This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] vundo

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I appear to have the vundo virus. It has been identified by ad-aware and spybot but neither one can remove it. It always reappears. The file awvvt.dll is always identified in my system32 file but even if I try to remove it in safe mode it says it is being used by another program. Any help would be greatly appreciated. Here is a copy of my HiJack This Log.


Logfile of HijackThis v1.99.1
Scan saved at 8:40:33 PM, on 1/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe
C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32 .exe
C:\Program Files\LogMeIn\LogMeInSystray .exe
C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient .exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\awvvt.exe
O4 - HKLM\..\Run: [NAV Agent] C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SM_IAN] C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe /auto
O4 - HKLM\..\Run: [a4b7127f] rundll32.exe "C:\WINDOWS\system32\tonhfjls.dll",b
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Thanks,

Redwings
Hi redwingsoh Welcome to the What the tech Forums My name is mschroe919 and I am going to read your log. I would like to help you So if you would…. Please be patient and I will be back as soon as possible. while I am reading please do this: Rename HijackThis There is probably an infection which is hiding part of the HijackThis log because it's called hijackthis.exe. Please rename hijackthis.exe to scanner.exe Here is how: go to C:\Program Files\Hijackthis\HijackThis.exe right click on HijackThis.exe click on rename and rename it scanner.exe It will look like this now: C:\Program Files\Hijackthis\scanner.exe Now scan again with the new scanner.exe and post a new log, please Please don't delete anything till asked to. thank you and good luck mschroe919
Thanks for the quick response. I renamed hijack this to scanner and here is the new file.

Logfile of HijackThis v1.99.1
Scan saved at 6:19:50 AM, on 1/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe
C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32 .exe
C:\Program Files\LogMeIn\LogMeInSystray .exe
C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient .exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
C:\Program Files\iTunes\iTunesHelper .exe
C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\awvvt.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: {41bb5f25-614d-6e4a-1654-65b738cda250} - {052adc83-7b56-4561-a4e6-d41652f5bb14} - C:\WINDOWS\system32\tiltoxbk.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: BndBlock4 BHO Class - {8F9E2BE3-766D-4831-BB0E-766D5B819995} - C:\Program Files\QdrDrive\QdrDrive9.dll (file missing)
O2 - BHO: (no name) - {B53C5B4E-4800-4189-977B-7BF8C63C690D} - C:\WINDOWS\system32\awvvt.dll
O2 - BHO: (no name) - {CA4F0D8D-5F2B-4F16-838A-8D52249EAB21} - C:\WINDOWS\system32\vtuvwxy.dll (file missing)
O4 - HKLM\..\Run: [NAV Agent] C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SM_IAN] C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe /auto
O4 - HKLM\..\Run: [a4b7127f] rundll32.exe "C:\WINDOWS\system32\tonhfjls.dll",b
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: vtuvwxy - vtuvwxy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Thanks again,

Redwings
Hi redwingsoh
Welcome back to the Forums. It worked changing the name now we got the whole log.
Notice:
DO NOT DELETE ANYTHING ON YOUR OWN. WHILE WE ARE
CLEANING, IF YOU DON'T UNDERSTAND SOMETHING ASK ME PLEASE

FIRST:
Download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
——————————————————————–
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results"
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net
——————————————————————–
2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****




After ComboFix has finished its run:
Restart/re-enable all the programs that you disabled before running the tools.
Physically reconnect to the internet
NEXT:
post these new logs:
C:\ComboFix.txt.
new HijackThis log
good luck mschroe919
Here are the two new logs.

ComboFix 08-01-28.2 - John 2008-01-28 12:40:10.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.155 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\awvvt.dll
C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe
C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe
C:\Documents and Settings\John\Application Data\SMANTE~1
C:\Documents and Settings\John\Application Data\SMANTE~1\r?gsvr32.exe
C:\Documents and Settings\John\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\John\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\John\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\outerinfo
C:\WINDOWS\b122.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\Temp
C:\WINDOWS\hosts
C:\WINDOWS\sks~1
C:\WINDOWS\sks~1\??sks\
C:\WINDOWS\sks~1\netdde .exe
C:\WINDOWS\sks~1\netdde.exe
C:\WINDOWS\system32\aciclssg.ini
C:\WINDOWS\system32\awvvt.dll
C:\WINDOWS\system32\awvvt.exe
C:\WINDOWS\system32\cqbknegq.ini
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\evoytsav.ini
C:\WINDOWS\system32\gjefbwsb.ini
C:\WINDOWS\system32\gudanqpq.dll
C:\WINDOWS\system32\gwxjgpbx.ini
C:\WINDOWS\system32\hylsxbwe.ini
C:\WINDOWS\system32\igryddvl.ini
C:\WINDOWS\system32\jwrypktk.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\ouibjpux.dll
C:\WINDOWS\system32\RCX1C.tmp
C:\WINDOWS\system32\RCX1F.tmp
C:\WINDOWS\system32\rirjsddw.ini
C:\WINDOWS\system32\rmdbbadr.ini
C:\WINDOWS\system32\srqiaoja.ini
C:\WINDOWS\system32\tvvwa.ini
C:\WINDOWS\system32\tvvwa.ini2
C:\WINDOWS\system32\wnscpicom32.exe
C:\WINDOWS\system32\wpkpsvmy.ini
C:\WINDOWS\system32\xwaxeqco.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_SVCHOST


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-28 )))))))))))))))))))))))))))))))
.

2008-01-28 12:54 . 2008-01-28 12:54 335,872 –a—— C:\WINDOWS\system32\awvvt.dll
2008-01-27 18:10 . 2008-01-27 18:10 d——– C:\Program Files\Lavasoft
2008-01-27 18:10 . 2008-01-27 18:11 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-27 06:59 . 2008-01-27 06:59 24,576 –a—— C:\WINDOWS\system32\VundoFixSVC.exe
2008-01-22 21:56 . 2008-01-22 21:56 4,608 –ahs—- C:\WINDOWS\system32\Thumbs.db
2008-01-21 16:35 . 2008-01-21 16:35 8,506,408 –a—— C:\Install_AIM59.exe
2008-01-18 15:44 . 2008-01-18 15:44 d——– C:\Program Files\Western Digital Technologies
2008-01-18 13:54 . 2008-01-18 13:54 d——– C:\Program Files\PQDVD
2008-01-18 13:51 . 2008-01-18 13:51 d——– C:\Documents and Settings\John\Application Data\vlc
2008-01-18 13:50 . 2008-01-18 13:50 d——– C:\Program Files\VideoLAN
2008-01-18 13:15 . 2008-01-18 13:15 d——– C:\ConverterOutput
2008-01-18 13:12 . 2008-01-18 13:12 d——– C:\Program Files\Cucusoft
2008-01-16 20:37 . 2008-01-16 20:37 339,456 –a—— C:\WINDOWS\system32\RCX10D.tmp
2008-01-16 19:44 . 2008-01-28 12:54 d——– C:\Program Files\AdvancedCleaner Free
2008-01-16 19:44 . 2003-03-19 08:20 1,060,864 –a—— C:\WINDOWS\system32\mfc71.dll
2008-01-16 19:37 . 2008-01-16 19:37 31,232 –a—— C:\_YnJubV9zYV9iYW5uZXJfZ2F2X21hNA_Z2FtZQ_bm1fMTUxMDc2X0RBNzc2NzFFQjc1QjExREM4
QzcwMTUxMDc2RERGRkZGX0Q2RTk3OUY3MTA1RTRGQzVCN0QzMjM2QzAwNDE5MTIy_.exe
2008-01-16 19:27 . 2008-01-16 19:27 45,640 –a—— C:\PerformanceOptimizerPre_Installer.exe
2008-01-15 14:34 . 2008-01-15 14:34 d——– C:\Documents and Settings\John\Application Data\Nexon
2008-01-15 14:29 . 2008-01-15 14:29 d——– C:\Nexon
2008-01-13 16:20 . 2008-01-13 16:20 339,456 –a—— C:\WINDOWS\system32\RCX10C.tmp
2008-01-12 19:22 . 2008-01-27 07:00 d——– C:\VundoFix Backups
2008-01-07 19:34 . 2008-01-21 17:11 748 –a—— C:\WINDOWS\wininit.ini
2007-12-31 20:37 . 2007-12-31 20:37 d——– C:\Documents and Settings\John\Application Data\Uniblue
2007-12-31 20:36 . 2007-12-31 20:36 d——– C:\Program Files\Uniblue
2007-12-31 20:07 . 2007-12-31 20:10 2,008 –a—— C:\WINDOWS\system32\tmp.reg
2007-12-31 20:06 . 2007-09-05 23:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2007-12-31 20:06 . 2006-04-27 16:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2007-12-31 20:06 . 2007-12-20 23:11 81,920 –a—— C:\WINDOWS\system32\IEDFix.exe
2007-12-31 20:06 . 2003-06-05 20:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2007-12-31 20:06 . 2004-07-31 17:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2007-12-31 20:06 . 2007-10-03 23:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2007-12-31 10:31 . 2008-01-27 20:39 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2007-12-31 08:12 . 2008-01-12 19:10 155,648 –a—— C:\WINDOWS\system32\NeroCheck .exe
2007-12-30 23:47 . 2007-12-31 20:12 380,416 –a—— C:\WINDOWS\mrofinu11.exe.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-28 17:48 ——— d—–w C:\Program Files\LogMeIn
2008-01-28 17:48 ——— d—–w C:\Program Files\iTunes
2008-01-28 01:22 ——— d—–w C:\Program Files\zilpe
2008-01-27 23:09 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 23:01 ——— d—–w C:\Documents and Settings\John\Application Data\Lavasoft
2008-01-21 21:44 ——— d—–w C:\Program Files\AIM
2008-01-21 21:37 ——— d—–w C:\Program Files\AOD
2008-01-17 00:37 31,232 —-a-w C:\_YnJubV9zYV9iYW5uZXJfZ2F2X21hNA_Z2FtZQ_bm1fMTUxMDc2X0RBNzc2NzFFQjc1QjExREM4
QzcwMTUxMDc2RERGRkZGX0Q2RTk3OUY3MTA1RTRGQzVCN0QzMjM2QzAwNDE5MTIy_.exe
2008-01-11 15:19 ——— d—–w C:\Program Files\QuickTime
2008-01-07 23:48 ——— d—–w C:\Program Files\SpywareBlaster
2007-12-31 13:04 ——— d—–w C:\Program Files\MSN Messenger
2007-12-27 22:19 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-26 01:32 ——— d—–w C:\Program Files\EA GAMES
2007-12-25 18:16 ——— d—–w C:\Program Files\WarRock
2007-12-25 14:31 ——— d–h–r C:\Documents and Settings\John\Application Data\SecuROM
2007-12-25 13:52 94,208 —-a-w C:\WINDOWS\DUMP8c51.tmp
2005-11-19 02:31 800,789 —-a-w C:\Documents and Settings\John\xw.exe
2005-06-21 02:07 280,064 —-a-w C:\Documents and Settings\John\Application Data\tizhook.bin
2005-06-21 02:07 154,384 —-a-w C:\Documents and Settings\John\Application Data\tizupd.bin
2005-02-15 20:45 456,208 —-a-w C:\Documents and Settings\procexpnt\procexp.exe
2004-08-07 19:14 187,904 —-a-w C:\Documents and Settings\HiJackThis\HijackThis.exe
2002-12-16 20:41 66,949 —-a-r C:\Documents and Settings\Drivers\AFLASH.EXE
.
—-a-w			75,384 2008-01-28 01:39:02  C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapw32 .exe
—-a-w		   693,520 2008-01-28 01:39:04  C:\Documents and Settings\John\My Documents\Programs\Zone Alarm\ZoneAlarm\zlclient .exe
—-a-w			57,344 2008-01-12 05:06:52  C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe
—-a-w		   581,632 2008-01-28 17:54:25  C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
—-a-w			66,672 2008-01-17 01:51:57  C:\Program Files\AIM\aim .exe
—-a-w		   344,064 2008-01-04 20:39:42  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w		   256,576 2008-01-28 01:39:04  C:\Program Files\iTunes\iTunesHelper .exe
—-a-w			36,975 2008-01-11 15:19:18  C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
—-a-w		   303,856 2008-01-28 01:39:04  C:\Program Files\LogMeIn\LogMeInSystray .exe
—-a-w		 5,354,792 2007-12-31 13:05:11  C:\Program Files\MSN Messenger\msnmsgr .exe
—-a-w		   282,624 2008-01-11 15:19:23  C:\Program Files\QuickTime\qttask			 .exe
—-a-w		   649,216 2008-01-11 15:19:11  C:\Program Files\QuickTime\qttask			.exe
—-a-w		   649,216 2008-01-10 16:35:19  C:\Program Files\QuickTime\qttask		   .exe
—-a-w		   649,216 2008-01-09 13:41:13  C:\Program Files\QuickTime\qttask		  .exe
—-a-w		   649,216 2008-01-07 22:34:48  C:\Program Files\QuickTime\qttask		 .exe
—-a-w		   649,216 2008-01-07 22:17:22  C:\Program Files\QuickTime\qttask		.exe
—-a-w		   649,216 2008-01-07 22:10:48  C:\Program Files\QuickTime\qttask	   .exe
—-a-w		   649,216 2008-01-07 13:02:46  C:\Program Files\QuickTime\qttask	  .exe
—-a-w		   649,216 2008-01-04 20:39:36  C:\Program Files\QuickTime\qttask	 .exe
—-a-w		   649,216 2008-01-03 06:27:52  C:\Program Files\QuickTime\qttask	.exe
—-a-w		   649,216 2008-01-01 01:29:16  C:\Program Files\QuickTime\qttask   .exe
—-a-w		   649,216 2008-01-01 01:12:19  C:\Program Files\QuickTime\qttask  .exe
—-a-w		   649,216 2007-12-31 15:31:46  C:\Program Files\QuickTime\qttask .exe
—-a-w		   500,224 2008-01-17 01:51:43  C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
—-a-w			15,360 2008-01-28 01:39:08  C:\WINDOWS\system32\ctfmon .exe
—-a-w		   155,648 2008-01-13 00:10:26  C:\WINDOWS\system32\NeroCheck .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{052adc83-7b56-4561-a4e6-d41652f5bb14}]
C:\WINDOWS\system32\tiltoxbk.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0D3694A-AF99-4804-B47B-BD2D701AC131}]
2008-01-28 12:54 335872 –a—— C:\WINDOWS\system32\awvvt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NAV Agent"="C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe" [ ]
"Zone Labs Client"="C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe" [ ]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [ ]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [ ]
"LogMeIn GUI"="C:\Program Files\LogMeIn\LogMeInSystray.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
"SM_IAN"="C:\Program Files\AdvancedCleaner Free\ian_monitor .exe" [2008-01-28 12:54 581632]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe" [2008-01-16 20:51 500224]
"a4b7127f"="C:\WINDOWS\system32\tonhfjls.dll" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2006-08-11 16:04 11496 C:\WINDOWS\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwxy]
vtuvwxy.dll

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\awvvt.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\awvvt

.
Contents of the 'Scheduled Tasks' folder
"2008-01-28 08:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\NAVW32.exe
"2008-01-28 18:00:02 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-28 12:54:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SM_IAN = C:\Program Files\AdvancedCleaner Free\ian_monitor .exe?|??????????@???@????????????????|??@?????????p???????? A?3??|???|??C???@???@???????C????????|??@?????????,?????@???@?d???u)?|??@??????????)?|???|??C???@?3??|??????C???@???@?????????? A????|??????@?d??????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\awvvt.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-01-28 13:01:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-28 18:01:09
.
2008-01-10 08:04:47 — E O F —




Logfile of HijackThis v1.99.1
Scan saved at 1:03:11 PM, on 1/28/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\NMain.exe
C:\Program Files\Hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\awvvt.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: {41bb5f25-614d-6e4a-1654-65b738cda250} - {052adc83-7b56-4561-a4e6-d41652f5bb14} - C:\WINDOWS\system32\tiltoxbk.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {A0D3694A-AF99-4804-B47B-BD2D701AC131} - C:\WINDOWS\system32\awvvt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SM_IAN] C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe /auto
O4 - HKLM\..\Run: [a4b7127f] rundll32.exe "C:\WINDOWS\system32\tonhfjls.dll",b
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: vtuvwxy - vtuvwxy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Thanks,

Redwings
Hi redwingsoh
Theses fixes are for your paticular problem, don't use on any other pc.
Please follow these in order.




A. Using the Add/Remove program module in your Control Panel, please UNINSTALL the following rogue program:

AdvancedCleaner Free

The reason for the deletion can be found here: http://www.bleepingcomputer.com/uninstall/Cat-A.html


B.
1. Please open Notepad
Click Start , then Run
Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:


KillAll::

File::
C:\WINDOWS\system32\awvvt.dll
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\system32\RCX10D.tmp
C:\Program Files\AdvancedCleaner Free
C:\_YnJubV9zYV9iYW5uZXJfZ2F2X21hNA_Z2FtZQ_bm1fMTUxMDc2X0RBNzc2NzFFQjc1QjExREM4
QzcwMTUxMDc2RERGRkZGX0Q2RTk3OUY3MTA1RTRGQzVCN0QzMjM2QzAwNDE5MTIy_.exe
C:\WINDOWS\system32\RCX10C.tmp
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\WS2Fix.exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\NeroCheck .exe
C:\WINDOWS\mrofinu11.exe.tmp
C:\WINDOWS\DUMP8c51.tmp
C:\Documents and Settings\John\xw.exe
C:\Documents and Settings\John\Application Data\tizhook.bin
C:\Documents and Settings\John\Application Data\tizupd.bin

Folder::
C:\Program Files\AdvancedCleaner Free

RenV::
—-a-w 75,384 2008-01-28 01:39:02 C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapw32 .exe
—-a-w 693,520 2008-01-28 01:39:04 C:\Documents and Settings\John\My Documents\Programs\Zone Alarm\ZoneAlarm\zlclient .exe
—-a-w 57,344 2008-01-12 05:06:52 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy .exe
—-a-w 581,632 2008-01-28 17:54:25 C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
—-a-w 66,672 2008-01-17 01:51:57 C:\Program Files\AIM\aim .exe
—-a-w 344,064 2008-01-04 20:39:42 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w 256,576 2008-01-28 01:39:04 C:\Program Files\iTunes\iTunesHelper .exe
—-a-w 36,975 2008-01-11 15:19:18 C:\Program Files\Java\jre1.5.0_06\bin\jusched .exe
—-a-w 303,856 2008-01-28 01:39:04 C:\Program Files\LogMeIn\LogMeInSystray .exe
—-a-w 5,354,792 2007-12-31 13:05:11 C:\Program Files\MSN Messenger\msnmsgr .exe
—-a-w 282,624 2008-01-11 15:19:23 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-11 15:19:11 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-10 16:35:19 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-09 13:41:13 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-07 22:34:48 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-07 22:17:22 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-07 22:10:48 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-07 13:02:46 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-04 20:39:36 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-03 06:27:52 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-01 01:29:16 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2008-01-01 01:12:19 C:\Program Files\QuickTime\qttask .exe
—-a-w 649,216 2007-12-31 15:31:46 C:\Program Files\QuickTime\qttask .exe
—-a-w 500,224 2008-01-17 01:51:43 C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\MSConfig .exe
—-a-w 15,360 2008-01-28 01:39:08 C:\WINDOWS\system32\ctfmon .exe
—-a-w 155,648 2008-01-13 00:10:26 C:\WINDOWS\system32\NeroCheck .exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{052adc83-7b56-4561-a4e6-d41652f5bb14}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A0D3694A-AF99-4804-B47B-BD2D701AC131}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvwxy]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"a4b7127f"=-

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.

8. Post the following logs/Reports:
ComboFix.txt
Fresh HijackThis log
run after all the other tools have performed their cleanup.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Good luck mschroe919
No Luck. There is no advancedcleaner free in my add/remove programs. Neither is there one in my programs list when I hit the start button. There is a file in my C drive but there is no uninstall there either. Next Problem. When I drag the text onto combofix the DOS box comes up and immediately disappears. I waited and nothing happens. Redwings
Hi redwingsoh
Not to worry we will get it,
FIRST UNINSTALL yourt current copy of ComboFix,
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]
download a fresh copy and run the script over the new copy.
HEREor

HERE
Good Luck
Okay, now ComboFix starts up, creates a restore point and then tells me it is checking for infected files and it should take no longer then 10 minutes. It never says anything else and after about 1 minute the box disappears and nothing else happens. Redwings
I don't know exactly what happened, but I asked you to download another ver, and rid the old one. Then run the script over the new copy. The script should have been there from the old one. So see if the script is still there and
. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
try it again please
The same thing happens. I deleted the old version and downloaded another version (twice - one from each site). When I drag CFScript onto combo fix it starts to run and does everything it did the first time—Except now it gets to the point where it says it is scanning for infected files and after about 1 minute it quits. The ComboFix box just disappears and my computer does not shutdown and restart automatically like it did before. No log file is created. ComboFix just appears to shutdown before it finishes. Redwings One more thing. I don't know if this is what normally happens but when I drag the txt file onto ComboFix it disappears. It is no longer on my desktop.
Good Morning to You. Here is my new HJT log. Thanks for your time and patience in helping me.

Logfile of HijackThis v1.99.1
Scan saved at 08:14, on 2008-01-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon .exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
C:\Program Files\Hijackthis\Scanner.exe
C:\WINDOWS\system32\wscntfy.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: {41bb5f25-614d-6e4a-1654-65b738cda250} - {052adc83-7b56-4561-a4e6-d41652f5bb14} - C:\WINDOWS\system32\tiltoxbk.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {57FF7507-2425-49D5-8AB9-39FE3BFDC8E2} - C:\WINDOWS\system32\awvvt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NAV Agent] C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SM_IAN] C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe /auto
O4 - HKLM\..\Run: [a4b7127f] rundll32.exe "C:\WINDOWS\system32\tonhfjls.dll",b
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: vtuvwxy - vtuvwxy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



Redwings
Hi Redwings
Your welcome that is what we do here.
Your doing fine your log looks better allready.
The following entry, shows that the Microsoft System Configuration Utility
is in use,

O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

We need to see all that is loading on that computer!!
go to start run and type in :
msconfig and hit ok
then got to startups and enable all; you will have to reboot and when the windows show mscofig check
the box ans enter.
NEXT:
I know you said that this is not in add remove programs. But this line says iy is on your
system.
C:\Program Files\AdvancedCleaner Free\ian_monitor.exe
So please look agai in start remove programs for either AdvancedCleaner Free
or ian_monitor.exe
if still not there thats ok will get it later in this post.

NEXT:
Run scanner.exe and click Scan and then check the following, if present (don't worry if any are missing):
O2 - BHO: {41bb5f25-614d-6e4a-1654-65b738cda250} - {052adc83-7b56-4561-a4e6-d41652f5bb14} - C:\WINDOWS\system32\tiltoxbk.dll (file missing)
O2 - BHO: (no name) - {57FF7507-2425-49D5-8AB9-39FE3BFDC8E2} - C:\WINDOWS\system32\awvvt.dll
O4 - HKLM\..\Run: [SM_IAN] C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
O4 - HKLM\..\Run: [a4b7127f] rundll32.exe "C:\WINDOWS\system32\tonhfjls.dll",b
O20 - Winlogon Notify: vtuvwxy - vtuvwxy.dll (file missing)

Close down all programs, browsers and other open windows. Make sure that only the above items are checked and then click on Fix checked.
NEXT:
Open windows explorer and find these and delete the folders in RED
C:\Program Files\AdvancedCleaner Free\ian_monitor .exe
C:\WINDOWS\system32\tonhfjls.dll


Reboot and post a new hjt log.
and let me know how your pc is behavimg.
good luck
Hello again. Here is the log you requested. The Advanced Cleaner and/or Ian_Monitor were no where to be found in add/remove programs. When I tried to delete them it said they were in use. I ended the process and was able to delete the files. No luck with msconfig though. When I type it in the run box it says that msconfig can not be found. There was no C:\WINDOWS\system32\tonhfjls file in explorer. As you can see we still have the awvvt.dll file. That appears to be my problem. The computer is running fine right now but if the past is any indication this will put files back on my computer. After a few startups and shutdowns a awvvt.exe will appear in my sys32 file along with a number of dll files and my adaware and spybot will inform me I have the vundo virus.

Thanks again.

Logfile of HijackThis v1.99.1
Scan saved at 11:52, on 2008-01-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon .exe
C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\Scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {53F2E36F-6B3D-4F2D-B5F3-6A7AF183AE56} - C:\WINDOWS\system32\awvvt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NAV Agent] C:\DOCUME~1\John\MYDOCU~1\Programs\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\DOCUME~1\John\MYDOCU~1\Programs\ZONEAL~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig .exe /auto
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Documents and Settings\John\My Documents\Programs\Norton Antivrus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Redwings

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI