• Welcome Guest, to the Spybot Forums! It's 2025, and we just upgraded our forum software.

    Today is Safer Internet Day, and with our new forum, you can finally use passkeys to login. That was about time!

    Of course, you could ask if a forum is still useful, with so many social media networks out there where you might already have an account, and met a lot of users. You can now use your login from some of those networks to log in here. And by posting here, your question and data is stored on our servers and not automatically shared with a whole social media network.

    We'll also start using the forum for small bits of information, announcements and more again.

whenever I open hijackthis, it automatically closes, amongst other things


New member
The problem started to manifest itself when my browser suddenly gets redirected to some anti virus sites. I decided to search around and got this vundofix program working. That seemed to fix it but I wasn't too sure I'm free of "infections" yet because whenever I try to open hijackthis, it closes after around 2 seconds. I was able to do a scan before it closed and was able to save the log. It's interesting to note that whenever I open the log, it too exits itself after a split second. The folder "hijackthis" also does the same.


Logfile of HijackThis v1.99.1
Scan saved at 12:33:56 PM, on 3/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\Program Files\Common Files\{C8182BD1-0BB8-1033-0429-050509080001}\Update.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Last.fm\LastFM.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Documents and Settings\hello\Desktop\hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {79310A4B-63D7-413A-A698-38C6563BEA64} - C:\WINDOWS\system32\nnnomjj.dll (file missing)
O2 - BHO: (no name) - {96482029-7B5F-4A87-ADBB-4EE5FCF68908} - C:\WINDOWS\system32\wipdjjmc.dll (file missing)
O2 - BHO: (no name) - {CC56E44F-0DC6-416A-99A0-DCE56447BBB8} - C:\WINDOWS\system32\geedc.dll (file missing)
O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [{C8182BD1-0BB8-1033-0429-050509080001}] "C:\Program Files\Common Files\{C8182BD1-0BB8-1033-0429-050509080001}\Update.exe" mc-110-12-0001291
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACP.EXE /P26 "EPSON Stylus CX3700 Series" /O6 "USB001" /M "Stylus CX3700"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\jxnvrfmq.dll",setvm
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1168219597203
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: notifyc - C:\WINDOWS\system32\ccc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winopn32 - C:\WINDOWS\SYSTEM32\winopn32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
Incident Status Location

Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.ct.360i.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.com.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.systemdoctor.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.systemdoctor.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.overture.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.atwola.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[server.iad.liveperson.net/hc/47296625]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\hello\Application Data\Mozilla\Firefox\Profiles\1c4dkgs7.default\cookies.txt[server.iad.liveperson.net/hc/90754820]
Adware:Adware/ActiveSearch Not disinfected C:\Documents and Settings\hello\Local Settings\Temp\b122.exe[²ÜÇ\Services.dll]
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\hello\Local Settings\Temp\b133.exe[webhdll.dll]
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\hello\Local Settings\Temp\b133.exe[whiehlpr.dll]
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\hello\Local Settings\Temp\b133.exe[whAgent.exe]
Adware:Adware/ActiveSearch Not disinfected C:\Documents and Settings\hello\Local Settings\Temp\b133.exe[²ÜÇ\Services.dll]
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\hello\Local Settings\Temp\uceiaynn.exe
Virus:Trj/Agent.ECN Disinfected C:\Documents and Settings\hello\Local Settings\Temporary Internet Files\Content.IE5\5S0W779K\xc60[1].exe
Virus:Trj/Downloader.NEG Disinfected C:\Documents and Settings\hello\Local Settings\Temporary Internet Files\Content.IE5\BR21CVOB\antzom[1].exe
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.com.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt[.burstnet.com/]
Virus:Bck/Agent.DFZ Disinfected C:\Documents and Settings\MEDIA CENTER\Local Settings\Temporary Internet Files\Content.IE5\8BAV6XMD\type32w[1].exe
Virus:Bck/Agent.DFZ Disinfected C:\Documents and Settings\MEDIA CENTER\Local Settings\Temporary Internet Files\Content.IE5\QNKNMDWZ\type32w[1].exe
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{38182BD1-0BB8-1033-0429-050509080001}\Bar888.dll
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{38182BD1-0BB8-1033-0429-050509080001}\UnInstall.exe
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{C8182BD1-0BB8-1033-0429-050509080001}\system.dll
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{C8182BD1-0BB8-1033-0429-050509080001}\Update.exe
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Ipwindows\ipwins.dll
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\jxnvrfmq.dll
Adware:Adware/Maxifiles Not disinfected C:\WINDOWS\system32\unsvchosts.exe
Virus:Trj/Agent.ECN Disinfected C:\WINDOWS\Temp\winBF.tmp.exe
Virus:Trj/Downloader.NEG Disinfected C:\WINDOWS\Temp\winD1.tmp.exe
Hacktool:HackTool/EvID Not disinfected D:\progs\progs really\EvID4226Patch223d-en.zip[EvID4226Patch.exe]
Hacktool:HackTool/EvID Not disinfected F:\New Folder\Unzipped\EvID4226Patch223d-en\EvID4226Patch.exe
Alright, I'm posting this from another computer because it seems that the problem isn't exclusive to the hijackthis files. Firefox, internet explorer, both of them now close without warning. I'll see if any other programs do this too
Hello nwwww and welcome to the Forums :)

You're definately infected...

Please run these tools if possible:

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Do not mouseclick combofix's window whilst it's running. That may cause it to stall


Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Thanks for the prompt response! Here are the logs as you requested:

"hello" - 07-03-23 12:00:23 Service Pack 2
ComboFix 07-03-22 - Running from: "C:\Documents and Settings\hello\Desktop"

/wow section not completed - STAGE #6D
((((((((((((((((((((((((((((((( Files Created from 2007-02-23 to 2007-03-23 ))))))))))))))))))))))))))))))))))

2007-03-22 10:10 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-03-22 09:58 140,288 --a------ C:\WINDOWS\system32\ccc.dll
2007-03-22 09:50 <DIR> d-------- C:\DOCUME~1\hello\.housecall6.6
2007-03-22 09:49 <DIR> d-------- C:\DOCUME~1\hello\APPLIC~1\Sun
2007-03-22 08:49 12,245,199 --------- C:\AVG7QT.DAT
2007-03-17 19:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Spybot - Search & Destroy
2007-03-17 17:08 123,412 --a------ C:\WINDOWS\system32\jxnvrfmq.dll
2007-03-17 17:01 19,968 --a------ C:\WINDOWS\system32\winopn32.dll
2007-03-17 11:15 <DIR> d-------- C:\Program Files\XP Codec Pack
2007-03-17 09:36 <DIR> d-------- C:\DOCUME~1\hello\APPLIC~1\Uniblue
2007-03-17 08:11 <DIR> d-------- C:\DOCUME~1\hello\APPLIC~1\SmartFTP
2007-03-14 18:53 <DIR> d-------- C:\Program Files\CD Wave
2007-03-04 14:58 <DIR> d-------- C:\New Folder
2007-02-23 21:07 53,248 --a------ C:\WINDOWS\system32\ImageOle.dll
2007-02-23 21:07 <DIR> d-------- C:\Program Files\Ocean Technology
2007-02-23 20:38 53,284 --a------ C:\WINDOWS\War3Unin.dat
2007-02-23 20:38 2,829 --a------ C:\WINDOWS\War3Unin.pif
2007-02-23 20:38 139,264 --a------ C:\WINDOWS\War3Unin.exe

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-03-23 11:50 -------- d-------- C:\DOCUME~1\hello\APPLIC~1\utorrent
2007-03-22 10:39 -------- d-------- C:\Program Files\winamp
2007-03-22 10:38 -------- d-------- C:\Program Files\poweriso
2007-03-22 10:35 -------- d-------- C:\Program Files\last.fm
2007-03-22 10:34 -------- d-------- C:\Program Files\itunes
2007-03-22 08:29 -------- d-------- C:\Program Files\java
2007-03-19 06:12 -------- d-------- C:\Program Files\soulseek
2007-03-14 19:03 -------- d-------- C:\Program Files\goldwave
2007-03-14 11:01 -------- d--h----- C:\Program Files\installshield installation information
2007-02-27 23:36 -------- d-------- C:\Program Files\utorrent
2007-02-24 19:31 43520 --a------ C:\WINDOWS\system32\cmdlineext03.dll
2007-02-06 19:21 -------- d-------- C:\Program Files\getright
2007-02-05 13:04 359808 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-01-29 20:58 27137 --a------ C:\WINDOWS\diiunin.dat
2007-01-29 20:51 21840 --a------ C:\WINDOWS\system32\sintfnt.dll
2007-01-29 20:51 17212 --a------ C:\WINDOWS\system32\sintf32.dll
2007-01-29 20:51 12067 --a------ C:\WINDOWS\system32\sintf16.dll
2007-01-29 20:41 94208 --a------ C:\WINDOWS\diiunin.exe
2007-01-29 20:41 2829 --a------ C:\WINDOWS\diiunin.pif
2007-01-08 20:57 36604 --a------ C:\WINDOWS\system32\spoonuninstall-dbpoweramp music converter.dat
2007-01-08 20:57 131072 --a------ C:\WINDOWS\system32\spoonuninstall.exe
2007-01-08 20:53 0 --a------ C:\WINDOWS\nsreg.dat
2007-01-08 19:20 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-01-08 19:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
2007-01-08 17:57 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-01-07 17:16 0 --a------ C:\AUTOEXEC.BAT
2007-01-07 17:14 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-01-07 09:03 62 --ahs---- C:\DOCUME~1\hello\APPLIC~1\desktop.ini

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""

"High Definition Audio Property Page Shortcut"="HDAShCut.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"EPSON Stylus CX3700 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIACP.EXE /P26 \"EPSON Stylus CX3700 Series\" /O6 \"USB001\" /M \"Stylus CX3700\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"2chkdsk"="rundll32.exe \"C:\\WINDOWS\\system32\\jxnvrfmq.dll\",setvm"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users.WINDOWS\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_Run]
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]
"command"="C:\\Program Files\\Ipwindows\\ipwins.exe"




"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\notifyc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winopn32

"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0

Shell\Auto\command K:\RavMonE.exe e
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

shell\Auto\command K:\RavMonE.exe e
shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

Shell\Auto\command K:\RavMonE.exe e
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

Shell\Auto\command RavMonE.exe e
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e

Contents of the 'Scheduled Tasks' folder


catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Completion time: 07-03-23 12:01:41

vundofix log:

VundoFix V6.3.17

Checking Java version...

Java version is
Old versions of java are exploitable and should be removed.

Java version is

Scan started at 12:03:02 PM 3/23/2007

Listing files found while scanning....


Beginning removal...

Attempting to delete C:\WINDOWS\system32\ccc.dll
C:\WINDOWS\system32\ccc.dll Has been deleted!

Performing Repairs to the registry.


I'd also like to point out that I had to rename combofix to run it since it closes prematurely when it's opened
Logfile of HijackThis v1.99.1
Scan saved at 12:17:48 PM, on 3/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Documents and Settings\hello\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {79310A4B-63D7-413A-A698-38C6563BEA64} - C:\WINDOWS\system32\nnnomjj.dll (file missing)
O2 - BHO: (no name) - {96482029-7B5F-4A87-ADBB-4EE5FCF68908} - C:\WINDOWS\system32\wipdjjmc.dll (file missing)
O2 - BHO: (no name) - {CC56E44F-0DC6-416A-99A0-DCE56447BBB8} - C:\WINDOWS\system32\geedc.dll (file missing)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACP.EXE /P26 "EPSON Stylus CX3700 Series" /O6 "USB001" /M "Stylus CX3700"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\jxnvrfmq.dll",setvm
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1168219597203
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: notifyc - C:\WINDOWS\system32\ccc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winopn32 - C:\WINDOWS\SYSTEM32\winopn32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

It isn't closing anymore after running combofix + vundofix. So far so good!
Hi again, we'll continue :)

You should print these instructions or save these to a text file. Follow these instructions carefully.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Download ATF Cleaner by Atribune to your desktop.
Do NOT run yet.

Make your hidden files visible:
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Uncheck "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.


Backup your registry:
  • Start
  • Run
  • Type the following to the box and hit Ok: regedit
  • A window opens, click on File
  • Choose Export form the menu
  • Change the save location to C:\
  • Give the filename, RegBackUp
  • Make sure that the filetype is set to Registryfiles (*.reg)
  • Click on Save and Close the window

Open Notepad (NOT WORDPAD!) and copy the following lines from the quote box below into a new document, leaving a blank line at the end. (don't forget to copy and paste the word REGEDIT4) :


[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IpWins]


Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Save the document to your desktop as Fix.reg and filetype: All Files
Go to your desktop and double click on the file to run Fix.reg and when it asks you if you want to merge the contents to the registry, click yes/ok.

Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.

O2 - BHO: (no name) - {79310A4B-63D7-413A-A698-38C6563BEA64} - C:\WINDOWS\system32\nnnomjj.dll (file missing)
O2 - BHO: (no name) - {96482029-7B5F-4A87-ADBB-4EE5FCF68908} - C:\WINDOWS\system32\wipdjjmc.dll (file missing)
O2 - BHO: (no name) - {CC56E44F-0DC6-416A-99A0-DCE56447BBB8} - C:\WINDOWS\system32\geedc.dll (file missing)
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\jxnvrfmq.dll",setvm
O20 - Winlogon Notify: notifyc - C:\WINDOWS\system32\ccc.dll (file missing)
O20 - Winlogon Notify: winopn32 - C:\WINDOWS\SYSTEM32\winopn32.dll

Restart your computer to the safe mode:
  • Restart your computer
  • Start tapping the F8 key when the computer restarts.
  • When the start menu opens, choose Safe mode
  • Press Enter. The computer then begins to start in Safe mode.

Go to the My Computer and delete the following files (if present):

Go to the My Computer and delete the following folders (if present):
C:\Program Files\Ipwindows
C:\Program Files\Common Files\{38182BD1-0BB8-1033-0429-050509080001}
C:\Program Files\Common Files\{C8182BD1-0BB8-1033-0429-050509080001}

Run ATF Cleaner
  • Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.


When you're ready, please post the following logs to here:
- AVG's report
- a fresh HijackThis log
ahoy, I was able to follow everything to the letter except for one thing. I wasn't able to delete "winopn32.dll" because it was being "used or write protected."

Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 12:02:13 AM, on 3/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\iPod\bin\iPodService.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACP.EXE /P26 "EPSON Stylus CX3700 Series" /O6 "USB001" /M "Stylus CX3700"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1168219597203
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winopn32 - C:\WINDOWS\SYSTEM32\winopn32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

anti virus scan:

AVG Anti-Spyware - Scan Report

+ Created at: 11:58:52 PM 3/24/2007

+ Scan result:

C:\Documents and Settings\MEDIA CENTER\Application Data\Install.dat -> Adware.Bravesent : Cleaned with backup (quarantined).
C:\WINDOWS\system32\clcrb.log -> Downloader.Agent.apb : Cleaned with backup (quarantined).
D:\progs\progs really\EvID4226Patch223d-en.zip/EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
F:\New Folder\Unzipped\EvID4226Patch223d-en\EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
:mozilla.50:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.51:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.60:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.61:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.62:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.94:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.95:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.96:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.97:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.17:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.135:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.98:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.45:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.55:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.56:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.115:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.116:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.117:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.41:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
C:\Documents and Settings\hello\Cookies\hello@search.live[1].txt -> TrackingCookie.Live : Cleaned.
:mozilla.122:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.106:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.15:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.16:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.46:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.47:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.48:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.49:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.139:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.101:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.11:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\hello\Cookies\hello@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\hello\Cookies\hello@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Cleaned.
:mozilla.133:C:\Documents and Settings\MEDIA CENTER\Application Data\Mozilla\Firefox\Profiles\fakfdi0x.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.

::Report end

Thanks again
Hi again :)

Open HijackThis.
  • Open the Misc Tools section
  • Delete a file on Reboot
  • Copy the following line to the filenamebox and press Open; C:\WINDOWS\SYSTEM32\winopn32.dll
  • Answer Yes
  • Reboot the computer if it isn't restarted automatically

Fix this line with HijackThis (if found):

O20 - Winlogon Notify: winopn32 - C:\WINDOWS\SYSTEM32\winopn32.dll

Restart the computer. post a fresh HijackThis log to here and let me know how the computer is running :bigthumb:
Logfile of HijackThis v1.99.1
Scan saved at 4:03:39 PM, on 3/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\iPod\bin\iPodService.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX3700 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACP.EXE /P26 "EPSON Stylus CX3700 Series" /O6 "USB001" /M "Stylus CX3700"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1168219597203
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

Running very smoothly if I do say so myself!
Hi again, it is looking clean now :)

You don't seem to have a third-party firewall installed. You must install one firewall.
It is possible that you're using the Windows XP firewall. That is of course better than nothing but I recommend that you install a more advanced firewall that gives more protection. Windows firewall doesn't eg protect your computer from inbound threats. This means that any malware on your computer is free to "phone home" for more instructions. Remember to use only one firewall at the same time. I'll give you a few alternatives if you want to install a third-party firewall:

These are good (free) firewalls:
Now you can clean AVG's Quarantine:
  • Open AVG Anti-Spyware
  • Click Infections
  • Click Quarantine tab
  • Click Select all
  • Click Remove finally
  • Close the program
You can remove the tools we used.

Then you should update your Java to the latest version (6.0)
  • [*]Start
    [*]Control Panel
    [*]Add/Remove Programs
  • Delete the old Java, J2SE Runtime Environment 5.0 Update 11
  • Download the latest version of Java Runtime Environment (JRE) 6.0.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement."
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Install it
Now you can make your hidden files hidden again.
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Check "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.


Now that you seem to be clean, please follow these simple steps in order to keep your computer clean and secure:

Stay clean and be safe ;)
Thanks a lot! It's very much appreciated; I'll be sure to follow those things you've mentioned. Thanks again!
That's great news and you're very welcome :D:

As the problem appears to be resolved this topic has been archived.

If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread; this applies only to the original topic starter.

Glad we could help :2thumb: