I was advised from the Tech Talk Forum to post my "Hijack This" in this Forum. I've had quite a few viruses and trojans in my system. I've run Ad-Aware, NoAdware, Spybot, PCBug Doctor, Scan & Repair Utilities and I ran my AVG Virus scan several times. My system is still infected with "System32ssec.exe, and "Trojan horse Generic UGR".
I'm running Windows 2000 Pro. Have constant pop-ups and had to install Pop-Up Stopper Pro. I have Zone Alarm running and Webroot Spy Sweeper, but without the Pop-up Stopper Pro running, I have uncontrollable pop-ups.
The problems originally started with the Task Manager being disabled when hitting Alt+Ctrl+Delete. I then discovered that most of my Administrative Tools are missing. The only tools I have are Internet Services Manager, Personal Web Manager, and Server Extensions Administrator, and Sis Utility Tray. I need help cleaning up the viruses/trojans/spam and recovering the Administrative Tools files that are missing.
Here's the Hijack This:
Logfile of HijackThis v1.97.7
Scan saved at 1:30:21 AM, on 7/28/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\system32\mqsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINNT\system32\cidaemon.exe
C:\WINNT\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\thiselt.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Linda Beres\Local Settings\Temp\wz502e\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.meloco.com/index.php?i=sm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=20073&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=20073&k=
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06D99B28-F33D-4E7F-AFE2-180BDE182540} - (no file)
O2 - BHO: CCHelper - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\Program Files\Panicware\Pop-Up Stopper Pro\CCHelper.dll
O2 - BHO: (no name) - {214B804F-7C16-4762-BE13-83ED51DFCFA5} - (no file)
O2 - BHO: (no name) - {2ADF7B9A-3C74-4C64-BBB5-1D1B062E2948} - (no file)
O2 - BHO: (no name) - {2D8ED8F1-7E54-44F1-A72F-DB798610CF7F} - (no file)
O2 - BHO: (no name) - {3052E7F9-685F-491B-9285-892D7657C8D5} - C:\Program Files\Accessories\horejoruj.dll (file missing)
O2 - BHO: (no name) - {32110540-5D44-4784-A6D5-E25C916F3CC1} - C:\Program Files\Accessories\horejoruj.dll (file missing)
O2 - BHO: (no name) - {385D17D9-B51D-D33B-695E-5C41DB1BCDBB} - (no file)
O2 - BHO: (no name) - {3D13C454-720F-4CEA-8BED-485B8FEFC401} - (no file)
O2 - BHO: (no name) - {3E0BD2B4-CD77-4173-980E-70CF86E92D35} - (no file)
O2 - BHO: (no name) - {420A7A1A-2B14-47A2-A84B-CD6630433B58} - (no file)
O2 - BHO: (no name) - {42C73763-6E85-480B-81AF-BC379CA5DB92} - \
O2 - BHO: (no name) - {52CD403A-4E70-455D-A93A-ACC877EB05AB} - C:\Program Files\Accessories\horejoruj.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {559727B9-61CA-42A1-8293-09F6A9FA91EF} - (no file)
O2 - BHO: (no name) - {59259AE4-C55E-4FA5-8687-E7D85CC76582} - (no file)
O2 - BHO: (no name) - {64E76C39-D2BA-47A5-B40B-EE4C883D583A} - (no file)
O2 - BHO: (no name) - {65585EF4-7D08-4A6A-A956-F7F2EDA2B6DE} - C:\Program Files\Accessories\horejoruj.dll (file missing)
O2 - BHO: (no name) - {732F0C99-F427-41D4-A741-B54F69404078} - (no file)
O2 - BHO: (no name) - {734A7701-E859-46B9-930A-FD8079B4B06C} - \
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {84FD810B-FA7D-4B09-8C38-06E9C685CF05} - C:\Program Files\Accessories\horejoruj.dll (file missing)
O2 - BHO: (no name) - {8C77204D-4C2B-4497-ABE0-8F7752CBF4D3} - \
O2 - BHO: (no name) - {958C2803-DAB8-4388-A43E-69442B1099B3} - C:\Program Files\Accessories\horejoruj.dll (file missing)
O2 - BHO: (no name) - {9843AEA8-0C52-472E-89CA-96EA9384236B} - \
O2 - BHO: (no name) - {99C1D1C5-BFC9-43BD-998D-2E625F91645A} - (no file)
O2 - BHO: Related Page - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINNT\system32\WinNB57.dll
O2 - BHO: (no name) - {A32E6C94-AD91-465C-900C-2B94E4EE9A53} - \
O2 - BHO: (no name) - {A51BF0F2-C65A-4C6F-BB66-7E4DFA532DDB} - (no file)
O2 - BHO: (no name) - {AF76883D-FB6C-4366-BF14-08C5E9D0ADC4} - C:\Program Files\Accessories\horejoruj.dll (file missing)
O2 - BHO: (no name) - {B4F14F3C-27A2-4920-BB9F-8752240D5032} - (no file)
O2 - BHO: (no name) - {B6053E7A-BE0A-4722-AB73-9599FCC77550} - \
O2 - BHO: (no name) - {C12925C5-B63A-45FE-BF65-D9E1D20C0C14} - (no file)
O2 - BHO: (no name) - {C6E467B4-FCF4-4407-8C3C-8C244FC49283} - (no file)
O2 - BHO: (no name) - {C82F2718-E958-4244-9735-57E8B18C1574} - \
O2 - BHO: (no name) - {DAA29E8C-370D-4F75-A152-E97AC2BC13A3} - (no file)
O2 - BHO: (no name) - {DFE7D27E-C021-4C72-80F3-254B776E0992} - C:\WINNT\system32\ubbv.dll
O2 - BHO: (no name) - {E57C8438-DFEA-46C8-A920-E25A4BA64B3C} - (no file)
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O2 - BHO: (no name) - {EC1B360D-2B60-4011-BFAD-FAF5E31C25F9} - (no file)
O2 - BHO: (no name) - {FB112B9D-9CFC-41C0-A5F3-659DE8E138CD} - (no file)
O2 - BHO: (no name) - {FBC4ACF6-D539-485F-B64E-D4B2B4781FB9} - (no file)
O2 - BHO: (no name) - {FCD1E220-7EB4-4F88-93FD-472AE9573870} - C:\Program Files\Accessories\horejoruj.dll (file missing)
O2 - BHO: (no name) - {FE18E734-E17C-465B-A92A-629ED66F6BDB} - \
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\Program Files\Panicware\Pop-Up Stopper Pro\popuppro.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINNT\system32\WinNB57.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\system32\khooker.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\system32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141787050\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [w0fc46dd.dll] RUNDLL32.EXE w0fc46dd.dll,I2 000c8a6200fc46dd
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "-embedding http://iesettingsupdate"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [tSdURg2] "C:\WINNT\system32\fhsxc.exe"
O4 - HKLM\..\Run: [ftexc] C:\WINNT\system32\mptft.exe
O4 - HKLM\..\Run: [Tau Monitor] C:\PROGRA~1\Agnitum\TAUSCA~1.6\taumon.exe
O4 - HKLM\..\Run: [pop06apelt] C:\WINNT\thiselt.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [faxvie] C:\WINNT\system32\faxvie.exe
O4 - HKCU\..\Run: [wallp2.exe] C:\Documents and Settings\Linda Beres\Application Data\System Restore\wallp2.exe
O4 - HKCU\..\Run: [VSL13.exe] C:\WINNT\system32\VSL13.exe
O4 - HKCU\..\Run: [1201.exe] C:\Documents and Settings\Linda Beres\Application Data\System Restore\1201.exe
O4 - HKCU\..\Run: [VSL07.exe] C:\WINNT\system32\VSL07.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Reboot.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .bmp: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin8.dll
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} - http://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {4B48D5DF-9021-45F7-A240-60304302A215} (Malicious Software Removal Tool) - http://download.microsoft.com/download/5/c/2/5c2fc4b7-3875-4eec-946b-ffe15472cabc/WebCleaner.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/21bef264df00ae6ab906/netzip/RdxIE601.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) - http://206.222.26.90/images/PopupSh.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Any help would be greatly appreciated. Thanks!