Unsolved

This post is more than 5 years old

25 Posts

2256

October 8th, 2006 15:00

I am Infected By system32

Hi,
I seem to be infected by a something called system32. it is always downloading spyware on. and giving me these extremely annoying pop-ups. I have tried to delete this file but it wont let me. not even my anti virus can delete it. it is a pain in the neck and im despretly in need of assistance. Please Help!!

10.4K Posts

October 8th, 2006 17:00

Hunter5153
 
Go Here And download HijackThis

Save it in a convenient permanent folder such as C:\\HJT\\, double click HijackThis.exe, and hit "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that, save the log, Ctrl-A to Select All, and copy its contents as a reply to this thread.
 
bamajim   Graduate of Malware Removal University


 

25 Posts

October 8th, 2006 18:00

hey thanks here is the log.
 
Logfile of HijackThis v1.99.1
Scan saved at 3:36:48 PM, on 10/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\1159963487\ee\services\safetyCore\ver2_5_4_1\aolavupd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\ismini.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\AOL\1159963487\ee\services\safetyCore\ver2_5_4_1\AOLSP Scheduler.exe
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\{5C49667B-0AE9-1033-0610-041116050001}\Update.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\AOL\1159963487\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\1159963487\ee\aolsoftware.exe
C:\Program Files\WordPerfect Office 12\Programs\wpwin12.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\hpbpro.exe
C:\WINDOWS\system32\hpboid.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aol\aol toolbar 3.1\aoltbhelper.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC12.exe
C:\WINDOWS\system32\HPZipm12.exe
c:\program files\common files\aol\1159963487\ee\aexplore.exe
C:\Documents and Settings\Owner\My Documents\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0C66DEB0-7356-A6C0-6EF1-01ECB82B7EEE} - C:\WINDOWS\system32\rftufqg.dll
O2 - BHO: (no name) - {0E24427B-DF2A-40EB-980B-A819F5FF3DD0} - C:\WINDOWS\system32\ddccaax.dll
O2 - BHO: (no name) - {185087B5-5A3B-A974-3599-09D1B346D78A} - C:\WINDOWS\system32\inahbei.dll
O2 - BHO: (no name) - {2CBFB094-1B49-B3AB-A763-0716F29D317E} - C:\WINDOWS\system32\gixeduk.dll
O2 - BHO: (no name) - {2F10DD51-51D1-AC11-4A75-0286BBDCDE6B} - C:\WINDOWS\system32\ziollqk.dll
O2 - BHO: (no name) - {4E5041D4-0032-7A67-0FBF-04EF165952AA} - C:\WINDOWS\system32\tswdhcb.dll
O2 - BHO: (no name) - {6EB0F0F8-BF32-4A87-95AD-BCBF48CD8208} - C:\WINDOWS\system32\ssttq.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: (no name) - {849B9523-785F-4014-9CAF-079FB4A74C61} - C:\WINDOWS\system32\oufwhltm.dll
O2 - BHO: (no name) - {A1D9C1E5-E192-4D90-8814-31A6C1F6CD6C} - C:\WINDOWS\system32\mllmn.dll (file missing)
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C49667B-0AE9-1033-0610-041116050001}\MyToolBar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C49667B-0AE9-1033-0610-041116050001}\MyToolBar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [WordPerfect Office 1215] C:\Program Files\WordPerfect Office 12\Programs\Registration.exe /title="WordPerfect Office 12" /date=101806 serial=wa12wrx-0000002-hmd lang=EN
O4 - HKLM\..\Run: [gixeduk.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\gixeduk.dll,wicltjb
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\mwintpes.exe ELT001
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1159963487\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1159963487\ee\services\safetyCore\ver2_5_4_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1159963487\ee\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [{96-66-67-7B-ZN}] c:\windows\system32\dwdsregt.exe ELT001
O4 - HKLM\..\Run: [gnbnefh.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\gnbnefh.dll,nwqpqc
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [spoblkc.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\spoblkc.dll,dxurjnd
O4 - HKLM\..\Run: [dkgnmx.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\dkgnmx.dll,mxzgzsd
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: ddccaax - C:\WINDOWS\SYSTEM32\ddccaax.dll
O20 - Winlogon Notify: ssttq - C:\WINDOWS\system32\ssttq.dll
O20 - Winlogon Notify: vturroo - vturroo.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winkve32 - C:\WINDOWS\SYSTEM32\winkve32.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll (file missing)
O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1159963487\ee\services\safetyCore\ver2_5_4_1\aolavupd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: Network Monitor - Unknown owner - C:\WINDOWS\.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
 

10.4K Posts

October 8th, 2006 18:00

Hunter5153
 
Please go here

And Download SmitFraudFix by S!ri


Save it to your Desktop->>Rt Click->>Extract all->>and extract it to your desktop
Open the Smitfraudfix folder
Double-click smitfraudfix.cmd
Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt
Open that file, Ctrl+A to copy, and post a copy of that log as a reply to this thread

Do Not run option 2 until instructed to do so

bamajim   Graduate of Malware Removal University
 

 

25 Posts

October 8th, 2006 19:00

hey here u go. and once again thanks
 
SmitFraudFix v2.105
Scan done at 16:31:50.00, Sun 10/08/2006
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\ishost.exe FOUND !
C:\WINDOWS\system32\ismini.exe FOUND !
C:\WINDOWS\system32\isnotify.exe FOUND !
C:\WINDOWS\system32\issearch.exe FOUND !
C:\WINDOWS\system32\ixt?.dll FOUND !
C:\WINDOWS\system32\ixt??.dll FOUND !
C:\WINDOWS\system32\components\flx?.dll FOUND !
C:\WINDOWS\system32\components\flx??.dll FOUND !
C:\WINDOWS\system32\components\flx???.dll FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1

»»»»»»»»»»»»»»»»»»»»»»»» Desktop

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
 
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}"
 
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection

»»»»»»»»»»»»»»»»»»»»»»»» End
 

10.4K Posts

October 8th, 2006 20:00


Hunter5153

1. Reboot your PC into Safe Mode
This can be done by
  • Restart your PC, and after it starts, but before you see the Windows Splash screen
    Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
    Use your arrow keys and select Safe Mode and then Enter


2. Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
  • Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : " Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
    The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question " Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if your computer does not restart automatically please do it yourself manually. Reboot in Safe Mode. to finihs the cleaning

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

3. Reboot into Normal mode

4. Re Run Hijackthis
  • At the Main window select " Open the misc tool section"
    Then select " Open uninstall manager"
    Then " save list" and save it to your desktop


Copy and paste that list as a reply to this thread

Your reply should inlcude
  • your rapport.txt log from Smitfraudfix
    your uninstall_list.txt from Hijackthis
      bamajim   Graduate of Malware Removal University


      25 Posts

      October 9th, 2006 00:00

      ok here are the results
       
      SmitFraudFix v2.106
      Scan done at 20:40:15.31, Sun 10/08/2006
      Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix\SmitfraudFix
      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
      Fix run in safe mode
      »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
      !!!Attention, following keys are not inevitably infected!!!
      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll
      »»»»»»»»»»»»»»»»»»»»»»»» Killing process

      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
       
       
      Hijack This List
       
      Logfile of HijackThis v1.99.1
      Scan saved at 3:36:48 PM, on 10/8/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\AOL\1159963487\ee\services\safetyCore\ver2_5_4_1\aolavupd.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\mcafee.com\personal firewall\MPFService.exe
      C:\WINDOWS\system32\ishost.exe
      C:\WINDOWS\system32\isnotify.exe
      C:\WINDOWS\system32\issearch.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\WINDOWS\system32\ismini.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
      C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Common Files\AOL\1159963487\ee\services\safetyCore\ver2_5_4_1\AOLSP Scheduler.exe
      C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Common Files\{5C49667B-0AE9-1033-0610-041116050001}\Update.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\Program Files\Common Files\AOL\1159963487\ee\aolsoftware.exe
      C:\Program Files\Common Files\AOL\1159963487\ee\aolsoftware.exe
      C:\Program Files\WordPerfect Office 12\Programs\wpwin12.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\hpbpro.exe
      C:\WINDOWS\system32\hpboid.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      c:\program files\aol\aol toolbar 3.1\aoltbhelper.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC12.exe
      C:\WINDOWS\system32\HPZipm12.exe
      c:\program files\common files\aol\1159963487\ee\aexplore.exe
      C:\Documents and Settings\Owner\My Documents\HijackThis.exe
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {0C66DEB0-7356-A6C0-6EF1-01ECB82B7EEE} - C:\WINDOWS\system32\rftufqg.dll
      O2 - BHO: (no name) - {0E24427B-DF2A-40EB-980B-A819F5FF3DD0} - C:\WINDOWS\system32\ddccaax.dll
      O2 - BHO: (no name) - {185087B5-5A3B-A974-3599-09D1B346D78A} - C:\WINDOWS\system32\inahbei.dll
      O2 - BHO: (no name) - {2CBFB094-1B49-B3AB-A763-0716F29D317E} - C:\WINDOWS\system32\gixeduk.dll
      O2 - BHO: (no name) - {2F10DD51-51D1-AC11-4A75-0286BBDCDE6B} - C:\WINDOWS\system32\ziollqk.dll
      O2 - BHO: (no name) - {4E5041D4-0032-7A67-0FBF-04EF165952AA} - C:\WINDOWS\system32\tswdhcb.dll
      O2 - BHO: (no name) - {6EB0F0F8-BF32-4A87-95AD-BCBF48CD8208} - C:\WINDOWS\system32\ssttq.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
      O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O2 - BHO: (no name) - {849B9523-785F-4014-9CAF-079FB4A74C61} - C:\WINDOWS\system32\oufwhltm.dll
      O2 - BHO: (no name) - {A1D9C1E5-E192-4D90-8814-31A6C1F6CD6C} - C:\WINDOWS\system32\mllmn.dll (file missing)
      O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll
      O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C49667B-0AE9-1033-0610-041116050001}\MyToolBar.dll
      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C49667B-0AE9-1033-0610-041116050001}\MyToolBar.dll
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
      O4 - HKLM\..\Run: [WordPerfect Office 1215] C:\Program Files\WordPerfect Office 12\Programs\Registration.exe /title="WordPerfect Office 12" /date=101806 serial=wa12wrx-0000002-hmd lang=EN
      O4 - HKLM\..\Run: [gixeduk.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\gixeduk.dll,wicltjb
      O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\mwintpes.exe ELT001
      O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1159963487\ee\AOLSoftware.exe
      O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1159963487\ee\services\safetyCore\ver2_5_4_1\AOLSP Scheduler.exe
      O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1159963487\ee\SSCRun.exe
      O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
      O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
      O4 - HKLM\..\Run: [{96-66-67-7B-ZN}] c:\windows\system32\dwdsregt.exe ELT001
      O4 - HKLM\..\Run: [gnbnefh.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\gnbnefh.dll,nwqpqc
      O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
      O4 - HKLM\..\Run: [spoblkc.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\spoblkc.dll,dxurjnd
      O4 - HKLM\..\Run: [dkgnmx.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\dkgnmx.dll,mxzgzsd
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
      O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O20 - Winlogon Notify: ddccaax - C:\WINDOWS\SYSTEM32\ddccaax.dll
      O20 - Winlogon Notify: ssttq - C:\WINDOWS\system32\ssttq.dll
      O20 - Winlogon Notify: vturroo - vturroo.dll (file missing)
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O20 - Winlogon Notify: winkve32 - C:\WINDOWS\SYSTEM32\winkve32.dll
      O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll (file missing)
      O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1159963487\ee\services\safetyCore\ver2_5_4_1\aolavupd.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
      O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
      O23 - Service: Network Monitor - Unknown owner - C:\WINDOWS\.exe (file missing)
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
       

      »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

      »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
       
      Registry Cleaning done.
       
      »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
      !!!Attention, following keys are not inevitably infected!!!
      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» End
       

      10.4K Posts

      October 9th, 2006 01:00

      Hunter5153
       
      I can't see the results of the Smitfruadfix option 2 log. Your Hijackthis log is posted in the center of it. Repost it please.
       
      Also Please review my previous post. I needed and uninstall list from Hijackthis, what you post was a Hijackthis log scan.
       
      Please repost both
       
      bamajim   Graduate of Malware Removal University


      25 Posts

      October 9th, 2006 10:00

      i cant seem to find where the un install list for hijack this has been saved. When i click on the save this button it doent tell me were it saved.
       
      But here is the other report.
       
      SmitFraudFix v2.106
      Scan done at  7:14:56.37, Mon 10/09/2006
      Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix\SmitfraudFix
      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
      Fix run in safe mode
      »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
      !!!Attention, following keys are not inevitably infected!!!
      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll
      »»»»»»»»»»»»»»»»»»»»»»»» Killing process

      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

      »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

      »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
       
      Registry Cleaning done.
       
      »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
      !!!Attention, following keys are not inevitably infected!!!
      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» End
       

      10.4K Posts

      October 9th, 2006 12:00

      Hunter5153
       
      First Please move Hijackthis to it's own folder, It can be done by

      Create a folder on the C: drive called C:\HJT.
      You can do this by going to My Computer (Windows key+e) then double click on C:
      then right click and select New then Folder and name it HJT.

      This way we will be able to find things easier
       

      Next Go here and Download AVG Anti-Spyware
      (30 day free trial version) Save it to Your Desktop
       
      Double Click AVG Anti-Spyware-setup
      (It will create its own folder)
      Once the program starts You will be at the Status menu

      • Under "Your computers Security"
        Click change status on Resident shield to inactive
        Click Update now (next to last update)
        After the update loads
        Under Automatic updates Uncheck download and install updates automatically(recommended)
        (you can always select maual updates the next day)
      At the top toolbar Click Scanner Then the settings tab
      • Under How to act? Set default action for detected malwareTo Quarantine
        Under how to scan All boxes should be checked
        Under Possibly unwanted software All boxes should be checked
        Under reports Select Automatically generate report after every scan
        Uncheck Only if threats were found
        Under what to scan Scan every file should be highlited
      Exit AVG(But do not run it yet)
       
      Reboot into Safe Mode
      This can be done by
      • Restart your PC, and after it starts, but before you see the Windows Splash screen
        Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
        Use your arrow keys and select Safe Mode and then Enter
      Run AVG Anti-Spyware
      • Click scanner
        Select Complete system scan
      Once the scan finishes
      • Select Apply all actions (The items found will be quarantined)
        Click save report as (Another window will open)
        Save it to your desktop
        (By default It will be saved in the AVG folder as)
        C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
      Exit AVG
       
      Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log
      • Double click the report-scan txt. you saved to your desktop
        It will open in Notepad
        Copy and paste that report as a reply to this thread

        Your reply should include
        a fresh Hijackthis log
        your report_scan.txt log from AVG
        bamajim   Graduate of Malware Removal University


        25 Posts

        October 9th, 2006 22:00

         
         
        ---------------------------------------------------------
        AVG Anti-Spyware - Scan Report
        ---------------------------------------------------------
          Created at: 7:01:45 PM 10/9/2006
          Scan result: 
         
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013028.exe -> Adware.CommAd : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013042.dll -> Adware.CommAd : Cleaned with backup (quarantined).
        HKU\S-1-5-21-1343024091-1336601894-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{052B12F7-86FA-4921-8482-26C42316B522} -> Adware.Generic : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013031.dll -> Adware.Mirar : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013032.dll -> Adware.Mirar : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013044.dll -> Adware.Mirar : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013073.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013043.dll -> Adware.Softomate : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0010003.dll -> Adware.TrafficSol : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013071.dll -> Adware.TrafficSol : Cleaned with backup (quarantined).
        C:\Downloads\Worms4MayhemSetup-dm[1].exe -> Adware.Trymedia : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP62\A0002213.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0014043.dll -> Adware.Virtumionde : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0018054.dll -> Adware.Virtumionde : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0019042.dll -> Adware.Virtumionde : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013040.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013067.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
        C:\WINDOWS\system32\mwintpes.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
        C:\WINDOWS\system32\pwintpes.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0010017.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013009.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013069.dll -> Downloader.Agent.awb : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013045.dll -> Downloader.Small : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013041.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013068.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0010004.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013010.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0010010.exe -> Downloader.Zlob.anw : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0011005.exe -> Downloader.Zlob.anw : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0012006.exe -> Downloader.Zlob.anw : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013006.exe -> Downloader.Zlob.anw : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0022051.exe -> Downloader.Zlob.anw : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0022052.exe -> Downloader.Zlob.anw : Cleaned with backup (quarantined).
        C:\WINDOWS\Temp\win4A.tmp -> Downloader.Zlob.aoc : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0038273.exe -> Downloader.Zlob.aop : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0009012.exe -> Hijacker.Small : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0018055.dll -> Logger.VBStat.e : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP62\A0002166.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0012014.dll -> Not-A-Virus.Hoax.Win32.Renos.ds : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0018052.dll -> Not-A-Virus.Hoax.Win32.Renos.ds : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0018053.dll -> Not-A-Virus.Hoax.Win32.Renos.ds : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0010011.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0011006.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0012005.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013005.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013039.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013050.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0014044.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0015045.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0017045.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0018045.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0018066.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0020051.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0021046.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0022045.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0022126.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0022130.exe -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0023129.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP87\A0023130.exe -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP88\A0023243.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP88\A0023247.exe -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP88\A0023258.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP88\A0023262.exe -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP88\A0024263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP88\A0025263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP89\A0026258.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP89\A0027263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0028258.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0029262.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0030263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0031263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0033263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0034263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0035263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0036263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0037263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0038263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0039263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0040263.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP90\A0040279.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP91\A0040290.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP91\A0040314.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP91\A0042334.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP91\A0043334.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP91\A0043367.dll -> Not-A-Virus.Hoax.Win32.Renos.fh : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013029.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
        C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@snapfish.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@z1.adserver[2].txt -> TrackingCookie.Adserver : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
        C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
        C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
        C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
        C:\Documents and Settings\LocalService\Cookies\system@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@ac2.valuead[2].txt -> TrackingCookie.Valuead : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@pmads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@reduxads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
        C:\Documents and Settings\Owner\Cookies\owner@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
        C:\WINDOWS\system32\winkve32.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).
         

        25 Posts

        October 9th, 2006 22:00

        here is the second part of the scan
         
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0018051.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP89\A0027273.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013019.exe -> Trojan.Starter.65 : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0010001.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0010002.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013025.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
        C:\System Volume Information\_restore{2173F9EA-4A7B-496A-A8D8-278692313FA5}\RP86\A0013076.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).

        ::Report end
         
        and i still cant find the report for the hijack un install list. Please help me find it
        I will imeediitly send it to u
         

        10.4K Posts

        October 10th, 2006 00:00


        Hunter5153

        It's possible the infection is interfering with it. When you select " save list" another window should open up allowing you to save it to your desktop.
        It will appear as uninstall_list.txt
        If you can rerun it and find it then you can repost it in your next reply

        First Copy and paste the following into NotePad (Not Wordpad)
        • sc stop "Network Monitor"
          sc delete "Network Monitor"

        Click File ->> Save as ->>type in cmd.bat
        • Under "Save as type" Select " all files" ->>Save it to your Desktop
          Close Notepad
          The cmd.bat file should now appear on your Desktop

          Double Click that file (It will appear that nothing has happened, but that's o.k.)

        Next Please download VundoFix.exe to your desktop.

        • Double-click VundoFix.exe to run it.
        • Click the Scan for Vundo button.
        • Once it's done scanning, click the Remove Vundo button.
        • You will receive a prompt asking if you want to remove the files, click YES
        • Once you click yes, your desktop will go blank as it starts removing Vundo.
        • When completed, it will prompt that it will reboot your computer, click OK.
        • Please post the contents of C:\vundofix.txt and a new HiJackThis log.

        Note: It is possible that VundoFix encountered a file it could not remove.

        In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

        your reply should include
        • your vundofix.txt log
          a fresh Hijackthis log
          bamajim   Graduate of Malware Removal University


          25 Posts

          October 10th, 2006 10:00

          heres the vundo list
           
          VundoFix V6.2.1
          Checking Java version...
          Java version is 1.5.0.8
          Scan started at 7:08:56 AM 10/10/2006
          Listing files found while scanning....
          C:\WINDOWS\system32\inahbei.dll
          C:\WINDOWS\system32\rftufqg.dll
          C:\WINDOWS\system32\spoblkc.dll
          C:\WINDOWS\system32\tswdhcb.dll
          C:\WINDOWS\system32\ziollqk.dll
          C:\WINDOWS\system32\xlpfcgoo.exe
          C:\WINDOWS\system32\ssttq.dll
          C:\WINDOWS\system32\qttss.ini
          C:\WINDOWS\system32\qttss.bak1
          C:\WINDOWS\system32\qttss.bak2
          C:\WINDOWS\system32\qttss.ini2
          C:\WINDOWS\system32\qttss.tmp
          Beginning removal...
           Attempting to delete C:\WINDOWS\system32\inahbei.dll
          C:\WINDOWS\system32\inahbei.dll Has been deleted!
           Attempting to delete C:\WINDOWS\system32\rftufqg.dll
          C:\WINDOWS\system32\rftufqg.dll Has been deleted!
           Attempting to delete C:\WINDOWS\system32\spoblkc.dll
          C:\WINDOWS\system32\spoblkc.dll Could not be deleted.
           Attempting to delete C:\WINDOWS\system32\tswdhcb.dll
          C:\WINDOWS\system32\tswdhcb.dll Has been deleted!
           Attempting to delete C:\WINDOWS\system32\ziollqk.dll
          C:\WINDOWS\system32\ziollqk.dll Has been deleted!
           Attempting to delete C:\WINDOWS\system32\xlpfcgoo.exe
          C:\WINDOWS\system32\xlpfcgoo.exe Has been deleted!
           Attempting to delete C:\WINDOWS\system32\ssttq.dll
          C:\WINDOWS\system32\ssttq.dll Could not be deleted.
           Attempting to delete C:\WINDOWS\system32\qttss.ini
          C:\WINDOWS\system32\qttss.ini Has been deleted!
           Attempting to delete C:\WINDOWS\system32\qttss.bak1
          C:\WINDOWS\system32\qttss.bak1 Has been deleted!
           Attempting to delete C:\WINDOWS\system32\qttss.bak2
          C:\WINDOWS\system32\qttss.bak2 Has been deleted!
           Attempting to delete C:\WINDOWS\system32\qttss.ini2
          C:\WINDOWS\system32\qttss.ini2 Has been deleted!
           Attempting to delete C:\WINDOWS\system32\qttss.tmp
          C:\WINDOWS\system32\qttss.tmp Has been deleted!
          Performing Repairs to the registry.
          Done!
          VundoFix V6.2.1
          Checking Java version...
          Java version is 1.5.0.8
          Scan started at 7:25:47 AM 10/10/2006
          Listing files found while scanning....
          C:\WINDOWS\system32\spoblkc.dll
          C:\WINDOWS\system32\ssttq.dll
          C:\WINDOWS\system32\qttss.ini
          C:\WINDOWS\system32\qttss.ini2
          Hijack This Log i was stull unable to find. I dont what is a matter. But ill try my best to do what ever you ask.

          10.4K Posts

          October 10th, 2006 18:00

          Hunter5153
           
          Good job so far
           
          Can I see a fresh Hijcakthis log please :smileyhappy:
           
          bamajim   Graduate of Malware Removal University

           

          25 Posts

          October 10th, 2006 19:00

          i cant seem to find the hijack this log. if there is any other thing i can do i will do it. it dosent prompt me where i want to save it. i just close's the application. If theres anyway we can find it i will surley do it. If not is there a way we can work around it.
          No Events found!

          Top