This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I'm Infected

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys

My computer has started opening IE and going to Spyware pages need help please!!!

Below is my Hijack this post.

Logfile of HijackThis v1.99.1
Scan saved at 17:14:23, on 12/06/2007
Platform: Windows 2000 SP4 (WinNT

5.00.2195)
MSIE: Internet Explorer v6.00 SP1

(6.00.2800.1106)

Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG

Anti-Spyware 7.5\guard.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\System32\svchost.exe
F:\WINNT\system32\regsvc.exe
F:\WINNT\system32\MSTask.exe
F:\WINNT\system32\stisvc.exe
F:\WINNT\System32\WBEM\WinMgmt.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\Explorer.EXE
F:\WINNT\system32\wuauclt.exe
F:\Program

Files\Java\jre1.6.0_01\bin\jusched.ex

e
F:\Program Files\Common

Files\Real\Update_OB\realsched.exe
F:\WINNT\system32\??sembly\dllhost.ex

e
F:\Documents and

Settings\andy\Desktop\hijack

this\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet

Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet

Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Local Page =
O2 - BHO: (no name) -

{57E218E6-5A80-4f0c-AB25-83598F25D7E9

} - F:\WINNT\system32\kooraluh.dll

(file missing)
O2 - BHO: SSVHelper Class -

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43

} - F:\Program

Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) -

{7F5FFCB8-4838-43CD-80EA-A7EC9C744281

} - F:\WINNT\system32\rqromnn.dll

(file missing)
O2 - BHO: (no name) -

{8A61098D-612B-4EF2-943D-64E920684061

} - F:\WINNT\system32\pmnonkl.dll
O2 - BHO: (no name) -

{8FF0D061-045C-4014-B375-C576E48A5D27

} - F:\WINNT\system32\xxyxw.dll (file

missing)
O2 - BHO: (no name) -

{900F4B18-F6A4-EF5A-D90E-8AADAFE373B4

} - F:\WINNT\system32\whnyunu.dll
O3 - Toolbar: &Radio -

{8E718888-423F-11D2-876E-00A0C9082467

} - F:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck]

F:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run:

[SunJavaUpdateSched] "F:\Program

Files\Java\jre1.6.0_01\bin\jusched.ex

e"
O4 - HKLM\..\Run: [TkBellExe]

"F:\Program Files\Common

Files\Real\Update_OB\realsched.exe"

-osboot
O4 - HKCU\..\Run: [Ndro]

"F:\WINNT\CROSOF~1\fast.exe" -vt yazb
O4 - HKCU\..\Run: [Qqknd]

F:\WINNT\system32\??sembly\dllhost.ex

e
O4 - Global Startup: Adobe Gamma

Loader.lnk = F:\Program Files\Common

Files\Adobe\Calibration\Adobe Gamma

Loader.exe
O8 - Extra context menu item: Convert

for CLIÉ - F:\Program

Files\Sony\Image Converter\menu.htm
O8 - Extra context menu item: E&xport

to Microsoft Excel -

res://F:\PROGRA~1\MICROS~3\OFFICE11\E

XCEL.EXE/3000
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501

} - F:\Program

Files\Java\jre1.6.0_01\bin\npjpi160_0

1.dll
O9 - Extra 'Tools' menuitem: Sun Java

Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501

} - F:\Program

Files\Java\jre1.6.0_01\bin\npjpi160_0

1.dll
O15 - Trusted Zone:

*.registration.sonystyle-europe.com

(HKLM)
O16 - DPF:

{17492023-C23A-453E-A040-C7C580BBF700

} (Windows Genuine Advantage

Validation Tool) -

http://go.microsoft.com/fwlink/?linki

d=39204
O16 - DPF:

{6414512B-B978-451D-A0D8-FCFDF33E833C

} (WUWebControl Class) -

http://update.microsoft.com/windowsup

date/v6/V5Controls/en/x86/client/wuwe

b_site.cab?1150718231732
O16 - DPF:

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3

} (MUWebControl Class) -

http://update.microsoft.com/microsoft

update/v6/V5Controls/en/x86/client/mu

web_site.cab?1150718337614
O20 - Winlogon Notify: pmnonkl -

F:\WINNT\SYSTEM32\pmnonkl.dll
O20 - Winlogon Notify: rqromnn -

rqromnn.dll (file missing)
O20 - Winlogon Notify: winwrk32 -

F:\WINNT\SYSTEM32\winwrk32.dll
O20 - Winlogon Notify: xxyxw -

F:\WINNT\system32\xxyxw.dll (file

missing)
O23 - Service: Ati HotKey Poller -

Unknown owner -

F:\WINNT\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard

- Anti-Malware Development a.s. -

F:\Program Files\Grisoft\AVG

Anti-Spyware 7.5\guard.exe
O23 - Service: Logical Disk Manager

Administrative Service (dmadmin) -

VERITAS Software Corp. -

F:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table

Manager (IDriverT) - Macrovision

Corporation - F:\Program Files\Common

Files\InstallShield\Driver\11\Intel

32\IDriverT.exe
O23 - Service: iPodService - Apple

Computer, Inc. - F:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP

- F:\WINNT\system32\HPZipm12.exe
Hi and welcome to the forums. :) I'm Markka and I will be helping you with your malware issues. I'll check your HijackThis log. Right now I'm MRU Undergrad, everything that I post to you must be checked by teachers of Malware Removal University. Please be patient. :)
Hello :)

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

****************************************************

Open notepad -> Edit -> Un-check; WordWrap.

Post:
- A fresh HijackThis log
- Contents of C:\ComboFix.txt
as instructed… combofix log first

ComboFix 07-06-13.3 - F:\Documents and Settings\andy\Desktop\hijack this\ComboFix.exe
"andy" - 13/06/2007 14:55:13 - Service Pack 4 NTFS


(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


F:\WINNT\system32\iifcb.dll
F:\WINNT\system32\kqvdkont.dll
F:\WINNT\system32\opnfslpg.dll
F:\WINNT\system32\wdkcfhgd.dll
F:\WINNT\system32\wgoiryoi.dll
F:\WINNT\system32\winwrk32.dll
F:\WINNT\system32\bcfii.ini
F:\WINNT\system32\npoqr.bak1
F:\WINNT\system32\npoqr.ini
F:\WINNT\system32\dghfckdw.ini
F:\WINNT\system32\npoqr.bak1
F:\WINNT\system32\npoqr.ini
F:\WINNT\system32\rqopn.dll
F:\WINNT\system32\pmnonkl.dll


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


F:\DOCUME~1\ANDYBA~1\APPLIC~1\netmon
F:\DOCUME~1\ANDYBA~1\APPLIC~1\netmon\domains.txt
F:\DOCUME~1\ANDYBA~1\APPLIC~1\netmon\log.txt
F:\DOCUME~1\DEFAUL~1\APPLIC~1\netmon
F:\DOCUME~1\DEFAUL~1\APPLIC~1\netmon\domains.txt
F:\DOCUME~1\DEFAUL~1\APPLIC~1\netmon\log.txt
F:\DOCUME~1\SYSTEM\APPLIC~1\netmon
F:\DOCUME~1\SYSTEM\APPLIC~1\netmon\domains.txt
F:\DOCUME~1\SYSTEM\APPLIC~1\netmon\log.txt
F:\Program Files\Common Files\microsoft shared\web folders\ibm00001.dll
F:\Program Files\Common Files\microsoft shared\web folders\ibm00002.dll
F:\Program Files\outerinfo
F:\Program Files\outerinfo\Terms.rtf
F:\WINNT\crosof~1
F:\WINNT\crosof~1\fast.exe~
F:\WINNT\retadpu1000272.exe
F:\WINNT\svchost.exe
F:\WINNT\system32\max1d1641.exe
F:\WINNT\system32\sembly~1
F:\WINNT\system32\sembly~1\dllhost.exe
F:\WINNT\system32\xpdx.sys
F:\WINNT\wr.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_LDRSVC
——-\LEGACY_NETWORK_MONITOR
——-\xpdx


((((((((((((((((((((((((( Files Created from 2007-05-13 to 2007-06-13 )))))))))))))))))))))))))))))))


2007-06-13 14:54 49,152 –a—— F:\WINNT\nircmd.exe
2007-06-12 18:22 2,580 –a—— F:\WINNT\system32\hnxtqstx.exe
2007-06-11 03:57 30,720 –a—— F:\WINNT\system32\ipmon.exe
2007-06-11 03:56 60,928 –a—— F:\WINNT\system32\whnyunu.dll
2007-06-11 03:56 2 –a—— F:\WINNT\system32\wcpicomsv.exe
2007-06-11 03:55 93,696 –a—— F:\WINNT\system32\drvnec.dll
2007-06-08 01:57 d——– F:\Program Files\WinUndelete
2007-06-08 01:55 d——– F:\Andy Install2
2007-06-05 12:18 d——– F:\Program Files\Common Files\xing shared
2007-06-05 12:06 d——– F:\DOCUME~1\andy\APPLIC~1\DivX
2007-05-31 04:49 36,624 ——— F:\WINNT\system32\drivers\PxHelp20.sys
2007-05-31 04:49 129,784 –a—— F:\WINNT\system32\pxafs.dll
2007-05-31 04:49 118,520 –a—— F:\WINNT\system32\pxinsi64.exe
2007-05-31 04:49 116,472 –a—— F:\WINNT\system32\pxcpyi64.exe
2007-05-23 18:53 d-a—— F:\WINNT\system32\SoftwareDistribution


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-06-12 16:01:37 ——– d—a-w F:\Program Files\Google
2007-06-08 06:04:33 ——– d—–w F:\Program Files\Sony Handheld
2007-06-05 11:18:43 ——– d—a-w F:\Program Files\Common Files\Real
2007-06-03 21:16:24 ——– d—–w F:\DOCUME~1\andy\APPLIC~1\dvdcss
2007-05-31 03:49:50 ——– d—a-w F:\Program Files\DivX
2007-05-11 17:54:15 524,288 —-a-w F:\WINNT\system32\DivXsm.exe
2007-05-11 04:37:15 823,296 —-a-w F:\WINNT\system32\divx_xx0c.dll
2007-05-11 04:37:15 823,296 —-a-w F:\WINNT\system32\divx_xx07.dll
2007-05-11 04:37:15 802,816 —-a-w F:\WINNT\system32\divx_xx11.dll
2007-05-11 04:37:15 740,442 —-a-w F:\WINNT\system32\DivX.dll
2007-04-23 00:15:29 3,596,288 —-a-w F:\WINNT\system32\qt-dx331.dll
2007-04-23 00:15:25 2,560 ——w F:\WINNT\system32\drivers\cdralw2k.sys
2007-04-23 00:15:24 2,432 ——w F:\WINNT\system32\drivers\cdr4_2K.sys
2007-04-23 00:15:18 200,704 —-a-w F:\WINNT\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 —-a-w F:\WINNT\system32\libdivx.dll
2007-04-23 00:02:34 73,728 —-a-w F:\WINNT\system32\dpl100.dll
2007-04-23 00:02:34 196,608 —-a-w F:\WINNT\system32\dtu100.dll
2007-04-23 00:02:33 53,248 —-a-w F:\WINNT\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 —-a-w F:\WINNT\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 —-a-w F:\WINNT\system32\dpv11.dll
2007-04-23 00:02:31 344,064 —-a-w F:\WINNT\system32\dpus11.dll
2007-04-23 00:02:31 294,912 —-a-w F:\WINNT\system32\dpu11.dll
2007-04-23 00:02:31 294,912 —-a-w F:\WINNT\system32\dpu10.dll
2007-04-23 00:01:47 12,288 —-a-w F:\WINNT\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 —-a-w F:\WINNT\system32\DivXCodecUpdateChecker.exe
2007-04-18 16:54:11 ——– d—a-w F:\Program Files\Motorola Phone Tools
2007-04-16 23:14:27 ——– d—–w F:\Program Files\Motorola
2007-04-16 23:14:27 ——– d—–w F:\Program Files\Common Files\MSSoap
2007-04-16 23:14:27 ——– d—–w F:\Program Files\Common Files\Motorola Shared
2007-04-16 21:47:36 33,624 —-a-w F:\WINNT\system32\wups.dll
2007-04-16 21:45:54 1,710,936 —-a-w F:\WINNT\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 —-a-w F:\WINNT\system32\wuapi.dll
2007-04-16 21:45:42 325,976 —-a-w F:\WINNT\system32\wucltui.dll
2007-04-16 21:45:36 203,096 —-a-w F:\WINNT\system32\wuweb.dll
2007-04-16 21:45:28 92,504 —-a-w F:\WINNT\system32\cdm.dll
2007-04-16 21:45:20 53,080 —-a-w F:\WINNT\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 —-a-w F:\WINNT\system32\wups2.dll
2007-04-16 21:44:20 271,224 —-a-w F:\WINNT\system32\mucltui.dll
2007-04-16 21:44:18 208,248 —-a-w F:\WINNT\system32\muweb.dll
2007-04-16 14:19:16 ——– d—a-w F:\Program Files\Avanquest update
2007-04-16 14:19:07 ——– d—–w F:\DOCUME~1\andy\APPLIC~1\InstallShield
2007-04-13 01:25:34 ——– d—a-w F:\Program Files\Microsoft AutoRoute
2007-04-10 17:06:38 798,898 –sha-w F:\WINNT\system32\wxyxx.bak2
2007-04-08 23:30:46 797,499 –sha-w F:\WINNT\system32\wxyxx.bak1


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=F:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [07-03-14 03:43 ]
{8FF0D061-045C-4014-B375-C576E48A5D27}=F:\WINNT\system32\xxyxw.dll []
{900F4B18-F6A4-EF5A-D90E-8AADAFE373B4}=F:\WINNT\system32\whnyunu.dll [07-05-21 14:59 ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="F:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [07-03-14 03:43 ]
"TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [07-06-05 12:17 ]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"Ndro"="F:\WINNT\CROSOF~1\fast.exe" []

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=F:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"internat.exe"=internat.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoColorChoice"=0 (0x0)
"NoSizeChoice"=0 (0x0)
"NoDispScrSavPage"=0 (0x0)
"NoDispCPL"=0 (0x0)
"NoVisualStyleChoice"=0 (0x0)
"NoDispSettingsPage"=0 (0x0)
"NoDispAppearancePage"=0 (0x0)
"NoDispBackgroundPage"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSaveSettings"=0 (0x0)
"NoThemesTab"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{40847941-2F5E-4BEB-802C-74849B8BA2E4}"="F:\WINNT\system32\ahdp.dll" []
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [06-09-28 15:13 ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqromnn]
rqromnn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyxw]
F:\WINNT\system32\xxyxw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=F:\WINNT\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=F:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=F:\WINNT\pss\HotSync Manager.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"F:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
F:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
F:\WINNT\system32\hphmon05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
F:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"F:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"F:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
NtmlSvc

*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS

Contents of the 'Scheduled Tasks' folder
2007-06-13 10:51:00 F:\WINNT\tasks\HP Usg Daily.job
2007-06-13 05:00:00 F:\WINNT\tasks\MP Scheduled Scan.job
2007-06-13 14:09:22 F:\WINNT\tasks\RegCure Program Check.job
2007-06-07 02:01:04 F:\WINNT\tasks\RegCure.job

**************************************************************************

catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-13 15:08:36
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

F:\WINNT\Windows Update Setup Files
F:\WINNT\Windows Update.log
F:\WINNT\WindowsUpdate.log
F:\WINNT\winhelp.exe
F:\WINNT\winhlp32.exe
F:\WINNT\WinInit.INI
F:\WINNT\winnt.bmp
F:\WINNT\winnt256.bmp
F:\WINNT\WINNT32.LOG
F:\WINNT\winrep.exe
F:\WINNT\winsxs
F:\WINNT\wmsetup.log
F:\WINNT\WMSysPr9.prx
F:\WINNT\WMSysPrx.prx
F:\WINNT\Zapotec.bmp
F:\WINNT\_default.pif
F:\WINNT\**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\regsvc]
"ImagePath"="C:\Program Files\Internet Explorer\SIGNUP\Service.exe /name:\"regsvc\" /start:\"C:\program files\internet explorer\SIGNUP\system\spoolers.exe\""

Completion time: 2007-06-13 15:10:26 - machine was rebooted
F:\ComboFix-quarantined-files.txt … 07-06-13 15:09

— E O F —

Logfile of HijackThis v1.99.1
Scan saved at 15:29:40, on 13/06/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\System32\svchost.exe
F:\WINNT\system32\regsvc.exe
F:\WINNT\system32\MSTask.exe
F:\WINNT\system32\stisvc.exe
F:\WINNT\System32\WBEM\WinMgmt.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\Explorer.EXE
F:\WINNT\system32\wuauclt.exe
F:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\WINNT\system32\notepad.exe
F:\Documents and Settings\andy\Desktop\hijack this\HiJackThis_v2.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\andy\Desktop\hijack this\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {8FF0D061-045C-4014-B375-C576E48A5D27} - F:\WINNT\system32\xxyxw.dll (file missing)
O2 - BHO: (no name) - {900F4B18-F6A4-EF5A-D90E-8AADAFE373B4} - F:\WINNT\system32\whnyunu.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Ndro] "F:\WINNT\CROSOF~1\fast.exe" -vt ndrv
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert for CLIÉ - F:\Program Files\Sony\Image Converter\menu.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O15 - Trusted Zone: *.registration.sonystyle-europe.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150718231732
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1150718337614
O20 - Winlogon Notify: rqromnn - rqromnn.dll (file missing)
O20 - Winlogon Notify: xxyxw - F:\WINNT\system32\xxyxw.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - F:\WINNT\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - F:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINNT\system32\HPZipm12.exe
Hello :) You have a backdoor on your machine, but don't worry we will get you cleaned up. When you're clean, then change all online passwords

You don't have a firewall on your computer. Here are free and good firewalls: (Install only one)

Comodo
OutPost
Kerio
Sygate
ZoneAlarm

******************************************************************

Open HijackThis, Click Do a system scan only, checkmark these. Then close all others windows except HijackThis and press fix checked.

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {8FF0D061-045C-4014-B375-C576E48A5D27} - F:\WINNT\system32\xxyxw.dll (file missing)
O2 - BHO: (no name) - {900F4B18-F6A4-EF5A-D90E-8AADAFE373B4} - F:\WINNT\system32\whnyunu.dll
O4 - HKCU\..\Run: [Ndro] "F:\WINNT\CROSOF~1\fast.exe" -vt ndrv
O15 - Trusted Zone: *.registration.sonystyle-europe.com (HKLM)
O20 - Winlogon Notify: rqromnn - rqromnn.dll (file missing)
O20 - Winlogon Notify: xxyxw - F:\WINNT\system32\xxyxw.dll (file missing)


******************************************************************
Make your hidden files visible:
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
******************************************************************
Delete these files: Using Windows Explorer (Windows Key + E)
F:\WINNT\system32\whnyunu.dll
F:\WINNT\system32\hnxtqstx.exe
F:\WINNT\system32\ipmon.exe
F:\WINNT\system32\wcpicomsv.exe
F:\WINNT\system32\drvnec.dll
F:\WINNT\system32\wxyxx.bak2
F:\WINNT\winrep.exe
F:\WINNT\system32\wxyxx.bak1

Delete this folder: Using Windows Explorer (Windows Key + E)
F:\WINNT\CROSOF~1
******************************************************************
Please download ATF-cleaner and save it to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

    If you use Firefox browser:

  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser:

  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
  • Click Exit on the Main menu to close the program.
******************************************************************

Kaspersky online scanner works only with Internet Explorer!

Please run an online scanner with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:

    o Scan using the following Anti-Virus database:

    + Extended (If available otherwise Standard)

    o Scan Options:

    + Scan Archives
    + Scan Mail Bases

  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

******************************************************************

Post:
- A fresh HijackThis log
- Kaspersky's report
Hi Dude
Thanks for everything so far.

Had one or two errs… in the delete files section couldnt find
F:\winnt\system32\whnyunu.dll
F:\winnt\CROSOF~1

also didnt do the Kaspersky online thing.. didnt wanna run IE…

if you need me to I will so let me know.

Conman



Logfile of HijackThis v1.99.1
Scan saved at 20:53:19, on 17/06/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\system32\spoolsv.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\System32\svchost.exe
F:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
F:\WINNT\system32\regsvc.exe
F:\WINNT\system32\MSTask.exe
F:\WINNT\system32\stisvc.exe
F:\WINNT\System32\WBEM\WinMgmt.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\Explorer.EXE
F:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\WINNT\system32\wuauclt.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\andy\Desktop\hijack this\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Outpost Firewall] "F:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe" /waitservice
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Convert for CLIÉ - F:\Program Files\Sony\Image Converter\menu.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O15 - Trusted Zone: *.registration.sonystyle-europe.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1150718231732
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1150718337614
O23 - Service: Ati HotKey Poller - Unknown owner - F:\WINNT\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - F:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - F:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINNT\system32\HPZipm12.exe
As requested here is Kasperskys report… and I'm keeping the scan report page open.. awaiting your reply. conman ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Tuesday, June 19, 2007 4:43:49 AM Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 19/06/2007 Kaspersky Anti-Virus database records: 348611 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ E:\ F:\ Scan Statistics: Total number of scanned objects: 46083 Number of viruses found: 22 Number of infected objects: 28 Number of suspicious objects: 0 Duration of the scan process: 03:23:35 Infected Object Name / Virus Name / Last Action C:\Andy Install NU\DirectX\Nero 6.06 Ultra Edition and Keygen\keygen.exe Infected: not-a-virus:AdWare.Win32.WinAD.bt skipped C:\Andy Install NU\Nero 6.06 Ultra Edition and Keygen\keygen.exe Infected: not-a-virus:AdWare.Win32.WinAD.bt skipped C:\wyjgsa.exe Infected: Trojan-Downloader.Win32.Tiny.ha skipped C:\llmbv.exe Infected: Trojan-Downloader.Win32.Small.cwj skipped C:\bsgvjmep.exe Infected: Trojan-Clicker.Win32.Agent.is skipped C:\Program Files\Internet Explorer\SIGNUP\site\ntmgmt.exe Infected: not-a-virus:RiskTool.Win32.HideRun skipped F:\3.tmp Infected: Trojan-Clicker.Win32.Costrat.ax skipped F:\Documents and Settings\andy\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\cert8.db Object is locked skipped F:\Documents and Settings\andy\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\history.dat Object is locked skipped F:\Documents and Settings\andy\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\key3.db Object is locked skipped F:\Documents and Settings\andy\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\parent.lock Object is locked skipped F:\Documents and Settings\andy\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\search.sqlite Object is locked skipped F:\Documents and Settings\andy\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\urlclassifier2.sqlite Object is locked skipped F:\Documents and Settings\andy\Application Data\Opera\Opera\profile\cache4\opr001P8.swf Infected: not-virus:Hoax.SWF.Alerter.a skipped F:\Documents and Settings\andy\Cookies\index.dat Object is locked skipped F:\Documents and Settings\andy\Desktop\hijack this\backups\backup-20070617-194003-671.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped F:\Documents and Settings\andy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped F:\Documents and Settings\andy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped F:\Documents and Settings\andy\Local Settings\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\Cache\_CACHE_001_ Object is locked skipped F:\Documents and Settings\andy\Local Settings\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\Cache\_CACHE_002_ Object is locked skipped F:\Documents and Settings\andy\Local Settings\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\Cache\_CACHE_003_ Object is locked skipped F:\Documents and Settings\andy\Local Settings\Application Data\Mozilla\Firefox\Profiles\i8r0j0dl.default\Cache\_CACHE_MAP_ Object is locked skipped F:\Documents and Settings\andy\Local Settings\History\History.IE5\index.dat Object is locked skipped F:\Documents and Settings\andy\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped F:\Documents and Settings\andy\NTUSER.DAT Object is locked skipped F:\Documents and Settings\andy\ntuser.dat.LOG Object is locked skipped F:\QooBox\Quarantine\catchme2007-06-13_150833.66.zip/xpdx.sys Infected: Trojan-Clicker.Win32.Costrat.ax skipped F:\QooBox\Quarantine\catchme2007-06-13_150833.66.zip ZIP: infected - 1 skipped F:\QooBox\Quarantine\F\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll.vir Infected: Trojan-PSW.Win32.Sinowal.m skipped F:\QooBox\Quarantine\F\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll.vir Infected: Trojan-PSW.Win32.Sinowal.m skipped F:\QooBox\Quarantine\F\WINNT\CROSOF~1\fast.exe~.vir Infected: Trojan-Downloader.Win32.PurityScan.ej skipped F:\QooBox\Quarantine\F\WINNT\retadpu1000272.exe.vir Infected: Trojan-Downloader.Win32.Agent.bls skipped F:\QooBox\Quarantine\F\WINNT\svchost.exe.vir Infected: Trojan-Spy.Win32.Agent.or skipped F:\QooBox\Quarantine\F\WINNT\system32\iifcb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped F:\QooBox\Quarantine\F\WINNT\system32\kqvdkont.dll.vir Infected: Trojan-Spy.Win32.VBStat.h skipped F:\QooBox\Quarantine\F\WINNT\system32\max1d1641.exe.vir Infected: not-a-virus:Porn-Dialer.Win32.GBDialer.j skipped F:\QooBox\Quarantine\F\WINNT\system32\opnfslpg.dll.vir Infected: Trojan-Spy.Win32.VBStat.h skipped F:\QooBox\Quarantine\F\WINNT\system32\pmnonkl.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped F:\QooBox\Quarantine\F\WINNT\system32\rqopn.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped F:\QooBox\Quarantine\F\WINNT\system32\SEMBLY~1\dllhost.exe.vir Infected: not-a-virus:AdWare.Win32.PurityScan.fn skipped F:\QooBox\Quarantine\F\WINNT\system32\wdkcfhgd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.ki skipped F:\QooBox\Quarantine\F\WINNT\system32\wgoiryoi.dll.vir Infected: Trojan.Win32.BHO.bd skipped F:\QooBox\Quarantine\F\WINNT\system32\winwrk32.dll.vir Infected: Trojan.Win32.Dialer.qn skipped F:\WINNT\Debug\ipsecpa.log Object is locked skipped F:\WINNT\Debug\oakley.log Object is locked skipped F:\WINNT\Debug\PASSWD.LOG Object is locked skipped F:\WINNT\SchedLgU.Txt Object is locked skipped F:\WINNT\security\logs\scepol.log Object is locked skipped F:\WINNT\smanager.7.exe~ Infected: Trojan-Downloader.Win32.Alphabet.gen skipped F:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped F:\WINNT\Sti_Trace.log Object is locked skipped F:\WINNT\system32\config\AppEvent.Evt Object is locked skipped F:\WINNT\system32\config\default Object is locked skipped F:\WINNT\system32\config\default.LOG Object is locked skipped F:\WINNT\system32\config\SAM Object is locked skipped F:\WINNT\system32\config\SAM.LOG Object is locked skipped F:\WINNT\system32\config\SecEvent.Evt Object is locked skipped F:\WINNT\system32\config\SECURITY Object is locked skipped F:\WINNT\system32\config\SECURITY.LOG Object is locked skipped F:\WINNT\system32\config\software Object is locked skipped F:\WINNT\system32\config\software.LOG Object is locked skipped F:\WINNT\system32\config\SysEvent.Evt Object is locked skipped F:\WINNT\system32\config\system Object is locked skipped F:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped F:\WINNT\system32\i Infected: Trojan-Downloader.BAT.Ftp.ab skipped F:\WINNT\WindowsUpdate.log Object is locked skipped Scan process completed.
Hello :)

One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
______________________________________________

Looking over your log, it seems you don't have any evidence of an anti-virus software.

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Detects and removes more than 50,000 viruses. Free support.
2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.

It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts.

________________________________________________

Delete these files: (Using Windows Explorer; Windows key + E)

C:\wyjgsa.exe
C:\llmbv.exe
C:\bsgvjmep.exe
C:\Program Files\Internet Explorer\SIGNUP\site\ntmgmt.exe
F:\WINNT\smanager.7.exec
F:\3.tmp


Delete this folder: (Using Windows Explorer; Windows key + E)
F:\QooBox
F:\WINNT\system32\i
C:\Andy Install NU\DirectX\Nero 6.06 Ultra Edition and Keygen
________________________________________

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!

Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
  • Click on the "Options" icon at the left side of the window, then click on "Advanced."
    deselect "Only delete files in Windows Temp folders older than 48 hours."
  • Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
  • Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
  • After CCleaner has completed its process, click Exit.
__________________________________________

Re-run with Kaspersky online scanner!

Post:
- A fresh HijackThis log
- Kaspersky's report
Your post has been Moved, Closed or Edited for one of the following reasons:

1.) You posted multiple topics and only one is required

2.) You are spamming links to other places without approval

3.) You have posted your hijackthis log to the wrong forum:
( http://forums.tomcoyote.org/index.php?showforum=27 ) <— correct forum for HijackThis Logs

4.) Abusive language or other problems in your text

5.) Your log is too old (20 days or more) and no replies from you after a volunteer tried to help you

If you came here for help, and you have not posted a Hijackthis log to the proper forum, then you may do so now, if you came here to spam or abuse, you will be dealt with harsher on your next offense

This is a family oriented forum to help those that need help.

==============================


Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI