This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Computer Has A Disease Of Some Kind.

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

There are so many things wrong with my computer I don't even know where to start. about:blank is now my default page and about a thousand other problems are happening at the same time. Can anyone tell me (very simply as I am NOT a computer genius) where to start to solve this problem before I put my computer out on the curb for trash removal? Thank you.
Greetings and welcome to TomCoyote.org!

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Download HijackThis into this folder.

If required a tutorial is here = Hijackthis Folder Tutorial

Links to Hijack This! v 1.98.2:

http://tools.radiosplace.com/HijackThis.exe
http://spywarewarrior.com/files/HijackThis.exe
http://tomcoyote.org/hjt/HijackThis.exe

Run it from that folder.

Click "Scan".

DO NOT "FIX" ANYTHING WITH IT YET!!!
FIXING THE WRONG THING COULD RENDER YOUR SYSTEM INOPERABLE!!!

Click "Save log".

Reply to this thread, and "copy/paste" the ENTIRE CONTENTS of the log file into this thread.
:)
Thank you so much for your help. I have copied the log to you, but had a terrible time getting here. Every time I tried to get back to Tomcoyote my computer wouldn't let me…hmmmm… I hope you can help me. :)

Logfile of HijackThis v1.98.2
Scan saved at 12:04:17 AM, on 10/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Spyware Nuker 2004\SWN2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\golum\services.exe
C:\windows\180solutions\saap.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\FBM Software\ZeroSpyware 2004\NetGuard.exe
C:\Program Files\FBM Software\ZeroAds\Zeroads.exe
C:\WINDOWS\system32\cisvc.exe
c:\progra~1\intern~1\iexplore.exe
C:\WINDOWS\System32\l?gonui.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\mrtMngr.EXE
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\hpoipm07.exe
C:\Documents and Settings\Sally Halcovage\Local Settings\Temporary Internet Files\Content.IE5\496ZKL2F\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mtgqyrhnkqfahdevqxhe.net/0FROsU…bRSnOqZJes6.cgi
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R3 - URLSearchHook: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\Downloaded Program Files\rundlg32.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\Downloaded Program Files\rundlg32.dll
O2 - BHO: (no name) - {3E8A4609-C41C-59B6-8122-115509A0714A} - C:\WINDOWS\System32\mer.dll
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
O2 - BHO: (no name) - {B19EC186-4DF3-4CAC-A2ED-5F33FB48E21A} - C:\WINDOWS\System32\nffcnd.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
O2 - BHO: (no name) - {D734E698-8578-F8E6-780E-1A822B846FC2} - C:\PROGRA~1\MODEKI~1\WINDOW MULTI.exe
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: Search Bar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\Downloaded Program Files\rundlg32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [ZeroAdsLAS] C:\Program Files\FBM Software\ZeroAds\LAS0Ads.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SPN2] C:\Program Files\Spyware Nuker 2004\SWN2.exe /Scan
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Golum] C:\WINDOWS\System32\golum\services.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\twink64.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [logdrv] C:\PROGRA~1\slow chin\Size Bat Tray.exe
O4 - HKLM\..\Run: [saap] c:\windows\180solutions\saap.exe
O4 - HKLM\..\Run: [nmjuzij] C:\WINDOWS\nmjuzij.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ZeroSpyware] "C:\Program Files\FBM Software\ZeroSpyware 2004\ZeroSpyware.exe" -STARTUP
O4 - HKCU\..\Run: [NetGuard] "C:\Program Files\FBM Software\ZeroSpyware 2004\NetGuard.exe" -STARTUP
O4 - HKCU\..\Run: [ZeroAds] C:\Program Files\FBM Software\ZeroAds\Zeroads.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Iik] C:\WINDOWS\System32\l?gonui.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
O4 - Global Startup: QuickBooks Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\QBDAgent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O10 - Broken Internet access because of LSP provider 'fbm.dll' missing
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchmeup.cc
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50188/QDow_AS2.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
O18 - Filter: text/html - {06966F21-606A-4470-93C0-5FA401451557} - C:\WINDOWS\System32\nffcnd.dll
O18 - Filter: text/plain - {06966F21-606A-4470-93C0-5FA401451557} - C:\WINDOWS\System32\nffcnd.dll
Gosh I hope you can get back here again.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mtgqyrhnkqfahdevqxhe.net/0FROsU…bRSnOqZJes6.cgi

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

R3 - URLSearchHook: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\Downloaded Program Files\rundlg32.dll

O2 - BHO: StartBHO Class - {30192F8D-0958-44E6-B54D-331FD39AC959} - C:\WINDOWS\Downloaded Program Files\rundlg32.dll

O2 - BHO: (no name) - {3E8A4609-C41C-59B6-8122-115509A0714A} - C:\WINDOWS\System32\mer.dll

O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll

O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll

O2 - BHO: (no name) - {B19EC186-4DF3-4CAC-A2ED-5F33FB48E21A} - C:\WINDOWS\System32\nffcnd.dll

O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll

O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll

O3 - Toolbar: Search Bar - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\Downloaded Program Files\rundlg32.dll

O4 - HKLM\..\Run: [Golum] C:\WINDOWS\System32\golum\services.exe

O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\twink64.exe internat.dll,LoadKeyboardProfile

O4 - HKLM\..\Run: [logdrv] C:\PROGRA~1\slow chin\Size Bat Tray.exe

O4 - HKLM\..\Run: [saap] c:\windows\180solutions\saap.exe

O4 - HKLM\..\Run: [nmjuzij] C:\WINDOWS\nmjuzij.exe

O4 - HKCU\..\Run: [Iik] C:\WINDOWS\System32\l?gonui.exe

O15 - Trusted Zone: *.clickspring.net

O15 - Trusted Zone: *.mt-download.com

O15 - Trusted Zone: *.my-internet.info

O15 - Trusted Zone: *.searchmeup.cc

O15 - Trusted Zone: *.searchmiracle.com

O15 - Trusted Zone: *.skoobidoo.com

O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50188/QDow_AS2.cab

O18 - Filter: text/html - {06966F21-606A-4470-93C0-5FA401451557} - C:\WINDOWS\System32\nffcnd.dll

O18 - Filter: text/plain - {06966F21-606A-4470-93C0-5FA401451557} - C:\WINDOWS\System32\nffcnd.dll

If you do not recognize this entry:

O2 - BHO: (no name) - {D734E698-8578-F8E6-780E-1A822B846FC2} - C:\PROGRA~1\MODEKI~1\WINDOW MULTI.exe

Check it as well. It looks like part of the LOP infection you have, but I cannot be sure (unless you don't know what it is either).

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

c:\program files\modeki~1 <— FOLDER
(Delete only if NOT recognized as useful)

c:\program files\slow chin <— FOLDER
(This is DEFINITELY part of a LOP infection)

c:\windows\180solutions <— FOLDER

c:\windows\downloaded program files\rundlg32.dll <— file
(Should already be deleted, just be sure)

c:\windows\nmjuzij.exe <— file

c:\windows\questmod.dll <— file
(Should already be deleted, just be sure)

c:\windows\system32\golum <— FOLDER
(This one may be dificult to remove)

c:\windows\system32\mer.dll <— file
(Should already be deleted, just be sure)

c:\windows\system32\msbe.dll <— file
(Should already be deleted, just be sure)

c:\windows\system32\mscb.dll <— file
(Should already be deleted, just be sure)

c:\windows\system32\nffcnd.dll <— file
(Should already be deleted, just be sure)

c:\windows\system32\nvms.dll <— file
(Should already be deleted, just be sure)

c:\windows\system32\twink64.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)

Please go here:

Rogue Anti-Spyware Programs

To read about these programs:

O4 - HKLM\..\Run: [SPN2] C:\Program Files\Spyware Nuker 2004\SWN2.exe /Scan

O4 - HKCU\..\Run: [ZeroSpyware] "C:\Program Files\FBM Software\ZeroSpyware 2004\ZeroSpyware.exe" -STARTUP

You may wish to uninstall them.
Hi Micah! Thank you so much for the help. Sorry it took so long to get here, but my computer was HIGHLY uncooperative. However, I am here at last and able to give you the new log. I did everything you said to do, the only problem is that I was unable to delete the first three items on your list because they didn't appear when I ran HJT again. (The ones that started with R1, R1, and R0). Also, about:blank is still my navigator which is really infuriating. Any suggestions? Here's the log:

Logfile of HijackThis v1.98.2
Scan saved at 11:53:16 PM, on 10/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\FBM Software\ZeroAds\Zeroads.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\QBDAgent.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\mrtMngr.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\System32\hpoipm07.exe
C:\WINDOWS\System32\msiexec.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Sally Halcovage\Local Settings\Temporary Internet Files\Content.IE5\496ZKL2F\HijackThis[1].exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\SALLYH~1\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\SALLYH~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.xitcffjqbkbpqmhevvtln.net/0FROs…RSnOqZJes6.html
R3 - URLSearchHook: (no name) - {30192F8D-0958-44E6-B54D-331FD39AC959} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\Program Files\McAfee.com\Agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [ZeroAdsLAS] C:\Program Files\FBM Software\ZeroAds\LAS0Ads.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SPN2] C:\Program Files\Spyware Nuker 2004\SWN2.exe /Scan
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ZeroAds] C:\Program Files\FBM Software\ZeroAds\Zeroads.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MiniMavis.lnk = C:\Program Files\Broderbund\Mavis Beacon Teaches Typing 12 Standard\MiniMavis.exe
O4 - Global Startup: QuickBooks Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks Pro\Components\QBAgent\QBDAgent.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\System32\ms.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O10 - Broken Internet access because of LSP provider 'fbm.dll' missing
LOL…

The presence of this:

\Temp\sp.html

In the log means it has morphed into something a little more "tedious" to remove (maybe).

Click here to download DllCompare. Start the Program with and click the Run Locate.com - be sure the \Windows\System32 directory is in the box and wait until the the blue text says it has 'completed the scan'.

Click the Compare button to start the next process. The results appear in two panes - files in the upper pane have been verified to 'exist', files in the lower pane were 'not able to be accessed'. Very few files should be listed in the lower pane when the Compare scan is complete. Click on each of the listed entries in the lower pane to select them. Right-click on the file and use the option Rescan. This will cause Windows Find to see if the file does exist, and then if so it will be removed from the list to reduce the number of identified files.

Click the Make a Log of what was found button and post the log here in this thread and wait for further instructions.
I just want to clarify my "LOL" in the last post. This is the kind of infection I've been looking for, and it just was "amusing" to me that it sort of "fell into my lap". I didn't want you to think I was laughing at your misfortune, because I'm not. I'm here to do what it takes to get your machine back to normal. And if I can't, I'll find someone else who can. :)
* DLLCompare Log version() Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ Hello, again, Micah. Thanks for your prompt response. It is so appreciated. There is one important update: about:blank was only my navigation page the first time I went back on IE after all the previous removals and now it is back at dellnet.com again…go figure… but it still doesn't answer the R1, R1, R0 question so here is the latest log for you. I hope I did it correctly. And, I didn't think you were laughing at my misfortune at all. I understood your amusement at this pesky little puzzle and am glad that my "infection" is just what you've been looking for! It makes me feel I'm contributing something in a very strange sort of way. :D Have fun and thanks again! C:\WINDOWS\SYSTEM32\kbdcnaj.dll Mon Aug 30 2004 9:06:40p A…R 57,344 56.00 K C:\WINDOWS\SYSTEM32\msvcirt.dll Thu Aug 29 2002 7:00:00a ..SH. 50,688 49.50 K C:\WINDOWS\SYSTEM32\msvcrt.dll Thu Aug 29 2002 7:00:00a ..SH. 323,072 315.50 K C:\WINDOWS\SYSTEM32\oleaut32.dll Thu Aug 29 2002 7:00:00a ..SH. 569,344 556.00 K C:\WINDOWS\SYSTEM32\olepro32.dll Thu Aug 29 2002 7:00:00a ..SH. 106,496 104.00 K ________________________________________________ 1,250 items found: 1,250 files (6 H/S), 0 directories. Total of file sizes: 266,638,278 bytes 254.29 M Administrator Account = True ——————–End log———————
Click here to download and install Registrar Lite. Install, run, copy and paste this line to reglite's address bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows\\AppInit_DLLs

Click the "go" tab. Find the: "Appinit_Dlls" key in the right hand pane and and double click to find the "Value" data. Confirm that C:\WINDOWS\SYSTEM32\kbdcnaj.dll appears in the 'Value' field.

Using Windows Explorer, go to your root drive: C:\ and create a new folder called 'Hijack' and within that folder, create two new folders, one called 'Backups' and one called 'Junk'.

Copy and paste the key below into reglite's address bar and click 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows\

Click on the Windows key to highlight it in purple, and use the top menu File> Export > "save as" (be sure to save in the "C:\Hijack\Backups folder"):

Winkey.reg (Save as type: regedit4 .reg type)
Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)

Use windows explorer to navigate to C:\Hijack\Backups and confirm both files have been successfully saved.

Run Registrar Lite again. Copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows

on the Windows key in the left pane and rename it to notwindows. Then "Appinit_Dlls" value in right pane and erase the data in the 'Value' box at the bottom of the new pane.

The data to remove will be:

"C:\WINDOWS\System32\kbdcnaj.dll", hit 'Apply' and 'Ok' to set.

Now, rename 'NotWindows' back to 'Windows' in the left pane

Close Registrar Lite and reboot. The hidden process will not run at startup and you should now be able to find this file with windows explorer:

C:\WINDOWS\System32\kbdcnaj.dll

Now, download and unzip Winfile from Winfile.zip. Run it, click File > Move

Copy and paste the next line into the 'From' box:

C:\WINDOWS\System32\kbdcnaj.dll

Now, copy and paste the next into the 'To' box:

C:\Hijack\Junk\kbdcnaj.dll

Click OK. Close Winfile and check in C:\Hijack\Junk for that file and post back the contents of the junk folder.
Hi Micah. I tried to do what you said, but the address bar would not allow me to paste the line you gave me, so I just typed it in. Originally, the word "Registry" was in the address bar, but I just replaced that with your "HKEY_…" line. then I clicked on "go" like you said. The only trouble is that there was no "Appinit_Dlls" key anywhere in the right hand OR left hand pane. I tried it three times and still no luck, so I guess I'm stuck right at the very beginning. Any new instructions?
Opps!! :oops:

Minor misspell….

This is the key:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs


I tried this on my machine. It works. :)
There's supposed to be a space between "Windows" and "NT":

This is wrong:

\WindowsNT\


This is right:

\Windows NT\


It makes a difference. I tried it on my machine, and I got the Appinit_Dlls key to show up.
Sorry, Ms. baffled… I'll repost with the right keys.. Amazing how just one little " " (space) makes a big difference…. :oops:

I copied that reply in from another document, and lost some spaces in the process.

Click here to download and install Registrar Lite. Install, run, copy and paste this line to reglite's address bar:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

Click the "go" tab. Find the: "Appinit_Dlls" key in the right hand pane and and double click to find the "Value" data. Confirm that C:\WINDOWS\SYSTEM32\kbdcnaj.dll appears in the 'Value' field.

Using Windows Explorer, go to your root drive: C:\ and create a new folder called 'Hijack' and within that folder, create two new folders, one called 'Backups' and one called 'Junk'.

Copy and paste the key below into reglite's address bar and click 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\

Click on the Windows key to highlight it in purple, and use the top menu File> Export > "save as" (be sure to save in the "C:\Hijack\Backups folder"):

Winkey.reg (Save as type: regedit4 .reg type)
Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)

Use windows explorer to navigate to C:\Hijack\Backups and confirm both files have been successfully saved.

Run Registrar Lite again. Copy and paste the key below into reglite's address bar and hit 'Go':

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

on the Windows key in the left pane and rename it to notwindows. Then "Appinit_Dlls" value in right pane and erase the data in the 'Value' box at the bottom of the new pane.

The data to remove will be:

"C:\WINDOWS\System32\kbdcnaj.dll", hit 'Apply' and 'Ok' to set.

Now, rename 'NotWindows' back to 'Windows' in the left pane

Close Registrar Lite and reboot. The hidden process will not run at startup and you should now be able to find this file with windows explorer:

C:\WINDOWS\System32\kbdcnaj.dll

Now, download and unzip Winfile from Winfile.zip. Run it, click File > Move

Copy and paste the next line into the 'From' box:

C:\WINDOWS\System32\kbdcnaj.dll

Now, copy and paste the next into the 'To' box:

C:\Hijack\Junk\kbdcnaj.dll

Click OK. Close Winfile and check in C:\Hijack\Junk for that file and post back the contents of the junk folder.
Hi Micah. I've done what you asked up until I get to the: Winkey.reg (Save as type: regedit4 .reg type) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files) I'm sorry but I'm not sure what to do with this. I did find it on the bottom of the page in the "save as" page, but am I supposed to do one, the other, or both. What is Winkey.reg and Winkey.hiv? I've tried it all three ways and nothing is saving to the folder. I'm sorry I'm not better at this stuff… :(
Hi again. I had help figuring it out up until downloading the winfile.zip. When I try to download it I get the following message. Also, for two days now about:blank has been my default browser page again. ( :rant2: ) You are not authorized to view this page You might not have permission to view this directory or page using the credentials you supplied. ——————————————————————————– If you believe you should be able to view this directory or page, please try to contact the Web site by using any e-mail address or phone number that may be listed on the www10.brinkster.com home page. You can click Search to look for information on the Internet. HTTP Error 403 - Forbidden Internet Explorer

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI