Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus problems


  • Please log in to reply
12 replies to this topic

#1 cd-spencer

cd-spencer

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 26 April 2005 - 02:47 PM

Hi

Thanks for your help so far...I have pasted my log file below

CS


Logfile of HijackThis v1.99.1
Scan saved at 8:37:34 PM, on 4/26/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\kernels32.exe
C:\Program Files\FaxTalk Communicator\FTCtrl32.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\RunDll32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\USBDRIVE\shwicon.exe
C:\windows\system32\taskmgn.exe
C:\temp\salm.exe
C:\Program Files\FaxTalk Communicator\FAPIEXE.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Documents and Settings\Chris Spencer\Local Settings\Temp\Temporary Directory 2 for HijackThis.zip\HijackThis.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Chris Spencer\Local Settings\Temp\Temporary Directory 8 for HijackThis.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://mshp.dll/index.html#22776
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#22776
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\kernels32.exe
O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~2\SEARCH~2.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {DE3BEBDB-AEE7-4277-8B6E-4EEFFA9508AE} - C:\WINDOWS\System32\kogiyu.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CallControl 4.5] C:\Program Files\FaxTalk Communicator\FTCtrl32.exe /autoload
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\image.new,Install
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [ShowIcon_Just Rams_USB Device Driver v1.25r004] "C:\Program Files\USBDRIVE\shwicon.exe" -t"Just Rams\USB Device Driver v1.25r004"
O4 - HKLM\..\Run: [Windows Task Manager] C:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [juzsh] C:\WINDOWS\juzsh.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels32.exe
O4 - HKLM\..\Run: [Pcu] C:\WINDOWS\Sea.exe
O4 - HKLM\..\Run: [Jhv] C:\WINDOWS\Ngp.exe
O4 - HKLM\..\Run: [Sqe] C:\WINDOWS\System32\Lvk.exe
O4 - HKLM\..\Run: [Ihj] C:\WINDOWS\System32\Utv.exe
O4 - HKLM\..\Run: [Aro] C:\WINDOWS\System32\Bqe.exe
O4 - HKLM\..\Run: [Kjg] C:\WINDOWS\System32\Cpm.exe
O4 - HKLM\..\Run: [One] C:\WINDOWS\Qcf.exe
O4 - HKLM\..\Run: [Pst] C:\WINDOWS\Dmh.exe
O4 - HKLM\..\Run: [Lla] C:\WINDOWS\Bqp.exe
O4 - HKLM\..\Run: [Utu] C:\WINDOWS\Rch.exe
O4 - HKLM\..\Run: [Tkr] C:\WINDOWS\Eet.exe
O4 - HKLM\..\Run: [Rdf] C:\WINDOWS\Bcb.exe
O4 - HKLM\..\Run: [Nsj] C:\WINDOWS\System32\Acp.exe
O4 - HKLM\..\Run: [Mgr] C:\WINDOWS\System32\Bcp.exe
O4 - HKLM\..\Run: [Epn] C:\WINDOWS\System32\Fjd.exe
O4 - HKLM\..\Run: [Ovq] C:\WINDOWS\Bmh.exe
O4 - HKLM\..\Run: [Fek] C:\WINDOWS\Lel.exe
O4 - HKLM\..\Run: [Lsk] C:\WINDOWS\System32\Gjd.exe
O4 - HKLM\..\Run: [Pip] C:\WINDOWS\System32\Had.exe
O4 - HKLM\..\Run: [Cld] C:\WINDOWS\Gph.exe
O4 - HKLM\..\Run: [Upe] C:\WINDOWS\Asl.exe
O4 - HKLM\..\Run: [Jrm] C:\WINDOWS\System32\Kio.exe
O4 - HKLM\..\Run: [Eev] C:\WINDOWS\System32\Sma.exe
O4 - HKLM\..\Run: [Cpu] C:\WINDOWS\Jqb.exe
O4 - HKLM\..\Run: [Vuv] C:\WINDOWS\Cas.exe
O4 - HKLM\..\Run: [Kdj] C:\WINDOWS\Uoj.exe
O4 - HKLM\..\Run: [Gds] C:\WINDOWS\Bgs.exe
O4 - HKLM\..\Run: [Aui] C:\WINDOWS\Pna.exe
O4 - HKLM\..\Run: [Uau] C:\WINDOWS\Lvj.exe
O4 - HKLM\..\Run: [Kpl] C:\WINDOWS\Uue.exe
O4 - HKLM\..\Run: [Bcv] C:\WINDOWS\Glq.exe
O4 - HKLM\..\Run: [Tlc] C:\WINDOWS\Iqj.exe
O4 - HKLM\..\Run: [Dst] C:\WINDOWS\Mft.exe
O4 - HKLM\..\Run: [Rmf] C:\WINDOWS\Gmj.exe
O4 - HKLM\..\Run: [Clj] C:\WINDOWS\Uvn.exe
O4 - HKLM\..\Run: [Ode] C:\WINDOWS\System32\Gds.exe
O4 - HKLM\..\Run: [Oco] C:\WINDOWS\Gsi.exe
O4 - HKLM\..\Run: [Mml] C:\WINDOWS\Ulu.exe
O4 - HKLM\..\Run: [Tsa] C:\WINDOWS\System32\Umg.exe
O4 - HKLM\..\Run: [Lqm] C:\WINDOWS\System32\Fau.exe
O4 - HKLM\..\Run: [Mln] C:\WINDOWS\System32\Iiu.exe
O4 - HKLM\..\Run: [Snq] C:\WINDOWS\Biu.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Rfg] C:\WINDOWS\Ikq.exe
O4 - HKLM\..\Run: [Igt] C:\WINDOWS\Qjs.exe
O4 - HKLM\..\Run: [Sdn] C:\WINDOWS\Loc.exe
O4 - HKLM\..\Run: [Ebj] C:\WINDOWS\System32\Der.exe
O4 - HKLM\..\Run: [Eoo] C:\WINDOWS\Jqe.exe
O4 - HKLM\..\Run: [Had] C:\WINDOWS\Mvf.exe
O4 - HKLM\..\Run: [Smq] C:\WINDOWS\System32\Auq.exe
O4 - HKLM\..\Run: [Tan] C:\WINDOWS\Ive.exe
O4 - HKLM\..\Run: [Afp] C:\WINDOWS\Dre.exe
O4 - HKLM\..\Run: [Urv] C:\WINDOWS\System32\Bhl.exe
O4 - HKLM\..\Run: [Ird] C:\WINDOWS\System32\Tto.exe
O4 - HKLM\..\Run: [Vea] C:\WINDOWS\Pvl.exe
O4 - HKLM\..\Run: [Umt] C:\WINDOWS\System32\Ohr.exe
O4 - HKLM\..\Run: [Bar] C:\WINDOWS\System32\Eae.exe
O4 - HKLM\..\Run: [Qft] C:\WINDOWS\Okf.exe
O4 - HKLM\..\Run: [Eme] C:\WINDOWS\Nff.exe
O4 - HKLM\..\Run: [Qsh] C:\WINDOWS\System32\Ddt.exe
O4 - HKLM\..\Run: [Cbq] C:\WINDOWS\Ver.exe
O4 - HKLM\..\Run: [Dsv] C:\WINDOWS\System32\Bcv.exe
O4 - HKLM\..\Run: [Lmj] C:\WINDOWS\Fei.exe
O4 - HKLM\..\Run: [Plt] C:\WINDOWS\Klu.exe
O4 - HKLM\..\Run: [Ibe] C:\WINDOWS\Iqk.exe
O4 - HKLM\..\Run: [Ipi] C:\WINDOWS\Qjj.exe
O4 - HKLM\..\Run: [Pin] C:\WINDOWS\System32\Gkv.exe
O4 - HKLM\..\Run: [Juf] C:\WINDOWS\Hih.exe
O4 - HKLM\..\Run: [Nlt] C:\WINDOWS\Fqj.exe
O4 - HKLM\..\Run: [Elm] C:\WINDOWS\Liq.exe
O4 - HKLM\..\Run: [Imu] C:\WINDOWS\Sok.exe
O4 - HKLM\..\Run: [Dpv] C:\WINDOWS\System32\Hcs.exe
O4 - HKLM\..\Run: [Jch] C:\WINDOWS\Mcd.exe
O4 - HKLM\..\Run: [Ios] C:\WINDOWS\System32\Lsi.exe
O4 - HKLM\..\Run: [Tnf] C:\WINDOWS\System32\Gdl.exe
O4 - HKLM\..\Run: [Icu] C:\WINDOWS\Qpu.exe
O4 - HKLM\..\Run: [Hsl] C:\WINDOWS\Qjl.exe
O4 - HKLM\..\Run: [Ibm] C:\WINDOWS\System32\Jht.exe
O4 - HKLM\..\Run: [Ohd] C:\WINDOWS\System32\Chi.exe
O4 - HKLM\..\Run: [Tjg] C:\WINDOWS\Vae.exe
O4 - HKLM\..\Run: [Tkn] C:\WINDOWS\Ulf.exe
O4 - HKLM\..\Run: [Iuc] C:\WINDOWS\System32\Qhq.exe
O4 - HKLM\..\Run: [Uvo] C:\WINDOWS\Ull.exe
O4 - HKLM\..\Run: [Gmp] C:\WINDOWS\Niv.exe
O4 - HKLM\..\Run: [Vde] C:\WINDOWS\System32\Qui.exe
O4 - HKLM\..\Run: [Tpa] C:\WINDOWS\Klq.exe
O4 - HKLM\..\Run: [Iud] C:\WINDOWS\Knc.exe
O4 - HKLM\..\Run: [Hjv] C:\WINDOWS\Flq.exe
O4 - HKLM\..\Run: [Snm] C:\WINDOWS\System32\Ttm.exe
O4 - HKLM\..\Run: [Jtr] C:\WINDOWS\System32\Bqc.exe
O4 - HKLM\..\Run: [Tvc] C:\WINDOWS\Mpr.exe
O4 - HKLM\..\Run: [Sfc] C:\WINDOWS\System32\Has.exe
O4 - HKLM\..\Run: [Sqq] C:\WINDOWS\System32\Unn.exe
O4 - HKLM\..\Run: [Obh] C:\WINDOWS\System32\Acg.exe
O4 - HKLM\..\Run: [Kih] C:\WINDOWS\Dit.exe
O4 - HKLM\..\Run: [Evo] C:\WINDOWS\System32\Shm.exe
O4 - HKLM\..\Run: [Teq] C:\WINDOWS\System32\Pod.exe
O4 - HKLM\..\Run: [Kjn] C:\WINDOWS\System32\Pmk.exe
O4 - HKLM\..\Run: [Pvn] C:\WINDOWS\System32\Ghn.exe
O4 - HKLM\..\Run: [Ssp] C:\WINDOWS\Jvr.exe
O4 - HKLM\..\Run: [Orj] C:\WINDOWS\Sif.exe
O4 - HKLM\..\Run: [Ehb] C:\WINDOWS\System32\Gga.exe
O4 - HKLM\..\Run: [Kgv] C:\WINDOWS\System32\Rcc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Pcu] C:\WINDOWS\Sea.exe
O4 - HKCU\..\Run: [Jhv] C:\WINDOWS\Ngp.exe
O4 - HKCU\..\Run: [Sqe] C:\WINDOWS\System32\Lvk.exe
O4 - HKCU\..\Run: [Ihj] C:\WINDOWS\System32\Utv.exe
O4 - HKCU\..\Run: [Aro] C:\WINDOWS\System32\Bqe.exe
O4 - HKCU\..\Run: [Kjg] C:\WINDOWS\System32\Cpm.exe
O4 - HKCU\..\Run: [One] C:\WINDOWS\Qcf.exe
O4 - HKCU\..\Run: [Pst] C:\WINDOWS\Dmh.exe
O4 - HKCU\..\Run: [Lla] C:\WINDOWS\Bqp.exe
O4 - HKCU\..\Run: [Utu] C:\WINDOWS\Rch.exe
O4 - HKCU\..\Run: [Tkr] C:\WINDOWS\Eet.exe
O4 - HKCU\..\Run: [Rdf] C:\WINDOWS\Bcb.exe
O4 - HKCU\..\Run: [Nsj] C:\WINDOWS\System32\Acp.exe
O4 - HKCU\..\Run: [Mgr] C:\WINDOWS\System32\Bcp.exe
O4 - HKCU\..\Run: [Epn] C:\WINDOWS\System32\Fjd.exe
O4 - HKCU\..\Run: [Ovq] C:\WINDOWS\Bmh.exe
O4 - HKCU\..\Run: [Fek] C:\WINDOWS\Lel.exe
O4 - HKCU\..\Run: [Lsk] C:\WINDOWS\System32\Gjd.exe
O4 - HKCU\..\Run: [Pip] C:\WINDOWS\System32\Had.exe
O4 - HKCU\..\Run: [Cld] C:\WINDOWS\Gph.exe
O4 - HKCU\..\Run: [Upe] C:\WINDOWS\Asl.exe
O4 - HKCU\..\Run: [Jrm] C:\WINDOWS\System32\Kio.exe
O4 - HKCU\..\Run: [Eev] C:\WINDOWS\System32\Sma.exe
O4 - HKCU\..\Run: [Cpu] C:\WINDOWS\Jqb.exe
O4 - HKCU\..\Run: [Vuv] C:\WINDOWS\Cas.exe
O4 - HKCU\..\Run: [Kdj] C:\WINDOWS\Uoj.exe
O4 - HKCU\..\Run: [Gds] C:\WINDOWS\Bgs.exe
O4 - HKCU\..\Run: [Aui] C:\WINDOWS\Pna.exe
O4 - HKCU\..\Run: [Uau] C:\WINDOWS\Lvj.exe
O4 - HKCU\..\Run: [Kpl] C:\WINDOWS\Uue.exe
O4 - HKCU\..\Run: [Bcv] C:\WINDOWS\Glq.exe
O4 - HKCU\..\Run: [Tlc] C:\WINDOWS\Iqj.exe
O4 - HKCU\..\Run: [Dst] C:\WINDOWS\Mft.exe
O4 - HKCU\..\Run: [Rmf] C:\WINDOWS\Gmj.exe
O4 - HKCU\..\Run: [Clj] C:\WINDOWS\Uvn.exe
O4 - HKCU\..\Run: [Ode] C:\WINDOWS\System32\Gds.exe
O4 - HKCU\..\Run: [Oco] C:\WINDOWS\Gsi.exe
O4 - HKCU\..\Run: [Mml] C:\WINDOWS\Ulu.exe
O4 - HKCU\..\Run: [Tsa] C:\WINDOWS\System32\Umg.exe
O4 - HKCU\..\Run: [Lqm] C:\WINDOWS\System32\Fau.exe
O4 - HKCU\..\Run: [Mln] C:\WINDOWS\System32\Iiu.exe
O4 - HKCU\..\Run: [Snq] C:\WINDOWS\Biu.exe
O4 - HKCU\..\Run: [Rfg] C:\WINDOWS\Ikq.exe
O4 - HKCU\..\Run: [Igt] C:\WINDOWS\Qjs.exe
O4 - HKCU\..\Run: [Sdn] C:\WINDOWS\Loc.exe
O4 - HKCU\..\Run: [Ebj] C:\WINDOWS\System32\Der.exe
O4 - HKCU\..\Run: [Eoo] C:\WINDOWS\Jqe.exe
O4 - HKCU\..\Run: [Had] C:\WINDOWS\Mvf.exe
O4 - HKCU\..\Run: [Smq] C:\WINDOWS\System32\Auq.exe
O4 - HKCU\..\Run: [Tan] C:\WINDOWS\Ive.exe
O4 - HKCU\..\Run: [Afp] C:\WINDOWS\Dre.exe
O4 - HKCU\..\Run: [Urv] C:\WINDOWS\System32\Bhl.exe
O4 - HKCU\..\Run: [Ird] C:\WINDOWS\System32\Tto.exe
O4 - HKCU\..\Run: [Vea] C:\WINDOWS\Pvl.exe
O4 - HKCU\..\Run: [Umt] C:\WINDOWS\System32\Ohr.exe
O4 - HKCU\..\Run: [Bar] C:\WINDOWS\System32\Eae.exe
O4 - HKCU\..\Run: [Qft] C:\WINDOWS\Okf.exe
O4 - HKCU\..\Run: [Eme] C:\WINDOWS\Nff.exe
O4 - HKCU\..\Run: [Qsh] C:\WINDOWS\System32\Ddt.exe
O4 - HKCU\..\Run: [Cbq] C:\WINDOWS\Ver.exe
O4 - HKCU\..\Run: [Dsv] C:\WINDOWS\System32\Bcv.exe
O4 - HKCU\..\Run: [Lmj] C:\WINDOWS\Fei.exe
O4 - HKCU\..\Run: [Plt] C:\WINDOWS\Klu.exe
O4 - HKCU\..\Run: [Ibe] C:\WINDOWS\Iqk.exe
O4 - HKCU\..\Run: [Ios] C:\WINDOWS\System32\Lsi.exe
O4 - HKCU\..\Run: [Tnf] C:\WINDOWS\System32\Gdl.exe
O4 - HKCU\..\Run: [Icu] C:\WINDOWS\Qpu.exe
O4 - HKCU\..\Run: [Hsl] C:\WINDOWS\Qjl.exe
O4 - HKCU\..\Run: [Ibm] C:\WINDOWS\System32\Jht.exe
O4 - HKCU\..\Run: [Ohd] C:\WINDOWS\System32\Chi.exe
O4 - HKCU\..\Run: [Tjg] C:\WINDOWS\Vae.exe
O4 - HKCU\..\Run: [Tkn] C:\WINDOWS\Ulf.exe
O4 - HKCU\..\Run: [Iuc] C:\WINDOWS\System32\Qhq.exe
O4 - HKCU\..\Run: [Uvo] C:\WINDOWS\Ull.exe
O4 - HKCU\..\Run: [Gmp] C:\WINDOWS\Niv.exe
O4 - HKCU\..\Run: [Vde] C:\WINDOWS\System32\Qui.exe
O4 - HKCU\..\Run: [Tpa] C:\WINDOWS\Klq.exe
O4 - HKCU\..\Run: [Iud] C:\WINDOWS\Knc.exe
O4 - HKCU\..\Run: [Hjv] C:\WINDOWS\Flq.exe
O4 - HKCU\..\Run: [Snm] C:\WINDOWS\System32\Ttm.exe
O4 - HKCU\..\Run: [Jtr] C:\WINDOWS\System32\Bqc.exe
O4 - HKCU\..\Run: [Tvc] C:\WINDOWS\Mpr.exe
O4 - HKCU\..\Run: [Sfc] C:\WINDOWS\System32\Has.exe
O4 - HKCU\..\Run: [Sqq] C:\WINDOWS\System32\Unn.exe
O4 - HKCU\..\Run: [Obh] C:\WINDOWS\System32\Acg.exe
O4 - HKCU\..\Run: [Kih] C:\WINDOWS\Dit.exe
O4 - HKCU\..\Run: [Evo] C:\WINDOWS\System32\Shm.exe
O4 - HKCU\..\Run: [Teq] C:\WINDOWS\System32\Pod.exe
O4 - HKCU\..\Run: [Kjn] C:\WINDOWS\System32\Pmk.exe
O4 - HKCU\..\Run: [Pvn] C:\WINDOWS\System32\Ghn.exe
O4 - HKCU\..\Run: [Ssp] C:\WINDOWS\Jvr.exe
O4 - HKCU\..\Run: [Orj] C:\WINDOWS\Sif.exe
O4 - HKCU\..\Run: [Ehb] C:\WINDOWS\System32\Gga.exe
O4 - HKCU\..\Run: [Kgv] C:\WINDOWS\System32\Rcc.exe
O4 - HKCU\..\RunServices: [Image] rundll32 C:\WINDOWS\image.new,Install
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O16 - DPF: Win32 Classes -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/AgeVerif...bridge-c420.cab
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
O20 - Winlogon Notify: f3dsl - C:\WINDOWS\SYSTEM32\MSplg7.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE

BC AdBot (Login to Remove)

 


#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:18 PM

Posted 26 April 2005 - 11:21 PM

Download cwshredder 2.12 from here:

http://cwshredder.net/bin/CWShredder.exe

Run the file after it is downloaded and click on the fix button. Let it do its thing and when its done, even if it crashes.

Please run two online virus scans:

http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
http://housecall.antivirus.com/

Then let us know if its working better and what the scans found.

#3 cd-spencer

cd-spencer
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 14 May 2005 - 11:09 AM

Hi

as advised I ran the cwshredder, and both of the web based scan, which removed a load of infected foles....but could not remove 2 called...

ker_ps.exe
kpssja.exe

....also once I logged off and then on again and went into Internet Explorer the virus alerts from AVG returned, many of the same ones as I had before.

Thanks for your help so far...any other ideas?

CS.

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:18 PM

Posted 14 May 2005 - 11:12 AM

Lets see a new hjt log

#5 cd-spencer

cd-spencer
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 15 May 2005 - 08:40 AM

New HJT log below, Thanks

CS


Logfile of HijackThis v1.99.1
Scan saved at 2:38:26 PM, on 5/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\kernels32.exe
C:\Program Files\FaxTalk Communicator\FTCtrl32.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\FaxTalk Communicator\FAPIEXE.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\RunDll32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\USBDRIVE\shwicon.exe
C:\windows\system32\taskmgn.exe
C:\temp\salm.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\kpssja.exe
C:\WINDOWS\System32\gah95on6.exe
C:\WINDOWS\System32\vxh8jkdq7.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\WINDOWS\System32\ker_ps.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\vxh8jkdq7.exe
C:\WINDOWS\System32\rundll32.exe
C:\Documents and Settings\Chris Spencer\Local Settings\Temp\Temporary Directory 4 for HijackThis.zip\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\kernels32.exe
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3 www.iframeprofit.com
O1 - Hosts: 127.0.0.3 www.loadcash.biz
O1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 www.iframedollars.biz
O1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3 www.aaasexypics.com
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 www.sexfiles.nu
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.autoescrowpay.com
O1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3 www.iframeprofit.com
O1 - Hosts: 127.0.0.3 www.loadcash.biz
O1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 www.iframedollars.biz
O1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3 www.aaasexypics.com
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 www.sexfiles.nu
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.autoescrowpay.com
O1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3 www.iframeprofit.com
O1 - Hosts: 127.0.0.3 www.loadcash.biz
O1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 www.iframedollars.biz
O1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3 www.aaasexypics.com
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 www.sexfiles.nu
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.autoescrowpay.com
O1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~2\SEARCH~2.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {DE3BEBDB-AEE7-4277-8B6E-4EEFFA9508AE} - C:\WINDOWS\System32\kogiyu.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CallControl 4.5] C:\Program Files\FaxTalk Communicator\FTCtrl32.exe /autoload
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [ShowIcon_Just Rams_USB Device Driver v1.25r004] "C:\Program Files\USBDRIVE\shwicon.exe" -t"Just Rams\USB Device Driver v1.25r004"
O4 - HKLM\..\Run: [Windows Task Manager] C:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [juzsh] C:\WINDOWS\juzsh.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels32.exe
O4 - HKLM\..\Run: [Pcu] C:\WINDOWS\Sea.exe
O4 - HKLM\..\Run: [Jhv] C:\WINDOWS\Ngp.exe
O4 - HKLM\..\Run: [Sqe] C:\WINDOWS\System32\Lvk.exe
O4 - HKLM\..\Run: [Ihj] C:\WINDOWS\System32\Utv.exe
O4 - HKLM\..\Run: [Aro] C:\WINDOWS\System32\Bqe.exe
O4 - HKLM\..\Run: [Kjg] C:\WINDOWS\System32\Cpm.exe
O4 - HKLM\..\Run: [One] C:\WINDOWS\Qcf.exe
O4 - HKLM\..\Run: [Pst] C:\WINDOWS\Dmh.exe
O4 - HKLM\..\Run: [Lla] C:\WINDOWS\Bqp.exe
O4 - HKLM\..\Run: [Utu] C:\WINDOWS\Rch.exe
O4 - HKLM\..\Run: [Tkr] C:\WINDOWS\Eet.exe
O4 - HKLM\..\Run: [Rdf] C:\WINDOWS\Bcb.exe
O4 - HKLM\..\Run: [Nsj] C:\WINDOWS\System32\Acp.exe
O4 - HKLM\..\Run: [Mgr] C:\WINDOWS\System32\Bcp.exe
O4 - HKLM\..\Run: [Epn] C:\WINDOWS\System32\Fjd.exe
O4 - HKLM\..\Run: [Ovq] C:\WINDOWS\Bmh.exe
O4 - HKLM\..\Run: [Fek] C:\WINDOWS\Lel.exe
O4 - HKLM\..\Run: [Lsk] C:\WINDOWS\System32\Gjd.exe
O4 - HKLM\..\Run: [Pip] C:\WINDOWS\System32\Had.exe
O4 - HKLM\..\Run: [Cld] C:\WINDOWS\Gph.exe
O4 - HKLM\..\Run: [Upe] C:\WINDOWS\Asl.exe
O4 - HKLM\..\Run: [Jrm] C:\WINDOWS\System32\Kio.exe
O4 - HKLM\..\Run: [Eev] C:\WINDOWS\System32\Sma.exe
O4 - HKLM\..\Run: [Cpu] C:\WINDOWS\Jqb.exe
O4 - HKLM\..\Run: [Vuv] C:\WINDOWS\Cas.exe
O4 - HKLM\..\Run: [Kdj] C:\WINDOWS\Uoj.exe
O4 - HKLM\..\Run: [Gds] C:\WINDOWS\Bgs.exe
O4 - HKLM\..\Run: [Aui] C:\WINDOWS\Pna.exe
O4 - HKLM\..\Run: [Uau] C:\WINDOWS\Lvj.exe
O4 - HKLM\..\Run: [Kpl] C:\WINDOWS\Uue.exe
O4 - HKLM\..\Run: [Bcv] C:\WINDOWS\Glq.exe
O4 - HKLM\..\Run: [Tlc] C:\WINDOWS\Iqj.exe
O4 - HKLM\..\Run: [Dst] C:\WINDOWS\Mft.exe
O4 - HKLM\..\Run: [Rmf] C:\WINDOWS\Gmj.exe
O4 - HKLM\..\Run: [Clj] C:\WINDOWS\Uvn.exe
O4 - HKLM\..\Run: [Ode] C:\WINDOWS\System32\Gds.exe
O4 - HKLM\..\Run: [Oco] C:\WINDOWS\Gsi.exe
O4 - HKLM\..\Run: [Mml] C:\WINDOWS\Ulu.exe
O4 - HKLM\..\Run: [Tsa] C:\WINDOWS\System32\Umg.exe
O4 - HKLM\..\Run: [Lqm] C:\WINDOWS\System32\Fau.exe
O4 - HKLM\..\Run: [Mln] C:\WINDOWS\System32\Iiu.exe
O4 - HKLM\..\Run: [Snq] C:\WINDOWS\Biu.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Rfg] C:\WINDOWS\Ikq.exe
O4 - HKLM\..\Run: [Igt] C:\WINDOWS\Qjs.exe
O4 - HKLM\..\Run: [Sdn] C:\WINDOWS\Loc.exe
O4 - HKLM\..\Run: [Ebj] C:\WINDOWS\System32\Der.exe
O4 - HKLM\..\Run: [Eoo] C:\WINDOWS\Jqe.exe
O4 - HKLM\..\Run: [Had] C:\WINDOWS\Mvf.exe
O4 - HKLM\..\Run: [Smq] C:\WINDOWS\System32\Auq.exe
O4 - HKLM\..\Run: [Tan] C:\WINDOWS\Ive.exe
O4 - HKLM\..\Run: [Afp] C:\WINDOWS\Dre.exe
O4 - HKLM\..\Run: [Urv] C:\WINDOWS\System32\Bhl.exe
O4 - HKLM\..\Run: [Ird] C:\WINDOWS\System32\Tto.exe
O4 - HKLM\..\Run: [Vea] C:\WINDOWS\Pvl.exe
O4 - HKLM\..\Run: [Umt] C:\WINDOWS\System32\Ohr.exe
O4 - HKLM\..\Run: [Bar] C:\WINDOWS\System32\Eae.exe
O4 - HKLM\..\Run: [Qft] C:\WINDOWS\Okf.exe
O4 - HKLM\..\Run: [Eme] C:\WINDOWS\Nff.exe
O4 - HKLM\..\Run: [Qsh] C:\WINDOWS\System32\Ddt.exe
O4 - HKLM\..\Run: [Cbq] C:\WINDOWS\Ver.exe
O4 - HKLM\..\Run: [Dsv] C:\WINDOWS\System32\Bcv.exe
O4 - HKLM\..\Run: [Lmj] C:\WINDOWS\Fei.exe
O4 - HKLM\..\Run: [Plt] C:\WINDOWS\Klu.exe
O4 - HKLM\..\Run: [Ibe] C:\WINDOWS\Iqk.exe
O4 - HKLM\..\Run: [Ipi] C:\WINDOWS\Qjj.exe
O4 - HKLM\..\Run: [Pin] C:\WINDOWS\System32\Gkv.exe
O4 - HKLM\..\Run: [Juf] C:\WINDOWS\Hih.exe
O4 - HKLM\..\Run: [Nlt] C:\WINDOWS\Fqj.exe
O4 - HKLM\..\Run: [Elm] C:\WINDOWS\Liq.exe
O4 - HKLM\..\Run: [Imu] C:\WINDOWS\Sok.exe
O4 - HKLM\..\Run: [Dpv] C:\WINDOWS\System32\Hcs.exe
O4 - HKLM\..\Run: [Jch] C:\WINDOWS\Mcd.exe
O4 - HKLM\..\Run: [Ios] C:\WINDOWS\System32\Lsi.exe
O4 - HKLM\..\Run: [Tnf] C:\WINDOWS\System32\Gdl.exe
O4 - HKLM\..\Run: [Icu] C:\WINDOWS\Qpu.exe
O4 - HKLM\..\Run: [Hsl] C:\WINDOWS\Qjl.exe
O4 - HKLM\..\Run: [Ibm] C:\WINDOWS\System32\Jht.exe
O4 - HKLM\..\Run: [Ohd] C:\WINDOWS\System32\Chi.exe
O4 - HKLM\..\Run: [Tjg] C:\WINDOWS\Vae.exe
O4 - HKLM\..\Run: [Tkn] C:\WINDOWS\Ulf.exe
O4 - HKLM\..\Run: [Iuc] C:\WINDOWS\System32\Qhq.exe
O4 - HKLM\..\Run: [Uvo] C:\WINDOWS\Ull.exe
O4 - HKLM\..\Run: [Gmp] C:\WINDOWS\Niv.exe
O4 - HKLM\..\Run: [Vde] C:\WINDOWS\System32\Qui.exe
O4 - HKLM\..\Run: [Tpa] C:\WINDOWS\Klq.exe
O4 - HKLM\..\Run: [Iud] C:\WINDOWS\Knc.exe
O4 - HKLM\..\Run: [Hjv] C:\WINDOWS\Flq.exe
O4 - HKLM\..\Run: [Snm] C:\WINDOWS\System32\Ttm.exe
O4 - HKLM\..\Run: [Jtr] C:\WINDOWS\System32\Bqc.exe
O4 - HKLM\..\Run: [Tvc] C:\WINDOWS\Mpr.exe
O4 - HKLM\..\Run: [Sfc] C:\WINDOWS\System32\Has.exe
O4 - HKLM\..\Run: [Sqq] C:\WINDOWS\System32\Unn.exe
O4 - HKLM\..\Run: [Obh] C:\WINDOWS\System32\Acg.exe
O4 - HKLM\..\Run: [Kih] C:\WINDOWS\Dit.exe
O4 - HKLM\..\Run: [Evo] C:\WINDOWS\System32\Shm.exe
O4 - HKLM\..\Run: [Teq] C:\WINDOWS\System32\Pod.exe
O4 - HKLM\..\Run: [Kjn] C:\WINDOWS\System32\Pmk.exe
O4 - HKLM\..\Run: [Pvn] C:\WINDOWS\System32\Ghn.exe
O4 - HKLM\..\Run: [Ssp] C:\WINDOWS\Jvr.exe
O4 - HKLM\..\Run: [Orj] C:\WINDOWS\Sif.exe
O4 - HKLM\..\Run: [Ehb] C:\WINDOWS\System32\Gga.exe
O4 - HKLM\..\Run: [Kgv] C:\WINDOWS\System32\Rcc.exe
O4 - HKLM\..\Run: [q64Q36W] kpssja.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 - HKLM\..\Run: [WindowsUpdate] C:\WINDOWS\System\svchost.exe /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Pcu] C:\WINDOWS\Sea.exe
O4 - HKCU\..\Run: [Jhv] C:\WINDOWS\Ngp.exe
O4 - HKCU\..\Run: [Sqe] C:\WINDOWS\System32\Lvk.exe
O4 - HKCU\..\Run: [Ihj] C:\WINDOWS\System32\Utv.exe
O4 - HKCU\..\Run: [Aro] C:\WINDOWS\System32\Bqe.exe
O4 - HKCU\..\Run: [Kjg] C:\WINDOWS\System32\Cpm.exe
O4 - HKCU\..\Run: [One] C:\WINDOWS\Qcf.exe
O4 - HKCU\..\Run: [Pst] C:\WINDOWS\Dmh.exe
O4 - HKCU\..\Run: [Lla] C:\WINDOWS\Bqp.exe
O4 - HKCU\..\Run: [Utu] C:\WINDOWS\Rch.exe
O4 - HKCU\..\Run: [Tkr] C:\WINDOWS\Eet.exe
O4 - HKCU\..\Run: [Rdf] C:\WINDOWS\Bcb.exe
O4 - HKCU\..\Run: [Nsj] C:\WINDOWS\System32\Acp.exe
O4 - HKCU\..\Run: [Mgr] C:\WINDOWS\System32\Bcp.exe
O4 - HKCU\..\Run: [Epn] C:\WINDOWS\System32\Fjd.exe
O4 - HKCU\..\Run: [Ovq] C:\WINDOWS\Bmh.exe
O4 - HKCU\..\Run: [Fek] C:\WINDOWS\Lel.exe
O4 - HKCU\..\Run: [Lsk] C:\WINDOWS\System32\Gjd.exe
O4 - HKCU\..\Run: [Pip] C:\WINDOWS\System32\Had.exe
O4 - HKCU\..\Run: [Cld] C:\WINDOWS\Gph.exe
O4 - HKCU\..\Run: [Upe] C:\WINDOWS\Asl.exe
O4 - HKCU\..\Run: [Jrm] C:\WINDOWS\System32\Kio.exe
O4 - HKCU\..\Run: [Eev] C:\WINDOWS\System32\Sma.exe
O4 - HKCU\..\Run: [Cpu] C:\WINDOWS\Jqb.exe
O4 - HKCU\..\Run: [Vuv] C:\WINDOWS\Cas.exe
O4 - HKCU\..\Run: [Kdj] C:\WINDOWS\Uoj.exe
O4 - HKCU\..\Run: [Gds] C:\WINDOWS\Bgs.exe
O4 - HKCU\..\Run: [Aui] C:\WINDOWS\Pna.exe
O4 - HKCU\..\Run: [Uau] C:\WINDOWS\Lvj.exe
O4 - HKCU\..\Run: [Kpl] C:\WINDOWS\Uue.exe
O4 - HKCU\..\Run: [Bcv] C:\WINDOWS\Glq.exe
O4 - HKCU\..\Run: [Tlc] C:\WINDOWS\Iqj.exe
O4 - HKCU\..\Run: [Dst] C:\WINDOWS\Mft.exe
O4 - HKCU\..\Run: [Rmf] C:\WINDOWS\Gmj.exe
O4 - HKCU\..\Run: [Clj] C:\WINDOWS\Uvn.exe
O4 - HKCU\..\Run: [Ode] C:\WINDOWS\System32\Gds.exe
O4 - HKCU\..\Run: [Oco] C:\WINDOWS\Gsi.exe
O4 - HKCU\..\Run: [Mml] C:\WINDOWS\Ulu.exe
O4 - HKCU\..\Run: [Tsa] C:\WINDOWS\System32\Umg.exe
O4 - HKCU\..\Run: [Lqm] C:\WINDOWS\System32\Fau.exe
O4 - HKCU\..\Run: [Mln] C:\WINDOWS\System32\Iiu.exe
O4 - HKCU\..\Run: [Snq] C:\WINDOWS\Biu.exe
O4 - HKCU\..\Run: [Rfg] C:\WINDOWS\Ikq.exe
O4 - HKCU\..\Run: [Igt] C:\WINDOWS\Qjs.exe
O4 - HKCU\..\Run: [Sdn] C:\WINDOWS\Loc.exe
O4 - HKCU\..\Run: [Ebj] C:\WINDOWS\System32\Der.exe
O4 - HKCU\..\Run: [Eoo] C:\WINDOWS\Jqe.exe
O4 - HKCU\..\Run: [Had] C:\WINDOWS\Mvf.exe
O4 - HKCU\..\Run: [Smq] C:\WINDOWS\System32\Auq.exe
O4 - HKCU\..\Run: [Tan] C:\WINDOWS\Ive.exe
O4 - HKCU\..\Run: [Afp] C:\WINDOWS\Dre.exe
O4 - HKCU\..\Run: [Urv] C:\WINDOWS\System32\Bhl.exe
O4 - HKCU\..\Run: [Ird] C:\WINDOWS\System32\Tto.exe
O4 - HKCU\..\Run: [Vea] C:\WINDOWS\Pvl.exe
O4 - HKCU\..\Run: [Umt] C:\WINDOWS\System32\Ohr.exe
O4 - HKCU\..\Run: [Bar] C:\WINDOWS\System32\Eae.exe
O4 - HKCU\..\Run: [Qft] C:\WINDOWS\Okf.exe
O4 - HKCU\..\Run: [Eme] C:\WINDOWS\Nff.exe
O4 - HKCU\..\Run: [Qsh] C:\WINDOWS\System32\Ddt.exe
O4 - HKCU\..\Run: [Cbq] C:\WINDOWS\Ver.exe
O4 - HKCU\..\Run: [Dsv] C:\WINDOWS\System32\Bcv.exe
O4 - HKCU\..\Run: [Lmj] C:\WINDOWS\Fei.exe
O4 - HKCU\..\Run: [Plt] C:\WINDOWS\Klu.exe
O4 - HKCU\..\Run: [Ibe] C:\WINDOWS\Iqk.exe
O4 - HKCU\..\Run: [Ios] C:\WINDOWS\System32\Lsi.exe
O4 - HKCU\..\Run: [Tnf] C:\WINDOWS\System32\Gdl.exe
O4 - HKCU\..\Run: [Icu] C:\WINDOWS\Qpu.exe
O4 - HKCU\..\Run: [Hsl] C:\WINDOWS\Qjl.exe
O4 - HKCU\..\Run: [Ibm] C:\WINDOWS\System32\Jht.exe
O4 - HKCU\..\Run: [Ohd] C:\WINDOWS\System32\Chi.exe
O4 - HKCU\..\Run: [Tjg] C:\WINDOWS\Vae.exe
O4 - HKCU\..\Run: [Tkn] C:\WINDOWS\Ulf.exe
O4 - HKCU\..\Run: [Iuc] C:\WINDOWS\System32\Qhq.exe
O4 - HKCU\..\Run: [Uvo] C:\WINDOWS\Ull.exe
O4 - HKCU\..\Run: [Gmp] C:\WINDOWS\Niv.exe
O4 - HKCU\..\Run: [Vde] C:\WINDOWS\System32\Qui.exe
O4 - HKCU\..\Run: [Tpa] C:\WINDOWS\Klq.exe
O4 - HKCU\..\Run: [Iud] C:\WINDOWS\Knc.exe
O4 - HKCU\..\Run: [Hjv] C:\WINDOWS\Flq.exe
O4 - HKCU\..\Run: [Snm] C:\WINDOWS\System32\Ttm.exe
O4 - HKCU\..\Run: [Jtr] C:\WINDOWS\System32\Bqc.exe
O4 - HKCU\..\Run: [Tvc] C:\WINDOWS\Mpr.exe
O4 - HKCU\..\Run: [Sfc] C:\WINDOWS\System32\Has.exe
O4 - HKCU\..\Run: [Sqq] C:\WINDOWS\System32\Unn.exe
O4 - HKCU\..\Run: [Obh] C:\WINDOWS\System32\Acg.exe
O4 - HKCU\..\Run: [Kih] C:\WINDOWS\Dit.exe
O4 - HKCU\..\Run: [Evo] C:\WINDOWS\System32\Shm.exe
O4 - HKCU\..\Run: [Teq] C:\WINDOWS\System32\Pod.exe
O4 - HKCU\..\Run: [Kjn] C:\WINDOWS\System32\Pmk.exe
O4 - HKCU\..\Run: [Pvn] C:\WINDOWS\System32\Ghn.exe
O4 - HKCU\..\Run: [Ssp] C:\WINDOWS\Jvr.exe
O4 - HKCU\..\Run: [Orj] C:\WINDOWS\Sif.exe
O4 - HKCU\..\Run: [Ehb] C:\WINDOWS\System32\Gga.exe
O4 - HKCU\..\Run: [Kgv] C:\WINDOWS\System32\Rcc.exe
O4 - HKCU\..\Run: [bxv4RWanj] ker_ps.exe
O4 - HKCU\..\RunServices: [Image] rundll32 C:\WINDOWS\image.new,Install
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O16 - DPF: Win32 Classes -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/AgeVerif...bridge-c420.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5695A50-A62D-468D-88E7-1EC6E218C163}: NameServer = 212.67.96.129 212.67.120.148
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
O20 - Winlogon Notify: f3dsl - C:\WINDOWS\SYSTEM32\MSplg7.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:18 PM

Posted 15 May 2005 - 01:14 PM

You are currently using hijackthis from a temp directory. This can cause problems. Please create a directory on your c: drive called c:\hijackthis and download and unzip hijackthis into that directory. Run the program from that directory from now on.

For a tutorial on how to use HijackThis please see the following link:

Using HijackThis to Remove Spyware, Browser Hijackers, and Dialers


Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button:

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\kernels32.exe
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3 www.iframeprofit.com
O1 - Hosts: 127.0.0.3 www.loadcash.biz
O1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 www.iframedollars.biz
O1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3 www.aaasexypics.com
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 www.sexfiles.nu
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.autoescrowpay.com
O1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3 www.iframeprofit.com
O1 - Hosts: 127.0.0.3 www.loadcash.biz
O1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 www.iframedollars.biz
O1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3 www.aaasexypics.com
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 www.sexfiles.nu
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.autoescrowpay.com
O1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 127.0.0.3 iframeprofit.com
O1 - Hosts: 127.0.0.3 www.iframeprofit.com
O1 - Hosts: 127.0.0.3 www.loadcash.biz
O1 - Hosts: 127.0.0.3 loadcash.biz
O1 - Hosts: 127.0.0.3 traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.traffic2cash.biz
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 www.iframedollars.biz
O1 - Hosts: 127.0.0.3 iframedollars.biz
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3 www.aaasexypics.com
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 www.sexfiles.nu
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.autoescrowpay.com
O1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~2\SEARCH~2.DLL
O2 - BHO: (no name) - {DE3BEBDB-AEE7-4277-8B6E-4EEFFA9508AE} - C:\WINDOWS\System32\kogiyu.dll (file missing)
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [Windows Task Manager] C:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [juzsh] C:\WINDOWS\juzsh.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels32.exe
O4 - HKLM\..\Run: [Pcu] C:\WINDOWS\Sea.exe
O4 - HKLM\..\Run: [Jhv] C:\WINDOWS\Ngp.exe
O4 - HKLM\..\Run: [Sqe] C:\WINDOWS\System32\Lvk.exe
O4 - HKLM\..\Run: [Ihj] C:\WINDOWS\System32\Utv.exe
O4 - HKLM\..\Run: [Aro] C:\WINDOWS\System32\Bqe.exe
O4 - HKLM\..\Run: [Kjg] C:\WINDOWS\System32\Cpm.exe
O4 - HKLM\..\Run: [One] C:\WINDOWS\Qcf.exe
O4 - HKLM\..\Run: [Pst] C:\WINDOWS\Dmh.exe
O4 - HKLM\..\Run: [Lla] C:\WINDOWS\Bqp.exe
O4 - HKLM\..\Run: [Utu] C:\WINDOWS\Rch.exe
O4 - HKLM\..\Run: [Tkr] C:\WINDOWS\Eet.exe
O4 - HKLM\..\Run: [Rdf] C:\WINDOWS\Bcb.exe
O4 - HKLM\..\Run: [Nsj] C:\WINDOWS\System32\Acp.exe
O4 - HKLM\..\Run: [Mgr] C:\WINDOWS\System32\Bcp.exe
O4 - HKLM\..\Run: [Epn] C:\WINDOWS\System32\Fjd.exe
O4 - HKLM\..\Run: [Ovq] C:\WINDOWS\Bmh.exe
O4 - HKLM\..\Run: [Fek] C:\WINDOWS\Lel.exe
O4 - HKLM\..\Run: [Lsk] C:\WINDOWS\System32\Gjd.exe
O4 - HKLM\..\Run: [Pip] C:\WINDOWS\System32\Had.exe
O4 - HKLM\..\Run: [Cld] C:\WINDOWS\Gph.exe
O4 - HKLM\..\Run: [Upe] C:\WINDOWS\Asl.exe
O4 - HKLM\..\Run: [Jrm] C:\WINDOWS\System32\Kio.exe
O4 - HKLM\..\Run: [Eev] C:\WINDOWS\System32\Sma.exe
O4 - HKLM\..\Run: [Cpu] C:\WINDOWS\Jqb.exe
O4 - HKLM\..\Run: [Vuv] C:\WINDOWS\Cas.exe
O4 - HKLM\..\Run: [Kdj] C:\WINDOWS\Uoj.exe
O4 - HKLM\..\Run: [Gds] C:\WINDOWS\Bgs.exe
O4 - HKLM\..\Run: [Aui] C:\WINDOWS\Pna.exe
O4 - HKLM\..\Run: [Uau] C:\WINDOWS\Lvj.exe
O4 - HKLM\..\Run: [Kpl] C:\WINDOWS\Uue.exe
O4 - HKLM\..\Run: [Bcv] C:\WINDOWS\Glq.exe
O4 - HKLM\..\Run: [Tlc] C:\WINDOWS\Iqj.exe
O4 - HKLM\..\Run: [Dst] C:\WINDOWS\Mft.exe
O4 - HKLM\..\Run: [Rmf] C:\WINDOWS\Gmj.exe
O4 - HKLM\..\Run: [Clj] C:\WINDOWS\Uvn.exe
O4 - HKLM\..\Run: [Ode] C:\WINDOWS\System32\Gds.exe
O4 - HKLM\..\Run: [Oco] C:\WINDOWS\Gsi.exe
O4 - HKLM\..\Run: [Mml] C:\WINDOWS\Ulu.exe
O4 - HKLM\..\Run: [Tsa] C:\WINDOWS\System32\Umg.exe
O4 - HKLM\..\Run: [Lqm] C:\WINDOWS\System32\Fau.exe
O4 - HKLM\..\Run: [Mln] C:\WINDOWS\System32\Iiu.exe
O4 - HKLM\..\Run: [Snq] C:\WINDOWS\Biu.exe
O4 - HKLM\..\Run: [Rfg] C:\WINDOWS\Ikq.exe
O4 - HKLM\..\Run: [Igt] C:\WINDOWS\Qjs.exe
O4 - HKLM\..\Run: [Sdn] C:\WINDOWS\Loc.exe
O4 - HKLM\..\Run: [Ebj] C:\WINDOWS\System32\Der.exe
O4 - HKLM\..\Run: [Eoo] C:\WINDOWS\Jqe.exe
O4 - HKLM\..\Run: [Had] C:\WINDOWS\Mvf.exe
O4 - HKLM\..\Run: [Smq] C:\WINDOWS\System32\Auq.exe
O4 - HKLM\..\Run: [Tan] C:\WINDOWS\Ive.exe
O4 - HKLM\..\Run: [Afp] C:\WINDOWS\Dre.exe
O4 - HKLM\..\Run: [Urv] C:\WINDOWS\System32\Bhl.exe
O4 - HKLM\..\Run: [Ird] C:\WINDOWS\System32\Tto.exe
O4 - HKLM\..\Run: [Vea] C:\WINDOWS\Pvl.exe
O4 - HKLM\..\Run: [Umt] C:\WINDOWS\System32\Ohr.exe
O4 - HKLM\..\Run: [Bar] C:\WINDOWS\System32\Eae.exe
O4 - HKLM\..\Run: [Qft] C:\WINDOWS\Okf.exe
O4 - HKLM\..\Run: [Eme] C:\WINDOWS\Nff.exe
O4 - HKLM\..\Run: [Qsh] C:\WINDOWS\System32\Ddt.exe
O4 - HKLM\..\Run: [Cbq] C:\WINDOWS\Ver.exe
O4 - HKLM\..\Run: [Dsv] C:\WINDOWS\System32\Bcv.exe
O4 - HKLM\..\Run: [Lmj] C:\WINDOWS\Fei.exe
O4 - HKLM\..\Run: [Plt] C:\WINDOWS\Klu.exe
O4 - HKLM\..\Run: [Ibe] C:\WINDOWS\Iqk.exe
O4 - HKLM\..\Run: [Ipi] C:\WINDOWS\Qjj.exe
O4 - HKLM\..\Run: [Pin] C:\WINDOWS\System32\Gkv.exe
O4 - HKLM\..\Run: [Juf] C:\WINDOWS\Hih.exe
O4 - HKLM\..\Run: [Nlt] C:\WINDOWS\Fqj.exe
O4 - HKLM\..\Run: [Elm] C:\WINDOWS\Liq.exe
O4 - HKLM\..\Run: [Imu] C:\WINDOWS\Sok.exe
O4 - HKLM\..\Run: [Dpv] C:\WINDOWS\System32\Hcs.exe
O4 - HKLM\..\Run: [Jch] C:\WINDOWS\Mcd.exe
O4 - HKLM\..\Run: [Ios] C:\WINDOWS\System32\Lsi.exe
O4 - HKLM\..\Run: [Tnf] C:\WINDOWS\System32\Gdl.exe
O4 - HKLM\..\Run: [Icu] C:\WINDOWS\Qpu.exe
O4 - HKLM\..\Run: [Hsl] C:\WINDOWS\Qjl.exe
O4 - HKLM\..\Run: [Ibm] C:\WINDOWS\System32\Jht.exe
O4 - HKLM\..\Run: [Ohd] C:\WINDOWS\System32\Chi.exe
O4 - HKLM\..\Run: [Tjg] C:\WINDOWS\Vae.exe
O4 - HKLM\..\Run: [Tkn] C:\WINDOWS\Ulf.exe
O4 - HKLM\..\Run: [Iuc] C:\WINDOWS\System32\Qhq.exe
O4 - HKLM\..\Run: [Uvo] C:\WINDOWS\Ull.exe
O4 - HKLM\..\Run: [Gmp] C:\WINDOWS\Niv.exe
O4 - HKLM\..\Run: [Vde] C:\WINDOWS\System32\Qui.exe
O4 - HKLM\..\Run: [Tpa] C:\WINDOWS\Klq.exe
O4 - HKLM\..\Run: [Iud] C:\WINDOWS\Knc.exe
O4 - HKLM\..\Run: [Hjv] C:\WINDOWS\Flq.exe
O4 - HKLM\..\Run: [Snm] C:\WINDOWS\System32\Ttm.exe
O4 - HKLM\..\Run: [Jtr] C:\WINDOWS\System32\Bqc.exe
O4 - HKLM\..\Run: [Tvc] C:\WINDOWS\Mpr.exe
O4 - HKLM\..\Run: [Sfc] C:\WINDOWS\System32\Has.exe
O4 - HKLM\..\Run: [Sqq] C:\WINDOWS\System32\Unn.exe
O4 - HKLM\..\Run: [Obh] C:\WINDOWS\System32\Acg.exe
O4 - HKLM\..\Run: [Kih] C:\WINDOWS\Dit.exe
O4 - HKLM\..\Run: [Evo] C:\WINDOWS\System32\Shm.exe
O4 - HKLM\..\Run: [Teq] C:\WINDOWS\System32\Pod.exe
O4 - HKLM\..\Run: [Kjn] C:\WINDOWS\System32\Pmk.exe
O4 - HKLM\..\Run: [Pvn] C:\WINDOWS\System32\Ghn.exe
O4 - HKLM\..\Run: [Ssp] C:\WINDOWS\Jvr.exe
O4 - HKLM\..\Run: [Orj] C:\WINDOWS\Sif.exe
O4 - HKLM\..\Run: [Ehb] C:\WINDOWS\System32\Gga.exe
O4 - HKLM\..\Run: [Kgv] C:\WINDOWS\System32\Rcc.exe
O4 - HKLM\..\Run: [q64Q36W] kpssja.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\System32\gah95on6.exe
O4 - HKLM\..\Run: [WindowsUpdate] C:\WINDOWS\System\svchost.exe /s
O4 - HKCU\..\Run: [Pcu] C:\WINDOWS\Sea.exe
O4 - HKCU\..\Run: [Jhv] C:\WINDOWS\Ngp.exe
O4 - HKCU\..\Run: [Sqe] C:\WINDOWS\System32\Lvk.exe
O4 - HKCU\..\Run: [Ihj] C:\WINDOWS\System32\Utv.exe
O4 - HKCU\..\Run: [Aro] C:\WINDOWS\System32\Bqe.exe
O4 - HKCU\..\Run: [Kjg] C:\WINDOWS\System32\Cpm.exe
O4 - HKCU\..\Run: [One] C:\WINDOWS\Qcf.exe
O4 - HKCU\..\Run: [Pst] C:\WINDOWS\Dmh.exe
O4 - HKCU\..\Run: [Lla] C:\WINDOWS\Bqp.exe
O4 - HKCU\..\Run: [Utu] C:\WINDOWS\Rch.exe
O4 - HKCU\..\Run: [Tkr] C:\WINDOWS\Eet.exe
O4 - HKCU\..\Run: [Rdf] C:\WINDOWS\Bcb.exe
O4 - HKCU\..\Run: [Nsj] C:\WINDOWS\System32\Acp.exe
O4 - HKCU\..\Run: [Mgr] C:\WINDOWS\System32\Bcp.exe
O4 - HKCU\..\Run: [Epn] C:\WINDOWS\System32\Fjd.exe
O4 - HKCU\..\Run: [Ovq] C:\WINDOWS\Bmh.exe
O4 - HKCU\..\Run: [Fek] C:\WINDOWS\Lel.exe
O4 - HKCU\..\Run: [Lsk] C:\WINDOWS\System32\Gjd.exe
O4 - HKCU\..\Run: [Pip] C:\WINDOWS\System32\Had.exe
O4 - HKCU\..\Run: [Cld] C:\WINDOWS\Gph.exe
O4 - HKCU\..\Run: [Upe] C:\WINDOWS\Asl.exe
O4 - HKCU\..\Run: [Jrm] C:\WINDOWS\System32\Kio.exe
O4 - HKCU\..\Run: [Eev] C:\WINDOWS\System32\Sma.exe
O4 - HKCU\..\Run: [Cpu] C:\WINDOWS\Jqb.exe
O4 - HKCU\..\Run: [Vuv] C:\WINDOWS\Cas.exe
O4 - HKCU\..\Run: [Kdj] C:\WINDOWS\Uoj.exe
O4 - HKCU\..\Run: [Gds] C:\WINDOWS\Bgs.exe
O4 - HKCU\..\Run: [Aui] C:\WINDOWS\Pna.exe
O4 - HKCU\..\Run: [Uau] C:\WINDOWS\Lvj.exe
O4 - HKCU\..\Run: [Kpl] C:\WINDOWS\Uue.exe
O4 - HKCU\..\Run: [Bcv] C:\WINDOWS\Glq.exe
O4 - HKCU\..\Run: [Tlc] C:\WINDOWS\Iqj.exe
O4 - HKCU\..\Run: [Dst] C:\WINDOWS\Mft.exe
O4 - HKCU\..\Run: [Rmf] C:\WINDOWS\Gmj.exe
O4 - HKCU\..\Run: [Clj] C:\WINDOWS\Uvn.exe
O4 - HKCU\..\Run: [Ode] C:\WINDOWS\System32\Gds.exe
O4 - HKCU\..\Run: [Oco] C:\WINDOWS\Gsi.exe
O4 - HKCU\..\Run: [Mml] C:\WINDOWS\Ulu.exe
O4 - HKCU\..\Run: [Tsa] C:\WINDOWS\System32\Umg.exe
O4 - HKCU\..\Run: [Lqm] C:\WINDOWS\System32\Fau.exe
O4 - HKCU\..\Run: [Mln] C:\WINDOWS\System32\Iiu.exe
O4 - HKCU\..\Run: [Snq] C:\WINDOWS\Biu.exe
O4 - HKCU\..\Run: [Rfg] C:\WINDOWS\Ikq.exe
O4 - HKCU\..\Run: [Igt] C:\WINDOWS\Qjs.exe
O4 - HKCU\..\Run: [Sdn] C:\WINDOWS\Loc.exe
O4 - HKCU\..\Run: [Ebj] C:\WINDOWS\System32\Der.exe
O4 - HKCU\..\Run: [Eoo] C:\WINDOWS\Jqe.exe
O4 - HKCU\..\Run: [Had] C:\WINDOWS\Mvf.exe
O4 - HKCU\..\Run: [Smq] C:\WINDOWS\System32\Auq.exe
O4 - HKCU\..\Run: [Tan] C:\WINDOWS\Ive.exe
O4 - HKCU\..\Run: [Afp] C:\WINDOWS\Dre.exe
O4 - HKCU\..\Run: [Urv] C:\WINDOWS\System32\Bhl.exe
O4 - HKCU\..\Run: [Ird] C:\WINDOWS\System32\Tto.exe
O4 - HKCU\..\Run: [Vea] C:\WINDOWS\Pvl.exe
O4 - HKCU\..\Run: [Umt] C:\WINDOWS\System32\Ohr.exe
O4 - HKCU\..\Run: [Bar] C:\WINDOWS\System32\Eae.exe
O4 - HKCU\..\Run: [Qft] C:\WINDOWS\Okf.exe
O4 - HKCU\..\Run: [Eme] C:\WINDOWS\Nff.exe
O4 - HKCU\..\Run: [Qsh] C:\WINDOWS\System32\Ddt.exe
O4 - HKCU\..\Run: [Cbq] C:\WINDOWS\Ver.exe
O4 - HKCU\..\Run: [Dsv] C:\WINDOWS\System32\Bcv.exe
O4 - HKCU\..\Run: [Lmj] C:\WINDOWS\Fei.exe
O4 - HKCU\..\Run: [Plt] C:\WINDOWS\Klu.exe
O4 - HKCU\..\Run: [Ibe] C:\WINDOWS\Iqk.exe
O4 - HKCU\..\Run: [Ios] C:\WINDOWS\System32\Lsi.exe
O4 - HKCU\..\Run: [Tnf] C:\WINDOWS\System32\Gdl.exe
O4 - HKCU\..\Run: [Icu] C:\WINDOWS\Qpu.exe
O4 - HKCU\..\Run: [Hsl] C:\WINDOWS\Qjl.exe
O4 - HKCU\..\Run: [Ibm] C:\WINDOWS\System32\Jht.exe
O4 - HKCU\..\Run: [Ohd] C:\WINDOWS\System32\Chi.exe
O4 - HKCU\..\Run: [Tjg] C:\WINDOWS\Vae.exe
O4 - HKCU\..\Run: [Tkn] C:\WINDOWS\Ulf.exe
O4 - HKCU\..\Run: [Iuc] C:\WINDOWS\System32\Qhq.exe
O4 - HKCU\..\Run: [Uvo] C:\WINDOWS\Ull.exe
O4 - HKCU\..\Run: [Gmp] C:\WINDOWS\Niv.exe
O4 - HKCU\..\Run: [Vde] C:\WINDOWS\System32\Qui.exe
O4 - HKCU\..\Run: [Tpa] C:\WINDOWS\Klq.exe
O4 - HKCU\..\Run: [Iud] C:\WINDOWS\Knc.exe
O4 - HKCU\..\Run: [Hjv] C:\WINDOWS\Flq.exe
O4 - HKCU\..\Run: [Snm] C:\WINDOWS\System32\Ttm.exe
O4 - HKCU\..\Run: [Jtr] C:\WINDOWS\System32\Bqc.exe
O4 - HKCU\..\Run: [Tvc] C:\WINDOWS\Mpr.exe
O4 - HKCU\..\Run: [Sfc] C:\WINDOWS\System32\Has.exe
O4 - HKCU\..\Run: [Sqq] C:\WINDOWS\System32\Unn.exe
O4 - HKCU\..\Run: [Obh] C:\WINDOWS\System32\Acg.exe
O4 - HKCU\..\Run: [Kih] C:\WINDOWS\Dit.exe
O4 - HKCU\..\Run: [Evo] C:\WINDOWS\System32\Shm.exe
O4 - HKCU\..\Run: [Teq] C:\WINDOWS\System32\Pod.exe
O4 - HKCU\..\Run: [Kjn] C:\WINDOWS\System32\Pmk.exe
O4 - HKCU\..\Run: [Pvn] C:\WINDOWS\System32\Ghn.exe
O4 - HKCU\..\Run: [Ssp] C:\WINDOWS\Jvr.exe
O4 - HKCU\..\Run: [Orj] C:\WINDOWS\Sif.exe
O4 - HKCU\..\Run: [Ehb] C:\WINDOWS\System32\Gga.exe
O4 - HKCU\..\Run: [Kgv] C:\WINDOWS\System32\Rcc.exe
O4 - HKCU\..\Run: [bxv4RWanj] ker_ps.exe
O4 - HKCU\..\RunServices: [Image] rundll32 C:\WINDOWS\image.new,Install
O16 - DPF: Win32 Classes -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/AgeVerif...bridge-c420.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O20 - Winlogon Notify: f3dsl - C:\WINDOWS\SYSTEM32\MSplg7.dll

Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)

C:\WINDOWS\System32\kernels32.exe
C:\Program Files\CxtPls\
C:\PROGRA~1\SEARCH~2\SEARCH~2.DLL
C:\Program Files\TheSearchAccelerator\
C:\windows\system32\taskmgn.exe
c:\temp\salm.exe
C:\WINDOWS\juzsh.exe
C:\WINDOWS\System32\kernels32.exe
O4 - HKLM\..\Run: [Pcu] C:\WINDOWS\Sea.exe
O4 - HKLM\..\Run: [Jhv] C:\WINDOWS\Ngp.exe
O4 - HKLM\..\Run: [Sqe] C:\WINDOWS\System32\Lvk.exe
O4 - HKLM\..\Run: [Ihj] C:\WINDOWS\System32\Utv.exe
O4 - HKLM\..\Run: [Aro] C:\WINDOWS\System32\Bqe.exe
O4 - HKLM\..\Run: [Kjg] C:\WINDOWS\System32\Cpm.exe
O4 - HKLM\..\Run: [One] C:\WINDOWS\Qcf.exe
O4 - HKLM\..\Run: [Pst] C:\WINDOWS\Dmh.exe
O4 - HKLM\..\Run: [Lla] C:\WINDOWS\Bqp.exe
O4 - HKLM\..\Run: [Utu] C:\WINDOWS\Rch.exe
O4 - HKLM\..\Run: [Tkr] C:\WINDOWS\Eet.exe
O4 - HKLM\..\Run: [Rdf] C:\WINDOWS\Bcb.exe
O4 - HKLM\..\Run: [Nsj] C:\WINDOWS\System32\Acp.exe
O4 - HKLM\..\Run: [Mgr] C:\WINDOWS\System32\Bcp.exe
O4 - HKLM\..\Run: [Epn] C:\WINDOWS\System32\Fjd.exe
O4 - HKLM\..\Run: [Ovq] C:\WINDOWS\Bmh.exe
O4 - HKLM\..\Run: [Fek] C:\WINDOWS\Lel.exe
O4 - HKLM\..\Run: [Lsk] C:\WINDOWS\System32\Gjd.exe
O4 - HKLM\..\Run: [Pip] C:\WINDOWS\System32\Had.exe
O4 - HKLM\..\Run: [Cld] C:\WINDOWS\Gph.exe
O4 - HKLM\..\Run: [Upe] C:\WINDOWS\Asl.exe
O4 - HKLM\..\Run: [Jrm] C:\WINDOWS\System32\Kio.exe
O4 - HKLM\..\Run: [Eev] C:\WINDOWS\System32\Sma.exe
O4 - HKLM\..\Run: [Cpu] C:\WINDOWS\Jqb.exe
O4 - HKLM\..\Run: [Vuv] C:\WINDOWS\Cas.exe
O4 - HKLM\..\Run: [Kdj] C:\WINDOWS\Uoj.exe
O4 - HKLM\..\Run: [Gds] C:\WINDOWS\Bgs.exe
O4 - HKLM\..\Run: [Aui] C:\WINDOWS\Pna.exe
O4 - HKLM\..\Run: [Uau] C:\WINDOWS\Lvj.exe
O4 - HKLM\..\Run: [Kpl] C:\WINDOWS\Uue.exe
O4 - HKLM\..\Run: [Bcv] C:\WINDOWS\Glq.exe
O4 - HKLM\..\Run: [Tlc] C:\WINDOWS\Iqj.exe
O4 - HKLM\..\Run: [Dst] C:\WINDOWS\Mft.exe
O4 - HKLM\..\Run: [Rmf] C:\WINDOWS\Gmj.exe
O4 - HKLM\..\Run: [Clj] C:\WINDOWS\Uvn.exe
O4 - HKLM\..\Run: [Ode] C:\WINDOWS\System32\Gds.exe
O4 - HKLM\..\Run: [Oco] C:\WINDOWS\Gsi.exe
O4 - HKLM\..\Run: [Mml] C:\WINDOWS\Ulu.exe
O4 - HKLM\..\Run: [Tsa] C:\WINDOWS\System32\Umg.exe
O4 - HKLM\..\Run: [Lqm] C:\WINDOWS\System32\Fau.exe
O4 - HKLM\..\Run: [Mln] C:\WINDOWS\System32\Iiu.exe
O4 - HKLM\..\Run: [Snq] C:\WINDOWS\Biu.exe
O4 - HKLM\..\Run: [Rfg] C:\WINDOWS\Ikq.exe
O4 - HKLM\..\Run: [Igt] C:\WINDOWS\Qjs.exe
O4 - HKLM\..\Run: [Sdn] C:\WINDOWS\Loc.exe
O4 - HKLM\..\Run: [Ebj] C:\WINDOWS\System32\Der.exe
O4 - HKLM\..\Run: [Eoo] C:\WINDOWS\Jqe.exe
O4 - HKLM\..\Run: [Had] C:\WINDOWS\Mvf.exe
O4 - HKLM\..\Run: [Smq] C:\WINDOWS\System32\Auq.exe
O4 - HKLM\..\Run: [Tan] C:\WINDOWS\Ive.exe
O4 - HKLM\..\Run: [Afp] C:\WINDOWS\Dre.exe
O4 - HKLM\..\Run: [Urv] C:\WINDOWS\System32\Bhl.exe
O4 - HKLM\..\Run: [Ird] C:\WINDOWS\System32\Tto.exe
O4 - HKLM\..\Run: [Vea] C:\WINDOWS\Pvl.exe
O4 - HKLM\..\Run: [Umt] C:\WINDOWS\System32\Ohr.exe
O4 - HKLM\..\Run: [Bar] C:\WINDOWS\System32\Eae.exe
O4 - HKLM\..\Run: [Qft] C:\WINDOWS\Okf.exe
O4 - HKLM\..\Run: [Eme] C:\WINDOWS\Nff.exe
O4 - HKLM\..\Run: [Qsh] C:\WINDOWS\System32\Ddt.exe
O4 - HKLM\..\Run: [Cbq] C:\WINDOWS\Ver.exe
O4 - HKLM\..\Run: [Dsv] C:\WINDOWS\System32\Bcv.exe
O4 - HKLM\..\Run: [Lmj] C:\WINDOWS\Fei.exe
O4 - HKLM\..\Run: [Plt] C:\WINDOWS\Klu.exe
O4 - HKLM\..\Run: [Ibe] C:\WINDOWS\Iqk.exe
O4 - HKLM\..\Run: [Ipi] C:\WINDOWS\Qjj.exe
O4 - HKLM\..\Run: [Pin] C:\WINDOWS\System32\Gkv.exe
O4 - HKLM\..\Run: [Juf] C:\WINDOWS\Hih.exe
O4 - HKLM\..\Run: [Nlt] C:\WINDOWS\Fqj.exe
O4 - HKLM\..\Run: [Elm] C:\WINDOWS\Liq.exe
O4 - HKLM\..\Run: [Imu] C:\WINDOWS\Sok.exe
O4 - HKLM\..\Run: [Dpv] C:\WINDOWS\System32\Hcs.exe
O4 - HKLM\..\Run: [Jch] C:\WINDOWS\Mcd.exe
O4 - HKLM\..\Run: [Ios] C:\WINDOWS\System32\Lsi.exe
O4 - HKLM\..\Run: [Tnf] C:\WINDOWS\System32\Gdl.exe
O4 - HKLM\..\Run: [Icu] C:\WINDOWS\Qpu.exe
O4 - HKLM\..\Run: [Hsl] C:\WINDOWS\Qjl.exe
O4 - HKLM\..\Run: [Ibm] C:\WINDOWS\System32\Jht.exe
O4 - HKLM\..\Run: [Ohd] C:\WINDOWS\System32\Chi.exe
O4 - HKLM\..\Run: [Tjg] C:\WINDOWS\Vae.exe
O4 - HKLM\..\Run: [Tkn] C:\WINDOWS\Ulf.exe
O4 - HKLM\..\Run: [Iuc] C:\WINDOWS\System32\Qhq.exe
O4 - HKLM\..\Run: [Uvo] C:\WINDOWS\Ull.exe
O4 - HKLM\..\Run: [Gmp] C:\WINDOWS\Niv.exe
O4 - HKLM\..\Run: [Vde] C:\WINDOWS\System32\Qui.exe
O4 - HKLM\..\Run: [Tpa] C:\WINDOWS\Klq.exe
O4 - HKLM\..\Run: [Iud] C:\WINDOWS\Knc.exe
O4 - HKLM\..\Run: [Hjv] C:\WINDOWS\Flq.exe
O4 - HKLM\..\Run: [Snm] C:\WINDOWS\System32\Ttm.exe
O4 - HKLM\..\Run: [Jtr] C:\WINDOWS\System32\Bqc.exe
O4 - HKLM\..\Run: [Tvc] C:\WINDOWS\Mpr.exe
O4 - HKLM\..\Run: [Sfc] C:\WINDOWS\System32\Has.exe
O4 - HKLM\..\Run: [Sqq] C:\WINDOWS\System32\Unn.exe
O4 - HKLM\..\Run: [Obh] C:\WINDOWS\System32\Acg.exe
O4 - HKLM\..\Run: [Kih] C:\WINDOWS\Dit.exe
O4 - HKLM\..\Run: [Evo] C:\WINDOWS\System32\Shm.exe
O4 - HKLM\..\Run: [Teq] C:\WINDOWS\System32\Pod.exe
O4 - HKLM\..\Run: [Kjn] C:\WINDOWS\System32\Pmk.exe
O4 - HKLM\..\Run: [Pvn] C:\WINDOWS\System32\Ghn.exe
O4 - HKLM\..\Run: [Ssp] C:\WINDOWS\Jvr.exe
O4 - HKLM\..\Run: [Orj] C:\WINDOWS\Sif.exe
O4 - HKLM\..\Run: [Ehb] C:\WINDOWS\System32\Gga.exe
O4 - HKLM\..\Run: [Kgv] C:\WINDOWS\System32\Rcc.exe
c:\windows\system32\kpssja.exe
C:\WINDOWS\System32\gah95on6.exe
C:\WINDOWS\System\svchost.exe
O4 - HKCU\..\Run: [Pcu] C:\WINDOWS\Sea.exe
O4 - HKCU\..\Run: [Jhv] C:\WINDOWS\Ngp.exe
O4 - HKCU\..\Run: [Sqe] C:\WINDOWS\System32\Lvk.exe
O4 - HKCU\..\Run: [Ihj] C:\WINDOWS\System32\Utv.exe
O4 - HKCU\..\Run: [Aro] C:\WINDOWS\System32\Bqe.exe
O4 - HKCU\..\Run: [Kjg] C:\WINDOWS\System32\Cpm.exe
O4 - HKCU\..\Run: [One] C:\WINDOWS\Qcf.exe
O4 - HKCU\..\Run: [Pst] C:\WINDOWS\Dmh.exe
O4 - HKCU\..\Run: [Lla] C:\WINDOWS\Bqp.exe
O4 - HKCU\..\Run: [Utu] C:\WINDOWS\Rch.exe
O4 - HKCU\..\Run: [Tkr] C:\WINDOWS\Eet.exe
O4 - HKCU\..\Run: [Rdf] C:\WINDOWS\Bcb.exe
O4 - HKCU\..\Run: [Nsj] C:\WINDOWS\System32\Acp.exe
O4 - HKCU\..\Run: [Mgr] C:\WINDOWS\System32\Bcp.exe
O4 - HKCU\..\Run: [Epn] C:\WINDOWS\System32\Fjd.exe
O4 - HKCU\..\Run: [Ovq] C:\WINDOWS\Bmh.exe
O4 - HKCU\..\Run: [Fek] C:\WINDOWS\Lel.exe
O4 - HKCU\..\Run: [Lsk] C:\WINDOWS\System32\Gjd.exe
O4 - HKCU\..\Run: [Pip] C:\WINDOWS\System32\Had.exe
O4 - HKCU\..\Run: [Cld] C:\WINDOWS\Gph.exe
O4 - HKCU\..\Run: [Upe] C:\WINDOWS\Asl.exe
O4 - HKCU\..\Run: [Jrm] C:\WINDOWS\System32\Kio.exe
O4 - HKCU\..\Run: [Eev] C:\WINDOWS\System32\Sma.exe
O4 - HKCU\..\Run: [Cpu] C:\WINDOWS\Jqb.exe
O4 - HKCU\..\Run: [Vuv] C:\WINDOWS\Cas.exe
O4 - HKCU\..\Run: [Kdj] C:\WINDOWS\Uoj.exe
O4 - HKCU\..\Run: [Gds] C:\WINDOWS\Bgs.exe
O4 - HKCU\..\Run: [Aui] C:\WINDOWS\Pna.exe
O4 - HKCU\..\Run: [Uau] C:\WINDOWS\Lvj.exe
O4 - HKCU\..\Run: [Kpl] C:\WINDOWS\Uue.exe
O4 - HKCU\..\Run: [Bcv] C:\WINDOWS\Glq.exe
O4 - HKCU\..\Run: [Tlc] C:\WINDOWS\Iqj.exe
O4 - HKCU\..\Run: [Dst] C:\WINDOWS\Mft.exe
O4 - HKCU\..\Run: [Rmf] C:\WINDOWS\Gmj.exe
O4 - HKCU\..\Run: [Clj] C:\WINDOWS\Uvn.exe
O4 - HKCU\..\Run: [Ode] C:\WINDOWS\System32\Gds.exe
O4 - HKCU\..\Run: [Oco] C:\WINDOWS\Gsi.exe
O4 - HKCU\..\Run: [Mml] C:\WINDOWS\Ulu.exe
O4 - HKCU\..\Run: [Tsa] C:\WINDOWS\System32\Umg.exe
O4 - HKCU\..\Run: [Lqm] C:\WINDOWS\System32\Fau.exe
O4 - HKCU\..\Run: [Mln] C:\WINDOWS\System32\Iiu.exe
O4 - HKCU\..\Run: [Snq] C:\WINDOWS\Biu.exe
O4 - HKCU\..\Run: [Rfg] C:\WINDOWS\Ikq.exe
O4 - HKCU\..\Run: [Igt] C:\WINDOWS\Qjs.exe
O4 - HKCU\..\Run: [Sdn] C:\WINDOWS\Loc.exe
O4 - HKCU\..\Run: [Ebj] C:\WINDOWS\System32\Der.exe
O4 - HKCU\..\Run: [Eoo] C:\WINDOWS\Jqe.exe
O4 - HKCU\..\Run: [Had] C:\WINDOWS\Mvf.exe
O4 - HKCU\..\Run: [Smq] C:\WINDOWS\System32\Auq.exe
O4 - HKCU\..\Run: [Tan] C:\WINDOWS\Ive.exe
O4 - HKCU\..\Run: [Afp] C:\WINDOWS\Dre.exe
O4 - HKCU\..\Run: [Urv] C:\WINDOWS\System32\Bhl.exe
O4 - HKCU\..\Run: [Ird] C:\WINDOWS\System32\Tto.exe
O4 - HKCU\..\Run: [Vea] C:\WINDOWS\Pvl.exe
O4 - HKCU\..\Run: [Umt] C:\WINDOWS\System32\Ohr.exe
O4 - HKCU\..\Run: [Bar] C:\WINDOWS\System32\Eae.exe
O4 - HKCU\..\Run: [Qft] C:\WINDOWS\Okf.exe
O4 - HKCU\..\Run: [Eme] C:\WINDOWS\Nff.exe
O4 - HKCU\..\Run: [Qsh] C:\WINDOWS\System32\Ddt.exe
O4 - HKCU\..\Run: [Cbq] C:\WINDOWS\Ver.exe
O4 - HKCU\..\Run: [Dsv] C:\WINDOWS\System32\Bcv.exe
O4 - HKCU\..\Run: [Lmj] C:\WINDOWS\Fei.exe
O4 - HKCU\..\Run: [Plt] C:\WINDOWS\Klu.exe
O4 - HKCU\..\Run: [Ibe] C:\WINDOWS\Iqk.exe
O4 - HKCU\..\Run: [Ios] C:\WINDOWS\System32\Lsi.exe
O4 - HKCU\..\Run: [Tnf] C:\WINDOWS\System32\Gdl.exe
O4 - HKCU\..\Run: [Icu] C:\WINDOWS\Qpu.exe
O4 - HKCU\..\Run: [Hsl] C:\WINDOWS\Qjl.exe
O4 - HKCU\..\Run: [Ibm] C:\WINDOWS\System32\Jht.exe
O4 - HKCU\..\Run: [Ohd] C:\WINDOWS\System32\Chi.exe
O4 - HKCU\..\Run: [Tjg] C:\WINDOWS\Vae.exe
O4 - HKCU\..\Run: [Tkn] C:\WINDOWS\Ulf.exe
O4 - HKCU\..\Run: [Iuc] C:\WINDOWS\System32\Qhq.exe
O4 - HKCU\..\Run: [Uvo] C:\WINDOWS\Ull.exe
O4 - HKCU\..\Run: [Gmp] C:\WINDOWS\Niv.exe
O4 - HKCU\..\Run: [Vde] C:\WINDOWS\System32\Qui.exe
O4 - HKCU\..\Run: [Tpa] C:\WINDOWS\Klq.exe
O4 - HKCU\..\Run: [Iud] C:\WINDOWS\Knc.exe
O4 - HKCU\..\Run: [Hjv] C:\WINDOWS\Flq.exe
O4 - HKCU\..\Run: [Snm] C:\WINDOWS\System32\Ttm.exe
O4 - HKCU\..\Run: [Jtr] C:\WINDOWS\System32\Bqc.exe
O4 - HKCU\..\Run: [Tvc] C:\WINDOWS\Mpr.exe
O4 - HKCU\..\Run: [Sfc] C:\WINDOWS\System32\Has.exe
O4 - HKCU\..\Run: [Sqq] C:\WINDOWS\System32\Unn.exe
O4 - HKCU\..\Run: [Obh] C:\WINDOWS\System32\Acg.exe
O4 - HKCU\..\Run: [Kih] C:\WINDOWS\Dit.exe
O4 - HKCU\..\Run: [Evo] C:\WINDOWS\System32\Shm.exe
O4 - HKCU\..\Run: [Teq] C:\WINDOWS\System32\Pod.exe
O4 - HKCU\..\Run: [Kjn] C:\WINDOWS\System32\Pmk.exe
O4 - HKCU\..\Run: [Pvn] C:\WINDOWS\System32\Ghn.exe
O4 - HKCU\..\Run: [Ssp] C:\WINDOWS\Jvr.exe
O4 - HKCU\..\Run: [Orj] C:\WINDOWS\Sif.exe
O4 - HKCU\..\Run: [Ehb] C:\WINDOWS\System32\Gga.exe
O4 - HKCU\..\Run: [Kgv] C:\WINDOWS\System32\Rcc.exe
c:\windows\system32\ker_ps.exe
C:\WINDOWS\image.new
C:\WINDOWS\SYSTEM32\MSplg7.dll

Reboot your computer to go back to normal mode and post a new log.

#7 cd-spencer

cd-spencer
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 16 May 2005 - 11:44 AM

Hi

I have tried to copy HJT to a new file as recomended, but a window still opens telling me I am using a temporary file, howeever it seems to have worked, see new log, thanks for your continued help.

CS.

Logfile of HijackThis v1.99.1
Scan saved at 5:39:32 PM, on 5/16/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O16 - DPF: Win32 Classes -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/AgeVerif...bridge-c420.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
O20 - Winlogon Notify: f3dsl - C:\WINDOWS\SYSTEM32\MSplg7.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:18 PM

Posted 16 May 2005 - 01:01 PM

Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button:

O16 - DPF: Win32 Classes -
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/AgeVerif...bridge-c420.cab
O20 - Winlogon Notify: f3dsl - C:\WINDOWS\SYSTEM32\MSplg7.dll

Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)

C:\WINDOWS\SYSTEM32\MSplg7.dll

Reboot your computer to go back to normal mode and post a new log.

#9 cd-spencer

cd-spencer
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 17 May 2005 - 01:00 PM

Thanks again for you assistance....please see new log below.

CS.

Logfile of HijackThis v1.99.1
Scan saved at 6:56:53 PM, on 5/17/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/keyword/%s
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\System32\catsrvut.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE

#10 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:18 PM

Posted 17 May 2005 - 05:03 PM

Your log is clean! Great job!

Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and reenable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and reenable system restore here:

Managing Windows Millenium System Restore

or

Windows XP System Restore Guide

Renable system restore with instructions from tutorial above


Next,

This process will clean out your Temp files and your Temporary Internet Files. Please do both steps:

Step 1:Delete Temp Files
To clean out your temp files, click on Start and then run, and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. Please delete all files that are found there. If you get an error when deleting a file, skip that file and delete all the others. If you had trouble deleting a file, reboot into Safe Mode and follow this step again. You should now be able to delete all the files.

Step 2: Delete Temporary Internet Files
Now I want you to open up Internet Explorer, and click on the Tools menu and then Internet Options. At the General tab, which should be the first tab you are currently on, click on the Delete Files button and put a checkmark in Delete offline content. Then press the OK button. This may take quite a while, so do not be alarmed with how long it takes. When it is done, your Temporary Internet Files will now be deleted.

Finally, and definitely the MOST IMPORTANT step, click on the following tutorial and follow each step listed there:

Simple and easy ways to keep your computer safe and secure on the Internet


Glad I was able to help and if there any other problems related to your computer please feel free to post them in the appropriate forum. Though we help people with spyware and viruses here at BC, we also help people with other computer problems! Do not forget to tell your friends about us!

#11 cd-spencer

cd-spencer
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 19 May 2005 - 02:59 AM

Hi

Thank you for all you assistance, I can get back to normal computing again.

I will spread the word about your excellent help!

Cheers

CS.

#12 cd-spencer

cd-spencer
  • Topic Starter

  • Members
  • 25 posts
  • OFFLINE
  •  
  • Local time:11:18 AM

Posted 01 September 2005 - 11:06 AM

Hi again

I am afriad that I have picked up a virus / some spware again...this time it is trying to dial out from my computer....I have already blocked my phone line from accessing all premium rate lines (after having a 30 call made by my computer 5 years ago). The problem is though that I can no longer access the web at all at home due to the fact that once the computer tries to dial out Internet Explorer crashes...any ideas?

Thanks again

CHRIS

#13 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:12:18 PM

Posted 01 September 2005 - 11:10 AM

Please create a brand new hijackthis log in its own new topic and someone will help you when they can




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users