Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
Luckily i'm not getting any instant access pop-ups as others have said on previous instant access threads. Instead it sets up shop in my Network Connections by adding an axfreeporn dial-up connection. When I delete the connection it comes back within an hour and disconnects my dsl connection if i'm online. It comes back even on Safe Mode.
I'm very loyal to Ad-Aware and Spybot but both won't detect it and Panda isn't any help either and I cannot find the .dll files that are suggested for removal. I was about to reformat my computer but decided not to give up that easily and should ask for help! Here's my log
Logfile of HijackThis v1.99.1
Scan saved at 12:04:11 PM, on 3/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Please download SmitfraudFix (by S!Ri) to your Desktop.
Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Scan done at 20:59:18.69, Tue 03/06/2007
Run from C:\Documents and Settings\My Computer\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is FAT32
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\My Computer
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\My Computer\Application Data
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
Right click the BFU folder on your desktop, and choose Extract All
Click "Next"
In the box to choose where to extract the files to,
Click "Browse"
Click on the + sign next to "My Computer"
Click on "Local Disk (C or whatever your primary drive is
Click "Make New Folder"
Type in BFU
Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
3.RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover. Save it in the same folder you made earlier (c:\BFU).
Do not do anything with these yet!
Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.
4. Once in Safe Mode, Open AVG Anti-Spyware:
Click on scanner
Click on Complete System Scan and the scan will begin.
AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time. Once the scan is complete do the following:
If you have any infections you will prompted, then select "Apply all actions"
Next select the "Reports" icon at the top.
Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
Close AVG Anti-Spyware
5. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
Start the Brute Force Uninstaller by doubleclicking BFU.exe
C:\WINDOWS\xinchg.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{7FD44536-9DF0-4034-939F-5BD4D98E3187} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\WINDOWS\ujxfdll.exe -> Downloader.VB.hj : Cleaned with backup (quarantined).
C:\WINDOWS\ceuydrl.exe -> Dropper.Agent.tb : Cleaned with backup (quarantined).
C:\Documents and Settings\My Computer\Local Settings\Temp\11732101828VvGa.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
C:\Documents and Settings\My Computer\Local Settings\Temp\1173231391VJx2a.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.24:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.25:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.26:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.81:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.82:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.83:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.39:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies-2.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.40:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies-2.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.41:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies-2.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.27:C:\FOUND.012\FILE0000.CHK -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.77:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.79:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.80:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.27:C:\Documents and Settings\My Computer\Application Data\Mozilla\Firefox\Profiles\xitimlpm.default\cookies-1.txt -> TrackingCookie.Sextracker : Cleaned.
C:\WINDOWS\SYSTEM32\DrPMon.dll_tobedeleted -> Trojan.Agent.ic : Cleaned with backup (quarantined).
C:\Program Files\BroadJump\Client Foundation\CFD.exe -> Trojan.Mitglieder : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -> Trojan.Mitglieder : Cleaned with backup (quarantined).
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe -> Trojan.Mitglieder : Cleaned with backup (quarantined).
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe -> Trojan.Mitglieder : Cleaned with backup (quarantined).
C:\Program Files\QuickTime\qttask.exe -> Trojan.Mitglieder : Cleaned with backup (quarantined).
C:\Program Files\iTunes\iTunesHelper.exe -> Trojan.Mitglieder : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\NeroCheck.exe -> Trojan.Mitglieder : Cleaned with backup (quarantined).
C:\WINDOWS\hosts -> Trojan.Qhosts.HE : Cleaned with backup (quarantined).
::Report end
HijackThis
Logfile of HijackThis v1.99.1
Scan saved at 11:36:53 AM, on 3/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Please do these 2 things next.
Also please try to limit your web surfing as much as possible until we can get you cleaned,
Open HijackThis.
Click on Open Misc Tools Section
Make sure that both boxes beside "Generate StartupList Log" are checked:
List all minor sections(Full)
List Empty Sections(Complete)
Click Generate StartupList Log.
Click Yes at the prompt.
It will open a text file. Please copy the entire contents of that page and paste it here.
Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.
Ooops, I thought AVG scan did the trick, the dialer seems to have disappeared. I haven't had any problems for 10 hours now but there's probably more work to be done right? Will limit my surfing. Thank you so much for your patience, Geri!
The Generate StartupList Log is awfully long. Here's the first half.
StartupList report, 3/7/2007, 10:43:33 PM
StartupList version: 1.52.2
Started from : C:\Program Files\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=aohpkeem.dll
C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present
- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINDOWS\Java\classes\xmldso.cab
OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
End of report, 34,791 bytes
Report generated in 1.342 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Download Manager 2.0 (Remove Only)
Adobe Photoshop 7.0
Adobe Photoshop CS
Adobe Reader 7.0.7
Adobe Shockwave Player
AT&T Yahoo! Applications
AVG Anti-Spyware 7.5
BitTorrent 4.0.4
BroadJump Client Foundation
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities EOS Utility
Canon Utilities ZoomBrowser EX
CleanUp!
DivX
DivX Player
GoldWave v5.12
HijackThis 1.99.1
Hotfix for Windows Media Format SDK (KB902344)
iScrobbler
iTunes
J2SE Runtime Environment 5.0 Update 6
LimeWire 4.8.1
Macromedia Flash Player 8
Messenger Plus! 3
mIRC
Mozilla Firefox (1.5.0.10)
MSN
MSN Messenger 7.5
MSN Music Assistant
MSXML 4.0 SP2 Parser and SDK
MUSICMATCH® Jukebox
Nero - Burning Rom
Panda Antivirus 2007
Power Tab Editor 1.7
QuickTime
RealPlayer
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB903235)
Shockwave
Spybot - Search & Destroy 1.4
StuffPlug-NG (Messenger Plus! Plugins)
The Sims 2
The Sims 2 University
Total Extreme Wrestling
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows VisFx Components
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
WinRAR archiver
I'm afraid so, You still have some unwanted friends and a few trojans.
OK Please Go to add/remove and delete the following.
Messenger Plus! 3 StuffPlug-NG (Messenger Plus! Plugins) LimeWire 4.8.1 << I Strongly suggest you remove Limewire, P2P file sharing is an excellent way it become infected and could be where you picked up what you got.
Note: In the event you already have Killbox, this is a new version that I need you to download.
Save it to your desktop.
Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
Return to Killbox, go to the File menu, and choose Paste from Clipboard.
Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.
Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.
I believe that pesky auto-dialer has been successfully uninstalled. It's been four days without a problem. Well I deleted the programs as I was told. After clicking Yes on the Delete on Reboot prompt and while the computer was getting ready to reboot I was suddenly prompted on about "an unknown file renaming itself" or something of the sorts. I wasn't able to finish reading because computer rebooted then.
With HijackThis, after clicking the items then clicking on Fix Checked I was prompted with this message:
"An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=020 - AppInit_DLLs: aohpkeem.dll) Error #5 - Invalid procedure call or argument."
Here's my current log:
Logfile of HijackThis v1.99.1
Scan saved at 5:56:58 PM, on 3/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You can delete any tools you were asked to download, (Brute Force Uninstaller, KillBox) There will be newer versions if ever needed again any way.
Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
Click Opera at the top and choose: Select All
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.
You need to update your Java. Here is how.
Updating Java and Clearing Cache
Go to Start > Control Panel double-click on the Java Icon (coffee cup) in the Control Panel.
It will say "Java Plug-in" under the icon.
Please find the update button or tab in the Java Control Panel. Update your Java then reboot.
If you are unable to update you can manually update by going here:
After the reboot, go back into the Control Panel and double-click the Java Icon.
Under Temporary Internet Files, click the Delete Files button.
There are three options in the window to clear the cache - Leave ALL 3 Checked
Downloaded Applets
Downloaded Applications
Other Files
Click OK on Delete Temporary Files Window Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
Click OK to leave the Java Control Panel.
We have just a few more things to do, mostly maintenance and then our recommendations:
This would also be a good time to set a new system restore point for your machine. Set New System Restore Point. Do not do this unless there are no other user accounts to be diagnosed.
Also, as you are an XP user, if there are any other accounts on this machine, they too, must be cleaned with AdAware, Spybot S&D, then HJT. Not all infections are global, nor are all the HJT fixes global. You can post each user account here into this thread, but please, do only one at a time to avoid confusion. It is very rare that anything significant is ever found.
The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.
IE-SpyAd - puts over 23,000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all,
and MVPS Hosts File will accomplish a similar tactic and provide another layer of protection.
Install WinPatrol to prevent unknown applications from being inserted to start up on your machine
Now just because you have security apps installed, they are useless unless updated regularly.
Another thing I would suggest, is to install SiteAdvisor. It gives sites a few different 'ratings' and while not fool proof, a good additional layer of information about many sites.
ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only, Cleans out temporary files all the garbage you collect while surfing the web.
Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein
Clean indeed! You are brilliant dear Geri! I think my biggest mistake was ignoring those Windows Updates. That is no longer the case, i've begun to download the available updates and looking into your recommendations.
Scan done at 22:22:33.19, Wed 03/14/2007
Run from C:\Documents and Settings\lori.LORI-QSB430ZP84\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\lori.LORI-QSB430ZP84
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\lori.LORI-QSB430ZP84\Application Data
Please start a thread of your own with this as the title "axfreeporn dialer".
Post a HJT log in the thread that you start, here is how.
* Click here to download HJTsetup.exe[list][*]Save HJTsetup.exe to your desktop.[*]Doubleclick on the HJTsetup.exe icon on your desktop.[*]By default it will install to C:\Program Files\Hijack This. [*]Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.[*]Put a check by Create a desktop icon then click Next again.[*]Continue to follow the rest of the prompts from there.[*]At the final dialogue box click Finish and it will launch Hijack This.[*]Click on the Scan button.
You will notice the [Scan] button will turn into a [Save Log] button. [/b] It will scan and the log should open in notepad.[*]Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.[*]Come back here to this thread and Paste the log in your next reply.[*]DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
DO NOT run any fixes unless told to do so. You can do harm to your system. Delete the smitfraud tool you downloaded. That will not help with axfreeporn.