infected PC

Please open HiJackThis.

Place a checkmark next to these entries, close all browsers and windows, and have HijackThis fix them by clicking Fix Checked:

R3 - URLSearchHook: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
O2 - BHO: (no name) - {DADCCFE7-103D-4566-9260-5C3806C2EE1B} - C:\WINDOWS\system32\wvULDWPf.dll (file missing)
O3 - Toolbar: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
O3 - Toolbar: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)


Please run HijackThis again and post a fresh log, just so I can make sure that all the malware was deleted according to plan. :)
First of all, he did not post the combofix log. Why are you already giving him new instructions?
Second of all, don't you have a problem yourself with a Vundo infection? better take care of that first.
Like i said in the other thread!! Arent you kinda young to give instructions on security??
Well you know, I suggest you watch how Ceewi1 and Buzz1927 do before answering every single HJT log that is not being helped.
Oh and age is nothing.

Don't under estimate us!
Lol you made my day :)
 
Please run HijackThis and choose Do a system scan only.

Place a check next to the following entries:

  • [*]R3 - URLSearchHook: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
    [*]O2 - BHO: {2c1063a0-1722-8898-8a04-ee705c64d5bb} - {bb5d46c5-07ee-40a8-8988-22710a3601c2} - C:\WINDOWS\system32\ljyrru.dll
    [*]O2 - BHO: (no name) - {DADCCFE7-103D-4566-9260-5C3806C2EE1B} - C:\WINDOWS\system32\wvULDWPf.dll (file missing)
    [*]O3 - Toolbar: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
    [*]O3 - Toolbar: (no name) - {7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
    [*]O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msltstsoft_updt.exe
    [*]O4 - HKLM\..\Run: [dcb59a0d] rundll32.exe "C:\WINDOWS\system32\qmtnywpc.dll",b
    [*]O4 - HKLM\..\Run: [BMdf86a991] Rundll32.exe "C:\WINDOWS\system32\owdgbbwt.dll",s
Please close all open windows except for HijackThis and choose Fix checked

Download The Avenger by Swandog46, and save it to your Desktop.
  • Extract avenger.exe from the Zip file and save it to your Desktop.
  • Run avenger.exe by double-clicking on it.
  • Do not change any check box options!!
  • Copy everything in the Code box below, and paste it into the Input script here: part of the window. Please do not include the word Code:

    Code:
    [b]Files to delete:
    C:\WINDOWS\system32\ljyrru.dll
    C:\WINDOWS\system32\msltstsoft_updt.exe
    C:\WINDOWS\system32\qmtnywpc.dll
    C:\WINDOWS\system32\owdgbbwt.dll
    [/b]
  • Now click the Execute button.
  • Click Yes to the prompt to confirm you want to execute.
  • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
  • Your PC should reboot, if not, reboot it yourself.
  • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
  • Please post the content of the logfile along with a new HijackThis log. How is your system running now?
 
Back
Top