Your`s has the dubious distinction of being the worst infected machine I have ever seen.
If this doesn`t put you off using P2P networks, then nothing will.
Follow all the instructions below Exactly.
Delete all files in AVG Antispyware quarantine.
Go to add remove programmes in your control panel and uninstall anything to do with(
if there).
viewpoint
viewpoint manager
viewpoint toolbar
AntispyStorm
WindowsUpdate
BraveSentry
Close control panel.
Click start/run and type services.msc into the run box and press the enter key.
When the window appears, maximise it. Double click on the following services(
if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.
Viewpoint Manager Service
Close the services window.
Open notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..
Pay particular attention to this :-
Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:
File::
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\system32\mstaskmgr.exe
C:\WINDOWS\noskrnl.exe
C:\windows\system32\wineij32.dll
C:\WINDOWS\system32\fccywvw.dll.vir
C:\WINDOWS\system32\stfv.bin
C:\WINDOWS\system32\dpqaqlqx.bin
C:\WINDOWS\system32\drvkun.dll
C:\Documents and Settings\Macy Leigh\update.exe
C:\WINDOWS\system32\owinkldq.exe
C:\WINDOWS\system32\2142364041.dll
C:\WINDOWS\system32\2143593741.dll
C:\n.bat
C:\z.dat
C:\WINDOWS\system32\winup.exe
C:\Documents and Settings\Macy Leigh\winlogo.exe
C:\Program Files\B.ico
C:\Program Files\A.ico
C:\WINDOWS\Fonts\Crack.exe
C:\Program Files\Uninstall Morpheus Toolbar.dll
C:\Program Files\Internet Explorer\mepovy83122.dll
C:\WINDOWS\system32\aivskurq.dll
C:\Documents and Settings\Compaq_Owner\0.bat
C:\Documents and Settings\Macy Leigh\4563.bat
C:\Program Files\Internet Explorer\mepovy.dll
C:\Program Files\Internet Explorer\mepovy4444.dll
C:\WINDOWS\system32\?icrosoft.NET
C:\WINDOWS\system32\drvkun.dll
C:\WINDOWS\system32\dbhalj.exe
C:\WINDOWS\system32\owinkldq.exe
C:\WINDOWS\system32\wtchdg.dll
C:\WINDOWS\tsitra1188.exe
C:\Windows\xpupdate.exe
c:\windows\system32\kjdsregs.exe
Folder::
C:\Program Files\Viewpoint
C:\Documents and Settings\Compaq_Owner\Application Data\?racle
C:\WINDOWS\system32\?icrosoft.NET
C:\VundoFix Backups
C:\temp\mZOr
C:\WINDOWS\system32\Mz18r
C:\Program Files\AntispyStorm
C:\Documents and Settings\Compaq_Owner
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Program Files\WindowsUpdate
C:\Documents and Settings\Compaq_Owner\My Documents\??crosoft
C:\Program Files\Common Files\?ecurity
C:\Program Files\BraveSentry
C:\Program Files\QuickTime\bak
C:\WINDOWS\system32\?ssembly
C:\WINDOWS\?dobe
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E7AEED7-3267-4DC7-8587-247217994FB0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6E432B4-D4C2-43B3-BF55-C364F8F7362A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DD1F03C7-7634-4D3D-EFA1-0061BD455062}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ED3E3F61-3159-46B7-9AFA-78C54B9E9741}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F5841E79-6B1E-4833-82D5-E5FD9DCAD3AF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Host Process"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Lftwutk"=-
"Osy"=-
"Flhn"=-
"Ljj"=-
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wineij32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4471c8db]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Brave-Sentry]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTDrive]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dslqlh]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gath]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\p2p networking]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Unoro]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vhyyxk]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yprsm]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{1C-C8-87-74-ZN}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]
Save this as
CFScript.txt
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.
Please open notepad and and copy and paste next bold in it:
(don't forget to copy and paste REGEDIT4)
REGEDIT4
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"="msv1_0"
Save this as "fix.reg" Choose to save as *all files and place it on your desktop.
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.
Regards Howard
This thread is for the use of CatBox only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.