Hi Sumo,
Wow, you got yourself really infected. One of your problems is that you are not properly updated. You aren't even updated as far as SP1, this leaves you open to all kinds of problems. It also appears that you are not running any protection software at all. Before beginning your fix, print out the PCHF Protecting Your PC article in my signature. You can read it while you are running all the scans and fixes you are going to have to do.
OK please download this removal tool from Symantec ]
Look2me Fix[/url]
Next I need you to download the following from my signature. CCleaner, Spybot S&D, Spy Sweeper, RegSupremePro, and Housecall.
Install them all, with Spybot and Spy Sweeper, please update their definitions.
You will need to boot into Safe Mode for this fix and stay there until completed.
Before beginning please do the following;
Show hidden files and folders:
For XP:
1.On the Tools menu in Windows Explorer, click Folder Options.
2.Click the View tab.
3.Under Hidden files and folders, click Show hidden files and folders.
4.If you see a warning message, click Yes.
5.Click Apply.
6.Click OK.
Disable system restore to prevent re-infection.
(if you have/use it.)
(you can turn it back on when youre pc is clean).
How to disable system restore:
WinXP.
Click the Start button.
Right-click My Computer, and then click Properties.
On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Run Housecall, this is an online virus scanner, allow it to fix whatever it finds.
Now boot into Safe Mode, on bootup continually click the F8 key until a menu appears, use your arrow keys to manuver until Safe Mode is selected, hit Enter.
Pre-work clean up
Run CCleaner. Make sure that all options are checked including Advanced, click OK to all warnings. Click on the Analyze button, let it run. When it is finished, click on the Run Cleaner button, exit CCleaner.
Run Ewido Security Suite.
If you have an "always on" connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode.
Close all open windows/programs/folders and then run Ewido.* Have nothing else open while ewido performs its scan!
- Click on Scanner , Settings
- Under "How to scan" all boxes should be selected
- Under "Possibly unwanted software" all boxes should be selected
- Under "What to scan" select scan every file
- Click OK, Complete system scan
- Let the program scan the machine
- If ewido finds anything, it will pop up a notification. Click on Perform Action with All Infections.
Save the log, this is important.
Next run the
Look2me Fix that you downloaded previously.
Run
Spybot S&D Run a full system scan and fix all items that show up in
Red
Next Run Spy Sweeper, click on Options, Sweep Options, make sure that all options except Do Not Scan System Restore Files, are checked. Click on Sweep Now, Start. Quarantine everything that it finds.
Now run
CCleaner again.
Reinstall
HijackThis so that it is in its own folder, not running from the desktop. Run HijackThis and put a checkmark next to, and fix the following if they are still there. Delete any items in bold if they are still present on your computer.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\j4n2le5o1h.dll
O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - C:\WINDOWS\System32\gadclaal.dll (file missing)
O21 - SSODL: SysTray.Exsn - {2368D1FC-2F5C-4f1b-B124-E67214FC78E2} - C:\WINDOWS\System32\hplmcnca.dll (file missing)
O21 - SSODL: CIJHGCI0 - {62951310-5FFE-5E07-75A4-791351A81A32} - C:\WINDOWS\System32\Dnnqnh32.dll (file missing)
O21 - SSODL: mtklef - {ED1E5EF0-C4F3-4B22-209B-28ED18CF4DE1} - C:\WINDOWS\System32\sgbou32.dll (file missing)
Run CCleaner again. Reboot into regular mode.
Clean your registry
Run RegSupremePro. It will want to make a backup of your cache, let it. When it has finished, click on Registry Cleaner and select Aggressive. Let it run. When it has finished, click on Select, choose All. Click on Fix, let it fix everything that it has found.
Run HijackThis again, and post both the new
HJT log and the saved ewido log back here. We'll worry about getting you updated and protected later.
Look forward to your post.
TTFN
LGW