Hello osteez,
I just returned from vacation. You have a seriously infected computer and DEFINITELY should NOT have installed SP2 until the computer was totally clean. That is the #1 requirement for installing SP2, a CLEAN COMPUTER. Honestly don't know if this has compromised the install or not.
Noob334 made that very clear in post #4;
You are showing the Troj/Ranck-FI with this entry;Do not worry about SP2 until one of the better malware fighters comes along and says that your computer is clean and ready to go
O4 - HKLM\..\Run: [Advanced DHTML Enable] C:\WINDOWS\System32\kvkh.exe
The ConHook aka Chisyne trojan a VirtuMonde/Vundoadware variant shown by these entries;
O2 - BHO: (no name) - {2C1CC116-7FC9-4024-AF30-C2D01E0F3A85} - C:\WINDOWS\System32\xxyxyax.dll
and
O20 - Winlogon Notify: xxyxyax - C:\WINDOWS\SYSTEM32\xxyxyax.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - C:\WINDOWS\System32\hmwdbsvx.dll (file missing)
O2 - BHO: (no name) - {CAD08EF4-8BE4-473E-B553-D1A0280746B1} - C:\WINDOWS\System32\mllmk.dll
O20 - Winlogon Notify: mllmk - C:\WINDOWS\System32\mllmk.dll
The items noted by phoenix73 are not true anti-virus programs but a rogue program called WinAntiVirus Pro 2006
I don't know if you downloaded this yourself but it is a rogue program and considered malware.
Getting rid of these items on the computer are going to require multiple steps. Please don't download anything else unless specifically requested. Do NO MORE UPDATING until we can say for sure the computer is clean. Follow each and every instruction through to the end before beginning another. If a log is requested then follow the instruction and post that log. Do nothing else until instructed to do so.
Now let's begin;
Please download VundoFix.exe to your desktop.Download Pocket KillBox
- Double-click VundoFix.exe to run it.
- Put a check next to Run VundoFix as a task.
- You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
- When VundoFix re-opens, click the Scan for Vundo button.
- Once it's done scanning, click the Remove Vundo button.
- You will receive a prompt asking if you want to remove the files, click YES
- Once you click yes, your desktop will go blank as it starts removing Vundo.
- When completed, it will prompt that it will shutdown your computer, click OK.
- Turn your computer back on.
Double-click on Killbox.exe to run it. When it loads copy/paste the following C:\Program Files\Common Files\WinAntiVirus Pro 2006 and press the Delete File button (looks like a red circle with a white X). It will prompt you to reboot, allow it to do so, and hopefully your file will now be deleted.
Once you have completed the above instructions then run a NEW HJT scan and post back here with the new log.
Judy


Reply With Quote