PDA

View Full Version : My HiJackThis log file: look/help?



The Vines Kid
2007-06-13, 09:46
I just downloaded HiJackThis and ran it.
Here is my log file.
I was just wondering if there is anything wrong, anything I should fix, ect.
So, if someone would be so kind... =)
plz and thank you

Logfile of HijackThis v1.99.1
Scan saved at 3:12:26 AM, on 6/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
E:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Viewpoint\Common\ViewpointService.exe
E:\Program Files\Common Files\AOL\1149662162\ee\AOLSoftware.exe
E:\Program Files\Real\RealPlayer\RealPlay.exe
E:\WINDOWS\BCMSMMSG.exe
E:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
E:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\Program Files\Zune\ZuneLauncher.exe
E:\Program Files\QuickTime\qttask.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\PROGRA~1\AMERIC~1.0\waol.exe
E:\Documents and Settings\Fullmetal Studios\Desktop\SetPoint\KEM.exe
E:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
E:\Documents and Settings\Fullmetal Studios\Desktop\SetPoint\KHALMNPR.EXE
E:\PROGRA~1\AMERIC~1.0\shellmon.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Documents and Settings\Fullmetal Studios\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://my.screenname.aol.com/_cqr/login/login.psp?mcState=initialized&seamless=novl&sitedomain=sns.webmail.aol.com&lang=en&locale=us&authLev=2&siteState=ver%3a1%252c0%26ac%3aWS%26ld%3awebmail.aol.com%26uv%3aAOL%26lc%3aen-us%26ud%3aaol.com%26br%3aWebSuite-Prod&checkAIM=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://a.tribalfusion.com/p.media/OSCKONGTROTDOGQLPYTTEOWODINKNNRSMNVIKLJDMONDFHHHERPPBWTMUFWNEKRGOJGBHMINNPPFM/137796/pop.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {01F49B0E-64C5-4E2B-B235-3C2FA4E498CD} - (no file)
O2 - BHO: (no name) - {046F63DC-EA85-451A-96AA-45E981A7DB8D} - (no file)
O2 - BHO: (no name) - {047AC1CF-836C-4E53-BD63-085323C5DA7F} - (no file)
O2 - BHO: (no name) - {09668770-320B-4567-B8F4-6AF393A718B9} - E:\WINDOWS\system32\mlljh.dll (file missing)
O2 - BHO: (no name) - {3E581F24-2769-42CA-84B8-F8981A89BDF2} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {61C03D27-31ED-496A-AA98-36EB2BC0FD84} - (no file)
O2 - BHO: (no name) - {700F5045-8BBF-4E6E-8336-6DF4EB5A9893} - (no file)
O2 - BHO: (no name) - {760FA4DF-112D-4414-B004-C812448D44F6} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7D27B3ED-C764-4B73-880F-BF36046C31D2} - E:\WINDOWS\system32\geeda.dll (file missing)
O2 - BHO: (no name) - {89CCDDCD-1006-4ACD-A39B-6E3615D6A205} - E:\WINDOWS\system32\geedb.dll (file missing)
O2 - BHO: (no name) - {8F53316B-A584-4186-840C-0A76AF3592C3} - E:\WINDOWS\system32\hvaoatdg.dll (file missing)
O2 - BHO: (no name) - {B6D30648-50CB-4FF3-842E-D20E7AFA8282} - (no file)
O2 - BHO: (no name) - {C210AB4F-B0F6-4863-BE9A-4316A641CE0A} - E:\WINDOWS\system32\ssttr.dll (file missing)
O2 - BHO: (no name) - {D81F8C3B-392E-4CA4-9B4B-79A971AF943A} - (no file)
O2 - BHO: (no name) - {DC56693D-C4BB-482A-A759-BB94DE8E161B} - (no file)
O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - (no file)
O2 - BHO: (no name) - {FCA7A742-DA07-43D8-B1B0-BD73C341FF91} - (no file)
O4 - HKLM\..\Run: [HostManager] E:\Program Files\Common Files\AOL\1149662162\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] E:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] E:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Pure Networks Port Magic] "E:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WorksFUD] E:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] E:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] E:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] E:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [USBDetector] C:\USBStorage\USBDetector.exe
O4 - HKLM\..\Run: [RemoteControl] "E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] E:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ProfileWatcher] E:\Documents and Settings\Fullmetal Studios\Desktop\ProfileWatcher\profilewatcher.exe
O4 - HKLM\..\Run: [Zune Launcher] "E:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PMXInit] E:\WINDOWS\system32\pmxinit.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "E:\WINDOWS\system32\nwpygbqx.dll",realset
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "E:\PROGRA~1\AMERIC~1.0\AOL.EXE" -b
O4 - Global Startup: Logitech SetPoint.lnk = E:\Documents and Settings\Fullmetal Studios\Desktop\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &AIM Search - res://E:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://E:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
O20 - Winlogon Notify: ddayv - E:\WINDOWS\
O20 - Winlogon Notify: ddccd - E:\WINDOWS\
O20 - Winlogon Notify: gebyv - E:\WINDOWS\
O20 - Winlogon Notify: geeda - E:\WINDOWS\system32\geeda.dll (file missing)
O20 - Winlogon Notify: geedb - E:\WINDOWS\system32\geedb.dll (file missing)
O20 - Winlogon Notify: jkhfg - E:\WINDOWS\
O20 - Winlogon Notify: mlljh - E:\WINDOWS\system32\mlljh.dll (file missing)
O20 - Winlogon Notify: pmkjh - E:\WINDOWS\
O20 - Winlogon Notify: pmkjj - E:\WINDOWS\
O20 - Winlogon Notify: pmnno - E:\WINDOWS\
O20 - Winlogon Notify: ssqrp - E:\WINDOWS\
O20 - Winlogon Notify: sstts - E:\WINDOWS\
O20 - Winlogon Notify: vtstu - E:\WINDOWS\
O20 - Winlogon Notify: vturr - E:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - E:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - E:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - E:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Net API (NETAPI) - Unknown owner - E:\WINDOWS\system32\ntps.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - E:\Program Files\Viewpoint\Common\ViewpointService.exe

The Vines Kid
2007-06-13, 18:36
I've used VundoFix, it detects these 3 .dll files, but won't remove them.
Everytime I reboot, they're still there.
Please help if you can.
I'll post my HiJackThis log file here, just in case.
Also, if there's any oher problems you see, please let me know.

Logfile of HijackThis v1.99.1
Scan saved at 12:35:46 PM, on 6/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
E:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Viewpoint\Common\ViewpointService.exe
E:\Program Files\Common Files\AOL\1149662162\ee\AOLSoftware.exe
E:\Program Files\Common Files\AOL\ACS\AOLDial.exe
E:\Program Files\Real\RealPlayer\RealPlay.exe
E:\WINDOWS\BCMSMMSG.exe
E:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
E:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\Program Files\Zune\ZuneLauncher.exe
E:\Program Files\QuickTime\qttask.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\WINDOWS\system32\ctfmon.exe
E:\PROGRA~1\AMERIC~1.0\waol.exe
E:\Documents and Settings\Fullmetal Studios\Desktop\SetPoint\KEM.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
E:\Documents and Settings\Fullmetal Studios\Desktop\SetPoint\KHALMNPR.EXE
E:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
E:\PROGRA~1\AMERIC~1.0\shellmon.exe
E:\Program Files\Internet Explorer\iexplore.exe
E:\Documents and Settings\Fullmetal Studios\Desktop\Protection Programs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://my.screenname.aol.com/_cqr/login/login.psp?mcState=initialized&seamless=novl&sitedomain=sns.webmail.aol.com&lang=en&locale=us&authLev=2&siteState=ver%3a1%252c0%26ac%3aWS%26ld%3awebmail.aol.com%26uv%3aAOL%26lc%3aen-us%26ud%3aaol.com%26br%3aWebSuite-Prod&checkAIM=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://a.tribalfusion.com/p.media/OSCKONGTROTDOGQLPYTTEOWODINKNNRSMNVIKLJDMONDFHHHERPPBWTMUFWNEKRGOJGBHMINNPPFM/137796/pop.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {01F49B0E-64C5-4E2B-B235-3C2FA4E498CD} - (no file)
O2 - BHO: (no name) - {046F63DC-EA85-451A-96AA-45E981A7DB8D} - (no file)
O2 - BHO: (no name) - {047AC1CF-836C-4E53-BD63-085323C5DA7F} - (no file)
O2 - BHO: (no name) - {09668770-320B-4567-B8F4-6AF393A718B9} - E:\WINDOWS\system32\mlljh.dll (file missing)
O2 - BHO: (no name) - {3E581F24-2769-42CA-84B8-F8981A89BDF2} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {61C03D27-31ED-496A-AA98-36EB2BC0FD84} - (no file)
O2 - BHO: (no name) - {700F5045-8BBF-4E6E-8336-6DF4EB5A9893} - (no file)
O2 - BHO: (no name) - {760FA4DF-112D-4414-B004-C812448D44F6} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7D27B3ED-C764-4B73-880F-BF36046C31D2} - E:\WINDOWS\system32\geeda.dll (file missing)
O2 - BHO: (no name) - {89CCDDCD-1006-4ACD-A39B-6E3615D6A205} - E:\WINDOWS\system32\geedb.dll (file missing)
O2 - BHO: (no name) - {8F53316B-A584-4186-840C-0A76AF3592C3} - E:\WINDOWS\system32\hvaoatdg.dll (file missing)
O2 - BHO: (no name) - {B6D30648-50CB-4FF3-842E-D20E7AFA8282} - (no file)
O2 - BHO: (no name) - {C210AB4F-B0F6-4863-BE9A-4316A641CE0A} - E:\WINDOWS\system32\ssttr.dll (file missing)
O2 - BHO: (no name) - {D81F8C3B-392E-4CA4-9B4B-79A971AF943A} - (no file)
O2 - BHO: (no name) - {DC56693D-C4BB-482A-A759-BB94DE8E161B} - (no file)
O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - (no file)
O2 - BHO: (no name) - {FCA7A742-DA07-43D8-B1B0-BD73C341FF91} - (no file)
O4 - HKLM\..\Run: [HostManager] E:\Program Files\Common Files\AOL\1149662162\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] E:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] E:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Pure Networks Port Magic] "E:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WorksFUD] E:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] E:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] E:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] E:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [USBDetector] C:\USBStorage\USBDetector.exe
O4 - HKLM\..\Run: [RemoteControl] "E:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] E:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ProfileWatcher] E:\Documents and Settings\Fullmetal Studios\Desktop\ProfileWatcher\profilewatcher.exe
O4 - HKLM\..\Run: [Zune Launcher] "E:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [PMXInit] E:\WINDOWS\system32\pmxinit.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "E:\WINDOWS\system32\nwpygbqx.dll",realset
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "E:\PROGRA~1\AMERIC~1.0\AOL.EXE" -b
O4 - Global Startup: Logitech SetPoint.lnk = E:\Documents and Settings\Fullmetal Studios\Desktop\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &AIM Search - res://E:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://E:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
O20 - Winlogon Notify: ddayv - E:\WINDOWS\
O20 - Winlogon Notify: ddccd - E:\WINDOWS\
O20 - Winlogon Notify: gebyv - E:\WINDOWS\
O20 - Winlogon Notify: geeda - E:\WINDOWS\system32\geeda.dll (file missing)
O20 - Winlogon Notify: geedb - E:\WINDOWS\system32\geedb.dll (file missing)
O20 - Winlogon Notify: jkhfg - E:\WINDOWS\
O20 - Winlogon Notify: mlljh - E:\WINDOWS\system32\mlljh.dll (file missing)
O20 - Winlogon Notify: pmkjh - E:\WINDOWS\
O20 - Winlogon Notify: pmkjj - E:\WINDOWS\
O20 - Winlogon Notify: pmnno - E:\WINDOWS\
O20 - Winlogon Notify: ssqrp - E:\WINDOWS\
O20 - Winlogon Notify: sstts - E:\WINDOWS\
O20 - Winlogon Notify: vtstu - E:\WINDOWS\
O20 - Winlogon Notify: vturr - E:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - E:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - E:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - E:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft Net API (NETAPI) - Unknown owner - E:\WINDOWS\system32\ntps.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - E:\Program Files\Viewpoint\Common\ViewpointService.exe

Edit:
If you have waited FOUR days for advice post here. (http://forums.spybot.info/showthread.php?p=4836#post4836)

"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Blade81
2007-06-14, 19:37
Hello


Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once the scan is complete, Right Click inside the listbox (white box) and click add more files
Copy&Paste the 2 entries below into the top 2 boxes
C:\WINDOWS\system32\geeda.dll
C:\WINDOWS\system32\adeeg.*
Click Add Files and Click Close Window
Repeat with these entries
C:\WINDOWS\system32\geedb.dll
C:\WINDOWS\system32\bdeeg.*
C:\WINDOWS\system32\mlljh.dll
C:\WINDOWS\system32\hjllm.*
Click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from
Click the Scan for Vundo button when VundoFix appears at reboot.



Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
Install AVG Anti-Spyware by double clicking the installer.
Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
On the main screen under Your Computer's security.
Click on Change state next to Resident shield. It should now change to inactive.
Click on Change state next to Automatic updates. It should now change to inactive.
Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
Wait until you see the Update succesfull message.
Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates (http://www.ewido.net/en/download/updates/).
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update. Don't run AVG yet. Will do it a bit later.


Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop. Don't run ATF yet. Will do it a bit later.




Start hjt, click do a system scan only, check:
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://a.tribalfusion.com/p.media/OS...37796/pop.html
O2 - BHO: (no name) - {01F49B0E-64C5-4E2B-B235-3C2FA4E498CD} - (no file)
O2 - BHO: (no name) - {046F63DC-EA85-451A-96AA-45E981A7DB8D} - (no file)
O2 - BHO: (no name) - {047AC1CF-836C-4E53-BD63-085323C5DA7F} - (no file)
O2 - BHO: (no name) - {09668770-320B-4567-B8F4-6AF393A718B9} - E:\WINDOWS\system32\mlljh.dll (file missing)
O2 - BHO: (no name) - {3E581F24-2769-42CA-84B8-F8981A89BDF2} - (no file)
O2 - BHO: (no name) - {61C03D27-31ED-496A-AA98-36EB2BC0FD84} - (no file)
O2 - BHO: (no name) - {700F5045-8BBF-4E6E-8336-6DF4EB5A9893} - (no file)
O2 - BHO: (no name) - {760FA4DF-112D-4414-B004-C812448D44F6} - (no file)
O2 - BHO: (no name) - {7D27B3ED-C764-4B73-880F-BF36046C31D2} - E:\WINDOWS\system32\geeda.dll (file missing)
O2 - BHO: (no name) - {89CCDDCD-1006-4ACD-A39B-6E3615D6A205} - E:\WINDOWS\system32\geedb.dll (file missing)
O2 - BHO: (no name) - {8F53316B-A584-4186-840C-0A76AF3592C3} - E:\WINDOWS\system32\hvaoatdg.dll (file missing)
O2 - BHO: (no name) - {B6D30648-50CB-4FF3-842E-D20E7AFA8282} - (no file)
O2 - BHO: (no name) - {C210AB4F-B0F6-4863-BE9A-4316A641CE0A} - E:\WINDOWS\system32\ssttr.dll (file missing)
O2 - BHO: (no name) - {D81F8C3B-392E-4CA4-9B4B-79A971AF943A} - (no file)
O2 - BHO: (no name) - {DC56693D-C4BB-482A-A759-BB94DE8E161B} - (no file)
O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - (no file)
O2 - BHO: (no name) - {FCA7A742-DA07-43D8-B1B0-BD73C341FF91} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "E:\WINDOWS\system32\nwpygbqx.dll",realset
O20 - Winlogon Notify: ddayv - E:\WINDOWS\
O20 - Winlogon Notify: ddccd - E:\WINDOWS\
O20 - Winlogon Notify: gebyv - E:\WINDOWS\
O20 - Winlogon Notify: geeda - E:\WINDOWS\system32\geeda.dll (file missing)
O20 - Winlogon Notify: geedb - E:\WINDOWS\system32\geedb.dll (file missing)
O20 - Winlogon Notify: jkhfg - E:\WINDOWS\
O20 - Winlogon Notify: mlljh - E:\WINDOWS\system32\mlljh.dll (file missing)
O20 - Winlogon Notify: pmkjh - E:\WINDOWS\
O20 - Winlogon Notify: pmkjj - E:\WINDOWS\
O20 - Winlogon Notify: pmnno - E:\WINDOWS\
O20 - Winlogon Notify: ssqrp - E:\WINDOWS\
O20 - Winlogon Notify: sstts - E:\WINDOWS\
O20 - Winlogon Notify: vtstu - E:\WINDOWS\
O20 - Winlogon Notify: vturr - E:\WINDOWS\

Close browsers and other windows. Click fix checked.


Show hidden files
-----------------
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.


Delete if found (in safe mode if needed):
E:\WINDOWS\system32\nwpygbqx.dll


Running temp cleaner & AVG Anti-Spyware
---------------------------------------



Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.



Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act?
Click on Recommended Action and choose Quarantine from the popup menu.
Under How to scan?
All checkboxes should be ticked.
Under Possibly unwanted software:
All checkboxes should be ticked.
Under Reports:
Select Automatically generate report after every scan and uncheck Only if threats were found.
Under What to scan?
Select Scan every file.
Click on the Scan tab.
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
When the scan has finished, follow the instructions below.
IMPORTANT : Don't click on the
Save Scan Report
button before you did hit the
Apply all Actions
button.
Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
At the bottom of the window click on the Apply all Actions button. (3)
http://img509.imageshack.us/img509/4851/scanavgjk2.jpg
When done, click the Save Scan Report button. (4)
Click the Save Report as button.
Save the report to your Desktop.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.



Post
-contents of c:\vundofix.txt
-AVG Anti-Spyware log
-a fresh HJT log.

The Vines Kid
2007-06-15, 20:31
well, I would definatly do all that but... my hard drive stopped working.
I got a new casing yesturday, and switched everything.
I know I hooked everything up right, but my hard drive is not detected.
It is spinning, just not being detected.
I even tried it on another computer, but no luck.
I don't know what to do, I can't find anything to help.
I can't afford to lose my files.
...any advice...?

Blade81
2007-06-15, 20:54
Hi

Since we're mainly focused on malware removing I advise you to write about your problem at PC PitStop (http://forums.pcpitstop.com/). There are qualified persons to help you. Keep us updated. :)

The Vines Kid
2007-06-15, 21:19
Alright, thank you so much!
I'm gonna go post on there now.
I'll let you know how its going.
thanx again!

Blade81
2007-06-15, 22:06
Shall be waiting for your input :)

The Vines Kid
2007-06-16, 06:50
ive been talking w/ a fee ppl in that forum.
nothings worked so far.
i think my drive is dead, i cant hear it spinning anymore, and the bottom gets really hot.

Blade81
2007-06-16, 11:52
Hi

I read thru your topic at PC Pitstop. I'm not very good when it comes to inner part of computer. However, that doesn't sound good. :sad:

The Vines Kid
2007-06-17, 02:17
yea, my friends dad has it atm.
he thinks its toast, but he still has a few more things to try and save the files.
its only like a year and a half old, idk how it could have died so quickly.
I must have somehow gotten a bad virus. this happend to my other drive, but that was before I got into malware removale, and i didn't have any firewalls or scans.

Blade81
2007-06-17, 15:48
Hopefully he can save your files. Do you want that we keep this thread open for a while or shall we close it now?

The Vines Kid
2007-06-20, 23:55
uh... close it I guess.
even if I do get all my data back, I'm changing a few things, b/c I think I somehow got a bad virus (AVG didn't block it! =[ ) and I'm pretty sure what program caused it.
so I'd have a new log to post anyways.
but thank you for all your help, though PCpitshop couldn't help, it's still a great site.

Blade81
2007-06-21, 20:52
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.