Here is the HiJackThis Log. I need to know everything to do, fast as posible. Much appreciated.
::EDIT::
Posted Logfile in Reply.
Edited by Chron8891, 08 May 2008 - 05:18 PM.
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
Edited by Chron8891, 08 May 2008 - 05:18 PM.
[kill explorer]C:\WINDOWS\system32\vtUlKdDS.dllC:\WINDOWS\system32\isrbcycv.dllC:\WINDOWS\system32\vtUoLDTL.dllC:\WINDOWS\system32\lyaeewyv.dllC:\WINDOWS\privacy_danger\index.htmC:\WINDOWS\system32\vyweeayl.ini2 C:\WINDOWS\system32\lyaeewyv.dll C:\WINDOWS\system32\isrbcycv.dll C:\WINDOWS\system32\hbunlncg.exe C:\WINDOWS\system32\cscnmifp.dll C:\WINDOWS\system32\phnoausb.dll C:\WINDOWS\system32\sneuoyrv.exe C:\WINDOWS\system32\flxtlsxt.dll C:\WINDOWS\system32\winpfz33.sys C:\WINDOWS\system32\qkqwdcud.dll C:\WINDOWS\system32\gvrvbrel.exe C:\WINDOWS\system32\lgdmpypk.dll C:\WINDOWS\system32\fwoncjpt.dll C:\WINDOWS\system32\TCffOXyb.ini2 C:\WINDOWS\system32\byXOffCT.dll C:\WINDOWS\system32\g93.exe C:\WINDOWS\system32\qoMeEUMg.dll C:\WINDOWS\system32\lxtuxsum.exe C:\WINDOWS\system32\xgosuetw.dll C:\WINDOWS\system32\tstfmjne.dll C:\WINDOWS\system32\LTDLoUtv.ini2 C:\WINDOWS\system32\vtUoLDTL.dll C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe C:\WINDOWS\system32\gside.exe C:\WINDOWS\system32\gjjiQqss.ini2C:\WINDOWS\system32\mysidesearch_sidebar.dllC:\WINDOWS\QW5uZSBSdXRsZWRnZQ C:\WINDOWS\system32\xIT2 C:\WINDOWS\system32\ViBE C:\WINDOWS\system32\ad1 C:\WINDOWS\system32\1019b C:\Documents and Settings\All Users\Application Data\cvuzcpahHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9506910A-0F94-4ea1-B567-7070428B8B2B}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{992CFEB9-FE49-4E64-B377-F97BC3728806}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d024223-33ed-6cea-c175-82dc5269d99f}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7E81B89-DF38-40C8-A767-6FBECB65B862}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d0f8a166-f0a2-4322-a034-40e434778328}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6F5A45F-2D7A-419D-BE5A-27FA6ED1611F}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BM9761686fHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\94525bf3HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0\\SourceHKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0\\FriendlyNameHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{A7E81B89-DF38-40C8-A767-6FBECB65B862}HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgGwtTnMHKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUlKdDS EmptyTemp[start explorer]
Begin copying here:Files to delete:C:\WINDOWS\system32\vtUlKdDS.dllC:\WINDOWS\system32\isrbcycv.dllC:\WINDOWS\system32\vtUoLDTL.dllC:\WINDOWS\system32\lyaeewyv.dllC:\WINDOWS\privacy_danger\index.htmC:\WINDOWS\system32\vyweeayl.ini2C:\WINDOWS\system32\lyaeewyv.dllC:\WINDOWS\system32\isrbcycv.dllC:\WINDOWS\system32\hbunlncg.exeC:\WINDOWS\system32\cscnmifp.dllC:\WINDOWS\system32\phnoausb.dllC:\WINDOWS\system32\sneuoyrv.exeC:\WINDOWS\system32\flxtlsxt.dllC:\WINDOWS\system32\winpfz33.sysC:\WINDOWS\system32\qkqwdcud.dllC:\WINDOWS\system32\gvrvbrel.exeC:\WINDOWS\system32\lgdmpypk.dllC:\WINDOWS\system32\fwoncjpt.dllC:\WINDOWS\system32\TCffOXyb.ini2C:\WINDOWS\system32\byXOffCT.dllC:\WINDOWS\system32\g93.exeC:\WINDOWS\system32\qoMeEUMg.dllC:\WINDOWS\system32\lxtuxsum.exeC:\WINDOWS\system32\xgosuetw.dllC:\WINDOWS\system32\tstfmjne.dllC:\WINDOWS\system32\LTDLoUtv.ini2C:\WINDOWS\system32\vtUoLDTL.dllC:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exeC:\WINDOWS\system32\gside.exeC:\WINDOWS\system32\gjjiQqss.ini2C:\WINDOWS\system32\mysidesearch_sidebar.dllFolders to delete:C:\WINDOWS\QW5uZSBSdXRsZWRnZQC:\WINDOWS\system32\xIT2C:\WINDOWS\system32\ViBEC:\WINDOWS\system32\ad1C:\WINDOWS\system32\1019bC:\Documents and Settings\All Users\Application Data\cvuzcpahRegistry Keys to delete:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9506910A-0F94-4ea1-B567-7070428B8B2B}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{992CFEB9-FE49-4E64-B377-F97BC3728806}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d024223-33ed-6cea-c175-82dc5269d99f}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7E81B89-DF38-40C8-A767-6FBECB65B862}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d0f8a166-f0a2-4322-a034-40e434778328}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6F5A45F-2D7A-419D-BE5A-27FA6ED1611F}HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgGwtTnMHKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUlKdDSReistry values to delete:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | BM9761686fHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | 94525bf3HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0 | SourceHKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0 | FriendlyNameHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks | {6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks | {A7E81B89-DF38-40C8-A767-6FBECB65B862}
////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 11 22:14:32 2008 22:14:13: Error: Invalid registry syntax in command: "Reistry values to delete:" Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program. Skipping line. (Registry key deletion mode) 22:14:17: Error: Invalid registry syntax in command: "HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0 | Source" Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program. Skipping line. (Registry key deletion mode) 22:14:18: Error: Invalid registry syntax in command: "HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0 | FriendlyName" Only registry keys under the HKEY_LOCAL_MACHINE hive are accessible to this program. Skipping line. (Registry key deletion mode) ////////////////////////////////////////// Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! File "C:\WINDOWS\system32\vtUlKdDS.dll" deleted successfully. Error: file "C:\WINDOWS\system32\isrbcycv.dll" not found! Deletion of file "C:\WINDOWS\system32\isrbcycv.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\vtUoLDTL.dll" not found! Deletion of file "C:\WINDOWS\system32\vtUoLDTL.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\lyaeewyv.dll" not found! Deletion of file "C:\WINDOWS\system32\lyaeewyv.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: could not open file "C:\WINDOWS\privacy_danger\index.htm" Deletion of file "C:\WINDOWS\privacy_danger\index.htm" failed! Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND) --> bad path / the parent directory does not exist Error: file "C:\WINDOWS\system32\vyweeayl.ini2" not found! Deletion of file "C:\WINDOWS\system32\vyweeayl.ini2" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\lyaeewyv.dll" not found! Deletion of file "C:\WINDOWS\system32\lyaeewyv.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\isrbcycv.dll" not found! Deletion of file "C:\WINDOWS\system32\isrbcycv.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\hbunlncg.exe" deleted successfully. File "C:\WINDOWS\system32\cscnmifp.dll" deleted successfully. Error: file "C:\WINDOWS\system32\phnoausb.dll" not found! Deletion of file "C:\WINDOWS\system32\phnoausb.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\sneuoyrv.exe" deleted successfully. Error: file "C:\WINDOWS\system32\flxtlsxt.dll" not found! Deletion of file "C:\WINDOWS\system32\flxtlsxt.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\winpfz33.sys" not found! Deletion of file "C:\WINDOWS\system32\winpfz33.sys" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\qkqwdcud.dll" deleted successfully. File "C:\WINDOWS\system32\gvrvbrel.exe" deleted successfully. Error: file "C:\WINDOWS\system32\lgdmpypk.dll" not found! Deletion of file "C:\WINDOWS\system32\lgdmpypk.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\fwoncjpt.dll" deleted successfully. Error: file "C:\WINDOWS\system32\TCffOXyb.ini2" not found! Deletion of file "C:\WINDOWS\system32\TCffOXyb.ini2" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\byXOffCT.dll" not found! Deletion of file "C:\WINDOWS\system32\byXOffCT.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\g93.exe" not found! Deletion of file "C:\WINDOWS\system32\g93.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\qoMeEUMg.dll" not found! Deletion of file "C:\WINDOWS\system32\qoMeEUMg.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\lxtuxsum.exe" deleted successfully. Error: file "C:\WINDOWS\system32\xgosuetw.dll" not found! Deletion of file "C:\WINDOWS\system32\xgosuetw.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\tstfmjne.dll" deleted successfully. Error: file "C:\WINDOWS\system32\LTDLoUtv.ini2" not found! Deletion of file "C:\WINDOWS\system32\LTDLoUtv.ini2" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\vtUoLDTL.dll" not found! Deletion of file "C:\WINDOWS\system32\vtUoLDTL.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe" not found! Deletion of file "C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist File "C:\WINDOWS\system32\gside.exe" deleted successfully. File "C:\WINDOWS\system32\gjjiQqss.ini2" deleted successfully. Error: file "C:\WINDOWS\system32\mysidesearch_sidebar.dll" not found! Deletion of file "C:\WINDOWS\system32\mysidesearch_sidebar.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Folder "C:\WINDOWS\QW5uZSBSdXRsZWRnZQ" deleted successfully. Folder "C:\WINDOWS\system32\xIT2" deleted successfully. Folder "C:\WINDOWS\system32\ViBE" deleted successfully. Folder "C:\WINDOWS\system32\ad1" deleted successfully. Folder "C:\WINDOWS\system32\1019b" deleted successfully. Folder "C:\Documents and Settings\All Users\Application Data\cvuzcpah" deleted successfully. Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9506910A-0F94-4ea1-B567-7070428B8B2B}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9506910A-0F94-4ea1-B567-7070428B8B2B}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{992CFEB9-FE49-4E64-B377-F97BC3728806}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{992CFEB9-FE49-4E64-B377-F97BC3728806}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d024223-33ed-6cea-c175-82dc5269d99f}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9d024223-33ed-6cea-c175-82dc5269d99f}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A7E81B89-DF38-40C8-A767-6FBECB65B862}" deleted successfully. Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d0f8a166-f0a2-4322-a034-40e434778328}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d0f8a166-f0a2-4322-a034-40e434778328}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6F5A45F-2D7A-419D-BE5A-27FA6ED1611F}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6F5A45F-2D7A-419D-BE5A-27FA6ED1611F}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgGwtTnM" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgGwtTnM" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Registry key "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtUlKdDS" deleted successfully. Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | BM9761686f" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | BM9761686f" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | 94525bf3" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | 94525bf3" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks | {6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks | {6A6EAE1B-4AD6-4035-974D-504D6DBAA9C3}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks | {A7E81B89-DF38-40C8-A767-6FBECB65B862}" not found! Deletion of registry key "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks | {A7E81B89-DF38-40C8-A767-6FBECB65B862}" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Completed script processing. ******************* Finished! Terminate.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:29:54 PM, on 5/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\igfxtray.exe C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avp.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avz.exe C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avz.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/ R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [AVP] "C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avp.exe" O4 - HKLM\..\Run: [94525bf3] rundll32.exe "C:\WINDOWS\system32\gcvaedvt.dll",b O4 - HKLM\..\Run: [BM9761686f] Rundll32.exe "C:\WINDOWS\system32\coeacnhe.dll",s O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\ie_banner_deny.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\scieplugin.dll O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1204587399750 O20 - AppInit_DLLs: C:\PROGRA~1\DEFEND~1\DEFEND~1.0\adialhk.dll O23 - Service: Defender Pro Internet Security (AVP) - Defender Pro - C:\Program Files\Defender Pro\Defender Pro Internet Security 6.0\avz.exe -- End of file - 3757 bytes
Begin copying here:Files to delete:C:\WINDOWS\system32\dspiamst.dll C:\WINDOWS\system32\iwevmnuu.exe C:\WINDOWS\system32\ngtluhdq.dll C:\WINDOWS\system32\beiyiyyg.dll C:\WINDOWS\system32\edyhlluh.dll C:\WINDOWS\system32\xdvvqtvo.exe C:\WINDOWS\system32\wplvlapn.dll C:\WINDOWS\system32\coeacnhe.dll C:\WINDOWS\system32\tCfLmnpo.ini2 C:\WINDOWS\system32\opnmLfCt.dll C:\WINDOWS\system32\tbycmnld.exe C:\WINDOWS\system32\lyoqyuix.dll C:\WINDOWS\system32\OYIRrBeg.ini2 C:\WINDOWS\system32\geBrRIYO.dll C:\WINDOWS\system32\ogqbcdal.exe C:\WINDOWS\system32\dfujnthe.dll C:\WINDOWS\system32\kweaxrjf.exe C:\WINDOWS\system32\rrxgcrvx.dll C:\WINDOWS\system32\geBrRIYO.dllC:\WINDOWS\system32\dspiamst.dllC:\WINDOWS\system32\ngtluhdq.dllC:\WINDOWS\system32\beiyiyyg.dllC:\WINDOWS\system32\qhezsbsj.exeRegistry keys to delete:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8CA63FF4-8B5A-4CB7-9370-13995BD65856}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A1AAD61C-8B51-4FCF-8A77-56DC91A4A8E5}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AD3418C5-8088-416B-82E1-E76692A6876D}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b567b8ac-9bf5-4844-97e3-96a0d0d94a48}HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fsvvcyfqRegistry values to delete:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | 94525bf3HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | BM9761686fHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks | {A7E81B89-DF38-40C8-A767-6FBECB65B862}
0 members, 0 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.