Your Help Greatly Appreciated...

Hi
Try this
Go start programs > accessories > system tools > task Scheduled Tasks
right click on At1 and choose run.
 
Ok, I go to Start >programs >accesories >System Tools >Scheduled Tasks. It's the only option in there involving tasks. I click it, and a window opens up called "Scheduled Tasks" and my only option is to "Add Scheduled Task." I went in there to look around, and I couldn't find At1, so I browsed for VundoFix.exe and told that to run when the next minute hit. It then gave me an error screen that says:

"The new task has been created, but may not run because the account information could not be set.The specific error is: 0x80041315: The task scheduler service is not running."

So, I click OK because I have to, the window closes, and the "Scheduled Tasks" folder window is open, this time with a "VundoFix" option right under the "Add Scheduled Task." So I right-click on that, click run, and I get another error message:

"Unable to start the service"

So, I don't know what to do. I'm running XP Professional, and I know that we are picky about what services we install, because some of them are annoying/unnecessary and are just there so Windows can try and contorl our computer for us. We might have taken it out of the installation. I'm going to look around online and see if I can get it anywhere, and then I'll check back here, and if you don't know what to do, I'll install it and go from your last step.

Thanks a lot man, I didn't know it was going to be this big a pain in the butt, haha, so thank you.
 
OK, I managed to get my Scheduled Tasks up and running now, so I can do what you said. I looked up how to enable on the Windows website. I'll run VundoFix through it and see what happens...

OK, it's working now. I'll post again with the log in a minute.
 
VundoFix Log
Attempting to delete C:\WINDOWS\system32\vturq.dll
C:\WINDOWS\system32\vturq.dll Has been deleted!

Performing Repairs to the registry.
Done!


HijackThis Log
Logfile of HijackThis v1.99.1
Scan saved at 2:22:10 PM, on 6/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\TEST.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {B420E0F6-BB74-4E08-8AA5-ECC16B5398BC} - C:\WINDOWS\system32\vturq.dll (file missing)
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Administrator"
O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120686901041
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - file://E:\games\WebDriverFullInstall.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: wintfj32 - wintfj32.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /Service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PDEngine - Unknown owner - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Unknown owner - C:\Program Files\Raxco\PerfectDisk\PDSched.exe


Alright, there they are. THe HT Log and the VundoFix log. What do I need next?
 
Good work

Start Hijackthis and place a check next to these items If there.
O2 - BHO: (no name) - {B420E0F6-BB74-4E08-8AA5-ECC16B5398BC} - C:\WINDOWS\system32\vturq.dll (file missing)
O20 - Winlogon Notify: wintfj32 - wintfj32.dll (file missing)
====================================
Hit fix checked and close Hijackthis.

Update suns java manualy
Sun Java V1.5.0_07 is Available:
http://forums.spybot.info/showpost.php?p=12880&postcount=2

Go get the latest version of adobe reader

Post a report from one or both of these free online scan
Panda ActiveScan-Free online scanner,
http://www.pandasoftware.com/products/activescan.htm
Do a full scan > Click the my computer button
After the scan click see report then Save the report and post it back here please.
Computer Associates eTrust AV Web Scanner: http://www3.ca.com/virusinfo/virusscan.aspx
select all drives, scan, Try to cure/repair, if it cannot choose delete! If it cannot delete tell us the files names and locations.

Post back with one more hijackthis log , mention any problems.
 
OK, results after upgrading JRE and Adobe, and then running both of the scans:

ActiveScan Log
Incident Status Location

Adware:adware/cws.searchmeup Not disinfected c:\windows\uniq
Adware:adware/commad Not disinfected Windows Registry
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-7943585a-2060316f.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-7943585a-2060316f.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-7943585a-2060316f.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-7943585a-2060316f.zip[Beyond.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-28679adb-2b1603d9.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-28679adb-2b1603d9.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-28679adb-2b1603d9.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-28679adb-2b1603d9.zip[NewURLClassLoader.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-47723671-4aaf42c0.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-47723671-4aaf42c0.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-47723671-4aaf42c0.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-47723671-4aaf42c0.zip[NewURLClassLoader.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-bae16f0-78637b84.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-bae16f0-78637b84.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-bae16f0-78637b84.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-bae16f0-78637b84.zip[NewURLClassLoader.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-cb66fa7-39213768.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-cb66fa7-39213768.zip[Installer.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-cb66fa7-39213768.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-cb66fa7-39213768.zip[NewURLClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-217a6652-58d6b294.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-217a6652-58d6b294.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-217a6652-58d6b294.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-217a6652-58d6b294.zip[Parser.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-5c362d1c-31f30a1a.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-5c362d1c-31f30a1a.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-5c362d1c-31f30a1a.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-5c362d1c-31f30a1a.zip[Parser.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-255146ea-58613cb0.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-255146ea-58613cb0.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-255146ea-58613cb0.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-255146ea-58613cb0.zip[Parser.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-897c2ff-2412db17.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-897c2ff-2412db17.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-897c2ff-2412db17.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-897c2ff-2412db17.zip[Parser.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv698.jar-2ad2754e-19780c7c.zip[Matrix.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv698.jar-2ad2754e-19780c7c.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv698.jar-2ad2754e-19780c7c.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv698.jar-2ad2754e-19780c7c.zip[Parser.class]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@2o7[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@ad.yieldmanager[2].txt
Log continued on next post...
 
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@adopt.hbmediapro[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@ads.pointroll[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@adtech[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@adultfriendfinder[2].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@as-us.falkag[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@belnk[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@bluestreak[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@bs.serving-sys[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@burstnet[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@cgi-bin[1].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@clickbank[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@com[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@dist.belnk[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@go[2].txt
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@hotlog[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@microsofteup.112.2o7[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@perf.overture[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@questionmarket[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@realmedia[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@revenue[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@searchportal.information[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@serving-sys[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@statcounter[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@stats1.reliablestats[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@tribalfusion[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@www.burstbeacon[1].txt
Spyware:Cookie/SecurityError Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@www.systemuptodate[2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@yadro[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Administrator.SHAYMUS\Cookies\administrator@zedo[1].txt
End Of Log

Next scan on next post...
 
ETrust Scan Results

11 viruses detected, only 2 could be deleted. The other 9 could not be deleted or cured.

Un-deletable files

java.jar-28679adb-2b1603d9.zip>GetAccess.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

java.jar-28679adb-2b1603d9.zip>Installer.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

java.jar-47723671-4aaf42c0.zip>GetAccess.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

java.jar-47723671-4aaf42c0.zip>Installer.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

java.jar-bae16f0-78637b84.zip>GetAccess.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

java.jar-bae16f0-78637b84.zip>Installer.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

java.jar-cb66fa7-39213768.zip>GetAccess.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

java.jar-cb66fa7-39213768.zip>Installer.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\

xpl[1].wmf
C:\Documents and Settings\Administrator.SHAYMUS\Local Settings\Temporary Internet Files\Content.IE5\H3BCECPV\

End Of Results

Here are the files that it could delete:

Anima.class-385e4912-5f663c7b.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\

Anima.class-6986d708-666a5ad2.class
C:\Documents and Settings\Administrator.SHAYMUS\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\

Ok, HT Log coming right up in the next post...
 
HijackThis Log
Logfile of HijackThis v1.99.1
Scan saved at 11:22:17 PM, on 6/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\TEST.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe "Administrator"
O4 - HKCU\..\RunServicesOnce: [washindex] C:\Program Files\Washer\washidx.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120686901041
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - file://E:\games\WebDriverFullInstall.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVP Control Centre Service (AVPCC) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /Service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: PDEngine - Unknown owner - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDScheduler (PDSched) - Unknown owner - C:\Program Files\Raxco\PerfectDisk\PDSched.exe


Alright, what do I need to do next? I haven't run into any problems since I ran the VundoFix thing, but then again, I haven't really used this computer since then. So nothing right now, but maybe at some point later, I'll keep this updated. I'm not getting any Win**** pop-ups anymore, thank god. Anything I can do to get rid of these infected files though?
 
Good, those are hamless (if java is updated)

Clear Sunjava"s cache
For the newer version's 1.5.xx > control panel > Java click "delete temps files".
Turn off it's auto-updater,(Its buggy) depending on the version you have, in control panel Sunjava plug-in > update tab uncheck its option to update automatically.

Clear the old system restore points
Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Then Reboot. < Dont skip that step.
Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
 
I've had System Restore off the whole time, I always have kept it off. Problem, or no? Should I just ignore your last step then?
 
From what I've heard, it tends to use a lot of processing power and memory. Plus, it isn't a necessity, so I just choose not to use it. Any specific reasons I really should use it?
 
If it were on and the pc was infected, If normal troubleshooting methods did not work using system restore probaly would have.

Surf safe
 
I got the HOSTS file to help protect me, and there isn't one thing I download that doesn't get scanned by Kaspersky the second it is done downloading. I'm usually very very careful about this kind of stuff, I've been taught pretty well. I just got kind of careless with it lately. This is the first time I've eally had any trouble with this sort of stuff before.

Thanks again for all your help man. I appreciate it more than I can say. Really, I don't know what I would have done without you guys here. I know where I'm coming to if I run into any more problems in the future.
 
Im Glad we could help :bigthumb:
Since the problems are solved Im going to close the topic now, this keeps others with similar problems from posting there logs/question here, they should start a new topic.

If you should need to post another log for the same PC let Me or Tashi know.
 
Back
Top