Hello,
It appears that you skipped the step about updating your Java Runtime!!!
It also appears you may have had Mcafee at one time and tried to remove it, please let me know if this is correct.
-------------------------------------------------------------------
* Download
VirtumundoBegone, place it on your desktop.
* Doubleclick VirtumundoBeGone.exe to start the tool.
* Follow the instructions on the screen.
* Don't worry if you'll get a Blue screen with an error in it - this is normal.
After reboot,
*
Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present (some entries won't be present anymore):
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.ca/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.ca/myway
O2 - BHO: (no name) - {55d5a256-365c-46ac-975c-3db886df75c4} - C:\WINDOWS\system32\hitemodo.dll (file missing)
O4 - HKLM\..\Run: [CPMb72cf228] Rundll32.exe "c:\windows\system32\mofanedo.dll",a
O4 - HKLM\..\Run: [yizuhopovi] Rundll32.exe "C:\WINDOWS\system32\mewunite.dll",s
O4 - HKUS\S-1-5-19\..\Run: [yizuhopovi] Rundll32.exe "C:\WINDOWS\system32\mewunite.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [yizuhopovi] Rundll32.exe "C:\WINDOWS\system32\mewunite.dll",s (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\kafujote.dll c:\windows\system32\mofanedo.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mofanedo.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mofanedo.dll
* Click on
Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!
-------------------------------------------------------------------
OTMoveit3 by OldTimer
Please
download the
OTMoveIt3 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt3.exe to run it. (Vista users, please right click on OTMoveit3.exe and select "Run as an Administrator")
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and
choose Copy):
Code:
:files
c:\windows\system32\mofanedo.dll
C:\WINDOWS\system32\kafujote.dll
C:\WINDOWS\system32\mewunite.dll
C:\WINDOWS\system32\hitemodo.dll
:commands
[EmptyTemp]
- Return to OTMoveIt3, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and
choose Paste.
- Click the red Moveit! button.
- A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please
open this log in Notepad and post its contents in your next reply.
- Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine
choose
Yes.
-----------------------------------------------
Attach here:
1) VBG.TXT
2) OTMoveit3 Log
3) Fresh Hijackthis log