Hya PJ.
Well , you probebly will understand that if the same member keeps coming back with malware infested
hjt logs , without a firewall , without an AV , and windows heavely out of date everytime , even after told dozens of times to install them and update that that can be very annoying to say the least.
And now in this thread you start with one infection , then you have two infections , and in the last log there are a hole bunch of infections on there..
Download Pocket Killbox:
http://www.atribune.org/downloads/KillBox.exe
Download Smitrem to your desktop:
http://noahdfear.geekstogo.com/click...click.php?id=1
Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.
Reboot into safe mode (Reboot and keep tapping F8 , then
choose safe mode from the list)
Run SmitRem:
Open the SmitRem folder and double click the "RunThis.bat" file to start the tool. Follow the prompts on screen , wait for the tool to complete , and disk cleanup to finish.
The tool will create a log named smitfiles.txt on the drive that you ran Smitrem on, eg; "C:\smitfiles.txt" , or the partition where your operating system is installed on.
Please attach this log to your next reply.
Then fix these with
hjt: (in safemode)
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - HKLM\..\Run: [funk] funk.exe
O4 - HKLM\..\Run: [86f02c7c.exe] C:\WINDOWS\System32\86f02c7c.exe
O4 - HKCU\..\Run: [86f02c7c.exe] C:\Documents and Settings\Quenton.PIMPS-HQ9ULWXMQ\Local Settings\Application Data\86f02c7c.exe
O16 - DPF: {10000000-1000-0000-1000-000000000000} -
file://C:\Program Files\Internet Explorer\urqcwhcc.exe
Then do a manual search for
funk.exe and delete what you find.
Start Killbox and place a tick next to [x]delete on reboot.
And press the "all files" button. (just above the yellow triangle)
Copy this list into the windows clipboard:
(highlight the text , and select "copy")
C:\ann.exe
C:\WINDOWS\system32\oleext.dll
C:\Program Files\Internet Explorer\btrdcixr.exe
C:\Documents and Settings\Quenton.PIMPS-HQ9ULWXMQ\Local Settings\Temporary Internet Files\Content.IE5\GQI1BCM5\p[1].anr
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
C:\WINDOWS\System32\86f02c7c.exe
C:\Documents and Settings\Quenton.PIMPS-HQ9ULWXMQ\Local Settings\Application Data\86f02c7c.exe
C:\Program Files\Internet Explorer\urqcwhcc.exe
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00000.exe
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll
C:\Program Files\Common Files\Microsoft Shared\Web Folders\tmp.tmp
Back in Killbox go > file > paste from clipboard,
Click the
red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.
Note:
You will need to reload your wallpaper as the SmitRem tool will reset it, you can do this in desktop properties on the Desktop tab , and choose the one you want to use and press apply.
And XP users using the XP theme may experience a change to the Classic Windows theme. This can be changed on the themes tab of desktop properties.
When done , post the smitrem log , plus a new
hjt log.