You've still got a bit of a mess there. I'd like to see logs from AVG AntiSpyware (C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports) and SmitfraudFix (C:\rapport.txt).
What 'last 4 scans' came up clean?
Download
SDFix and save it to your Desktop.
Double click
SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in
Safe Mode by doing the following :
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, the Advanced Options Menu should appear;
- Select the first option, to run Windows in Safe Mode, then press Enter.
- Choose your usual account.
Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist
(make sure you do not miss any) and click
Fix Checked
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: (no name) - {013A653B-49A6-4f76-8B68-E4875EA6BA54} - C:\WINDOWS\System32\mntkctlg.dll (file missing)
O2 - BHO: Rwfpt Class - {0BDB22C0-BD18-4A40-9A9D-71F314BB75DB} - C:\WINDOWS\System32\lt5vsrs.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {AECBB5D5-03BD-4A18-8A1E-FDF34FD183C4} - \
O2 - BHO: (no name) - {CC1A2C48-84F4-4DAC-AEAC-41DF6344C84D} - (no file)
O2 - BHO: (no name) - {E25B21B7-1E8E-44E2-AC8C-63FC8CFC9EDB} - C:\WINDOWS\Fonts\sissvs.dll (file missing)
O2 - BHO: (no name) - {ECC0749B-9C28-4FD5-AF5B-367DF325CF9F} - \
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKCU\..\Run: [aoapn] C:\WINDOWS\System32\eaovmp.exe reg_run
O18 - Filter: text/html - {D1C66A56-872E-4489-BA60-04AA1E2996BB} - C:\WINDOWS\System32\lt5vsrs.dll
O20 - Winlogon Notify: rqrrpmj - rqrrpmj.dll (file missing)
O20 - Winlogon Notify: sissvs - C:\WINDOWS\Fonts\sissvs.dll (file missing)
Close HijackThis now.
---------------------------------------------------------------------------------------------
Go to My Computer->Tools->Folder Options->View tab:
* Under the Hidden files and folders heading, select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Also make sure there is no checkmark beside Hide file extensions for known file types
* Click Yes to confirm and then click OK.
Delete the following if they exist:
C:\WINDOWS\System32\eaovmp.exe
C:\WINDOWS\System32\lt5vsrs.dll
---------------------------------------------------------------------------------------------
- Open the extracted SDFix folder and double click RunThis.bat to start the script.
- Type Y to begin the cleanup process.
- It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
- Press any Key and it will restart the PC.
- When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
- Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
- Finally paste the contents of the Report.txt back on the forum.
Also, please do this:
- Download combofix.exe to your desktop.
- Double click on combofix.exe & follow the prompts.
- When finished, it shall produce a log for you. Post that log in your next reply.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Establish an internet connection & perform an online scan using Internet Explorer at
http://www.kaspersky.com/service?chapter=161739400
Answer Yes, when prompted to install an ActiveX component.
- The program will then begin downloading the latest definition files.
- Once the files have been downloaded click on NEXT
- Locate the Scan Settings button & configure to:
- Scan using the following Anti-Virus database:
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK & have it scan My Computer
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
- Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
---------------------------------------------------------------------------------------------
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
Updating Java:- Download the latest version of Java Runtime Environment (JRE) 5.0 Update 9.
- Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
- Click the "Download" button to the right.
- Check the box that says: "Accept License Agreement".
- The page will refresh.
- Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
- Close any programs you may have running - especially your web browser.
- Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
- Check any item with Java Runtime Environment (JRE or J2SE) in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove each Java versions.
- Reboot your computer once all Java components are removed.
- Then from your desktop double-click on jre-1_5_0_09-windowsi586-p.exe to install the newest version.
---------------------------------------------------------------------------------------------
Open Hijack This and click on 'Do a System Scan and save a Logfile'. Save the log file and post it here.
---------------------------------------------------------------------------------------------
Please return with results from:
AVG A/S (if you ran it before posting HJT log)
C:\rapport.txt (as you said you ran the tool)
C:\SDFix\report.txt
ComboFix.txt
Kaspersky online scan
How is your system behaving?
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006