Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis and reboot into Safe Mode:R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {823481ea-e5a4-46e2-9eaf-e09fe18b47c8} - (no file)
O2 - BHO: Trixie.Bho - {B0744341-96E0-4341-9ED2-8BC36CE0CCD0} - mscoree.dll (file missing)
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKCU\..\Run: [qmir] C:\PROGRA~1\COMMON~1\qmir\qmirm.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O20 - AppInit_DLLs: lxihqx.dll
Please download VundoFix.exe (http://www.atribune.org/ccount/click.php?id=4) to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
The other is removing the old restore points which are infected.We'll do that if the next log is okay.O2 - BHO: (no name) - {F5B8433B-512A-481B-9811-F0C6439BBFDB} - (no file)
I can't ID the CLSID above- it did appear in the HijackThis log on Post#3, but I missed it. Reopen HijackThis, check the entry> check Fixed Checked and reboot.
Source: Geekstogo.com1. Open Regional and Language Options in Control Panel.
To open Regional and Language Options, click Start, click Control Panel, click Date, Time, Language, and Regional Options, and then click Regional and Language Options.
2. On the Regional Options tab, under Standards and formats, click Customize.
3. On the Time tab, specify any changes you want to make.
4. If you do not see the format you want in Time format, follow these guidelines:
Display time in a 12-hour format Type lowercase h or hh for the hour
Display leading zeros in single-digit hours Type two characters, HH or hh
Suppress the display of leading zeros in single-digit hours, minutes, or seconds Type a single uppercase H, or lowercase letter, such as h, m, or s
Display a single letter to indicate AM or PM Type lowercase t
Display two letters to indicate AM or PM Type lowercase tt
Display text Type single quotation marks (') around text
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis and reboot.C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE
O4 - HKLM\..\Run: [PTHOSTTR] C:\Program Files\HPQ\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start
PTHOSTTR.EXE - This is a legitimate process that is installed on HP computers but it has some security issues: http://h20331.www2.hp.com/Hpsub/cache/292230-0-0-225-121.html
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
Default settings software in Hewlett Packard notebook
O9 - Extra button: (no name) - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL (mscoree.dll is a net framework file)
O9 - Extra 'Tools' menuitem: Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\system32\mscoree.DLL
018 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
Clear your existing system restore points and establish a new clean restore pointClick the CleanUp! button.
It will go through the list and remove all of the tools it finds and then delete itself (requiring a reboot).
1. Go to Start > All Programs > Accessories > System Tools > System Restore
2. Select Create a restore point, and Ok it.
3. Next, go to Start > Run and type in cleanmgr
4. Select the More options tab
5.Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created.