Lets have a go at cleaning that up.
Before fixing things with HijackThis Please Do the Following:
Show hidden files and folders:
For XP:- On the Tools menu in Windows Explorer, click Folder Options.
- Click the View tab.
- Under Hidden files and folders, click Show hidden files and folders.
- If you see a warning message, click Yes.
- Click Apply.
- Click OK.
Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).
How to disable system restore:
WinXP.- Click the Start button.
- Right-click My Computer, and then click Properties.
- On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.
Please download
CCleaner
Then uninstall Viewpoint Toolbar in add/remove programs.
After that boot in safemode and fix these with
hjt:
O2 - BHO: (no name) - {1768B6BA-2E00-5684-2BB2-7395CCABDC9E} - C:\WINDOWS\System32\
kuvrun.dll (file missing)
O2 - BHO: (no name) - {A12DC733-55AB-2E7F-879B-71A2A8F766B5} - C:\WINDOWS\System32\
vla.dll (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\
Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe /server"
O4 - HKCU\..\Run: [Uahe] "C:\Program Files\
csaa\srai.exe" -vt ndrv
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} -
http://install.wildtangent.com/Activ...veLauncher.cab
Then delete the files in bold if present , and run ccleaner. Also delete these files:
C:\WINDOWS\System32\
kii.dll
C:\WINDOWS\inf\
biU.inf
C:\WINDOWS\system32\
??sembly\spoolsv.exe (you wont see question marks , but letters or numbers , if unsure , post what you find first)
And do you know what these two are from? :
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 172.34.1.5;
O17 - HKLM\System\CCS\Services\Tcpip\..\{4667A043-1022-4AE6-A1E6-32E2F48C0A16}: NameServer = 172.16.2.116
Also are you aware that there is a bunch of remote/vpn software running on youre pc?
If you use them youreself then it is ok , but it could also mean that someone else uses them to control youre pc.
PLSRemote Service
DameWare Mini Remote Control
iSeries Access for Windows Remote Command
Cisco Systems, Inc. VPN Service
pcAnywhere Host Service
Please post a new
hjt log when done.