Multiple Problems keep returning

  1. #1
    dan77 is offline Junior Member

    Multiple Problems keep returning

    Hello. Long story made shorter: I'm trying to cleanup my in-laws Win 2000 computer without much luck. It seems that even after running both Ad Aware and SpyBot S & D, and supposedly fixing the myriad problems, the problems return on next reboot, even though I have not re-connected to the Net. I've checked Add/Remove programs and don't see anything to remove.

    Anyway here is the HJ This Log. Thanks in advance for your help.

    Logfile of HijackThis v1.99.1
    Scan saved at 11:35:56 AM, on 10/14/2006
    Platform: Windows 2000 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\dllmgr64.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\sysmgr64.exe
    C:\WINNT\win32host.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\rundll32.exe
    C:\WINNT\Explorer.exe
    C:\WINNT\System32\dllsys64.exe
    C:\WINNT\System32\updated.exe
    C:\WINNT\System32\win32bootcfg.exe
    C:\WINNT\System32\taskmngr32.exe
    C:\kybrdff_17.exe
    C:\WINNT\Duce6.exe
    C:\WINNT\win3208087584923.exe
    C:\dfndrff_e1.exe
    C:\WINNT\win3207308758492.exe
    C:\program files\popupwithcast\septpop06apsept.exe
    C:\Program Files\Common Files\{3434660E-010A-1033-0723-980725960001}\Update.exe
    C:\PROGRA~1\COMMON~1\irof\irofm.exe
    C:\WINNT\System32\YMANTE~1\spool32.exe
    C:\Program Files\Common Files\?ecurity\??plorer.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
    C:\PROGRA~1\COMMON~1\irof\irofa.exe
    c:\winnt\system32\dwdsregt.exe
    C:\PROGRA~1\COMMON~1\irof\irofl.exe
    C:\Program Files\HijackThis.exe
    C:\Program Files\Internet Explorer\iexplore.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
    R3 - URLSearchHook: (no name) - {8396A36A-3D80-1E5E-F2F5-601348D53EC1} - C:\WINNT\System32\shdmexc.dll
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINNT\System32\rpdpq.exe
    F2 - REG:system.ini: UserInit=userinit.exe,dkjsbaw.exe
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {8396A36A-3D80-1E5E-F2F5-601348D53EC1} - C:\WINNT\System32\shdmexc.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: COMCASTTOOLBAR - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [MS DLL Library Manager] C:\WINNT\System32\dllsys64.exe
    O4 - HKLM\..\Run: [IRC Client] updated.exe
    O4 - HKLM\..\Run: [Windows Core Kernel Update] C:\WINNT\System32\win32bootcfg.exe
    O4 - HKLM\..\Run: [Task Manager Win32] C:\WINNT\System32\taskmngr32.exe
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_17.exe
    O4 - HKLM\..\Run: [TheMonitor] C:\WINNT\Duce6.exe
    O4 - HKLM\..\Run: [rsy3d3d1] RUNDLL32.EXE w0049f89.dll,n 0043d3cd000000030049f89
    O4 - HKLM\..\Run: [win3208087584923] C:\WINNT\win3208087584923.exe
    O4 - HKLM\..\Run: [defender] C:\\dfndrff_e1.exe
    O4 - HKLM\..\Run: [sys02584923087] C:\WINNT\sys02584923087.exe
    O4 - HKLM\..\Run: [win3207308758492] C:\WINNT\win3207308758492.exe
    O4 - HKLM\..\Run: [septpop06apsept] C:\program files\popupwithcast\septpop06apsept.exe
    O4 - HKLM\..\Run: [ntdll.dll] C:\WINNT\System32\bgllqt.exe reg_run
    O4 - HKLM\..\Run: [{46-66-60-0E-ZN}] c:\winnt\system32\dwdsregt.exe GEN001
    O4 - HKLM\..\RunServices: [IRC Client] updated.exe
    O4 - HKCU\..\Run: [IRC Client] updated.exe
    O4 - HKCU\..\Run: [irof] C:\PROGRA~1\COMMON~1\irof\irofm.exe
    O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
    O4 - HKCU\..\Run: [cprocsvc] C:\WINNT\System32\crunner\cproc.exe
    O4 - HKCU\..\Run: [Casb] "C:\WINNT\System32\YMANTE~1\spool32.exe" -vt yazr
    O4 - HKCU\..\Run: [Winsvr] C:\DOCUME~1\Paula\LOCALS~1\Temp\stdrun135632.exe
    O4 - HKCU\..\Run: [Xnfwyjw] C:\Program Files\Common Files\?ecurity\??plorer.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
    O4 - Startup: TA_Start.lnk = C:\TIGEN001.exe
    O15 - Trusted Zone: *.elitemediagroup.net
    O15 - Trusted Zone: *.media-motor.net
    O15 - Trusted Zone: *.mmohsix.com
    O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/...reeInstall.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...46/mcfscan.cab
    O20 - Winlogon Notify: Explorer - C:\WINNT\system32\fpno0353e.dll
    O23 - Service: dllmgr64 - Unknown owner - C:\WINNT\dllmgr64.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: sysmgr64 - Unknown owner - C:\WINNT\sysmgr64.exe
    O23 - Service: Win32 Kernel Update (Win32Kernel) - Unknown owner - C:\WINNT\win32host.exe
    Attached Files

  2. #2
    Neal is offline Dedicated Member
    Welcome, well that computer has a lot of infections for sure.



    Please download Look2Me-Remover.exe by Atribune to your desktop.
    • Close all windows before continuing.
    • Double-click Look2Me-Remover.exe to run it.
    • Put a check next to Run this program as a task.
    • You will receive a message saying Look2Me-Remover will close and re-open in approximately 10 seconds. Click OK
    • When Look2Me-Remover re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
    • Once it's done scanning, click the Remove L2M button.
    • You will receive a Done Scanning message, click OK.
    • When completed, you will receive this message: Done removing infected files! Look2Me-Remover will now shutdown your computer, click OK.
    • Your computer will then shutdown.
    • Turn your computer back on.
    • Please post the contents of C:\Look2Me-Remover.txt and a new HiJackThis log.
    If you receive a message from your firewall about this program accessing the internet please allow it.

    If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
    http://www.ascentive.com/support/new...b/MSWINSCK.OCX


    Also...


    Please download Qoofix by RubbeR DuckY from one of the following locations:

    http://www.malwarebytes.org/Qoofix.zip or
    http://www.besttechie.net/tools/Qoofix.zip
    1. Unzip all files to a convenient location such as C:\Qoofix.
    2. Go to the folder you unzipped all files and run Qoofix.exe.
    3. Click Begin Removal and wait for the scan to finish.
    4. If an infection has been found, select yes to restart your computer.

    Finally post a new Hijack This log and the contents of the Qoofix logfile and the look2me log. Thanks.

  3. #3
    dan77 is offline Junior Member
    Thanks for your help. It took me a while but here are the logs:Look2Me-Destroyer V1.0.12

    Scanning for infected files.....
    Scan started at 10/22/2006 8:34:09 AM


    Attempting to delete infected files...

    Making registry repairs.


    Restoring Windows certificates.

    Replaced hosts file with default windows hosts file


    Restoring SeDebugPrivilege for Administrators - Succeeded
    Qoofix v1.03 by http://www.malwarebytes.org
    Scan started on [10/22/2006] at [5:00:35 PM]
    -------------------------------------------------------------
    Terminated module: hnllhch.dll found in Qoofix.exe (1156)
    Terminated module: hnllhch.dll found in rundll32.exe (772)
    Terminated module: hnllhch.dll found in bgllqt.exe (876)
    Terminated module: hnllhch.dll found in rpdpq.exe (884)
    Terminated module: hnllhch.dll found in rpdpq.exe (924)
    Terminated module: hnllhch.dll found in rpdpq.exe (932)
    Terminated module: hnllhch.dll found in septpop06apsept (2084)
    Terminated module: hnllhch.dll found in 5Eplorer.exe (2276)
    Terminated module: hnllhch.dll found in PSFREE.EXE (2280)
    Terminated module: hnllhch.dll found in spool32.exe (716)
    Terminated module: hnllhch.dll found in Explorer.exe (732)
    -------------------------------------------------------------
    C:\WINNT\System32\bgllqt.exe will be deleted on reboot!
    C:\WINNT\System32\dkjsbaw.exe will be deleted on reboot!
    C:\WINNT\System32\hnllhch.dll will be deleted on reboot!
    C:\WINNT\System32\rpdpq.exe will be deleted on reboot!
    C:\WINNT\System32\hdboc.dat will be deleted on reboot!
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\tnxmw.exe will be deleted on reboot!

    User prompted YES to reboot, system now rebooting...
    -------------------------------------------------------------
    Scan COMPLETED SUCCESSFULLY on [10/22/2006] at [5:03:47 PM]

    Note: Some registry keys may have been removed.

    Logfile of HijackThis v1.99.1
    Scan saved at 5:13:03 PM, on 10/22/2006
    Platform: Windows 2000 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\UGF1bGEgU29tbWVycw\command.exe
    C:\WINNT\dllmgr64.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Network Monitor\netmon.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\sysmgr64.exe
    C:\WINNT\win32host.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\Explorer.exe
    C:\WINNT\System32\rundll32.exe
    C:\WINNT\System32\dllsys64.exe
    C:\WINNT\System32\updated.exe
    C:\WINNT\System32\win32bootcfg.exe
    C:\WINNT\System32\taskmngr32.exe
    C:\kybrdff_e34.exe
    C:\program files\popupwithcast\septpop06apsept.exe
    C:\WINNT\System32\mstskmgr.exe
    C:\WINNT\System32\winhelp32.exe
    C:\Program Files\Common Files\?ecurity\??plorer.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
    C:\WINNT\System32\YMANTE~1\spool32.exe
    C:\WINNT\System32\winhelp32.exe
    C:\Program Files\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
    R3 - URLSearchHook: (no name) - {3B3C9437-5BF1-2620-D6DD-73B5E3B4DDB8} - C:\WINNT\System32\ipzwrjdf.dll
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    F2 - REG:system.ini: Shell=Explorer.exe, C:\WINNT\System32\rpdpq.exe
    F2 - REG:system.ini: UserInit=C:\WINNT\System32\Userinit.exe,dkjsbaw.ex e
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: COMCASTTOOLBAR - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [MS DLL Library Manager] C:\WINNT\System32\dllsys64.exe
    O4 - HKLM\..\Run: [IRC Client] updated.exe
    O4 - HKLM\..\Run: [Windows Core Kernel Update] C:\WINNT\System32\win32bootcfg.exe
    O4 - HKLM\..\Run: [Task Manager Win32] C:\WINNT\System32\taskmngr32.exe
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e34.exe
    O4 - HKLM\..\Run: [bwpcqr] C:\WINNT\System32\bgllqt.exe reg_run
    O4 - HKLM\..\Run: [rsy3d3d1] RUNDLL32.EXE w0049f89.dll,n 0043d3cd000000030049f89
    O4 - HKLM\..\Run: [septpop06apsept] C:\program files\popupwithcast\septpop06apsept.exe
    O4 - HKLM\..\Run: [{46-66-60-0E-ZN}] c:\winnt\system32\omdsregp.exe GEN001
    O4 - HKLM\..\Run: [MS Task Manager 32] C:\WINNT\System32\mstskmgr.exe
    O4 - HKLM\..\Run: [Windows Help] winhelp32.exe
    O4 - HKLM\..\Run: [ntdll.dll] C:\WINNT\System32\win32bootcfg.exe
    O4 - HKLM\..\RunServices: [IRC Client] updated.exe
    O4 - HKLM\..\RunServices: [Windows Help] winhelp32.exe
    O4 - HKCU\..\Run: [IRC Client] updated.exe
    O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
    O4 - HKCU\..\Run: [cprocsvc] C:\WINNT\System32\crunner\cproc.exe
    O4 - HKCU\..\Run: [Winsvr] C:\DOCUME~1\Paula\LOCALS~1\Temp\stdrun135632.exe
    O4 - HKCU\..\Run: [Xnfwyjw] C:\Program Files\Common Files\?ecurity\??plorer.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
    O4 - HKCU\..\Run: [Casb] "C:\WINNT\System32\YMANTE~1\spool32.exe" -vt ndrv
    O4 - HKCU\..\Run: [wtwer] C:\WINNT\System32\bgllqt.exe reg_run
    O4 - Startup: TA_Start.lnk = C:\WINNT\system32\dwdsregt.exe
    O15 - Trusted Zone: *.elitemediagroup.net
    O15 - Trusted Zone: *.media-motor.net
    O15 - Trusted Zone: *.mmohsix.com
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1161469514928
    O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/...reeInstall.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...46/mcfscan.cab
    O20 - Winlogon Notify: IPConfMSP - C:\WINNT\system32\mhr2cenu.dll
    O20 - Winlogon Notify: WindowsUpdate - C:\WINNT\system32\lvp6097se.dll
    O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINNT\UGF1bGEgU29tbWVycw\command.exe
    O23 - Service: dllmgr64 - Unknown owner - C:\WINNT\dllmgr64.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
    O23 - Service: sysmgr64 - Unknown owner - C:\WINNT\sysmgr64.exe
    O23 - Service: Win32 Kernel Update (Win32Kernel) - Unknown owner - C:\WINNT\win32host.exe

  4. #4
    Neal is offline Dedicated Member
    Well part of the instructions worked and part did not, so...



    Go to Start > Run and type in Services.msc then click OK

    Click the Extended tab.

    Scroll down until you find Command Service.

    Click once on the service to highlight it.

    Click Stop

    Right-Click on the service.

    Click on 'Properties'

    Select the 'General' tab

    Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box

    From the drop-down menu, click on 'Disabled'

    Click the 'Apply' tab, then click 'OK'

    Next:

    Please run HijackThis and click Config -> Misc Tools -> Delete an NT service. In the Delete window, type Command Service and press OK. OK any prompts, close HijackThis, and restart your computer.


    Do the same for these bad services below one at a time:

    sysmgr64
    dllmgr64
    Win32 Kernel Update



    Go here to learn how to show hidden files/folders:

    http://www.xtra.co.nz/help/0,,4155-1916458,00.html#5

    Re-hide after we are done



    Go to next site:
    http://www.virustotal.com/en/indexf.html
    On top you'll find 'Browse'
    Click the browse button and browse to next file:

    C:\Program Files\Network Monitor\netmon.exe

    Click open.
    Then click the 'Send' button next to it.
    This will scan the file. Please be patient.
    Once scanned, copy and paste the results as well in your next reply.


    Also go to post #2 and run the the Look2Me Remover again and post that log please and a new hijackthis log, plus the scan results for the file above. Thanks.

  5. #5
    dan77 is offline Junior Member
    Neal,
    First of all, things seem to be slowly getting better, thanks to you. I tried to follow the instructions and was only partially successful.
    Hijack this was not able to find and fix Command service or Win32 Kernel Update even though they were both evident in services.msc. The other two were found by HJT.
    Also, C:\Program Files\Network Monitor\netmon.exe was not found, so could not be scanned.
    Here are the two logs you requested:
    Look2Me-Destroyer V1.0.12

    Scanning for infected files.....
    Scan started at 10/23/2006 5:44:08 PM

    Infected! C:\WINNT\system32\mhr2cenu.dll
    Infected! C:\WINNT\system32\rNsman.dll
    Infected! C:\WINNT\system32\nhmsdba.dll
    Infected! C:\WINNT\system32\rNsman.dll
    Infected! C:\WINNT\system32\n0p4la7q1d.dll
    Infected! C:\WINNT\System32\guard.tmp

    Attempting to delete infected files...

    Attempting to delete: C:\WINNT\system32\rNsman.dll
    C:\WINNT\system32\rNsman.dll Deleted successfully!

    Attempting to delete: C:\WINNT\system32\nhmsdba.dll
    C:\WINNT\system32\nhmsdba.dll Deleted successfully!

    Attempting to delete: C:\WINNT\system32\rNsman.dll
    C:\WINNT\system32\rNsman.dll Deleted successfully!

    Attempting to delete: C:\WINNT\system32\n0p4la7q1d.dll
    C:\WINNT\system32\n0p4la7q1d.dll Deleted successfully!

    Attempting to delete: C:\WINNT\System32\guard.tmp
    C:\WINNT\System32\guard.tmp Deleted successfully!

    Making registry repairs.

    Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Applets
    Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnceEx

    Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\She ll Extensions\Approved "{95FAB6FD-22F1-4084-8654-D5E8A77966AA}"
    HKCR\Clsid\{95FAB6FD-22F1-4084-8654-D5E8A77966AA}

    Restoring Windows certificates.

    Replaced hosts file with default windows hosts file


    Restoring SeDebugPrivilege for Administrators - Succeeded
    Logfile of HijackThis v1.99.1
    Scan saved at 7:03:35 PM, on 10/23/2006
    Platform: Windows 2000 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\System32\svchost.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\win32host.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\explorer.exe
    C:\WINNT\System32\dllsys64.exe
    C:\WINNT\System32\updated.exe
    C:\WINNT\System32\win32bootcfg.exe
    C:\WINNT\System32\taskmngr32.exe
    C:\kybrdff_e35.exe
    C:\program files\popupwithcast\septpop06apsept.exe
    C:\WINNT\System32\mstskmgr.exe
    C:\WINNT\System32\winhelp32.exe
    C:\dfndrff_e35.exe
    C:\nwnmff_e35.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Common Files\?ecurity\??plorer.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE
    C:\WINNT\System32\YMANTE~1\spool32.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\Mp***ent.exe
    C:\Program Files\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
    R3 - URLSearchHook: (no name) - {57DBB665-7CA5-5629-D7BD-55A7025AE2B8} - C:\WINNT\System32\vvgqsbqr.dll
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {57DBB665-7CA5-5629-D7BD-55A7025AE2B8} - C:\WINNT\System32\vvgqsbqr.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: COMCASTTOOLBAR - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [MS DLL Library Manager] C:\WINNT\System32\dllsys64.exe
    O4 - HKLM\..\Run: [IRC Client] updated.exe
    O4 - HKLM\..\Run: [Windows Core Kernel Update] C:\WINNT\System32\win32bootcfg.exe
    O4 - HKLM\..\Run: [Task Manager Win32] C:\WINNT\System32\taskmngr32.exe
    O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e35.exe
    O4 - HKLM\..\Run: [bwpcqr] C:\WINNT\System32\bgllqt.exe reg_run
    O4 - HKLM\..\Run: [rsy3d3d1] RUNDLL32.EXE w0049f89.dll,n 0043d3cd000000030049f89
    O4 - HKLM\..\Run: [septpop06apsept] C:\program files\popupwithcast\septpop06apsept.exe
    O4 - HKLM\..\Run: [{46-66-60-0E-ZN}] c:\winnt\system32\omdsregp.exe GEN001
    O4 - HKLM\..\Run: [MS Task Manager 32] C:\WINNT\System32\mstskmgr.exe
    O4 - HKLM\..\Run: [Windows Help] winhelp32.exe
    O4 - HKLM\..\Run: [defender] C:\\dfndrff_e35.exe
    O4 - HKLM\..\Run: [newname] C:\\nwnmff_e35.exe
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\RunServices: [IRC Client] updated.exe
    O4 - HKLM\..\RunServices: [Windows Help] winhelp32.exe
    O4 - HKCU\..\Run: [IRC Client] updated.exe
    O4 - HKCU\..\Run: [CMFibula] "C:\Program Files\CMFibula\CMFibula.exe"
    O4 - HKCU\..\Run: [cprocsvc] C:\WINNT\System32\crunner\cproc.exe
    O4 - HKCU\..\Run: [Winsvr] C:\DOCUME~1\Paula\LOCALS~1\Temp\stdrun135632.exe
    O4 - HKCU\..\Run: [Xnfwyjw] C:\Program Files\Common Files\?ecurity\??plorer.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.EXE"
    O4 - HKCU\..\Run: [Casb] "C:\WINNT\System32\YMANTE~1\spool32.exe" -vt ndrv
    O4 - Startup: TA_Start.lnk = C:\WINNT\system32\dwdsregt.exe
    O15 - Trusted Zone: *.elitemediagroup.net
    O15 - Trusted Zone: *.media-motor.net
    O15 - Trusted Zone: *.mmohsix.com
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1161469514928
    O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/...reeInstall.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...46/mcfscan.cab
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)

    Thank you again.

  6. #6
    Neal is offline Dedicated Member
    Hi,



    Download AVG anti-spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
    1. Once you have downloaded AVG anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right click on ewido in the system tray and uncheck "Start with Windows".
    3. Go to Start > Run and type: services.msc
    4. Press "OK".
    5. In Services, click the "Extended tab" and scroll down the list to find AVG anti-spyware 7.5 guard.
    6. When you find the guard service, double-click on it.
    7. In the Properties Window > General Tab that opens, click the "Stop" button.
    8. From the drop-down menu next to "Startup Type", click on "Manual".
    9. Now click "Apply", then "OK" and close the Services window.
    10. Once the setup is complete you will need run AVG anti-spyware and update the definition files.
    11. On the main screen select the icon "Update" then select the "Update now" link.
    12. Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
      If you are having problems with the updater, manually update with the AVG anti-spyware Full database installer from here.
    [*]Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.[*]Once in the Settings screen click on "Recommended actions" and then select "Quarantine".[*]Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
    Close AVG anti-spyware Do Not run a scan yet.
    Click My Computer, then C:\
    In the menu bar, File->New->Folder.
    That will create a folder named New Folder, which you can rename to "BFU"

    Please download Brute Force Uninstaller to your desktop.
    • Right click the BFU folder on your desktop, and choose Extract All
    • Click "Next"
    • In the box to choose where to extract the files to,
    • Click "Browse"
    • Click on the + sign next to "My Computer"
    • Click on "Local Disk (C or whatever your primary drive is
    • Click "Make New Folder"
    • Type in BFU
    • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
    3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
    Save it in the same folder you made earlier (c:\BFU).

    Do not run the Uninstaller and the Remover yet.

    Please reboot into Safemode:
    Turn on the computer.
    Immediately begin tapping the F8 key.
    Use the arrow keys to highlight Safe Mode and press the Enter key.
    • Lauch AVG anti-spyware by double-clicking the icon on your desktop.
    • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    • ewido will now begin the scanning process, be patient this may take a little time.
      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions"
    • Next select the "Reports" icon at the top.
    • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system. Make sure to remember where you save that file.
    Now close AVG anti-spyware..

    Open My Computer and navigate to the c:\BFU folder. Start the Brute Force Uninstaller by doubleclicking BFU.exe

    Behind the scriptline to execute field click the folder icon and select alcanshorty.bfu

    Press execute and let it do its job.

    Wait for the complete script execution box to pop up and press OK.
    Press exit to terminate the BFU program.


    Then...



    Open Hijackthis.

    Click the "Open the Misc Tools" section Button.

    Click the "Open Uninstall Manager" Button.

    Click the "Save list..." Button.

    Save it to your desktop. Copy and paste the contents into your reply.

  7. #7
    dan77 is offline Junior Member
    Ok, that went fairly smoothly thanks to your excellent instructions. In case I forget later, just another sincere word of thanks for all of your efforts. They are appreciated very much.
    Here are both of the reports:

    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 12:28:19 PM 10/25/2006

    + Scan result:



    C:\WINNT\thiselt.exe -> Adware.Agent : Cleaned with backup (quarantined).
    C:\WINNT\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINNT\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINNT\rbcwxtuv.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
    C:\WINNT\system32\BattyRun2.dll -> Adware.CASClient : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.fr015A -> Adware.CommAd : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.frEDF7 -> Adware.CommAd : Cleaned with backup (quarantined).
    C:\WINNT\system32\nsdD.dll -> Adware.EZula : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.fr0C56 -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.fr309F -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.fr7C77 -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.fr84B9 -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.frC700 -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.frD907 -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.frFF02 -> Adware.Look2Me : Cleaned with backup (quarantined).
    C:\WINNT\em.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
    C:\Program Files\PSCloner\PSCloner.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
    C:\Program Files\PSLister\PSLister.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
    C:\WINNT\MirarSetup_876057.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Program Files\Deskbar -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Program Files\Deskbar\Cache -> Adware.Softomate : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\GLB13.tmp/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined).
    C:\WINNT\TIELT001.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
    C:\WINNT\dllmgr64.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
    C:\WINNT\sysmgr64.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
    C:\WINNT\system32\eraseme_11313.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
    C:\WINNT\system32\eraseme_87421.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
    C:\WINNT\system32\eraseme_88045.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
    C:\WINNT\win32host.exe -> Backdoor.SdBot.xd : Cleaned with backup (quarantined).
    C:\nwnmff_17.exe_tobedeleted -> Downloader.Adload.fg : Cleaned with backup (quarantined).
    C:\nwnmff_18.exe -> Downloader.Adload.fg : Cleaned with backup (quarantined).
    C:\dfndrff_18.exe -> Downloader.Adload.fk : Cleaned with backup (quarantined).
    C:\mc44a34.exe -> Downloader.Adload.fu : Cleaned with backup (quarantined).
    C:\dfndrff_e34.exe -> Downloader.Adload.ha : Cleaned with backup (quarantined).
    C:\nwnmff_e34.exe -> Downloader.Adload.hb : Cleaned with backup (quarantined).
    C:\WINNT\system32\dmonwv.dll_tobedeleted -> Downloader.Agent.agw : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\7.exe -> Downloader.Agent.aox : Cleaned with backup (quarantined).
    C:\topaff.exe -> Downloader.Agent.aqx : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\web2.exe -> Downloader.Agent.xq : Cleaned with backup (quarantined).
    C:\WINNT\srvvrazriw.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
    C:\814.exe -> Downloader.Dyfuca.fb : Cleaned with backup (quarantined).
    C:\WINNT\system32\qaz -> Downloader.Ftp.cb : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\!update.exe -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
    C:\installerwnusnewer.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.fr9BF5 -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\WINNT\idlemg.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
    C:\WINNT\ac3_0002.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
    C:\ac3_0003.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\stdrun132560.exe -> Downloader.Small.dtl : Cleaned with backup (quarantined).
    C:\Program Files\Common Files\irof\irofd\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
    C:\803_104.exe -> Dropper.Mudrop.bq : Cleaned with backup (quarantined).
    C:\dfndrff_e1.exe -> Hijacker.VB.ia : Cleaned with backup (quarantined).
    C:\WINNT\thkpkum.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
    C:\dfndrff_e.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\temp.frA0B8 -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\CC33TYYK\update[1].exe -> Proxy.Agent.hd : Cleaned with backup (quarantined).
    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\J8EJBYC1\update[1].exe -> Proxy.Agent.hd : Cleaned with backup (quarantined).
    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\ROW97HXG\j2update[1].exe -> Proxy.Agent.hd : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temporary Internet Files\Content.IE5\8RATU4EX\update[1].exe -> Proxy.Agent.hd : Cleaned with backup (quarantined).
    C:\WINNT\system32\taskmngr32.exe -> Proxy.Agent.hd : Cleaned with backup (quarantined).
    C:\winhelp32.exe -> Proxy.Agent.hd : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Local Settings\Temp\sp_m3_v81.exe -> Proxy.Dlena.w : Cleaned with backup (quarantined).
    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\J8EJBYC1\j2update[1].exe -> Proxy.Ranky : Cleaned with backup (quarantined).
    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\ROW97HXG\k2sys64[1].exe -> Proxy.Ranky : Cleaned with backup (quarantined).
    C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\VLCBSQNF\mstskmgr[1].exe -> Proxy.Ranky : Cleaned with backup (quarantined).
    C:\WINNT\system32\mstskmgr.exe -> Proxy.Ranky : Cleaned with backup (quarantined).
    C:\mstskmgr.exe -> Proxy.Ranky : Cleaned with backup (quarantined).
    C:\msutil64.exe -> Proxy.Ranky : Cleaned with backup (quarantined).
    C:\Documents and Settings\Paula\Cookies\paula@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Paula\Cookies\paula@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Paula\Cookies\paula@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\WINNT\uni_ehhhh.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\WINNT\uninst104.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
    C:\WINNT\system32\msvcrl.dll -> Worm.Locksky.ao : Cleaned with backup (quarantined).


    ::Report end

    Adobe Flash Player 9 ActiveX
    AVG Anti-Spyware 7.5
    HijackThis 1.99.1
    McAfee Personal Firewall Plus
    McAfee SecurityCenter
    McAfee VirusScan
    Microsoft Excel 97
    Microsoft Internet Explorer 6 SP1
    Microsoft Word 97
    Pop-Up Stopper Free Edition
    PowerArchiver 2006 v9.63
    Windows 2000 Service Pack 4

  8. #8
    Neal is offline Dedicated Member
    Save 20% on AVG Internet Security 2012 Suite!
    Good job and your welcome,


    I need to see a new hijackthis log and tell me how your computer is behaving now please.

+ Reply to Thread