Where is the log produced by the BFU? The logs seems to indicate that either you failed/forgot to run it or something else prevented it from running properly. If so, I'm terribly dissapointed as this throws the sequence of the fix out-of-sync & will most likely trigger a re-infection.
It's important that you follow the sequence strictly
For this pass, I shall require you to
run the BFU again (please refer to previous instructions)
You will need to update Ewido to the latest definition files.
Launch Ewido & click Update from the left pane
Then click on Start Update.
If you are having problems with the updater, you can use this
link to manually update Ewido
When you have finished updating, EXIT Ewido.
Please download the file attached -
regdel.zip
Keep it for use in SafeMode
* * * * * * * *
Reboot to Safe Mode to carry out these directions
* * * * * * UN-INSTALLING PROGRAMS * * * * * * * * * * * * * *
Go to Start -> Control Panel -> Add or Remove Programs and uninstall the following programs:
- AXVenore
Internet Optimizer
PECarlin
TClock
WebRebates
websearch
spywarevanisher-free
* * * * * * FIXING ENTRIES WITH HIJACKTHIS * * * * * * * * * *
Do a HijackThis scan & place a check next to these items and select "Fix checked":
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll (file missing)
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB57.dll (file missing)
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll (file missing)
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
* * * * * * BATCHES / REG FIXES * * * * * * * * * * * * * * * * *
From within regdel.zip, doubleclick
regdel.reg & permit it to merge into the registry
* * * * * * DELETING FILES/FOLDERS * * * * * * * * * * * * * * *
If you have not done so already, please enable the viewing of Hidden files
From Windows Explorer, go to Tools -> Folder Options -> View tab.
- Tick - 'Show hidden files and folder'
- Untick - 'Hide file extensions for known types'
- Untick - 'Hide protected operating system files'
- Click Yes to confirm & then click OK
Locate and delete the following files/folders:
(let me know if you fail to find/delete any)- C:\526_620.exe
C:\mc-110-12-0000228.exe
C:\Program Files\AXVenore\
C:\Program Files\CleanUp!\readme.exe
C:\Program Files\Common Files\Download\
C:\Program Files\Common Files\furf\
C:\Program Files\Common Files\furf\
C:\Program Files\Common Files\InetGet\
C:\Program Files\Common Files\misc001\
C:\Program Files\Common Files\simtest\
C:\Program Files\Common Files\svchostsys\
C:\Program Files\InetGet2\
C:\Program Files\Internet Optimizer\
C:\Program Files\ipwins
C:\Program Files\outlook\
C:\Program Files\PECarlin\
C:\Program Files\TClock
C:\Program Files\WebRebates\
C:\Program Files\websearch\
C:\Program Files\Windows\
C:\Program Files\winsupdater\
c:\spywarevanisher-free\
C:\SS1001.exe
C:\stub_113_4_0_4_0.exe
C:\stub_sca3.exe
C:\Trelew.exe
C:\visfx500.exe
C:\VSL02.exe
C:\wd7gi8n.exe
C:\WINDOWS\gealddah.exe
C:\WINDOWS\IA\
C:\WINDOWS\kctyfaro.exe
C:\WINDOWS\pf78.exe
C:\WINDOWS\pf79.exe
C:\WINDOWS\srvqdohaxb.exe
C:\WINDOWS\system32\ftuninst.exe
C:\WINDOWS\system32\gbe90qs.exe
C:\WINDOWS\system32\nt68rrtc12.sys
C:\WINDOWS\system32\SDRunner.dll
C:\WINDOWS\system32\tpuninstall.exe
C:\WINDOWS\system32\tpuninstall.exe
C:\WINDOWS\system32\VSL05.exe
C:\WINDOWS\system32\VSL05.exe
C:\WINDOWS\system32\WinDmy.dll
C:\WINDOWS\system32\wnsintsv.exe
C:\WINDOWS\system32ftuninst.exe
C:\WINDOWS\system32ssec.exe
C:\WINDOWS\system32tfthot.exe
C:\WINDOWS\vfumehnu.exe
C:\WINDOWS\vvlahskc.exe
C:\ZIGID003.exe
* * * * * * PURGING TEMP FOLDERS * * * * * * * * * * * * * * *
Run
Cleanup! using the following configuration:
1. Click Options...
2. Set the slider initially to
Standard CleanUp!
3.
Uncheck the following:
- Delete Newsgroup cache
- Delete Newsgroup Subscriptions
- Delete Cookies
4. Click OK
5. Press the CleanUp! button to start the program.
6. Do NOT reboot/logoff if prompted.
* CleanUp! will not create any backups!!
* * * * * * RUNNING ADDITIONAL SCANNERS * * * * * * * * * * *
Run
Ewido with it's updated definitions:(...it's important that all windows must be closed)
- Click Scanner
- Click Complete System Scan to begin scanning.
- Click OK when prompted to clean files
With the first file it prompts to clean, select the option:
- "Perform action on all infections"
- .Choose clean and click OK.
Once finished, click the
Save report button & save the report to your desktop
* * * * * * REBOOT TO NORMAL MODE * * * * * * * * * * * * * *
Establish an internet connection & perform an online scan with Internet Explorer at
Kaspersky Online Scanner
Answer Yes, when prompted to install an ActiveX component.
- The program will then begin downloading the latest definition files.
- Once the files have been downloaded click on NEXT
- Locate the Scan Settings button & configure to:
- Scan using the following Anti-Virus database:
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK & have it scan My Computer
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
- Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
* * * * * * CHECK LIST * * * * * * * * * * * * * * * * * * * * *
In your next post, please include fresh logs from:
- HiJackThis log
- BFU's log
- Fresh ComboFix log (done after doing the online scan)
- Online Scan
- Ewido
Most importantly, tell me how the machine is behaving now. If you did it right, it will be working well. :)
__________________
Question - what have you done for the community today?