This thread's last reply is from January 9, 2006, 9:32 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
AVG says I have a Klone virus, Zone Alarm says something about a Win32.Sinteri and Win32.Sinteri!Downloader.
Hijack This gave me the following log:
Logfile of HijackThis v1.99.1
Scan saved at 10:22:18 AM, on 12/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
STEP 1.
======
Open HijackThis. Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake: R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://maxysearch.info/google/redir2.fcgi?
O20 - Winlogon Notify: ssldr - ssldr32.dll (file missing)
Click Fix Checked.
Reboot normally and scan with HijackThis. Post (reply) with a new hijackthis log to this thread.
STEP 2.
====== MWAV Scan
Please download MWAV to a convenient location.
This scan only produces a report, it doesn't clean your system. I will analyze the report and recommend a course of action depending on the results. This scan might take around 3+ hours to finish when set to scan everything.
Double-click on mwav.exe.
Put a check next to the below items before scanning:
Memory
Startup Folders
Drive - All Local Drives
Folder - then click "browse" to change the directory to C: (default is C:\Windows)
Registry
System Folders
Services
Include Sub-Directory
Scan All Files
Please make sure ALL of these are checked, then press the Scan button. This typically will take hours to complete.
**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.
On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.
Thanks for your help Susan. Here is the second Hijack This Log. The infected files log from mwav will be coming soon...
Logfile of HijackThis v1.99.1
Scan saved at 2:57:14 PM, on 1/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Also it appears that you have two anti-virus applications installed and running?
eTrust AntiVirus and
Grisoft Internet security suite
You should only have one anti-virus application installed and running because more than one can interfere with each other.
Show Hidden Files
Please show all files for your system. You will need to reverse this process when all steps are done.
Delete Files and Folders
Please delete the following files/folders: C:\Documents and Settings\David\Local Settings\Temp\temp.frBB3C
C:\WINDOWS\system32\084c0f6g.dll
C:\WINDOWS\system32\DH9013.exe
If you have any problem deleting these items, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.
Cleanmgr
To clean temporary files:
Go > start > run and type cleanmgr and click OK
Scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files and Recycle Bin are the only things checked.
Click OK to remove those files.
Click Yes to confirm deletion.
System Restore for Windows XP Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Reboot.
Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
Please repeat the MWAV scan so we can double-check that those files are deleted.
Did you follow the instructions to Reset and Re-enable your System Restore? Those infected "_restore" files still showed in the MWAV scan. You need to reset and re-enable your System restore to get rid of those infected files.
Also what is the dll error you received? Are you still receiving it? MWAV is just a scan. It does not delete anything.
Open HijackThis. Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake: O4 - HKLM\..\Run: [084c0f6g.dll] RUNDLL32.EXE 084c0f6g.dll,b 29579562
Click Fix Checked.
Please try this again!
Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)
1. Right-click My Computer, and then click Properties.
2. On the System Restore tab, put a check mark in the 'Turn Off System Restore' check box.
3. Click OK, and then click Yes.
4. Restart the computer.
5. Repeat steps 1 - 2, this time clearing the box beside 'Turn Off System Restore', click 'OK'.
Reboot normally.
Please do the MWAV scan again. scan with HijackThis. Post (reply) with a new hijackthis log and the results of the MWAV scan to this thread.
Please let us know of any complications you had and how the computer is behaving.
Thanks Susan, here is the Hijack This log. MWAV will be scanning momentarily, so the scan will be forthcoming.
Logfile of HijackThis v1.99.1
Scan saved at 11:04:20 AM, on 1/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Since the _restore files are still present in the MWAV, something is not working right. Normally resetting and re-enabling your system restore would clear out those bad files.
You must have Administrator privileges to do this. But with a limited user account, I would have thought you would receive a warning that you do not have these privileges. Were you signed on with administrator privileges when you did this? Did you receive any error messages or warning?
You can try this script.
http://windowsxp.mvps.org/resetsr.htm
After you save it, double-click it to execute it. You may receive a message asking if you want to allow the script to run. Please allow it since it is safe.
Then instead of running MWAV again (just to check for the _restore files) go to:
Start => All Programs => Accessories => System Tools => System Restore
You should only have one restore point and it should have been created after the execution of the script.
Susan,
I do have Admin priviledges, so I can't imagine why the manual system restore didn't work, but the script seems to have done the trick as I only have one restore point now.
Sorry to be taking so much of your time. Do these types of things usually take this long?
Either way, I am so grateful for your aid. I could never do this on my own.
Glad the script seemed to work. Please repeat the MWAV scan. I believe the _restore files will be gone now. Then I will be able to give you the final instructions.
Some logs take longer than others. What disappoints me is when I put time into studying and planning response, responding and then never hearing back from the victim. You have been great at responding which I appreciate very much and thank you!
File C:\Documents and Settings\David\Desktop\ResetSR.VBS infected by "Backdoor.Win32.Delf.akf" Virus! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\InterVideo\Common\Bin\IVIPromotion.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\system32\cmmgr32.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\setup.exe" refers to invalid object "C:\Program Files\ATI Technologies\ATI Control Panel\setup.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\yourapp.Exe" refers to invalid object "C:\WINDOWS\yourapp.Exe". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bak". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".frBB3C". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".gba". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".j31". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".pf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{00FC6799-866E-44A1-A60C-DCF394CF56FD}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QuickTime". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "WebNexus". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{09C6BF52-6DBA-4A97-9939-B6C24E4738BF}". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8EC31897-D1E6-4758-80BE-31E873AC2903}" refers to invalid object "C:\Program Files\Grisoft\AVG Free\avgamui.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8EC31898-D1E6-4758-80BE-31E873AC2903}" refers to invalid object "C:\Program Files\Grisoft\AVG Free\avgamui.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{aac8802e-d17a-4ad6-89a7-bd133078b0c6}" refers to invalid object "C:\WINDOWS\system32\gkgfe.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{c0164c20-33c8-4f60-bfd1-557e08a93f58}" refers to invalid object "C:\Program Files\MSN\MSNCoreFiles\OOBE\obemetal.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C5AF2622-8C75-4dfb-9693-23AB7686A456}" refers to invalid object "C:\WINDOWS\DH.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C7976BEB-AB1E-46F7-8CCD-D4C9CD83BF49}" refers to invalid object "C:\PROGRA~1\SPYWAR~1\swdoctor.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D9C027CF-DF75-4D2C-B763-AC1CA31C4AF8}" refers to invalid object "C:\Program Files\Grisoft\AVG Free\avgamiui.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{ec48db94-98df-4c2f-932f-bbc28af0a316}" refers to invalid object "C:\Program Files\MSN\MSNCoreFiles\OOBE\obemetal.dll". Action Taken: No Action Taken.
Entry "HKCR\.acl" refers to invalid object "ACLFile". Action Taken: No Action Taken.
Entry "HKCR\.aw" refers to invalid object "AWFile". Action Taken: No Action Taken.
Entry "HKCR\.col" refers to invalid object "COLFile". Action Taken: No Action Taken.
Entry "HKCR\.elm" refers to invalid object "ELMFile". Action Taken: No Action Taken.
Entry "HKCR\.ffa" refers to invalid object "FFAFile". Action Taken: No Action Taken.
Entry "HKCR\.ffl" refers to invalid object "FFLFile". Action Taken: No Action Taken.
Entry "HKCR\.fft" refers to invalid object "FFTFile". Action Taken: No Action Taken.
Entry "HKCR\.ffx" refers to invalid object "FFXFile". Action Taken: No Action Taken.
Entry "HKCR\.gst" refers to invalid object "MSMap.Datainst.8". Action Taken: No Action Taken.
Entry "HKCR\.lex" refers to invalid object "LEXFile". Action Taken: No Action Taken.
Entry "HKCR\.opc" refers to invalid object "OPCFile". Action Taken: No Action Taken.
Entry "HKCR\.pip" refers to invalid object "PIPFile". Action Taken: No Action Taken.
Entry "HKCR\.stf" refers to invalid object "STFFile". Action Taken: No Action Taken.
Entry "HKCR\.tuw" refers to invalid object "TUWFile". Action Taken: No Action Taken.
Entry "HKCR\.wll" refers to invalid object "Word.Addin.8". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\Connection Manager Profile\shell\open\command" refers to invalid object "C:\WINDOWS\system32\CMMGR32.EXE "%1"". Action Taken: No Action Taken.
Entry "HKCR\DSP.DSP" refers to invalid object "{9C123EA9-AEC9-4f75-BBC0-7565FA1398966}". Action Taken: No Action Taken.
Entry "HKCR\DSP.DSPDMOProp_Chorus.1" refers to invalid object "{6F63B172-5543-4593-91CE-EDBA65B9FACDB}". Action Taken: No Action Taken.
Entry "HKCR\msbackupfile\shell\open\command" refers to invalid object "%SystemRoot%\system32\ntbackup.exe". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.EBankProblem" refers to invalid object "{AE612304-E8F9-45D9-A444-32409D33E954}". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.QuarantinedItemProxy" refers to invalid object "{C2CE6266-0404-4C54-96B4-8829852E3537}". Action Taken: No Action Taken.
Entry "HKCR\SpyDoctor.ScripterProxy" refers to invalid object "{9FEF02F5-B3B8-4D7B-8939-72A1C989D1B9}". Action Taken: No Action Taken.
Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken.
File C:\Documents and Settings\David\Desktop\ResetSR.VBS infected by "Backdoor.Win32.Delf.akf" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001059.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001074.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001115.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001120.dll tagged as "not-a-virus:AdWare.Win32.Ihbo.gen". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001160.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001183.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP14\A0001465.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\David\Desktop\ResetSR.VBS infected by "Backdoor.Win32.Delf.akf" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001059.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001074.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001115.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001120.dll tagged as "not-a-virus:AdWare.Win32.Ihbo.gen". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001160.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP12\A0001183.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{EB635C80-91F6-44CA-A791-6C1B6A6F3650}(2)\RP14\A0001465.exe infected by "Trojan-Proxy.Win32.Delf.an" Virus! Action Taken: No Action Taken.
✨ Ask AI about this thread
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.