This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Poppups And A Bad Virus

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This computer experiences lots of popups for WinAntivirus. I also have no access to the "Control Panel" or "Add/Remove Programs". It is as if the Administrator account is no longer an administrator.

Any help greatly appreciated.

Thanks for the responses before. I am still having big issues with popups and I cannot access the control panel or add/remove programs even as the local administrator.

Below is the programs list requested and the new HJT scan log with hijack this renamed to Hello.exe

PROGRAM LIST:

Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 9 ActiveX
Adobe Reader 6.0.1
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
Banctec Service Agreement
ClienTrak
CSTextControl Update
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Dell Media Experience
Dell Support 5.0.0 (630)
EarthLink Setup Files
Enhanced Ads by Think-Adz removal
Get High Speed Internet!
Hijackthis 1.99.1
HijackThis 1.99.1
HP Customer Participation Program 7.0
HP Imaging Device Functions 7.0
HP Photosmart and Deskjet 7.0 Software
HP Photosmart Essential
HP Software Update
HP Solution Center 7.0
Intel® 537EP V9x DF PCI Modem
Intel® Extreme Graphics 2 Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet for Wired Connections
Internet Explorer Default Page
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
LiveUpdate 2.5 (Symantec Corporation)
Macromedia Shockwave Player
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Office 2000 Premium
Modem Event Monitor
Modem Helper
Modem On Hold
Mozilla Firefox (1.5.0.12)
MSN
MUSICMATCH® Jukebox
NetZeroInstallers
Norton WMI Update
Outerinfo
Panda ActiveScan
Panda Antivirus + Firewall 2008
PowerDVD 5.1
QuickBooks Pro 2002
QuickTime
RealPlayer Basic
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Spybot - Search & Destroy 1.4
Think-Adz Search Assistant removal
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
UPS WorldShip® (US Origin)
Viewpoint Media Player
Web Buying
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WordPerfect Office 12
Yahoo! Toolbar

___________________________________

HJT LOG RENAMED TO HELLO.EXE

Logfile of HijackThis v1.99.1
Scan saved at 3:23:57 AM, on 9/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\WebProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hijackthis\hello.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\avciman.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\psimreal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
O2 - BHO: (no name) - {85113B1D-B84D-4945-AC5B-943E72D6C435} - C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll
O2 - BHO: (no name) - {d6b7adad-2742-49cf-885c-7c18fcc705a7} - C:\WINDOWS\system32\mqxhlig.dll
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [spoolsys] C:\WINDOWS\system32\dirservice.exe
O4 - HKLM\..\Run: [cryptspoolx] C:\WINDOWS\system32\datarun.exe %srun%
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\ubybmvjr.dll",forkonce
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: autorun.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks 2002 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\qbdagent2002.exe
O4 - Global Startup: UPS OnLine PLD Reminder Utility.lnk = C:\UPS\UOWS\PldReminder.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097894359988
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132094679895
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE467829-2ECC-493F-B08A-1D4264E07975}: NameServer = 167.206.3.136,216.41.101.15
O20 - AppInit_DLLs: C:\WINDOWS\system32\systems.txt
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: awtqp - C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: opnnkih - opnnkih.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\qlupfaxa.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

An unexpected error has occurred at procedure: modMain_CheckOther1Item()
Error #75 - Path/File access error

Please email me at [removed], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.2180
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.
Hello chigins,

Please download this file - combofix.exe by sUBs
  • Save it to your Desktop
  • Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    "%userprofile%\desktop\ComboFix.exe" /KillAll


  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Combo fix didn't give me the option of taking a log. The computer shut down when it was done. here is teh new HJT log.

Thanks again

Logfile of HijackThis v1.99.1
Scan saved at 20:17, on 2007-09-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\WebProxy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\hello.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\psimreal.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\avciman.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AvTask.exe

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
O2 - BHO: (no name) - {DCAFB458-162F-400D-9581-D25DB78F888C} - C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [spoolsys] C:\WINDOWS\system32\dirservice.exe
O4 - HKLM\..\Run: [cryptspoolx] C:\WINDOWS\system32\datarun.exe %srun%
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\ubybmvjr.dll",forkonce
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: system.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: UPS OnLine PLD Reminder Utility.lnk = C:\UPS\UOWS\PldReminder.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097894359988
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132094679895
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE467829-2ECC-493F-B08A-1D4264E07975}: NameServer = 167.206.3.136,167.206.3.202
O20 - AppInit_DLLs: C:\WINDOWS\system32\systems.txt
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: awtqp - C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: opnnkih - opnnkih.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello chigins,

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.
Below is the Vudofix Log and a new HJT Log. Thanks :thumbup:


VundoFix V6.5.8

Checking Java version…

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Scan started at 06:27:45 2007-09-14

Listing files found while scanning….

C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.bak1
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.bak2
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.ini
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.ini2
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.tmp
C:\windows\system32\aalrofhd.dll
C:\windows\system32\cyjiyhwu.dll
C:\windows\system32\dhforlaa.ini
C:\WINDOWS\system32\dtvhprwa.dll
C:\windows\system32\ebbiyfdl.dll
C:\windows\system32\eegqqbpl.dll
C:\windows\system32\ejgvqhvs.ini
C:\windows\system32\eqrbgwwy.dll
C:\windows\system32\ewiupwhq.dll
C:\windows\system32\ftnlylmn.ini
C:\windows\system32\gcgafiij.ini
C:\windows\system32\gisltoly.dll
C:\windows\system32\gjiivbjk.dll
C:\windows\system32\hcxmbkcp.dll
C:\windows\system32\hrvothil.ini
C:\windows\system32\humnkhxo.ini
C:\WINDOWS\system32\husmweei.ini
C:\windows\system32\idnqksqf.dll
C:\WINDOWS\system32\ieewmsuh.dll
C:\windows\system32\jiifagcg.dll
C:\windows\system32\jqvubqjp.dll
C:\windows\system32\jwrhgbdt.dll
C:\windows\system32\kjbviijg.ini
C:\windows\system32\ldfyibbe.ini
C:\windows\system32\lihtovrh.dll
C:\windows\system32\lpbqqgee.ini
C:\windows\system32\mgvpovts.ini
C:\windows\system32\msklnerx.dll
C:\windows\system32\ngerymjv.ini
C:\windows\system32\nmlylntf.dll
C:\windows\system32\nvvkiigw.ini
C:\windows\system32\oiucrsvp.dll
C:\windows\system32\olahexbq.dll
C:\windows\system32\oqkanbps.dll
C:\windows\system32\ostlpsvi.dll
C:\windows\system32\oxhknmuh.dll
C:\windows\system32\pckbmxch.ini
C:\windows\system32\pjqbuvqj.ini
C:\windows\system32\pvsrcuio.ini
C:\windows\system32\qbxehalo.ini
C:\windows\system32\rjvmbybu.ini
C:\windows\system32\spbnakqo.ini
C:\windows\system32\stvopvgm.dll
C:\windows\system32\svhqvgje.dll
C:\windows\system32\tdbghrwj.ini
C:\windows\system32\tyrotouv.ini
C:\windows\system32\ubybmvjr.dll
C:\windows\system32\ugalcxpy.dll
C:\windows\system32\unwxlfux.dll
C:\windows\system32\uwhyijyc.ini
C:\windows\system32\vjmyregn.dll
C:\windows\system32\vuotoryt.dll
C:\windows\system32\wgiikvvn.dll
C:\windows\system32\wnkdvimu.dll
C:\windows\system32\wpojhrhn.dll
C:\windows\system32\wwcqgvyy.ini
C:\windows\system32\xjrtqeld.dll
C:\windows\system32\xuflxwnu.ini
C:\windows\system32\ypxclagu.ini
C:\windows\system32\ywwgbrqe.ini
C:\windows\system32\yyvgqcww.dll

Beginning removal…

Attempting to delete C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll
C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll Has been deleted!

Attempting to delete C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.bak1
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.bak1 Has been deleted!

Attempting to delete C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.bak2
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.bak2 Has been deleted!

Attempting to delete C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.ini
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.ini Has been deleted!

Attempting to delete C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.ini2
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.ini2 Has been deleted!

Attempting to delete C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.tmp
C:\DOCUME~1\Counter\LOCALS~1\Temp\pqtwa.tmp Has been deleted!

Attempting to delete C:\windows\system32\aalrofhd.dll
C:\windows\system32\aalrofhd.dll Has been deleted!

Attempting to delete C:\windows\system32\cyjiyhwu.dll
C:\windows\system32\cyjiyhwu.dll Has been deleted!

Attempting to delete C:\windows\system32\dhforlaa.ini
C:\windows\system32\dhforlaa.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\dtvhprwa.dll
C:\WINDOWS\system32\dtvhprwa.dll Has been deleted!

Attempting to delete C:\windows\system32\ebbiyfdl.dll
C:\windows\system32\ebbiyfdl.dll Has been deleted!

Attempting to delete C:\windows\system32\eegqqbpl.dll
C:\windows\system32\eegqqbpl.dll Has been deleted!

Attempting to delete C:\windows\system32\ejgvqhvs.ini
C:\windows\system32\ejgvqhvs.ini Has been deleted!

Attempting to delete C:\windows\system32\eqrbgwwy.dll
C:\windows\system32\eqrbgwwy.dll Has been deleted!

Attempting to delete C:\windows\system32\ewiupwhq.dll
C:\windows\system32\ewiupwhq.dll Has been deleted!

Attempting to delete C:\windows\system32\ftnlylmn.ini
C:\windows\system32\ftnlylmn.ini Has been deleted!

Attempting to delete C:\windows\system32\gcgafiij.ini
C:\windows\system32\gcgafiij.ini Has been deleted!

Attempting to delete C:\windows\system32\gisltoly.dll
C:\windows\system32\gisltoly.dll Has been deleted!

Attempting to delete C:\windows\system32\gjiivbjk.dll
C:\windows\system32\gjiivbjk.dll Has been deleted!

Attempting to delete C:\windows\system32\hcxmbkcp.dll
C:\windows\system32\hcxmbkcp.dll Has been deleted!

Attempting to delete C:\windows\system32\hrvothil.ini
C:\windows\system32\hrvothil.ini Has been deleted!

Attempting to delete C:\windows\system32\humnkhxo.ini
C:\windows\system32\humnkhxo.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\husmweei.ini
C:\WINDOWS\system32\husmweei.ini Has been deleted!

Attempting to delete C:\windows\system32\idnqksqf.dll
C:\windows\system32\idnqksqf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ieewmsuh.dll
C:\WINDOWS\system32\ieewmsuh.dll Could not be deleted.

Attempting to delete C:\windows\system32\jiifagcg.dll
C:\windows\system32\jiifagcg.dll Has been deleted!

Attempting to delete C:\windows\system32\jqvubqjp.dll
C:\windows\system32\jqvubqjp.dll Has been deleted!

Attempting to delete C:\windows\system32\jwrhgbdt.dll
C:\windows\system32\jwrhgbdt.dll Has been deleted!

Attempting to delete C:\windows\system32\kjbviijg.ini
C:\windows\system32\kjbviijg.ini Has been deleted!

Attempting to delete C:\windows\system32\ldfyibbe.ini
C:\windows\system32\ldfyibbe.ini Has been deleted!

Attempting to delete C:\windows\system32\lihtovrh.dll
C:\windows\system32\lihtovrh.dll Has been deleted!

Attempting to delete C:\windows\system32\lpbqqgee.ini
C:\windows\system32\lpbqqgee.ini Has been deleted!

Attempting to delete C:\windows\system32\mgvpovts.ini
C:\windows\system32\mgvpovts.ini Has been deleted!

Attempting to delete C:\windows\system32\msklnerx.dll
C:\windows\system32\msklnerx.dll Has been deleted!

Attempting to delete C:\windows\system32\ngerymjv.ini
C:\windows\system32\ngerymjv.ini Has been deleted!

Attempting to delete C:\windows\system32\nmlylntf.dll
C:\windows\system32\nmlylntf.dll Has been deleted!

Attempting to delete C:\windows\system32\nvvkiigw.ini
C:\windows\system32\nvvkiigw.ini Has been deleted!

Attempting to delete C:\windows\system32\oiucrsvp.dll
C:\windows\system32\oiucrsvp.dll Has been deleted!

Attempting to delete C:\windows\system32\olahexbq.dll
C:\windows\system32\olahexbq.dll Has been deleted!

Attempting to delete C:\windows\system32\oqkanbps.dll
C:\windows\system32\oqkanbps.dll Has been deleted!

Attempting to delete C:\windows\system32\ostlpsvi.dll
C:\windows\system32\ostlpsvi.dll Has been deleted!

Attempting to delete C:\windows\system32\oxhknmuh.dll
C:\windows\system32\oxhknmuh.dll Has been deleted!

Attempting to delete C:\windows\system32\pckbmxch.ini
C:\windows\system32\pckbmxch.ini Has been deleted!

Attempting to delete C:\windows\system32\pjqbuvqj.ini
C:\windows\system32\pjqbuvqj.ini Has been deleted!

Attempting to delete C:\windows\system32\pvsrcuio.ini
C:\windows\system32\pvsrcuio.ini Has been deleted!

Attempting to delete C:\windows\system32\qbxehalo.ini
C:\windows\system32\qbxehalo.ini Has been deleted!

Attempting to delete C:\windows\system32\rjvmbybu.ini
C:\windows\system32\rjvmbybu.ini Has been deleted!

Attempting to delete C:\windows\system32\spbnakqo.ini
C:\windows\system32\spbnakqo.ini Has been deleted!

Attempting to delete C:\windows\system32\stvopvgm.dll
C:\windows\system32\stvopvgm.dll Has been deleted!

Attempting to delete C:\windows\system32\svhqvgje.dll
C:\windows\system32\svhqvgje.dll Has been deleted!

Attempting to delete C:\windows\system32\tdbghrwj.ini
C:\windows\system32\tdbghrwj.ini Has been deleted!

Attempting to delete C:\windows\system32\tyrotouv.ini
C:\windows\system32\tyrotouv.ini Has been deleted!

Attempting to delete C:\windows\system32\ubybmvjr.dll
C:\windows\system32\ubybmvjr.dll Has been deleted!

Attempting to delete C:\windows\system32\ugalcxpy.dll
C:\windows\system32\ugalcxpy.dll Has been deleted!

Attempting to delete C:\windows\system32\unwxlfux.dll
C:\windows\system32\unwxlfux.dll Has been deleted!

Attempting to delete C:\windows\system32\uwhyijyc.ini
C:\windows\system32\uwhyijyc.ini Has been deleted!

Attempting to delete C:\windows\system32\vjmyregn.dll
C:\windows\system32\vjmyregn.dll Has been deleted!

Attempting to delete C:\windows\system32\vuotoryt.dll
C:\windows\system32\vuotoryt.dll Has been deleted!

Attempting to delete C:\windows\system32\wgiikvvn.dll
C:\windows\system32\wgiikvvn.dll Has been deleted!

Attempting to delete C:\windows\system32\wnkdvimu.dll
C:\windows\system32\wnkdvimu.dll Has been deleted!

Attempting to delete C:\windows\system32\wpojhrhn.dll
C:\windows\system32\wpojhrhn.dll Has been deleted!

Attempting to delete C:\windows\system32\wwcqgvyy.ini
C:\windows\system32\wwcqgvyy.ini Has been deleted!

Attempting to delete C:\windows\system32\xjrtqeld.dll
C:\windows\system32\xjrtqeld.dll Has been deleted!

Attempting to delete C:\windows\system32\xuflxwnu.ini
C:\windows\system32\xuflxwnu.ini Has been deleted!

Attempting to delete C:\windows\system32\ypxclagu.ini
C:\windows\system32\ypxclagu.ini Has been deleted!

Attempting to delete C:\windows\system32\ywwgbrqe.ini
C:\windows\system32\ywwgbrqe.ini Has been deleted!

Attempting to delete C:\windows\system32\yyvgqcww.dll
C:\windows\system32\yyvgqcww.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\ieewmsuh.dll
C:\WINDOWS\system32\ieewmsuh.dll Has been deleted!

Performing Repairs to the registry.
Done!


Logfile of HijackThis v1.99.1
Scan saved at 06:36, on 2007-09-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\avciman.exe
C:\Program Files\Hijackthis\hello.exe
C:\WINDOWS\system32\wscntfy.exe

O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [spoolsys] C:\WINDOWS\system32\dirservice.exe
O4 - HKLM\..\Run: [cryptspoolx] C:\WINDOWS\system32\datarun.exe %srun%
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: UPS OnLine PLD Reminder Utility.lnk = C:\UPS\UOWS\PldReminder.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097894359988
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132094679895
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE467829-2ECC-493F-B08A-1D4264E07975}: NameServer = 167.206.3.136,167.206.3.202
O20 - AppInit_DLLs: C:\WINDOWS\system32\systems.txt
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: opnnkih - opnnkih.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
I logged on as another user and wasn't able to get to control panel again. I ran combofix on that user the log file is below. Am I going to have to do that for all users on this computer? (There is only one more) or is there another way to fix it?

ComboFix 07-09-13.1 - "Counter" 2007-09-14 6:51:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.210 [GMT -4:00]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\Counter\APPLIC~1\ASEMBL~1
C:\DOCUME~1\Counter\APPLIC~1\DOBE~1
C:\DOCUME~1\Counter\APPLIC~1\STEM~1
C:\DOCUME~1\Counter\APPLIC~1\STEM~1\??stem\
C:\DOCUME~1\Counter\APPLIC~1\WinAntiSpyware 2007
C:\DOCUME~1\Counter\APPLIC~1\WinAntiSpyware 2007\Logs\update.log
C:\DOCUME~1\Counter\APPLIC~1\WinTouch
C:\DOCUME~1\Counter\APPLIC~1\WinTouch\wintouch.cfg
C:\DOCUME~1\Counter\APPLIC~1\YSTEM3~1
C:\DOCUME~1\Counter\APPLIC~1\YSTEM3~1\w?aclt.exe
C:\DOCUME~1\FRONTD~1\STARTM~1\Programs\Startup\system.exe
C:\Program Files\Common Files\ymante~1
C:\Program Files\Online Services\profsycyrtys.html
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\poolsv
C:\Program Files\racle~1
C:\Program Files\racle~2
C:\Program Files\svhost
C:\Program Files\winpop
C:\tempc2
C:\tempc2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\b143.exe
C:\WINDOWS\b148.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\fnts~1
C:\WINDOWS\system32\ajcvxept.dll
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\b10FdUe
C:\WINDOWS\system32\coyhkecp.dll
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\ebcruwpe.dll
C:\WINDOWS\system32\efhaqbu.dll
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\gytygtin.dll
C:\WINDOWS\system32\ileqxvbv.dll
C:\WINDOWS\system32\jfjognmm.dll
C:\WINDOWS\system32\klfndlor.dll
C:\WINDOWS\system32\mqxhlig.dll
C:\WINDOWS\system32\oubtjuae.dll
C:\WINDOWS\system32\oxixnnna.dll
C:\WINDOWS\system32\plyfpvbb.dll
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\rgccgexe.dll
C:\WINDOWS\system32\sdkqdqxi.dll
C:\WINDOWS\system32\sixsimrp.dll
C:\WINDOWS\system32\tlkrbvdx.dll
C:\WINDOWS\system32\vjmcguhx.dll
C:\WINDOWS\system32\win
C:\WINDOWS\system32\WinAvXX.exe
C:\WINDOWS\system32\wvrkcjad.dll
C:\WINDOWS\system32\ymbols~1
C:\WINDOWS\system32\Z1
C:\WINDOWS\system32\Z11
C:\WINDOWS\system32\Z3
C:\WINDOWS\system32\Z5
C:\WINDOWS\system32\Z7
C:\WINDOWS\tsks~1
C:\WINDOWS\wr.txt

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\LEGACY_FOPN


((((((((((((((((((((((((( Files Created from 2007-08-14 to 2007-09-14 )))))))))))))))))))))))))))))))
.

2007-09-14 06:27 d——– C:\VundoFix Backups
2007-09-14 05:58 26,496 –a–c— C:\WINDOWS\SYSTEM32\DLLCACHE\usbstor.sys
2007-09-13 22:57 135,168 –a—— C:\WINDOWS\SYSTEM32\igfxres.dll
2007-09-13 22:32 24,661 –a–c— C:\WINDOWS\SYSTEM32\DLLCACHE\spxcoins.dll
2007-09-13 22:32 24,661 –a—— C:\WINDOWS\SYSTEM32\spxcoins.dll
2007-09-13 22:32 13,312 –a–c— C:\WINDOWS\SYSTEM32\DLLCACHE\irclass.dll
2007-09-13 22:32 13,312 –a—— C:\WINDOWS\SYSTEM32\irclass.dll
2007-09-13 22:01 d——– C:\5dd134fbb7e8df8630a4d8a989a3
2007-09-13 21:39 d——– C:\ec71b08234026c381613022639
2007-09-13 20:35 d–hs—- C:\found.000
2007-09-12 19:45 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-11 02:20 d——– C:\Clienttrack Backup
2007-09-10 21:46 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-09-10 02:14 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Talkback
2007-09-08 11:33 139,536 –a—— C:\WINDOWS\SYSTEM32\javaee.dll
2007-09-08 11:28 13,880 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\COMFiltr.sys
2007-09-08 11:26 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\sentinel
2007-09-08 11:23 83,640 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\pavdrv51.sys
2007-09-08 11:23 281 –a—— C:\WINDOWS\SYSTEM32\PavCPL.dat
2007-09-08 11:23 224,812 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\APPFCONT.DAT
2007-09-08 11:22 71,736 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\APPFLT.SYS
2007-09-08 11:22 51,256 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\dsaflt.sys
2007-09-08 11:22 37,304 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\smsflt.sys
2007-09-08 11:22 30,648 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\wnmflt.sys
2007-09-08 11:22 22,072 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\fnetmon.sys
2007-09-08 11:22 191,672 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\idsflt.sys
2007-09-08 11:22 132,920 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\NETFLTDI.SYS
2007-09-08 11:22 d——– C:\WINDOWS\SYSTEM32\PAV
2007-09-08 11:21 63,024 –a—— C:\WINDOWS\SYSTEM32\pavipc.dll
2007-09-08 11:21 50,736 –a—— C:\WINDOWS\SYSTEM32\avldr.dll
2007-09-08 11:21 292,144 –a—— C:\WINDOWS\SYSTEM32\PavSHook.dll
2007-09-08 11:21 24,760 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\cpoint.sys
2007-09-08 11:21 161,328 –a—— C:\WINDOWS\SYSTEM32\TpUtil.dll
2007-09-08 11:21 142,128 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\netimflt.sys
2007-09-08 11:21 101,888 –a—— C:\WINDOWS\SYSTEM32\SYSTOOLS.DLL
2007-09-08 11:21 d——– C:\Program Files\Panda Security
2007-09-08 11:18 38,968 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\ShlDrv51.sys
2007-09-08 11:18 178,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\PavProc.sys
2007-09-08 09:56 d——– C:\WINDOWS\SYSTEM32\ActiveScan
2007-09-07 11:51 39,424 –a—— C:\WINDOWS\SYSTEM32\vtr.dll
2007-08-30 12:59 d——– C:\Program Files\Words
2007-08-29 11:20 d——– C:\WINDOWS\zkrf
2007-08-23 10:36 d——– C:\DOCUME~1\Counter\APPLIC~1\Corel
2007-08-21 14:21 d——– C:\WINDOWS\SYSTEM32\tmps7
2007-08-21 14:21 d——– C:\WINDOWS\SYSTEM32\ICM23
2007-08-21 14:21 d——– C:\WINDOWS\SYSTEM32\dllsz
2007-08-21 14:21 d——– C:\WINDOWS\SYSTEM32\cofig1

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-14 06:57 224812 –a—— C:\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2007-09-14 06:57 1224 –a—— C:\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2007-09-14 06:57 1224 –a—— C:\WINDOWS\system32\drivers\APPFLTR.CFG
2007-09-11 20:18 ——— d——– C:\Program Files\ClienTrak
2007-09-10 17:09 ——— d——– C:\Program Files\Yahoo!
2007-09-08 11:18 ——— d——– C:\Program Files\Common Files\Panda Software
2007-09-08 11:09 ——— d——– C:\Program Files\TightVNC
2007-08-04 14:34 ——— d——– C:\Program Files\XoftSpySE
2007-08-04 14:26 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-04 14:26 ——— d——– C:\Program Files\Panda Software
2007-08-01 20:14 ——— d——– C:\DOCUME~1\Counter\APPLIC~1\AdobeUM
2007-07-31 19:03 ——— d——– C:\DOCUME~1\FRONTD~1\APPLIC~1\Talkback
2007-07-30 19:19 43352 –a—— C:\WINDOWS\SYSTEM32\wups2.dll
2007-07-28 06:56 3638 –a—— C:\WINDOWS\248w2k9v.exe
2007-07-28 06:45 126016 –a—— C:\WINDOWS\SYSTEM32\yajdeidm.dll
2007-07-28 06:41 126016 –a—— C:\WINDOWS\SYSTEM32\iejfdnyy.dll
2007-07-21 09:27 ——— d——– C:\Program Files\Viewpoint
2007-07-21 09:27 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
2007-07-21 09:25 ——— d——– C:\Program Files\Bodog Poker
2001-02-06 13:40 6115328 –a—— C:\DOCUME~1\ALLUSE~1\ClienTrak.exe
1989-12-12 14:10:10 486,352 –sha-r C:\WINDOWS\qahgaskA.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 12:43]
"spoolsys"="C:\WINDOWS\system32\dirservice.exe" []
"cryptspoolx"="C:\WINDOWS\system32\datarun.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 03:41]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"winhost"="C:\WINDOWS\system32\dirservice.exe" []
"Evyiak"="C:\WINDOWS\T?sks\w?nspool.exe" []
"Yxl"="C:\Documents and Settings\Counter\Application Data\?ystem32\w?aclt.exe" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2007-09-13 22:46:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 11:05:56]

C:\DOCUME~1\ADMINI~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-11 18:15:06]

C:\DOCUME~1\Counter\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-11 18:15:06]
Launch TightVNC Server.lnk - C:\Program Files\TightVNC\WinVNC.exe [2003-08-01 19:28:24]

C:\DOCUME~1\DEFAUL~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2007-09-13 22:46:46]

C:\DOCUME~1\FRONTD~1\STARTM~1\Programs\Startup\
DESKTOP.INI [2004-08-11 18:15:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2007-02-15 20:02 50736 C:\WINDOWS\SYSTEM32\avldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnnkih]
opnnkih.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\awd_qYzjwx]lcogHd`]
C:\WINDOWS\system32\iemzdjay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmds]
rundll32.exe C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll,CreateProtectProc

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI.UWAS7_0001_N91M2703]
"C:\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exe" -nag

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"C:\Program Files\Dell\Media Experience\PCMService.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qahgaskA]
C:\WINDOWS\qahgaskA.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Salestart]
"C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6w]
C:\Documents and Settings\Counter\Application Data\Microsoft\Windows\exhurr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\oqkanbps.dll",forkonce

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tair]
"C:\DOCUME~1\Counter\APPLIC~1\ASEMBL~1\mmc.exe" -vt yazb

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearch]
"C:\Program Files\WhenUSearch\Search.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPop]
C:\Program Files\WinPop\winpop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTouch]
C:\Documents and Settings\Counter\Application Data\WinTouch\WinTouch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yknebnoe]
"C:\Documents and Settings\Counter\Application Data\?dobe\w?nword.exe"

R1 APPFLT;App Filter Plugin;\??\C:\WINDOWS\system32\Drivers\APPFLT.SYS
R1 DSAFLT;DSA Filter Plugin;\??\C:\WINDOWS\system32\Drivers\DSAFLT.SYS
R1 FNETMON;NetMon Filter Plugin;\??\C:\WINDOWS\system32\Drivers\fnetmon.SYS
R1 IDSFLT;Ids Filter Plugin;\??\C:\WINDOWS\system32\Drivers\IDSFLT.SYS
R1 NETFLTDI;Panda Net Driver [TDI Layer];\??\C:\WINDOWS\system32\Drivers\NETFLTDI.SYS
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\DRIVERS\ShlDrv51.sys
R1 SMSFLT;SMS Filter Plugin;\??\C:\WINDOWS\system32\Drivers\SMSFLT.SYS
R1 WNMFLT;Wifi Monitor Filter Plugin;\??\C:\WINDOWS\system32\Drivers\WNMFLT.SYS
R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\Drivers\cpoint.sys
R2 PAVDRV;pavdrv;C:\WINDOWS\system32\DRIVERS\pavdrv51.sys
R2 PavProc;Panda Process Protection Driver;\??\C:\WINDOWS\system32\DRIVERS\PavProc.sys
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys
R3 ComFiltr;Panda Anti-Dialer;\??\C:\WINDOWS\system32\DRIVERS\COMFiltr.sys
R3 NETIMFLT;PANDA NDIS IM Filter Miniport;C:\WINDOWS\system32\DRIVERS\netimflt.sys
R3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\system32\PavSRK.sys
R3 PavTPK.sys;PavTPK.sys;\??\C:\WINDOWS\system32\PavTPK.sys

*Newly Created Service* - COMFILTR
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-14 06:57:10
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-14 6:59:53 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-14 06:59
.
— E O F —
Hello chigins,

We will need to go through each user account individually and clean them out one by one.

I see that you are running msconfig in /auto mode which means that you may have selectively removed some items in the past from the startup procedure. This can be bad if they are malware, so we would like you to reenable those startup entries by doing the following:

Please click on start, then run, and type msconfig and then press enter. When the window opens click on the startup tab and make sure there are checkmarks in every entry. Then press ok until you are out of the program. If it asks to reboot, do not reboot.

Now please create a new Hijackthis Log and post it as a reply.
Logfile of HijackThis v1.99.1
Scan saved at 11:58:07 AM, on 9/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\AVENGINE.EXE
c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\ApvxdWin.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\WebProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\hello.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\avciman.exe
C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\psimreal.exe
C:\WINDOWS\SoftwareDistribution\Download\f040a43a7788e207ef67f26bf9f0471f\update\update.exe

O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [spoolsys] C:\WINDOWS\system32\dirservice.exe
O4 - HKLM\..\Run: [cryptspoolx] C:\WINDOWS\system32\datarun.exe %srun%
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [WhenUSearch] "C:\Program Files\WhenUSearch\Search.exe"
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\oqkanbps.dll",forkonce
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [qahgaskA] C:\WINDOWS\qahgaskA.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [awd_qYzjwx]lcogHd`] C:\WINDOWS\system32\iemzdjay.exe
O4 - HKCU\..\Run: [winhost] C:\WINDOWS\system32\dirservice.exe
O4 - HKCU\..\Run: [Evyiak] C:\WINDOWS\T?sks\w?nspool.exe
O4 - HKCU\..\Run: [Yxl] "C:\Documents and Settings\Counter\Application Data\?ystem32\w?aclt.exe"
O4 - HKCU\..\Run: [Yknebnoe] "C:\Documents and Settings\Counter\Application Data\?dobe\w?nword.exe"
O4 - HKCU\..\Run: [WinTouch] C:\Documents and Settings\Counter\Application Data\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [WinPop] C:\Program Files\WinPop\winpop.exe
O4 - HKCU\..\Run: [Tair] "C:\DOCUME~1\Counter\APPLIC~1\ASEMBL~1\mmc.exe" -vt yazb
O4 - HKCU\..\Run: [SfKg6w] C:\Documents and Settings\Counter\Application Data\Microsoft\Windows\exhurr.exe
O4 - HKCU\..\Run: [NI.UWAS7_0001_N91M2703] "C:\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exe" -nag
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\DOCUME~1\Counter\LOCALS~1\Temp\awtqp.dll,CreateProtectProc
O4 - Startup: Launch TightVNC Server.lnk = C:\Program Files\TightVNC\WinVNC.exe
O4 - Startup: UPS WorldShip PLD Reminder Utility.lnk = C:\UPS\UOWS\PldReminder.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: UPS OnLine PLD Reminder Utility.lnk = C:\UPS\UOWS\PldReminder.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1189768624234
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1132094679895
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE467829-2ECC-493F-B08A-1D4264E07975}: NameServer = 204.17.65.2,216.41.101.15
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: opnnkih - opnnkih.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsCtrls.exe
O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PavFnSvr.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\pavsrv51.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program files\panda security\panda antivirus + firewall 2008\firewall\PSHOST.EXE
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\PsImSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Panda TPSrv (TPSrv) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus + Firewall 2008\TPSrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe




An unexpected error has occurred at procedure: modMain_CheckOther1Item()
Error #75 - Path/File access error

Please email me at [removed], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.2180
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.
Hello chigins,

Let's run through combofix again real quick, it looks like some of the files have regenerated.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI