Hi RuffRyder357, welcome to DaniWeb :D
Please follow the recommendations in these threads to help protect, and start the cleanup process, of your system:
http://www.daniweb.com/techtalkforums/thread27519.html
http://www.daniweb.com/techtalkforums/thread27570.html
Download, install, update, and run these utilities:
CWShredder -- http://www.intermute.com/spysubtract/cwshredder_download.html
about:Buster -- http://www.majorgeeks.com/download4289.html
HSRemove -- http://www.majorgeeks.com/download4286.html
After you've completed that, get the self-extracting version of HijackThis from here (in line 2):
http://www.malwareremoval.com/downloads.html
Then, close any open browser windows, 'Scan and Save Log' with HijackThis, and then copy and paste the log here.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
Please follow these instructions (from the first link above):
"3.) Updates
Get the Critical Updates for Windows using Windows Update (it should be in your Start menu). If your OS is Windows XP, and you do not currently have SP2, don’t get it, at least until your system has been verified as clean. You must have a least SP1 installed, if you don’t currently have any XP updates, get SP1a. If you do not have your PC set to check for updates automatically, check manually at least weekly.
Get the Critical Updates for Internet Explorer using Windows Update (open IE, click on Tools, and then Windows Update). You need to have the latest version of Internet Explorer, which is currently version 6 (IE6). If you do not already have SP2, do not get it, at least until your system has been verified as clean. You must have a least SP1 installed; if you don’t currently have any IE updates, get SP1a."
Then follow the instructions in this thread:
http://www.daniweb.com/techtalkforums/thread24085.html
After you've moved HijackThis, close any open browser windows, scan with HJT, and post a new log please.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
According to your HijackThis log, you don't have any Windows Updates at all.
Yes there are things that should be fixed in your HJT log, but it needs to be in its own permanent folder first -- so that it, and the backups it will create, will not be deleted during the cleanup process.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214
When you have the current updates, your HJT log will show entries like these:
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Your log still shows that you don't have the Critical Updates you should. On an upatched system, infections are very likely to return.
Get Ewido from here:
http://www.download.com/Ewido-Security-Suite/3000-8022_4-10326287.html?tag=lst-0-1 , but don't scan with it yet.
Reboot into Safe Mode.
Scan with Ewido, allowing it to clean whatever it finds (note: you will be posting the log from this scan in your next reply).
Still in Safe Mode, scan with HJT and have it fix the following entries:
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=G:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {4EFF303A-9F81-C092-2E28-03548849D849} - (no file)
O4 - HKLM\..\Run: [VID INTERNET WEB DRIVERS FOR WIN32] phqghu.exe
O4 - HKLM\..\RunServices: [VID INTERNET WEB DRIVERS FOR WIN32] phqghu.exe
O4 - HKCU\..\Run: [Lov4RjGFj] rcims.exe
O4 - HKCU\..\Run: [VID INTERNET WEB DRIVERS FOR WIN32] phqghu.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/M...e/bridge-c9.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windows...b?1121341222278
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/M...pDownloader.cab
If the following IP addresses are not related to your ISP, have HJT fix this entry as well --
O17 - HKLM\System\CCS\Services\Tcpip\..\{525A457A-79D0-4A58-B9F0-6327978E942B}: NameServer = 209.43.75.190 206.246.140.14
O23 - Service: Windows lsass Service (lsass) - Unknown owner - G:\WINDOWS\lsass.exe
O23 - Service: MAPI Mail Client (MAPI) - Unknown owner - G:\WINDOWS\System32\mapi32.exe (file missing)
O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - G:\WINDOWS\wkssvc.exe (file missing)
O23 - Service: Windows Process Moniter - Unknown owner - G:\WINDOWS\winmon.exe
Close any open windows, other then HijackThis, before hitting Fix checked.
Go to the following locations and delete the highlighted files:
G:\WINDOWS\System32\Userinit.exe
G:\WINDOWS\lsass.exe -- Caution! Do not delete the file located in the system32 folder "G:\WINDOWS\system32\lsass.exe"
G:\WINDOWS\System32\mapi32.exe
G:\WINDOWS\wkssvc.exe
G:\WINDOWS\winmon.exe
Do a search for the following files and delete any instances found:
phqghu.exe
rcims.exe
Empty your Recycle Bin and reboot normally.
Close any open browser windows, scan with HJT, and post a new log along with the Ewido log.
dlh6213
Posting Maven
3,117 posts since Jul 2004
Reputation Points: 63
Solved Threads: 214