This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Lots of malware in computer

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, first of all, I'm using Windows XP. I'm getting bombarded with popups from sgviralscan[dot]com. I've tried and run Spybot S&D and Spyware Terminator but they don't pick it up. (not sure if these are good?) If these aren't good programs to use, please let me know of freeware that are good and I'll be sure to use those instead from now on as I think these may be bad programs…

Anyway, I get lots of redirects to sgviralscan.com, partners.mamma.com, cleanyourpc-now.com and scan.avnanocheck.com along with others I can't remember. I also was unable to open Explorer the other day until I restarted my machine… I also can't search google without being redirected! It's seriously getting out of hand…


Anyway, here's my HJT log. Thank you in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:32 AM, on 12/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\dipset.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\elections toolbar\ElectionsTbServer.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust…search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R3 - URLSearchHook: Elections Toolbar Search Class - {228c1d47-ddce-463a-802f-1f880261bc2a} - C:\Program Files\Elections Toolbar\electionstb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {31065C7D-466B-E9D6-E5D7-01E29F863683} - C:\WINDOWS\system32\zaxkeak.dll
O2 - BHO: Elections Loader - {355314af-a23c-4435-a356-2570dce4221f} - C:\Program Files\Elections Toolbar\electionstb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8F373D12-81F1-8256-A57E-8D5ACF7140C2} - C:\WINDOWS\System32\vbfl.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Elections Toolbar - {8791c498-5f4f-47bc-831d-8a3af1109fe0} - C:\Program Files\Elections Toolbar\electionstb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\dipset.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /waitstart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\RunServices: [wuosdial] wuosdial.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\Run: [wuosdial] wuosdial.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [WindowsRegKey Autoupdate] explorer.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Remote Procedure Call] winsysrpc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Remote Procedure Call] winsysrpc.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [wuosdial] wuosdial.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Remote Procedure Call] winsysrpc.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &Elections Search - C:\Documents and Settings\All Users\Application Data\Elections Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/p…er/install.cab
O20 - AppInit_DLLs: C:\WINDOWS\System32\camocx32.dll
O20 - Winlogon Notify: 64bc8b6e509 - C:\WINDOWS\System32\camocx32.dll
O20 - Winlogon Notify: __c00F6C5E - C:\WINDOWS\system32\__c00F6C5E.dat
O21 - SSODL: WildTangent CDA - {D216FD1B-89CF-76C3-342F-882439A2762D} - C:\Program Files\WildTangent\Apps\DRM0302Java.dll (file missing)
O21 - SSODL: OyWFgDIrJo - {64BC8B6F-CE16-21C5-75CB-3F0E7BF44889} - C:\WINDOWS\system32\ozjefc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
–
End of file - 7781 bytes
Hi SLove1106 and welcome to the forums here at WTT.

:welcome:

You are pretty seriously infected here, as you already know I guess….one of the main problems is you have no Anti-Virus. There is nothing wrong with the programs you are running (Spybot and Spyware Terminator) but a real time Anti-Virus is definitely needed as soon as we get you somewhat cleaner here. There are several good free ones available. I'm afraid if we try to install one now it will just get in the way of cleaning and go off like crazy. So let's run a couple tools and do some cleanup, then we'll get an AV installed ASAP.

First,
Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Next,
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Please also post an updated HijackThis log and let me know how it's running.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
First of all, thank you for the quick resonse. The following is are the logs for SDFix and a new HJT log.

I tried running ComboFix, but when it finished, all it said was Done on the screen, and no check was run nor was a log saved. I tried to run it again from my desktop but all that happens is I get a small screen that says ComboFix with the green dots that should mean it's loading, but nothing happens. Thank you.

SDFix Log


Checking Files :

Trojan Files Found:

C:\WINDOWS\system32\ozjefc.dll - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-10 10:44:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"c:\\aogly4.exe"="c:\\aogly4.exe:*:Enabled:DHCP Client"
"C:\\WINDOWS\\system32\\cssrss.exe"="C:\\WINDOWS\\system32\\cssrss.exe:*:Enabled:DHCP Client"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip


Infected System Files Found!

Below Files have been patched to load C:\WINDOWS\system32\ozjefc.dll :

C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe

Note - Run System File Checker To Restore Original Files - SFC /SCANNOW

Files with Hidden Attributes :

Sat 10 Jan 2009 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\1.tmp"
Thu 11 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\10.tmp"
Fri 12 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\11.tmp"
Sat 13 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\12.tmp"
Sun 14 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\13.tmp"
Mon 15 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\14.tmp"
Sat 20 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\15.tmp"
Sun 21 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\16.tmp"
Mon 22 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\17.tmp"
Tue 16 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\18.tmp"
Tue 16 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\19.tmp"
Wed 17 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\1A.tmp"
Thu 18 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\1B.tmp"
Wed 24 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\1C.tmp"
Mon 29 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\2F.tmp"
Sun 28 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\4.tmp"
Tue 30 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\42.tmp"
Sun 7 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\4EB.tmp"
Thu 25 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\51.tmp"
Fri 26 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\56.tmp"
Fri 9 Jan 2009 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\7.tmp"
Tue 6 Jan 2009 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\77.tmp"
Fri 25 Jan 2008 104,822 ..SHR — "C:\WINDOWS\SYSTEM32\amvo.exe"
Sat 10 Jan 2009 54,784 ..SHR — "C:\WINDOWS\SYSTEM32\amvo0.dll"
Tue 9 Dec 2008 373,760 A.SH. — "C:\WINDOWS\SYSTEM32\D.tmp"
Thu 3 Feb 2005 106 A..H. — "C:\WINDOWS\SYSTEM32\lsytni.dll"
Sat 24 Apr 2004 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 24 Apr 2004 401 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv15.bak"
Thu 10 Mar 2005 79,872 ..SHR — "C:\Documents and Settings\Delia\Application Data\eetu.exe"
Sat 10 Jan 2009 29,812 A..H. — "C:\Documents and Settings\Abet\Local Settings\Temp\9i.dll"
Thu 8 Jan 2009 45,568 A.SH. — "C:\Documents and Settings\Sandra\Local Settings\Temp\3.tmp"
Sat 10 Jan 2009 29,812 A..H. — "C:\Documents and Settings\Sandra\Local Settings\Temp\9i.dll"
Fri 19 Dec 2008 45,568 A.SH. — "C:\Documents and Settings\Sandra\Local Settings\Temp\D.tmp"
Fri 9 Jan 2009 45,568 A.SH. — "C:\Documents and Settings\Sandra\Local Settings\Temp\_A00F1203472E.exe"
Fri 19 Dec 2008 45,568 A.SH. — "C:\Documents and Settings\Sandra\Local Settings\Temp\_A00F2B5352E.exe"
Sat 10 Jan 2009 45,568 A.SH. — "C:\Documents and Settings\Sandra\Local Settings\Temp\_A00F25EDF.exe"
Thu 8 Jan 2009 45,568 A.SH. — "C:\Documents and Settings\Sandra\Local Settings\Temp\_A00FCDBC089.exe"
Mon 15 Jan 2007 3,584 ..SHR — "C:\Documents and Settings\Sherill\Local Settings\Temp\96729437.exe"
Sat 10 Jun 2000 1,285,632 A..H. — "C:\Program Files\eGames\Fishing\Fishing\WCSUP.DLL"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP172\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP172\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP173\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP173\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP174\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP174\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP175\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP175\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP176\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP176\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP177\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP177\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP178\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP178\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP179\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP179\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP180\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP180\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP181\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP183\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP183\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP184\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP184\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP185\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP185\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP186\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP186\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP187\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP187\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP188\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP188\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP189\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP189\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP190\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP190\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP191\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP191\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP192\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP192\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP193\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP193\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP194\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP194\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP195\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP195\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP196\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP196\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP197\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP197\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP198\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP198\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP200\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP200\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP201\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP201\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP202\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP202\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sun 7 Dec 2008 3,145,728 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP203\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Mon 18 Apr 2005 262,144 A..H. — "C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP203\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2144424107-1561912300-4230340574-1008.bak"
Sat 24 Apr 2004 4,348 …H. — "C:\Documents and Settings\Sandra\My Documents\My Music\License Backup\drmv1key.bak"
Tue 29 Aug 2006 401 A..H. — "C:\Documents and Settings\Sandra\My Documents\My Music\License Backup\drmv1lic.bak"
Thu 17 Aug 2006 400 …H. — "C:\Documents and Settings\Sandra\My Documents\My Music\License Backup\drmv2key.bak"
Tue 29 Aug 2006 1,536 A..H. — "C:\Documents and Settings\Sandra\My Documents\My Music\License Backup\drmv2lic.bak"

Finished!
HJT Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:23, on 2009-01-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\dipset.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R3 - URLSearchHook: Elections Toolbar Search Class - {228c1d47-ddce-463a-802f-1f880261bc2a} - C:\Program Files\Elections Toolbar\electionstb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {31065C7D-466B-E9D6-E5D7-01E29F863683} - C:\WINDOWS\system32\zaxkeak.dll
O2 - BHO: Elections Loader - {355314af-a23c-4435-a356-2570dce4221f} - C:\Program Files\Elections Toolbar\electionstb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {8F373D12-81F1-8256-A57E-8D5ACF7140C2} - C:\WINDOWS\System32\vbfl.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Elections Toolbar - {8791c498-5f4f-47bc-831d-8a3af1109fe0} - C:\Program Files\Elections Toolbar\electionstb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck /autofix /waitstart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\dipset.exe
O4 - HKLM\..\RunServices: [wuosdial] wuosdial.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKUS\S-1-5-18\..\Run: [wuosdial] wuosdial.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [WindowsRegKey Autoupdate] explorer.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Remote Procedure Call] winsysrpc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Remote Procedure Call] winsysrpc.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [wuosdial] wuosdial.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Remote Procedure Call] winsysrpc.exe (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: &Elections Search - C:\Documents and Settings\All Users\Application Data\Elections Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} - http://install.wildtangent.com/bgn/partner…ler/install.cab
O20 - Winlogon Notify: 64bc8b6e509 - C:\WINDOWS\System32\camocx32.dll
O20 - Winlogon Notify: __c00F6C5E - C:\WINDOWS\system32\__c00F6C5E.dat
O21 - SSODL: WildTangent CDA - {D216FD1B-89CF-76C3-342F-882439A2762D} - C:\Program Files\WildTangent\Apps\DRM0302Java.dll (file missing)
O21 - SSODL: OyWFgDIrJo - {64BC8B6F-CE16-21C5-75CB-3F0E7BF44889} - C:\WINDOWS\system32\ozjefc.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 8124 bytes
Oh, and please tell me how to run ComboFix since as I stated, it will not run and nothing happens. Also, no change from what I've seen. I still get redirected to other sites when I'm on the internet. Thank you.

Oh, and please tell me how to run ComboFix since as I stated, it will not run and nothing happens.


We have some options there but we need to deal with some issues and I need to advise you here….


Also, no change from what I've seen. I still get redirected to other sites when I'm on the internet.

Yes, this thing is very badly infected. Along with backdoors and god knows what else, you have a file infector and critical system files are infected as noted in the SDFix log.

Infected System Files Found!

Below Files have been patched to load C:\WINDOWS\system32\ozjefc.dll :

C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe

Note - Run System File Checker To Restore Original Files - SFC /SCANNOW

I don't normally advise this but considering the infections that you have and the risk I believe you need to be advised.

Important information: You have signs of a backdoor trojan and/or rootkit on your system (more info). These have the potential to harvest confidential data, and require special attention. Although rare, identity theft, or other fraudulent financial activity is a possibility. We generally have good success removing all signs of these infections. However, if you have adequate backups, required media (CDs), and the ability, at this point it would be wise to consider reformatting and reinstalling your operating system and applications. We can provide you with some helpful links if needed.

Since these infections may be used for remote access, or even remote control of an infected system, we recommend that you temporarily disconnect it from the Internet to protect yourself, and others. If you don’t have access to another system, and require Internet access, be sure to have a firewall installed. We recommend the free version of Comodo. Note: never run more than one firewall.

If you do online banking, any online financial transactions (including eBay and Paypal), or access any sensitive information online, please use a known clean computer, and change your passwords as soon as possible. It would also be wise to contact those same financial institutions to let them know your account information and passwords may have been compromised. Closely monitor all bank and credit card statements. In the event you do notice suspicious activity, it's important you act quickly. Follow these steps recommended by the FTC: Defend: Recover From Identity Theft.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

With that said, we do have good tools to clean these infections, but there are no guarantees with systems this bad. Let me know what you want to do and we'll go from there.
I'm in the process of downloading Comodo. Since these things have been happening to my computer, I have stopped logging onto personal accounts with this computer so I think I should be safe there. Please instruct me on what I should do next. By the way, I really do appreciate your taking time to help me. I've posted this problem in another forum over 3 weeks ago and still have not received a response, not even to tell me they'll be with me soon or anything. I know these tech forums run with volunteers so I'm understanding to their situation, which also makes me very thankful for your response here… So I'm VERY thankful you have helped and have at least acknowledged my existence… :) Thank you VERY much!
OK let's try this for combofix….

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]

  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
I can't seem to get ComboFix. Both links you've led me to in the above posts I've tried opening and all I get is the following. (See screenshot in attachment) I have saved it as Combo-Fix as opposed to ComboFix but I keep getting this in both. I have disabled all blockers and malware programs… Also so far, no redirects or pop-ups since downloading Comodo… Thank you. :) Just want to make sure everything else is ok now.

Attachments:

Hi,

Also so far, no redirects or pop-ups since downloading Comodo… Thank you. smile.gif Just want to make sure everything else is ok now.

While I'm glad you're not seeing the symptoms of the issue, I strongly doubt everything is ok. Unless you have done something I'm unaware of. Let's run the System File Checker as advised by SDFix. I was going to hold off on this until we were hopefully a little cleaner here. As the files may just get re-infected. Follow the instructions at the following link, then try downloading and running combofix again.

http://forums.majorgeeks.com/showthread.php?t=147786

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI