This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tried Most Solutions Already, Hope You Can Help

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello folks,

I suppose in the end I'm just another helpless, frustrated guys looking for advice on where to turn next.

I've somehow got my computer infected with spyware and probably viruses and trojans or whatever, and I've spent nearly a couple hundred bucks on supposed spyware removal programs as well as virus scan programs to no avail.

I've used Spybot S&D several times only to keep finding the same stuff each time.

As time goes on my computer seems to keep getting more and more full of garbage each day to where its almost unuseable.

Anyways I see this site and a few others who seem to be willing to help those of us with problems and thought I'd give it a try.

I have scanned using hijack this and will attach the log file here.

Logfile of HijackThis v1.98.0
Scan saved at 7:01:52 AM, on 7/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\scagent.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\WINDOWS\hrtcm.exe
C:\documents and settings\owner\local settings\temp\9fI.exe
C:\WINDOWS\System32\ncordsvr.exe
C:\Program Files\WhenUSearch\Search.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\Program Files\Common Files\Dpi\dpi.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\VVSN\VVSN.exe
C:\windows\winserv.exe
C:\WINDOWS\System32\ntstsub.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\System32\Zoq5n71j.exe
C:\WINDOWS\System32\Mjm3.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://drusearch.com/user6/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://drusearch.com/user6/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://drusearch.com/user6/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://drusearch.com/user6/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Owner\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\Program Files\ClearSearch\CSIE.DLL (file missing)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NavErrRedir Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\IncrediFind\BHO\IncFindBHO150.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {6EAD6C52-7D22-4BC2-8257-ECFB1F046DE7} - C:\WINDOWS\System32\gppnca.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [hrtcm] C:\WINDOWS\hrtcm.exe
O4 - HKLM\..\Run: [9fI] C:\documents and settings\owner\local settings\temp\9fI.exe
O4 - HKLM\..\Run: [t3rQ34S] ncordsvr.exe
O4 - HKLM\..\Run: [WhenUSearch] C:\Program Files\WhenUSearch\Search.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Dpi] C:\Program Files\Common Files\Dpi\dpi.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe
O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\Owner\LOCALS~1\Temp\app97.tmp
O4 - HKLM\..\Run: [2P6WFAX43ZHE7C] C:\WINDOWS\System32\QhqYq.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [winlogon] c:\windows\winserv.exe
O4 - HKCU\..\Run: [c004RQe8P] ntstsub.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: Microsoft® JavaScript® Console - {1FEE3894-85A1-46A6-AA07-F02796E9149D} - C:\WINDOWS\System32\comdlg32.ocx
O9 - Extra 'Tools' menuitem: JavaScript Console - {1FEE3894-85A1-46A6-AA07-F02796E9149D} - C:\WINDOWS\System32\comdlg32.ocx
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Microsoft® JavaScript® Console - {1FEE3894-85A1-46A6-AA07-F02796E9149D} - C:\WINDOWS\System32\comdlg32.ocx (HKCU)
O9 - Extra 'Tools' menuitem: JavaScript Console - {1FEE3894-85A1-46A6-AA07-F02796E9149D} - C:\WINDOWS\System32\comdlg32.ocx (HKCU)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\digfilt.dll
O18 - Filter: text/plain - {8ED861AD-D7C9-41E7-A85C-B9E80D86AE90} - C:\WINDOWS\System32\gppnca.dll


Any help will be greatly appreciated.

Thanks in advance

-Ben
Yikes, there's a lot in there. Do all this:

Click here to download the PeperFix tool, save it to your desktop, doubleclick on it, click 'Find and Fix' and reboot if prompted.

Click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'. Reboot when done.

Click here to download Spybot Search & Destroy - install, update, scan and fix all RED items it finds. Reboot when done.

Click here to download Ad-Aware and install. Before scanning click on "check for updates now" to make sure you have the latest reference file. Then click the gear wheel at the top and check these options:

General> activate these: "Automatically save log-file" and "Automatically quarantine objects prior to removal"

Scanning > activate these: "Scan within archives", "Scan active processes", "Scan registry", "Deep scan registry", "Scan my IE Favorites for banned sites" and "Scan my Hosts file"

Tweaks > Scanning Engine> activate this: "Unload recognized processes during scanning."

Tweaks > Cleaning Engine: activate these: "Automatically try to unregister objects prior to deletion" and "Let Windows remove files in use after reboot."

Click "Proceed" to save your settings, then click "Start", make sure "Activate in-depth scan" is ticked green then scan your system. When the scan is finished, the screen will tell you if anything has been found, click "Next". The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".

Reboot when done.

Go here and run online scans (all), allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan

Reboot when done.

Rescan with HJT and post a new log here.

Click here or here to download FindnFix.exe (2K/XP only!) by freeatlast. Double-click on the FINDnFIX.exe and it will install a folder called FINDnFIX on your system. Go to that folder and double-click on !LOG!.bat. The program takes a few minutes to collect the necessary information. When done post the contents of Log.txt in this thread.
Whew….okay, finally went and did all those suggestions…

I will post below a Hijackthis log file.

I also tried using the findandfix log at the end, but it say it cannot find NOTEPAD, and that access is denied???? anyways hope this helps.

-Ben

Logfile of HijackThis v1.98.0
Scan saved at 8:03:34 PM, on 7/27/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\WINDOWS\hrtcm.exe
C:\documents and settings\owner\local settings\temp\9fI.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\documents and settings\owner\local settings\temp\80aZ.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\sccrator.exe
C:\WINDOWS\System32\scldefui.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
c:\Program Files\Norton AntiVirus\OPScan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.efi101.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {583767D9-7890-42C1-9A67-0CFF7AAA01FB} - C:\WINDOWS\System32\beco.dll (file missing)
O2 - BHO: (no name) - {8403CB53-12B3-4537-9DEC-4F12F70A883D} - C:\WINDOWS\System32\anti-pp.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Program Files\Common Files\midaddle\midaddle.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [hrtcm] C:\WINDOWS\hrtcm.exe
O4 - HKLM\..\Run: [9fI] C:\documents and settings\owner\local settings\temp\9fI.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\Owner\LOCALS~1\Temp\app97.tmp
O4 - HKLM\..\Run: [2P6WFAX43ZHE7C] C:\WINDOWS\System32\Dyf0o5.exe
O4 - HKLM\..\Run: [80aZ] C:\documents and settings\owner\local settings\temp\80aZ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [t3rQ34S] sccrator.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [c004RQe8P] scldefui.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\digfilt.dll
Click here to download xphidden.zip (so you can see hidden files and folders). Extract xphidden.reg from the zip file and save it to the desktop. When done, double-click the xphidden.reg and when asked to merge say yes.

Then using Explorer, navigate to C:\Windows\System32\dllcache

You should see a version of notepad.exe in there, 65KB in size. Copy it to both these places:

C:\Windows\
C:\Windows\System32\

Then try again.

Also go here : http://www.dougknox.com/xp/utils/xp_starttrack.htm

Download and install. Run StartupTracker and post the log it generates.
Thanks again for all the help, Here is the log from Startup Tracker: 7/31/2004 2:18:40 PM – Registry – HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce No Items Found – Registry – HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run ccApp "c:\Program Files\Common Files\Symantec Shared\ccApp.exe" TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot HPDJ Taskbar Utility C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe NeroFilterCheck C:\WINDOWS\system32\NeroCheck.exe hrtcm C:\WINDOWS\hrtcm.exe 9fI C:\documents and settings\owner\local settings\temp\9fI.exe mmtask C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe Prein C:\DOCUME~1\Owner\LOCALS~1\Temp\app97.tmp 2P6WFAX43ZHE7C C:\WINDOWS\System32\Dyf0o5.exe 80aZ C:\documents and settings\owner\local settings\temp\80aZ.exe QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime AutoUpdater "C:\Program Files\AutoUpdate\AutoUpdate.exe" t3rQ34S upstvid.exe – Registry – HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce No Items Found – Registry – HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run BackupNotify c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe c004RQe8P cdofmsp.exe – Registry – HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce No Items Found – Start Menu - Current User – spamsubtract.lnk – Start Menu - All Users – HP Digital Imaging Monitor.lnk QuickBooks Update Agent.lnk Quicken Scheduled Updates.lnk – Disabled Items – AGRSMMSG ALCXMNTR hphmon05 hphupd05 hpsysdrv NAV CfgWiz ps2 RECGUARD Reminder jusched shwicon2k TkBellExe sgtray VTTimer – Registry - Shell Value - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon – Explorer.exe – Running Processes – System Idle Process System smss.exe \SystemRoot\System32\smss.exe csrss.exe winlogon.exe winlogon.exe services.exe C:\WINDOWS\system32\services.exe lsass.exe C:\WINDOWS\system32\lsass.exe svchost.exe C:\WINDOWS\system32\svchost -k rpcss svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe CCSETMGR.EXE "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" CCEVTMGR.EXE "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" explorer.exe C:\WINDOWS\Explorer.EXE spoolsv.exe C:\WINDOWS\system32\spoolsv.exe NAVAPSVC.EXE "c:\Program Files\Norton AntiVirus\navapsvc.exe" SAVSCAN.EXE "c:\Program Files\Norton AntiVirus\SAVScan.exe" CCAPP.EXE "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" realsched.exe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot svchost.exe hpztsb08.exe "C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" hrtcm.exe "C:\WINDOWS\hrtcm.exe" 9fI.exe "C:\documents and settings\owner\local settings\temp\9fI.exe" mmtask.exe "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" 80aZ.exe "C:\documents and settings\owner\local settings\temp\80aZ.exe" qttask.exe "C:\Program Files\QuickTime\qttask.exe" -atboottime cdofmsp.exe "C:\WINDOWS\System32\cdofmsp.exe" hpqtra08.exe "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" rnathchk.exe "C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe" qbupdate.exe "C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe" wuauclt.exe "C:\WINDOWS\System32\wuauclt.exe" IEXPLORE.EXE "C:\Program Files\Internet Explorer\iexplore.exe" cmd.exe cmd /c ""C:\FINDnFIX\!LOG!.BAT" " ntvdm.exe "C:\WINDOWS\system32\ntvdm.exe" -f StartupTracker3.exe "C:\Documents and Settings\Owner\Local Settings\Temp\Temporary Directory 1 for StartupTracker3[1].zip\StartupTracker3.exe" wmiprvse.exe – Running Services – Name: AudioSrv Description: Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Startup Mode: Auto Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: BITS Description: Uses idle network bandwidth to transfer data. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: ccEvtMgr Description: Symantec Event Manager Startup Mode: Auto Run from: "c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" Name: ccSetMgr Description: Symantec Settings Manager Startup Mode: Auto Run from: "c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" Name: CryptSvc Description: Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Startup Mode: Auto Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs Name: Dhcp Description: Manages network configuration by registering and updating IP addresses and DNS names. Startup Mode: Auto Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: Dnscache Description: Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Startup Mode: Auto Run from: C:\WINDOWS\System32\svchost.exe -k NetworkService Name: Eventlog Description: Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Startup Mode: Auto Run from: C:\WINDOWS\system32\services.exe Name: EventSystem Description: Supports System Event Notification Service (SENS), which provides automatic distribution of events to subscribing Component Object Model (COM) components. If the service is stopped, SENS will close and will not be able to provide logon and logoff notifications. If this service is disabled, any services that explicitly depend on it will fail to start. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: FastUserSwitchingCompatibility Description: Provides management for applications that require assistance in a multiple user environment. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: lanmanworkstation Description: Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Startup Mode: Auto Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: navapsvc Description: Handles Norton AntiVirus Auto-Protect events. Startup Mode: Auto Run from: "c:\Program Files\Norton AntiVirus\navapsvc.exe" Name: Netman Description: Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: Nla Description: Collects and stores network configuration and location information, and notifies applications when this information changes. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: PlugPlay Description: Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Startup Mode: Auto Run from: C:\WINDOWS\system32\services.exe Name: ProtectedStorage Description: Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Startup Mode: Auto Run from: C:\WINDOWS\system32\lsass.exe Name: RasMan Description: Creates a network connection. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: RpcSs Description: Provides the endpoint mapper and other miscellaneous RPC services. Startup Mode: Auto Run from: C:\WINDOWS\system32\svchost -k rpcss Name: SamSs Description: Stores security information for local user accounts. Startup Mode: Auto Run from: C:\WINDOWS\system32\lsass.exe Name: SAVScan Description: Handles Norton AntiVirus Auto-Protect Archive Scanning Startup Mode: Auto Run from: c:\Program Files\Norton AntiVirus\SAVScan.exe Name: Schedule Description: Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Startup Mode: Auto Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: SENS Description: Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Startup Mode: Auto Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs Name: ShellHWDetection Description: Startup Mode: Auto Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: Spooler Description: Loads files to memory for later printing. Startup Mode: Auto Run from: C:\WINDOWS\system32\spoolsv.exe Name: srservice Description: Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties Startup Mode: Auto Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: SSDPSRV Description: Enables discovery of UPnP devices on your home network. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k LocalService Name: TapiSrv Description: Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: TermService Description: Allows multiple users to be connected interactively to a machine as well as the display of desktops and applications to remote computers. The underpinning of Remote Desktop (including RD for Administrators), Fast User Switching, Remote Assistance, and Terminal Server. Startup Mode: Manual Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: Themes Description: Provides user experience theme management. Startup Mode: Auto Run from: C:\WINDOWS\System32\svchost.exe -k netsvcs Name: winmgmt Description: Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Startup Mode: Auto Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs Name: wuauserv Description: Enables the download and installation of critical Windows updates. If the service is disabled, the operating system can be manually updated at the Windows Update Web site. Startup Mode: Auto Run from: C:\WINDOWS\system32\svchost.exe -k netsvcs And here is the FindNFix log: »»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» Microsoft Windows XP [Version 5.1.2600] »»»IE build and last SP(s) 6.0.2800.1106 SP1-Q330994-Q824145-Q828750-Q832894-Q837009-Q831167-Q823353 The type of the file system is NTFS. C: is not dirty. Sat 31 Jul 04 14:22:53 2:22pm up 0 days, 4:59 »»»»»»'Dos devices'… Location Type Name/Units Attributes ====================================================== XXXX:XXXX CHAR NUL 1000000000000100 02E6:0000 CHAR XMSXXXX0 1010000000000000 0070:0024 CHAR CON 1000000000010011 0070:0036 CHAR AUX 1000000000000000 0070:0048 CHAR PRN 1010100011000000 0070:005A CHAR CLOCK$ 1000000000001000 0070:006C CHAR COM1 1000000000000000 0070:007E CHAR LPT1 1010100011000000 0070:0090 CHAR LPT2 1010100011000000 0070:00A2 CHAR LPT3 1010100011000000 0070:00B4 CHAR COM2 1000000000000000 0070:00C6 CHAR COM3 1000000000000000 0070:00D8 CHAR COM4 1000000000000000 ====================================================== »»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»» The list will produce a small database of files that will match certain criteria. You must know how to ID the file based on the filters provided in the scan, as not all the files flagged are bad. Ex: read only files, s/h files, last modified date. size, etc. The filters provided should help narrow down the list, and hopefully pinpoint the culprit. Along with that,registry scan logged at the end should match the corresponding file(s) listed. »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Unless the file match the entire criteria, it should not be pointed to remove without attempting to confirm it's nature! »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» At times there could be several (legit) files flagged, and/or duplicate culprit file(s)! If in doubt, always search the file(s) and properties according to criteria! The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder »»»»»»»»»»»»»»»»»»***LOG!***(*updated 7/30)»»»»»»»»»»»»»»»» »»»*»»»*Use at your own risk!»»»*»»»* Scanning for file(s)… »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»»»» (*1*) »»»»» ……… »»Locked or 'Suspect' file(s) found… C:\WINDOWS\System32\WDMEO.DLL +++ File read error \\?\C:\WINDOWS\System32\WDMEO.DLL +++ File read error »»»»» (*2*) »»»»»…….. WDMEO.DLL Can't Open! »»»»» (*3*) »»»»»…….. C:\WINDOWS\SYSTEM32\ wdmeo.dll Thu Jun 17 2004 7:48:54a A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K unknown/hidden files… No matches found. »»»»» (*4*) »»»»»……… Sniffing………. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\WDMEO.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL »»»»»(*5*)»»»»» ¯ Access denied ® ………………… WDMEO.DLL …..57344 17.06.2004 »»»»»(*6*)»»»»» fgrep: can't open input C:\WINDOWS\SYSTEM32\WDMEO.DLL »»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»» »»»»»Search by size… C:\WINDOWS\SYSTEM32\ wdmeo.dll Thu Jun 17 2004 7:48:54a A…R 57,344 56.00 K 1 item found: 1 file, 0 directories. Total of file sizes: 57,344 bytes 56.00 K No matches found. No matches found. Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. Sniffed -> C:\WINDOWS\SYSTEM32\WDMEO.DLL SNiF 1.34 statistics Matching files : 1 Amount in bytes : 57344 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15. SNiF 1.34 statistics Matching files : 0 Amount in bytes : 0 Directories searched : 1 Commands executed : 0 Masks sniffed for: *.DLL »»Size of Windows key: (*Default-450 *No AppInit-398 *fake(infected)-448,504,512…) Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448 »»Dumping Values…….. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***) DeviceNotSelectedTimeout = 15 GDIProcessHandleQuota = REG_DWORD 0x00002710 Spooler = yes swapdisk = TransmissionRetryTimeout = 90 USERProcessHandleQuota = REG_DWORD 0x00002710 »»Security settings for 'Windows' key: RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de) This program is Freeware, use it on your own risk! Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: (ID-NI) ALLOW Read BUILTIN\Users (ID-IO) ALLOW Read BUILTIN\Users (ID-NI) ALLOW Full access BUILTIN\Administrators (ID-IO) ALLOW Full access BUILTIN\Administrators (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM (ID-IO) ALLOW Full access CREATOR OWNER Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows: Read BUILTIN\Users Full access BUILTIN\Administrators Full access NT AUTHORITY\SYSTEM »»Member of…: (Admin logon required!) User is a member of group BEN2\None. User is a member of group \Everyone. User is a member of group BUILTIN\Administrators. User is a member of group BUILTIN\Users. User is a member of group \LOCAL. User is a member of group NT AUTHORITY\INTERACTIVE. User is a member of group NT AUTHORITY\Authenticated Users. »»»»»»Backups created…»»»»»» 2:23pm up 0 days, 5:00 Sat 31 Jul 04 14:23:45 A C:\FINDnFIX\keyback.hiv –a– - - - - - 8,192 07-27-2004 keyback.hiv A C:\FINDnFIX\keys1\winkey.reg –a– - - - - - 287 07-27-2004 winkey.reg *Temp backups… . .. keyback2.hi_ winkey2.re_ C:\FINDNFIX\ JUNKXXX Tue Jul 27 2004 7:54:54p .D… 1 item found: 0 files, 1 directory. »»Performing string scan…. 00001150: vk < f AppInit_DLLs G 00001190: C : \ W I N D O W S \ S y s t e m 3 2 \ w d m e o . d l l 000011D0: h vk UDeviceNotSelectedTimeout 1 5 00001210: ( 9 0 =t vk ' zGDIProcessHandle 00001250:Quota" vk x Spooler2 y e s _ h 00001290: ( X vk 5swapdisk vk 000012D0: . TransmissionRetryTimeout h ( X 00001310: vk ' R USERProcessHandleQuota2 00001350: 00001390: 000013D0: 00001410: 00001450: 00001490: 000014D0: 00001510: 00001550: 00001590: 000015D0: ———- WIN.TXT fùAppInit_DLLs֍æGÀÿÿÿC ————– ————– $01180: AppInit_DLLs $011EF: UDeviceNotSelectedTimeout $0123F: zGDIProcessHandleQuota $012D8: TransmissionRetryTimeout $01328: USERProcessHandleQuota2 ————– ————– C:\WINDOWS\System32\wdmeo.dll ————– ————– REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 A handle was successfully obtained for the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key. This key has 0 subkeys. The AppInitDLLs value exists and reports as 60 bytes, including the 2 for string termination. [AppInitDLLs] Ansi string : "C:\WINDOWS\System32\wdmeo.dll" 0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 44 00 4f 00 | C.:.\.W.I.N.D.O. 0010 57 00 53 00 5c 00 53 00 79 00 73 00 74 00 65 00 | W.S.\.S.y.s.t.e. 0020 6d 00 33 00 32 00 5c 00 77 00 64 00 6d 00 65 00 | m.3.2.\.w.d.m.e. 0030 6f 00 2e 00 64 00 6c 00 6c 00 00 00 | o…d.l.l… ———— Dos mem debug… Segment Size Owner Type Vectors ======================================================= 0216 021E0 IO SYSTEM DATA 0435 00A20 COMMAND PROGRAM 22 23 24 2E D3 04D8 00070 MSDOS FREE 04E0 00420 COMMAND ENVIRONMENT 0523 00350 MSDOS FREE 0559 00840 LMEM PROGRAM 05DE 9A210 MSDOS FREE =======================================================  I hope this gets us somewhere! Can't say enough thanks for the effort so far. Ben
Create a new folder called C:\HijackThis, move the HijackThis.exe file into the new folder and run it from there. This is necessary to ensure you have backups should anything go wrong.

Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R3 - URLSearchHook: (no name) - _{4FC95EDD-4796-4966-9049-29649C80111D} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem219.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {583767D9-7890-42C1-9A67-0CFF7AAA01FB} - C:\WINDOWS\System32\beco.dll (file missing)
O2 - BHO: (no name) - {8403CB53-12B3-4537-9DEC-4F12F70A883D} - C:\WINDOWS\System32\anti-pp.dll
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Program Files\Common Files\midaddle\midaddle.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O4 - HKLM\..\Run: [hrtcm] C:\WINDOWS\hrtcm.exe
O4 - HKLM\..\Run: [9fI] C:\documents and settings\owner\local settings\temp\9fI.exe
O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\Owner\LOCALS~1\Temp\app97.tmp
O4 - HKLM\..\Run: [2P6WFAX43ZHE7C] C:\WINDOWS\System32\Dyf0o5.exe
O4 - HKLM\..\Run: [80aZ] C:\documents and settings\owner\local settings\temp\80aZ.exe
O4 - HKLM\..\Run: [t3rQ34S] sccrator.exe
O4 - HKCU\..\Run: [c004RQe8P] scldefui.exe
O18 - Filter: text/html - {EE7A946E-61FA-4979-87B8-A6C462E6FA62} - C:\WINDOWS\digfilt.dll

Click here, for instructions on how to enable hidden files and folders to be visible. After enabling, reboot into safe mode by tapping F8 after the BIOS has loaded, find and delete the following:

C:\WINDOWS\hrtcm.exe
C:\documents and settings\owner\local settings\temp\9fI.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\app97.tmp
C:\documents and settings\owner\local settings\temp\80aZ.exe
C:\WINDOWS\System32\sccrator.exe
C:\WINDOWS\System32\scldefui.exe

Reboot when done. Click here to download System Security Suite. Extract it from the zip file into a folder and doubleclick on sss.exe. Check the boxes under the 'Items to Clear' tab and click 'Clear Selected Items'. You will be prompted to reboot, do so. Repeat for all log-in accounts on your computer.

Then disable Norton. Open FindnFix again. In the keys1 folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot. On restart, open Explorer and navigate to C:\Windows\System32 folder, find the WDMEO.DLL file (it should be visible now). Highlight the file and using top menu, click Edit>Move to folder…

Select C:\Findnfix\junkxxx as destination. Move the file.

Open the FINDnFIX folder again and double-click on RESTORE.bat. When it is finished, in FINDnFIX folder, there will be a file called Log2.txt - post it's contents in your next reply. Also post a new HJT log.
Thanks again for all the great help you've given….

Man if this works, I'll be the first one standing in line to donate some funds to help this cause!

Why don't more people know about you guys?

Anyways,

Here is the log file of FindNFix from LOG2.bat

»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»

Sun 01 Aug 04 13:45:41
1:45pm up 0 days, 0:03

Microsoft Windows XP [Version 5.1.2600]
»»»IE build and last SP(s)
6.0.2800.1106 SP1-Q330994-Q824145-Q828750-Q832894-Q837009-Q831167-Q823353-Q867801
The type of the file system is NTFS.
C: is not dirty.

»»»»»»»»»»»»»»»»»»***LOG2!(*updated 7/30)***»»»»»»»»»»»»»»»»

This log will confirm if the file was successfully moved, and/or
the right file was selected…

Scanning for file(s) in System32…

»»»»»»» (1) »»»»»»»

»»»»»»» (2) »»»»»»»

»»»»»»» (3) »»»»»»»

No matches found.
Unknown/hidden files…

No matches found.

»»»»»»» (4) »»»»»»»
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

SNiF 1.34 statistics

Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.DLL

»»»»»(5)»»»»»

»»»»»(6)»»»»»

»»»»»»» Search by size…


No matches found.

No matches found.

No matches found.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

SNiF 1.34 statistics

Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

SNiF 1.34 statistics

Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

SNiF 1.34 statistics

Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.DLL

»»»*»»» Scanning for moved file… »»»*»»»



No matches found.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

SNiF 1.34 statistics

Matching files : 0 Amount in bytes : 0
Directories searched : 1 Commands executed : 0

Masks sniffed for: *.*

fgrep: no files found for C:\FINDNFIX\JUNKXXX\*.*


File not found - C:\FINDnFIX\junkxxx\*.*

CHK-SAFE.EXE Ver 2.51 by Bill Lambdin Don Peters and Robert Bullock.
MD5 Message Digest Algorithm by RSA Data Security, Inc.

File name Size Date Time MD5 Hash
________________________________________________________________________

CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk

C:\FINDNFIX\JUNKXXX
No files found



#######################################################
*Known files are…
——————–
File: ((56k; (57,344 bytes)
(CRC16 : 3138)
CRC-32 : D5C9FB2E
MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249
——————–
File: ((35k; (35,840 bytes)
(CRC16 : EEB1)
CRC-32 : 33081C8B
MD5 : 1DE9A8E2 4C826006 7A479B09 577D9CAE
——————–
File: ((21k; (21,504 bytes)
(CRC16 : 90A5)
CRC-32 : 2258F59E
MD5 : EFEE2CB3 B342A351 51802356 9637F8E6
#######################################################
»»Permissions:
ERROR: There are no more files.

Directory "C:\FINDnFIX\junkxxx\."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 00000002 tc– 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000009 –o- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000002 tc– 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 00000009 –o- 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 00000013 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 00000013 tco- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000010 t— 001F01FF —- DSPO rw+x BEN2\Owner
Allow 0000001B -co- 10000000 —A —- —- \CREATOR OWNER
Allow 00000013 tco- 001200A9 —- -S– r–x BUILTIN\Users
Allow 00000012 tc– 00000004 —- —- –+- BUILTIN\Users
Allow 00000012 tc– 00000002 —- —- -w– BUILTIN\Users

Owner: BEN2\Owner

Primary Group: BEN2\None

Directory "C:\FINDnFIX\junkxxx\.."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF —- DSPO rw+x BUILTIN\Administrators
Allow 00000003 tco- 001F01FF —- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000000 t— 001F01FF —- DSPO rw+x BEN2\Owner
Allow 0000000B -co- 10000000 —A —- —- \CREATOR OWNER
Allow 00000003 tco- 001200A9 —- -S– r–x BUILTIN\Users
Allow 00000002 tc– 00000004 —- —- –+- BUILTIN\Users
Allow 00000002 tc– 00000002 —- —- -w– BUILTIN\Users

Owner: BEN2\Owner

Primary Group: BEN2\None




»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512…)

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

»»Dumping Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs =

»»Security settings for 'Windows' key:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM



00001150: ; b vk UDeviceNotSelecte
00001190:dTimeout 1 5 ( h vk ' zGDIProce
000011D0:ssHandleQuota" 9 0 =t vk Spooler2
00001210: y e s _ vk 5swapdisk h
00001250: X vk . TransmissionRetryTimeout vk
00001290: ' R USERProcessHandleQuota2 h X
000012D0: vk y AppInit_DLLsecte e b
00001310: b w b  b $ b
00001350: b b P b b b
00001390: b | b b b
000013D0: b b b b
00001410: b b % b b
00001450: 9 b D b O b Z b h b v b b b
00001490: P b b b
000014D0: b b b b b b & b
00001510: b > b $ b S b
00001550:

———- NEWWIN.TXT
AppInit_DLLsecte
————–
————–
$00084: PeekMessageA
$00094: DispatchMessageA
$000A8: TranslateMessage
$000BC: MsgWaitForMultipleObjects
$000D8: SetWindowPos
$000E8: SetWindowRgn
$00112: IntersectRect
$00142: SetWindowLongA
$00154: RegisterClassExA
$00182: GetClassInfoExA
$00194: CreateWindowExA
$001A6: DefWindowProcA
$001D2: DestroyWindow
$001EE: InvalidateRect
$0117F: UDeviceNotSelectedTimeout
$011C7: zGDIProcessHandleQuota
$01270: TransmissionRetryTimeout
$012A0: USERProcessHandleQuota2
$012F0: AppInit_DLLsecte
$01D50: CxxFrameHandler
$01DDA: InitializeCriticalSection
$01DF6: DeleteCriticalSection
$01E0E: InterlockedIncrement
$01E26: InterlockedDecrement
$01E3E: DisableThreadLibraryCalls
$01E66: EnterCriticalSection
$01E7E: LeaveCriticalSection
$01E96: FlushInstructionCache
$01EAE: GetCurrentProcess
$01ECE: GetProcessHeap
$01EEC: MultiByteToWideChar
$01F02: WideCharToMultiByte
$01F24: GetCurrentThreadId
$01F3A: GetLastError
$01F7E: GetModuleFileNameA
$01F94: GlobalUnlock
$01FDA: SizeofResource
$01FEC: LoadResource
————–
————–
No strings found.


d…. 0 Jul 27 19:54 .
d…. 0 Jul 27 19:54 ..

2 files found occupying -1024 bytes


===============================================================================
0 bytes 0 cps
Files: 0 Records: 0 Matches: 0 Elapsed Time: 00:00:00.01

VDIR v1.00
Path: C:\FINDNFIX\JUNKXXX\*.*
—————————————+—————————————
. 07-27-:4 19:54|.. 07-27-:4 19:54
—————————————+—————————————
2 files totaling 0 bytes consuming 0 bytes of disk space.
17299968 bytes available on Drive C: Volume label: HP_PAVILION

…File dump…

junkxxx\*.*
The system cannot find the file specified.
0 file(s) copied.

Detecting…

C:\FINDnFIX\junkxxx


And here is the latest HJT log file:

Logfile of HijackThis v1.98.0
Scan saved at 1:51:35 PM, on 8/1/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\mmfshell.exe
C:\documents and settings\owner\local settings\temp\cqr87sFDm.exe
C:\WINDOWS\System32\vga71.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} - C:\Program Files\SysAI\AproposPlugin.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Owner\Local Settings\Temp\bGQ1P18Fe.dll
O2 - BHO: (no name) - {EE7B14C2-02BA-422D-8001-89EED4EF2140} - C:\WINDOWS\System32\gbjmi.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [t3rQ34S] mmfshell.exe
O4 - HKLM\..\Run: [cqr87sFDm] C:\documents and settings\owner\local settings\temp\cqr87sFDm.exe
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [c004RQe8P] vga71.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

Thanks so much again!

You guys rock!

-ben
Looking better. Delete the entire FindnFix folder.

Click here to download TheKillbox by Option^Explicit. Extract it from the zip file then double-click on Killbox.exe to run it. In the 'Paste Full Path of File to Delete' box, copy and paste this entry:

C:\WINDOWS\System32\vga71.exe

Don't click any of the buttons though, instead please click on the Action menu and choose "Delete on Reboot". In the window that opens up, click on the File menu and choose "Add File". The C:\WINDOWS\System32\vga71.exe listing should show up in the window. Then repeat the process, this time adding:

C:\WINDOWS\System32\mmfshell.exe

If that's successful you should have the two files listed. Then repeat so that all these files appear in the list as well:

C:\documents and settings\owner\local settings\temp\cqr87sFDm.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\Documents and Settings\Owner\Local Settings\Temp\bGQ1P18Fe.dll

When they are all there, in the same window choose the Action menu and select "Process and Reboot". You'll be prompted to reboot, do so.

With only HijackThis running, scan and when complete, remove the following entries (if still there) by checking the box to the left and clicking 'fixed checked':

O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} - C:\Program Files\SysAI\AproposPlugin.dll (file missing)
O2 - BHO: WinPage Affiliate - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Owner\Local Settings\Temp\bGQ1P18Fe.dll
O2 - BHO: (no name) - {EE7B14C2-02BA-422D-8001-89EED4EF2140} - C:\WINDOWS\System32\gbjmi.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [t3rQ34S] mmfshell.exe
O4 - HKLM\..\Run: [cqr87sFDm] C:\documents and settings\owner\local settings\temp\cqr87sFDm.exe
O4 - HKCU\..\Run: [c004RQe8P] vga71.exe

Reboot when done. Rescan with HJT and post a new log.
WOW! Thanks you guys!

The fast response times are great!

Ok, I did all the last instructions, and here is the HJT log:

Logfile of HijackThis v1.98.0
Scan saved at 4:41:44 PM, on 8/1/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
c:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.efi101.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tri…Transporter.cab?
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

Lets hope that got the last of 'em! :wavey:

I can't wait to find out!

-Ben
You're welcome - glad to help :D (there's a link at the top of the page to support the site)

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI