Ok, the attached HJT log in this thread shows a LOT more items than the log in your original thread of 8/17/2007
Frankly, I am not certain the difference is because you are using the newer version of HJT here or not. But there is definitely much more showing.
Your Kaspersky log here shows a lot of nasties in various temp files. Let's see if we can get rid of those. PLUS it also shows me that sometime you have run the VundoFix tool as there are infections in a VundoFix Backups folder. When did you run this tool?
Please download the CleanupXP
Reboot to Safe Mode and run the program. When it is complete then reboot again to safe mode and continue with instruction below.
Next go to Add/Remove and UNINSTALL all listings of the following that you find;
WinAntiSpyware 2007
Reboot to Normal Mode.
Right off the bat in your HJT log I still see a vundo infection, even after you had sometime run the vundofix so let's start with that one;
Please download VundoFix.exe to your desktop if you do not still have it on your machine.Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.
- Double-click VundoFix.exe to run it.
- You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
- When VundoFix re-opens, click the Scan for Vundo button.
- Once it's done scanning, click the Remove Vundo button.
- You will receive a prompt asking if you want to remove the files, click YES
- Once you click yes, your desktop will go blank as it starts removing Vundo.
- When completed, it will prompt that it will shutdown your computer, click OK.
- Turn your computer back on.
- Please post the contents of C:\vundofix.txt and a new HiJackThis log.
After you have run that I want you to relocate your HiJackThis program to it's own folder following the instructions given on the Read Me Sticky. It needs to be in it's own folder.
To create a new folder:
Click START > My Computer > Local Disc C: > Program Files
Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and Click ENTER. This is where you need to locate your HiJackThis program and please rename it hjtscan.exe.
After you have relocated and renamed HJT please run a new scan with it and save the log. Post back here with that new HJT log and the VundoFix log.


Reply With Quote