I have a friends laptop that has a lot of virus, trogans and adware. I got rid of most of with a scan from Avast antivirus. Now I did see that it removed something from winantivirus but when I open explorer Avast found the virus again. I am posting the Avast log and the HJT log. Can someone tell me what I have to do. You guys helped a while ago with the virusburst viruses and got rid of them. Thanks Logs: Avast: 11/01/2007 02:28 Scan of all local drives File C:\Documents and Settings\Marjorie\Application Data\winantiviruspro2007freeinstall[1].exe is infected by Win32ownloader-KK [Trj], Deleted File C:\Documents and Settings\Marjorie\Local Settings\Temp\!update.exe\[PECompact] is infected by Win32urityscan-Q [Trj], Deleted File C:\Documents and Settings\Marjorie\Local Settings\Temp\is68131.exe is infected by Win32:Vundo-gen46 [Adw], Deleted File C:\Documents and Settings\Marjorie\Local Settings\Temp\k11u72.exe is infected by Win32:Trojan-gen. {Other}, Deleted File C:\Documents and Settings\Marjorie\Local Settings\Temp\svhost.exe is infected by Win32:Trojan-gen. {Other}, Deleted File C:\Documents and Settings\Marjorie\Local Settings\Temp\WinAntiSpyware 2007 FreeInstall.exe is infected by Win32ownloader-KK [Trj], Deleted File C:\Documents and Settings\Marjorie\Local Settings\Temp\wr-1-0000077.exe\[UPX] is infected by Win32:Small-GWM [Trj], Deleted File C:\Documents and Settings\Marjorie\Local Settings\Temp\yazzlesnet.exe is infected by Win32:Trojan-gen. {Other}, Deleted File C:\Program Files\Common Files\WinAntiVirus Pro 2007\wa7pinst.exe is infected by Win32ownloader-KK [Trj], Deleted File C:\Program Files\Common Files\Yazzle1281OinAdmin.exe\[PECompact] is infected by Win32urityScan-AF [Trj], Deleted File C:\Program Files\func.exe is infected by Win32:Small-BSJ [Trj], Deleted File C:\Program Files\MSN\qubaqib.dll is infected by Win32:Small-AHY [Trj], Deleted File C:\Program Files\MSN\qubaqib668.dll is infected by Win32:Small-AHY [Trj], Deleted File C:\Program Files\Online Services\mewemewyn22011.exe is infected by Win32:Trojan-gen. {Other}, Deleted File C:\Program Files\svhost\wr-1-0000077.exe is infected by Win32:Small-HRY [Trj], Deleted File C:\Program Files\svhost\wr-1-77.exe\[UPX] is infected by Win32:Small-GWM [Trj], Deleted File C:\Program Files\WinAntiVirus Pro 2007\fopn.sys is infected by Win32:Adware-gen. [Adw], Deleted File C:\Program Files\WinAntiVirus Pro 2007\plugins\SCANKRNL.DLL\[UPX] is infected by PS/MPC-gen5, Deleted File C:\WINDOWS\A?pPatch\ping.exe\[UPX] is infected by Win32urityscan-Q [Trj], Deleted File C:\WINDOWS\Downloaded Program Files\DailyToolbar.dll is infected by Win32:Trojan-gen. {Other}, Deleted File C:\WINDOWS\Downloaded Program Files\vzbb.dll is infected by Win32:Adware-gen. [Adw], Deleted File C:\WINDOWS\offun.exe is infected by Win32:Agent-CWW [Trj], Deleted File C:\WINDOWS\rau001978.exe is infected by Win32:Adware-gen. [Adw], Deleted File C:\WINDOWS\retadpu1000106.exe\[UPX] is infected by Win32:Agent-HKJ [Trj], Deleted File C:\WINDOWS\retadpu77.exe.tmp\[UPX] is infected by Win32:Agent-HKJ [Trj], Deleted File C:\WINDOWS\svhost.exe is infected by Win32:Trojan-gen. {Other}, Deleted File C:\WINDOWS\SYSTEM32\acmpnjoq.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\altkxgio.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\awtqnlk.dll is infected by Win32:Vundo-gen46 [Adw], Deleted File C:\WINDOWS\SYSTEM32\byxuvtr.dll is infected by Win32:Vundo-gen47 [Adw], Deleted File C:\WINDOWS\SYSTEM32\cdcclfdm.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\cfhgwwkv.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\djdcmlyx.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\DRIVERS\fopn.sys is infected by Win32:Adware-gen. [Adw], Deleted File C:\WINDOWS\SYSTEM32\dwdsrngt.exe is infected by Win32:Adware-gen. [Adw], Deleted File C:\WINDOWS\SYSTEM32\ebayhcqt.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\emqbladp.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\f02WtR\f02WtR1065.exe is infected by Win32:VB-ESB [Trj], Deleted File C:\WINDOWS\SYSTEM32\f10WtR\f10WtR1099.exe is infected by Win32:VB-ESB [Trj], Deleted File C:\WINDOWS\SYSTEM32\femlmyri.exe is infected by Win32:Agent-LML [Trj], Deleted File C:\WINDOWS\SYSTEM32\fidpu.dll\[PECompact] is infected by Win32:Agent-RY [Trj], Deleted File C:\WINDOWS\SYSTEM32\flvewwgj.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\fmbhdbrh.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\ftaqvhju.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\gmlfoaws.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\gnsmmmef.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\ijoysrve.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\iqlpxtaw.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\latarxyh.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\lhwvluaj.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\lpdsrngk.exe is infected by Win32:Adware-gen. [Adw], Deleted File C:\WINDOWS\SYSTEM32\mljkjih.dll is infected by Win32:Vundo-gen46 [Adw], Deleted File C:\WINDOWS\SYSTEM32\nmnfbvxk.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\nvcdmqlf.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\oademmlx.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\plrsespu.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\qtbtudmk.exe is infected by Win32:Agent-LML [Trj], Deleted File C:\WINDOWS\SYSTEM32\rebnvdjc.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\redftiua.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\rqrsstu.dll is infected by Win32:Vundo-gen46 [Adw], Deleted File C:\WINDOWS\SYSTEM32\sfynmibc.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\tjsqnpyn.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\tkivbsvf.exe is infected by Win32:Agent-LML [Trj], Deleted File C:\WINDOWS\SYSTEM32\tunfoxle.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\tuvspqr.dll is infected by Win32:Vundo-gen47 [Adw], Deleted File C:\WINDOWS\SYSTEM32\tvcilmjj.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\twinqmdt.exe is infected by Win32ownloader-IB [Trj], Deleted File C:\WINDOWS\SYSTEM32\ukwnomnv.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\urqqq.dll is infected by Win32:Vundo-gen46 [Adw], Deleted File C:\WINDOWS\SYSTEM32\wbymdksd.exe is infected by Win32:Agent-LML [Trj], Deleted File C:\WINDOWS\SYSTEM32\win\w71.exe\[UPX] is infected by Win32:Small-GWM [Trj], Deleted File C:\WINDOWS\SYSTEM32\wsqguuuk.dll is infected by Win32:Vundo-gen49 [Adw], Deleted File C:\WINDOWS\SYSTEM32\xoasejpq.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\SYSTEM32\Y2\x55.exe\[UPX] is infected by Win32:Agent-COV [Trj], Deleted File C:\WINDOWS\SYSTEM32\ycbuncmu.exe is infected by Win32:Agent-LML [Trj], Deleted File C:\WINDOWS\SYSTEM32\yorvojwm.exe is infected by Win32:Agent-LAP [Trj], Deleted File C:\WINDOWS\TISKY009.exe is infected by Win32:Adware-gen. [Adw], Deleted File C:\WINDOWS\tk58.exe is infected by Win32:Small-AHY [Trj], Deleted File C:\WINDOWS\xyjeyua.exe is infected by Win32:Trojan-gen. {Other}, Deleted File C:\WINDOWS\xyjeyuaA.exe is infected by Win32:VB-ESA [Trj], Deleted File C:\WINDOWS\?icrosoft\t?skmgr.exe\[PECompact] is infected by Win32urityScan-AF [Trj], Deleted Number of searched folders: 5197 Number of tested files: 47955 Number of infected files: 81 This was the warning I got when I opened IE: 11/1/2007 3:09:14 AM 1193900954 SYSTEM 1216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\WinAntiVirus Pro 2007\winpgi.dll" file. 11/1/2007 3:09:34 AM 1193900974 SYSTEM 1216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\WinAntiVirus Pro 2007\winpgi.dll" file. HJT Log: Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 3:18:15 AM, on 11/1/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Apoint\Apoint.exe C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe C:\WINDOWS\retadpu77.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Marjorie\Desktop\HiJackThis_v2.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.portalsearching.com/search/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.portalsearching.com/search.php?phrase=%s R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.jasc.com/command.asp?app=dlp&version=2&function=print&lang=english O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {16E9067F-5746-4562-B6B6-4093CEF48A64} - C:\WINDOWS\system32\urqqq.dll (file missing) O2 - BHO: (no name) - {2A4CD887-3262-3FB6-6556-4A71B17993B9} - C:\WINDOWS\system32\fidpu.dll (file missing) O2 - BHO: (no name) - {2B4CD8F1-3214-4FC4-6521-4D71B27493CA} - C:\WINDOWS\system32\fidpu.dll (file missing) O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing) O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: 0 - {7D139317-54C1-4E62-F2B4-605043738FD5} - C:\Program Files\MSN\qubaqib.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\uvvbkabf.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O2 - BHO: (no name) - {D6862A22-1DD6-11D3-BB7C-444553540000} - (no file) O2 - BHO: (no name) - {E9BD0828-1FD9-410C-A50F-43EBE65D310F} - C:\WINDOWS\system32\mljkjih.dll (file missing) O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing) O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A28452DA545E9B1894E754BE54C29159A7DA197C7734672DE3F516CAC59B6 O4 - HKLM\..\Run: [xyjeyuaA] C:\WINDOWS\xyjeyuaA.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\APPATC~1\ping.exe" -vt yazb O4 - HKCU\..\Run: [Arbwjgq] "C:\Documents and Settings\Marjorie\Application Data\??stem\r?gsvr32.exe" O4 - HKCU\..\Run: [Tld] C:\WINDOWS\?icrosoft\t?skmgr.exe O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: IEToolbarCab - http://www.lesbiantoolbar.com/DailyToolbar.CAB O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab O16 - DPF: {666E4D35-E955-11D0-A707-000000521958} - http://ads.dropspam.com/landing/aac/upgrade.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153417888490 O20 - Winlogon Notify: mljkjih - mljkjih.dll (file missing) O20 - Winlogon Notify: urqqq - C:\WINDOWS\system32\urqqq.dll (file missing) O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\femlmyri.exe (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\xyjeyua.exe (file missing) O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe -- End of file - 8717 bytes
Here are instructions on how to remove winantivirus. An Avast scan is not enough. http://www.xp-vista.com/spyware-removal/winantivirus-pro-2007-removal-instructions