tasks' folder
2007-06-09 04:00:33 C:\WINDOWS\tasks\At1.job
2007-06-08 13:00:30 C:\WINDOWS\tasks\At10.job
2007-06-08 14:01:17 C:\WINDOWS\tasks\At11.job
2007-06-08 15:01:35 C:\WINDOWS\tasks\At12.job
2007-06-08 16:00:36 C:\WINDOWS\tasks\At13.job
2007-06-08 17:00:30 C:\WINDOWS\tasks\At14.job
2007-06-08 18:01:25 C:\WINDOWS\tasks\At15.job
2007-06-08 19:00:30 C:\WINDOWS\tasks\At16.job
2007-06-08 20:00:30 C:\WINDOWS\tasks\At17.job
2007-06-08 21:00:30 C:\WINDOWS\tasks\At18.job
2007-06-08 22:00:30 C:\WINDOWS\tasks\At19.job
2007-06-09 05:01:19 C:\WINDOWS\tasks\At2.job
2007-06-08 23:00:30 C:\WINDOWS\tasks\At20.job
2007-06-09 00:00:30 C:\WINDOWS\tasks\At21.job
2007-06-09 01:00:30 C:\WINDOWS\tasks\At22.job
2007-06-09 02:00:30 C:\WINDOWS\tasks\At23.job
2007-06-09 03:15:43 C:\WINDOWS\tasks\At24.job
2007-06-09 06:00:30 C:\WINDOWS\tasks\At3.job
2007-06-09 07:00:30 C:\WINDOWS\tasks\At4.job
2007-06-08 08:00:30 C:\WINDOWS\tasks\At5.job
2007-06-08 09:00:30 C:\WINDOWS\tasks\At6.job
2007-06-08 10:00:30 C:\WINDOWS\tasks\At7.job
2007-06-08 11:00:30 C:\WINDOWS\tasks\At8.job
2007-06-09 12:01:39 C:\WINDOWS\tasks\At9.job

**************************************************************************

catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-09 08:07:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-06-09 8:13:06 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-06-09 08:13

— E O F —








Logfile of HijackThis v1.99.1
Scan saved at 9:36:01 AM, on 6/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ResChanger XP\ResChangerXP.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O4 - HKLM\..\Run: [ResChangerXP] "C:\Program Files\ResChanger XP\ResChangerXP.exe"
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\odmlbats.dll",realset
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Rcca] "C:\PROGRA~1\ASEMBL~1\notepad.exe" -vt ndrv
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Logfile of HijackThis v1.99.1
Scan saved at 10:22:52 AM, on 6/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ResChanger XP\ResChangerXP.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {272b88a1-0d6d-4a18-85d7-5e55baaa3a18} - C:\WINDOWS\system32\klroqok.dll (file missing)
O2 - BHO: 0 - {2A1A336F-30E9-43D0-68A5-34DF9BB000DD} - C:\Program Files\Windows NT\lazuqoh.dll (file missing)
O2 - BHO: (no name) - {55C2B437-041F-4FA3-9D06-BAE536E5D48C} - C:\WINDOWS\system32\vtsqp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\ddcyxwv.dll
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
O2 - BHO: (no name) - {CE0A4C3F-F4D8-8971-DF0B-89ADDBE8289B} - C:\WINDOWS\system32\hblmlo.dll (file missing)
O2 - BHO: (no name) - {DE1EBFCE-310C-4707-B0DB-FB229430226F} - C:\Program Files\MSN Gaming Zone\honew.dll (file missing)
O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\kamdpqaw.dll
O4 - HKLM\..\Run: [ResChangerXP] "C:\Program Files\ResChanger XP\ResChangerXP.exe"
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\odmlbats.dll",realset
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Rcca] "C:\PROGRA~1\ASEMBL~1\notepad.exe" -vt ndrv
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: ddcyxwv - C:\WINDOWS\SYSTEM32\ddcyxwv.dll
O20 - Winlogon Notify: vtsqp - C:\WINDOWS\system32\vtsqp.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
It looks like you have been infected by a backdoor trojan. C:\DOCUMENTS AND SETTINGS\chad1\APPLICCATION DATA\inst.exe

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found
here

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.
If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Should you decide to clean this machine start by doing the following.



_____________________________________________________
Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\TQ0
    C:\WINDOWS\system32\T7
    C:\WINDOWS\system32\T6
    C:\WINDOWS\system32\T
    C:\DOCUMENTS AND SETTINGS\chad1\APPLICCATION DATA\inst.exe
    C:\WINDOWS\system32\pCHOH3PJ.exe
    C:\WINDOWS\MBDownloader_876916.exe
    C:\WINDOWS\jybvrwzA.exe
    C:\WINDOWS\system32\T1QaSQ
    C:\WINDOWS\system32\TQ0
    C:\WINDOWS\system32\T7
    C:\WINDOWS\system32\T6
    C:\WINDOWS\system32\T
    C:\DOCUMENTS AND SETTINGS\chad1\APPLICCATION DATA\GetRightToGo
    C:\WINDOWS\system32\scchk32.exe
    C:\WINDOWS\system32\winpfz32.sys


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\\_OTMoveIt\\MovedFiles\\********_******.log
(where "********_******" is the "date_time")





_________________________________________________

Please download VundoFix.exe to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will shutdown your computer, click OK.
Turn your computer back on.
Please post the contents of C:\\vundofix.txt and a new HiJackThis log.






______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).
____________________________________

Navigate to and just look inside this folder for me and let me know if you recognize anything in there. Please don't click on anything in there.

C:\Temp




_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer


Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.


In your next reply I would like to see:
  • A new HJT log
  • The report from Kasperskys
  • The report from Vundo
  • The report from OT MOVE IT
Logfile of HijackThis v1.99.1
Scan saved at 6:45:39 PM, on 6/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ResChanger XP\ResChangerXP.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {272b88a1-0d6d-4a18-85d7-5e55baaa3a18} - C:\WINDOWS\system32\klroqok.dll (file missing)
O2 - BHO: 0 - {2A1A336F-30E9-43D0-68A5-34DF9BB000DD} - C:\Program Files\Windows NT\lazuqoh.dll (file missing)
O2 - BHO: ofb1 - {3E1500AC-87A5-416b-A211-82E848649DA9} - C:\PROGRA~1\Ofb11\Ofb11.dll (file missing)
O2 - BHO: (no name) - {55C2B437-041F-4FA3-9D06-BAE536E5D48C} - C:\WINDOWS\system32\vtsqp.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\ddcyxwv.dll (file missing)
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\dnsersnd.dll (file missing)
O2 - BHO: (no name) - {CE0A4C3F-F4D8-8971-DF0B-89ADDBE8289B} - C:\WINDOWS\system32\hblmlo.dll (file missing)
O2 - BHO: (no name) - {DE1EBFCE-310C-4707-B0DB-FB229430226F} - C:\Program Files\MSN Gaming Zone\honew.dll (file missing)
O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\kamdpqaw.dll
O4 - HKLM\..\Run: [ResChangerXP] "C:\Program Files\ResChanger XP\ResChangerXP.exe"
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\odmlbats.dll",realset
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels32.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Rcca] "C:\PROGRA~1\ASEMBL~1\notepad.exe" -vt ndrv
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\chad1\Desktop\TICHD001.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: winhoq32 - winhoq32.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe




Tuesday, June 12, 2007 6:46:11 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 12/06/2007
Kaspersky Anti-Virus database records: 342767


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan Statistics
Total number of scanned objects 61520
Number of viruses found 32
Number of infected objects 81
Number of suspicious objects 0
Duration of the scan process 02:22:53

Infected Object Name Virus Name Last Action
C:\Documents and Settings\chad1\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\chad1\Desktop\hijackthis\backups\backup-20070608-092413-779.dll Infected: not-a-virus:AdWare.Win32.Mirar.e skipped

C:\Documents and Settings\chad1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\chad1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\chad1\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\chad1\Local Settings\History\History.IE5\MSHist012007061220070613\index.dat Object is locked skipped

C:\Documents and Settings\chad1\Local Settings\Temp\BCG8B.tmp Object is locked skipped

C:\Documents and Settings\chad1\Local Settings\Temp\BCG8C.tmp Object is locked skipped

C:\Documents and Settings\chad1\Local Settings\Temp\Compinst1.exe/data.rar/installfile1.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\Documents and Settings\chad1\Local Settings\Temp\Compinst1.exe/data.rar Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\Documents and Settings\chad1\Local Settings\Temp\Compinst1.exe RarSFX: infected - 2 skipped

C:\Documents and Settings\chad1\Local Settings\Temp\installfile2.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped

C:\Documents and Settings\chad1\Local Settings\Temp\win27.tmp Infected: Trojan-Downloader.Win32.Alphabet.gen skipped

C:\Documents and Settings\chad1\Local Settings\Temp\~DF8B79.tmp Object is locked skipped

C:\Documents and Settings\chad1\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\chad1\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\chad1\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Program Files\mIRC\download\alf-01x07-help.me.rhonda.avi Object is locked skipped

C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\368.tmp Infected: Trojan.Win32.Agent.ady skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\36C.tmp/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\36C.tmp NSIS: infected - 1 skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\36C.tmp CryptFF.b: infected - 1 skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\36D.tmp Infected: Trojan-Proxy.Win32.Xorpix.ar skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\36E.tmp Infected: Trojan-Proxy.Win32.Wopla.ag skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\36F.tmp Infected: Trojan-Downloader.Win32.Murlo.fi skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\370.tmp Infected: Trojan-Downloader.Win32.Agent.boy skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\372.tmp Infected: Trojan.Win32.Qhost.it skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\373.tmp Infected: Trojan-Downloader.Win32.Agent.bnf skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\374.tmp/stream/Script Infected: Trojan.Win32.DNSChanger.jb skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\374.tmp/stream Infected: Trojan.Win32.DNSChanger.jb skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\374.tmp NSIS: infected - 2 skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\374.tmp CryptFF.b: infected - 2 skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\3A6.tmp Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine\3A7.tmp Infected: Trojan-Spy.Win32.VBStat.h skipped

C:\QooBox\Quarantine\C\Documents and Settings\All Users\Documents\Settings\partnership.dll.vir Infected: Trojan-Proxy.Win32.Xorpix.ar skipped

C:\QooBox\Quarantine\C\Program Files\Common Files\Yazzle1281OinAdmin.exe.vir Infected: Trojan-Downloader.Win32.PurityScan.eg skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\runtime2.sys.vir Infected: Rootkit.Win32.Agent.ey skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\jkkll.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\KB96926207.exe.vir Infected: Trojan.Win32.Agent.vk skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\KB98879216.exe.vir Infected: Trojan-Downloader.Win32.Tibs.le skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\T4\amst5.exe.vir Infected: Trojan-Dropper.Win32.Agent.bfr skipped

C:\QooBox\Quarantine\catchme2007-06-09_ 80703.18.zip/kprof Infected: Trojan-Proxy.Win32.Wopla.ag skipped

C:\QooBox\Quarantine\catchme2007-06-09_ 80703.18.zip/koos.exe Infected: Trojan-Proxy.Win32.Wopla.ag skipped

C:\QooBox\Quarantine\catchme2007-06-09_ 80703.18.zip/poof Infected: Trojan-Proxy.Win32.Wopla.ag skipped

C:\QooBox\Quarantine\catchme2007-06-09_ 80703.18.zip ZIP: infected - 3 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006615.exe/data0005 Infected: Trojan-Downloader.Win32.VB.awj skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006615.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006623.exe/data.rar/installfile2.exe Infected: not-a-virus:AdWare.Win32.SaveNow.bj skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006623.exe/data.rar/Compinst1.exe/data.rar/installfile1.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006623.exe/data.rar/Compinst1.exe/data.rar Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006623.exe/data.rar/Compinst1.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006623.exe/data.rar Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006623.exe RarSFX: infected - 5 skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006624.exe/data0002 Infected: not-a-virus:AdWare.Win32.Relevant.a skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006624.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006626.dll Infected: Trojan.Win32.Agent.qt skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006628.exe Infected: Trojan-Downloader.Win32.Tibs.lf skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006629.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP11\A0006630.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP12\change.log Object is locked skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP7\A0000361.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP7\A0000361.exe RAR: infected - 1 skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004384.sys Infected: Rootkit.Win32.Agent.ey skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004455.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004456.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004457.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004458.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004465.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004466.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004467.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004517.exe/data0000.cab/is67528.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.if skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004517.exe/data0000.cab Infected: not-a-virus:AdWare.Win32.Virtumonde.if skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004517.exe Rsrc-Package: infected - 2 skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004518.exe/Stream/data0005 Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004518.exe/Stream Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004518.exe Inno: infected - 2 skipped

C:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP9\A0004520.exe Infected: not-a-virus:Server-FTP.Win32.BulletProof.231 skipped

C:\VundoFix Backups\ddcyxwv.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped

C:\VundoFix Backups\mllmm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped

C:\VundoFix Backups\odmlbats.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped

C:\VundoFix Backups\rsjoctoi.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ar skipped

C:\VundoFix Backups\urqrqop.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped

C:\VundoFix Backups\vtsqp.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped

C:\VundoFix Backups\vtustsq.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped

C:\WINDOWS\cfg32r.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped

C:\WINDOWS\cfg32s.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\stub_track3.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped

C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped

C:\WINDOWS\system32\drivers\core.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\kamdpqaw.dll Infected: Trojan.Win32.BHO.bd skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\__delete_on_reboot__c_f_g_3_2_o_._d_l_l_ Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped

D:\Programs\mIRC6.12Invision2.0.rar/mIRC6.12Invision2.0/mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.612 skipped

D:\Programs\mIRC6.12Invision2.0.rar RAR: infected - 1 skipped

D:\Programs\Nero 7.8.5.0\Nero 7.8.5.0.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped

D:\Programs\Nero 7.8.5.0\Nero 7.8.5.0.exe RAR: infected - 1 skipped

D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

D:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP12\change.log Object is locked skipped

G:\System Volume Information\_restore{7F673BA0-A195-41EB-99C7-9ADA4E2F1EB3}\RP12\change.log Object is locked skipped

Scan process completed.




VundoFix V6.4.2

Checking Java version…

Scan started at 9:03:21 PM 6/9/2007

Listing files found while scanning….

C:\WINDOWS\system32\ddcyxwv.dll
C:\WINDOWS\system32\iotcojsr.ini
C:\WINDOWS\system32\mllmm.dll
C:\WINDOWS\system32\odmlbats.dll
C:\WINDOWS\system32\pqstv.bak1
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\rsjoctoi.dll
C:\WINDOWS\system32\stablmdo.ini
C:\WINDOWS\system32\urqrqop.dll
C:\WINDOWS\system32\vtsqp.dll
C:\WINDOWS\system32\vtustsq.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ddcyxwv.dll
C:\WINDOWS\system32\ddcyxwv.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\iotcojsr.ini
C:\WINDOWS\system32\iotcojsr.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mllmm.dll
C:\WINDOWS\system32\mllmm.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\odmlbats.dll
C:\WINDOWS\system32\odmlbats.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\pqstv.bak1
C:\WINDOWS\system32\pqstv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\rsjoctoi.dll
C:\WINDOWS\system32\rsjoctoi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\stablmdo.ini
C:\WINDOWS\system32\stablmdo.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqrqop.dll
C:\WINDOWS\system32\urqrqop.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtsqp.dll
C:\WINDOWS\system32\vtsqp.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\vtustsq.dll
C:\WINDOWS\system32\vtustsq.dll Has been deleted!

Performing Repairs to the registry.
Done!


C:\WINDOWS\system32\TQ0 moved successfully.
C:\WINDOWS\system32\T7 moved successfully.
C:\WINDOWS\system32\T6 moved successfully.
File/Folder C:\WINDOWS\system32\T not found.
File/Folder C:\DOCUMENTS AND SETTINGS\chad1\APPLICCATION DATA\inst.exe not found.
C:\WINDOWS\system32\pCHOH3PJ.exe moved successfully.
C:\WINDOWS\MBDownloader_876916.exe moved successfully.
C:\WINDOWS\jybvrwzA.exe moved successfully.
C:\WINDOWS\system32\T1QaSQ moved successfully.
File/Folder C:\WINDOWS\system32\TQ0 not found.
File/Folder C:\WINDOWS\system32\T7 not found.
File/Folder C:\WINDOWS\system32\T6 not found.
File/Folder C:\WINDOWS\system32\T not found.
File/Folder C:\DOCUMENTS AND SETTINGS\chad1\APPLICCATION DATA\GetRightToGo not found.
C:\WINDOWS\system32\scchk32.exe moved successfully.
C:\WINDOWS\system32\winpfz32.sys moved successfully.

Created on 06/09/2007 20:59:33
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once the scan is complete, Right Click inside the listbox (white box) and click add more files
  • Copy&Paste the 1 entrie below into the top box
    • C:\WINDOWS\system32\kamdpqaw.dll
  • Click Add Files and Click Close Window
  • Click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\\vundofix.txt and a new HiJackThis log.



______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked




O2 - BHO: (no name) - {272b88a1-0d6d-4a18-85d7-5e55baaa3a18} - C:\WINDOWS\system32\klroqok.dll (file missing)
O2 - BHO: 0 - {2A1A336F-30E9-43D0-68A5-34DF9BB000DD} - C:\Program Files\Windows NT\lazuqoh.dll (file missing)
O2 - BHO: ofb1 - {3E1500AC-87A5-416b-A211-82E848649DA9} - C:\PROGRA~1\Ofb11\Ofb11.dll (file missing)
O2 - BHO: (no name) - {55C2B437-041F-4FA3-9D06-BAE536E5D48C} - C:\WINDOWS\system32\vtsqp.dll (file missing)
O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\ddcyxwv.dll (file missing)
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
O2 - BHO: IE Redirector - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\WINDOWS\system32\dnsersnd.dll (file missing)
O2 - BHO: (no name) - {CE0A4C3F-F4D8-8971-DF0B-89ADDBE8289B} - C:\WINDOWS\system32\hblmlo.dll (file missing)
O2 - BHO: (no name) - {DE1EBFCE-310C-4707-B0DB-FB229430226F} - C:\Program Files\MSN Gaming Zone\honew.dll (file missing)
O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\kamdpqaw.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\odmlbats.dll",realset
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernels32.exe
O4 - HKCU\..\Run: [Rcca] "C:\PROGRA~1\ASEMBL~1\notepad.exe" -vt ndrv
O4 - Startup: TA_Start.lnk = C:\Documents and Settings\chad1\Desktop\TICHD001.exe
O20 - Winlogon Notify: winhoq32 - winhoq32.dll (file missing)




_____________________________
Navigate to

C:\Documents and Settings\chad1\Local Settings\Temp

Select all and empty that folder to the recycle bin.
Do not delete the folder

________________________________

Navigate to

C:\Program Files\Trend Micro\Internet Security 2007\Quarantine

Select all and empty that folder to the recycle bin.
Do not delete the folder

__________________________________

Navigate to

C:\QooBox\Quarantine

Select all and empty that folder to the recycle bin

____________________________

Navigate to

C:\VundoFix Backups

Select all and empty that folder to the recycle bin

___________________________

navigate to

D:\Programs\Nero 7.8.5.0\Nero 7.8.5.0.exe << delete that file.. watch the cracked versions.. Their trouble.
You may want to condsider removing the program all together through add/remove programs

___________________________

navigate to and delete these file I have in bold text.


C:\WINDOWS\cfg32r.dll

C:\WINDOWS\stub_track3.exe

_____________________________________________


Empty your recycle bin

_________________________________


Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
________________________________

In your next reply I would like to see:
  • A new HJT log
  • The report from S&D fix

    Things should be improving by now
SDFix: Version 1.87

Run by [removed]
Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\chad1\Desktop\SDFix

Safe Mode:
Checking Services:

Name:
core

ImagePath:
system32\drivers\core.sys

core - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Missing SharedAccess Service

Rebooting…


Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted
C:\WINDOWS\tcb.pmw - Deleted



Removing Temp Files…

ADS Check:

Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.

Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.

Checking if ADS is attached to ntoskrnl.exe
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\DOCUME~1\\chad1\\LOCALS~1\\Temp\\win25.tmp.exe"="C:\\DOCUME~1\\chad1\\LOCALS~1\\Temp\\win25.tmp.exe:*:Enabled:win25.tmp"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————

Backups Folder: - C:\DOCUME~1\chad1\Desktop\SDFix\backups\backups.zip

Listing Files with Hidden Attributes:

C:\_OTMoveIt\MovedFiles\WINDOWS\jybvrwzA.exe
C:\NTBOOTDD.SYS
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\SAM.tmp.LOG
C:\WINDOWS\system32\config\SECURITY.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG

Listing User Accounts:

User accounts for \\CHAD

Administrator chad1 Guest
HelpAssistant SUPPORT_388945a0


Finished



Logfile of HijackThis v1.99.1
Scan saved at 11:58:09 PM, on 6/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\Program Files\ResChanger XP\ResChangerXP.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [ResChangerXP] "C:\Program Files\ResChanger XP\ResChangerXP.exe"
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\DOCUMEnts AND SETTINGS1\chad1\LOCAL SETTINGS\Temp\win25.tmp.exe

  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
  • Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes.
  • Close OTMoveIt
**If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at :
C:\\_OTMoveIt\\MovedFiles\\********_******.log
(where "********_******" is the "date_time")


___________________________________________________

What you found in add remove programs is part of the purity infection that has been mostly cleaned with combo fix.

____________________________________________________

Look in your control panels add/remove programs for any of these and uninstall them:

Oin
Yazzle by Oin
Purityscan by Oin
Snowballwars by Oin
or anything similar with Oin or Outerinfo in it.
Zolero
Tizzletalk
MediaTickets
Cowabanga
and any other programs you didn't install or don't recognize - if your not sure please ask first


Download and run this uninstaller:
http://www.outerinfo.com/OiUninstaller.exe

Tutorial for the uninstaller if needed

Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items:



_______________________________________

Now install MVPS HOSTS:

Download and unzip hosts.zip from HERE to a folder (hosts).

When you get a chance please read more about what we are doing HERE.

Here's a Tutorial on how to install it, but it's installed like this:

Open up the hosts folder and double-click on the mvps.bat file, it will rename your present HOSTS file to HOSTS.MVP, then it will copy the new HOSTS file to the correct location on your machine. It happens very quickly so don't blink!

__________________________________________________________

Post 1 more HJT log and let me know how things are running.
when i went to remove the related page it send me to d/l the uninstaller and it said i may have manually removed it but its still in my list and the outer info thing wont run.
but its seems to be running good


Logfile of HijackThis v1.99.1
Scan saved at 8:21:05 AM, on 6/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ResChanger XP\ResChangerXP.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [ResChangerXP] "C:\Program Files\ResChanger XP\ResChangerXP.exe"
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] "C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Open HJT this time click on Mics. tools /open uninstall manager.

Highlight OutterInfo
Click delete entry.

_____________________________




I see no signs of an anti virus program.. I suggest you get one in asap.
AVG antispyware is NOT an anitvirus program.
I will list 2 free anti virus programs just choose 1.

AVG FREE

Avast


__________________________________


I see no evidence of a fire wall. I suggest you get one in place now.

A few words on Microsofts firewall. It only works in one direction. Incoming.
That means if something gets by it you would never know it was trying
to contact the internet.
Example: A bad program installs itself. You would never know it was contacting the internet.
Downloading other nasties and so forth.

If you decide to run one of these you should be certain Microsofts firewall is disabled.
To disable it.

I will list a few free firewalls for you. These are good (free) firewalls:

Never run 2 firwalls together. They will interfere with each other.
So just download and install one!



Zone Alarm Easiest to use
Kerio
Sygate
Outpost







Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!


___________________________________
Run the CCleaner program once again.

___________________________________
Please create a 'clean' System Restore Point:
The reason for doing this is in case you need system restore you don't put back all we just took out.
Right click My Computer
Then Propeties then system restore
Place a check mark by turn off system restore
Click APPLY
Windows will give you a warning click yes
REBOOT

Now go right back to the same place and unchecksystem restore
Click APPLYand OK




A few things to help with possible threats

These are optional . But will help protect you further.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and keep these updated and run weekly if you don't already have them.

Adaware
Tutorial

spybot seach & destroy
Tutorial





___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.

  • Be certain windows stays updated here




___________________________________
Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you do not have to be registered to post.. just find your country room and register your complaint.
The infections you had was Vundo/Purity infection

Safe and Happy Surfing. :)
Ive heard you guys say that it is nero that maybe causing my problems. can you suggest a program that is good to burn data dvd and audio cds. thank you
I have relooked through the log. Something befiore made me thing Nero was a cracked version . By cracked I mean downoladed from the net with a key generator. Or some sort of crack that made it work without paying for it. Was it?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI