Yesterday I made the stupid (very stupid) mistake of visiting a handful of questionable serial/keygen/crack websites. Of course the one time I do, my system gets infected. I was able to get rid of most of the garbage that instantly latched onto my system, but I am having some residual problems with ulwindowsUrl & ulwindowseek pop-ups which occur about every ten minutes. I also get about 5-10 other pop-ups in IE when I leave the laptop on overnight. I've used every spyware product I can get my hands on (to no avail) so am finally resorting to asking the experts. Hopefully someone can help. Here is my HJT log...I can also provide a SMITFRAUDFIX log if it would help.
Logfile of HijackThis v1.99.1
Scan saved at 1:36:26 AM, on 6/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Please update Ewido.
dont run yet.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates -> http://download.ewido.net/ewido-signatures-full-current.exe Make sure to close Ewido before installing the update.
Run Killbox.exe
-> Choose Delete on Reboot
-> Click All Files option.
Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)
C:\WINDOWS\system32\48786c75.exe
C:\Documents and Settings\me\Local Settings\Application Data\48786c75.exe
C:\WINDOWS\SYSTEM32\winhdn32.dll
Then go back to Killbox
-> go to File
-> choose Paste from Clipboard
-> Click the red-white Delete File option.
-> Click Yes to Delete on Reboot question
-> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
-> Restart your computer if Killbox won't do it.
(If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)
Reboot your computer in SafeMode by doing the following:
1. Restart your computer
2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3. Instead of Windows loading as normal, a menu should appear
4. Select the first option, to run Windows in Safe Mode.
Then launch ewido:
* Click on scanner
* Click settings
* put mark to Scan every file
* Click on scanner
* Click on Complete System Scan and the scan will begin.
* You will be prompted to clean the first infection.
* Select "Perform action on all infections", then proceed.
* Once the scan has completed, there will be a button located on the bottom of the screen named Save report
* Click Save report.
* Save the report .txt file to your desktop or a location where you can find it easily.
+ Created on: 9:25:04 AM, 6/5/2006
+ Report-Checksum: B61F4F69
+ Scan result:
HKLM\SOFTWARE\Clickspring -> Adware.PurityScan : Cleaned with backup
C:\!KillBox\winhdn32.dll -> Trojan.Agent.qt : Cleaned with backup
C:\!KillBox\winhdn32.dll( 1) -> Trojan.Agent.qt : Cleaned with backup
:mozilla.14:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\5vv06vpj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.15:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\5vv06vpj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\me\Cookies\me@122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\me\Cookies\me@adtech[2].txt -> TrackingCookie.Adtech : Cleaned with backup
C:\Documents and Settings\me\Cookies\me@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\me\Local Settings\Temp\sdexe.exe -> Downloader.PurityScan.cl : Cleaned with backup
C:\WINDOWS\MSVISI.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\Temp\win20.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINDOWS\Temp\win2BB.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINDOWS\Temp\win2C0.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINDOWS\Temp\win5D.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
C:\WINDOWS\Temp\win63.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup
::Report End
Logfile of HijackThis v1.99.1
Scan saved at 9:30:02 AM, on 6/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
When I was removing "C:\WINDOWS\MSVISI.exe" in Killbox (I couldn't find the file in the windows explorer, so just typed in that destination in killbox) I got the PendingFileRenameOperations error box. I think everything still works and the spyware is removed as I haven't gotten any IE or ulwindows pop-ups since I followed your first instructions. If needed, I can post another HjT log. Thanks so much for your help!