This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Big Problem

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I don't know how it got here but I want it gone. I have used Spybot, Ad-Aware and ContentCleanup but can not get rid of it. It only uses Internet Explorer to pull up this crap on its own. I have been using Mozilla Firefox and it will not come up with it. I have Zone Alarm as a fire wall and use a cable for internet connection. All my virus software is updated. Please help me get rid of this. I have a 5 year old and do not want him to see all of this trash.

Thank you,

Logfile of HijackThis v1.98.2
Scan saved at 10:32:54 PM, on 10/15/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Smith Micro Shared\FAX\SMLoader.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\MICROS~4\GAMECO~1\Common\SWTrayV4.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\PEPEPE32.exe
C:\WINDOWS\system32\sy646464ms.exe
C:\WINDOWS\hh6432PE32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\PE32PEsy.exe
C:\WINDOWS\system32\6464sy64.exe
C:\WINDOWS\sysy64ms.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Shawn\Local Settings\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tncomputers.com
R3 - URLSearchHook: (no name) - {AE4A0B26-E61C-BF7C-F8AB-6A66A5AD96D6} - C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
O1 - Hosts: comments (such as these) may be inserted on individual
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SMSI Loader] C:\Program Files\Common Files\Smith Micro Shared\FAX\SMLoader.exe /PRNDRV
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~4\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [Open Site] C:\Program Files\Open Site\opnste.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB002" /M "Stylus CX5400"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EBC41166] C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ms64] C:\WINDOWS\ms64.exe
O4 - HKCU\..\Run: [sy32orntPE] C:\WINDOWS\system32\sy32orntPE.exe
O4 - HKCU\..\Run: [PEPEPE32] C:\WINDOWS\PEPEPE32.exe
O4 - HKCU\..\Run: [sy646464ms] C:\WINDOWS\system32\sy646464ms.exe
O4 - HKCU\..\Run: [ms3232ntnt] C:\WINDOWS\system32\ms3232ntnt.exe
O4 - HKCU\..\Run: [hh6432PE32] C:\WINDOWS\hh6432PE32.exe
O4 - HKCU\..\Run: [msmsPE] C:\WINDOWS\msmsPE.exe
O4 - HKCU\..\Run: [ororhh] C:\WINDOWS\ororhh.exe
O4 - HKCU\..\Run: [PE32PEsy] C:\WINDOWS\PE32PEsy.exe
O4 - HKCU\..\Run: [6464sy64] C:\WINDOWS\system32\6464sy64.exe
O4 - HKCU\..\Run: [EBC41166] C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
O4 - HKCU\..\Run: [sysy64ms] C:\WINDOWS\sysy64ms.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Corel Network monitor worker - {70018AD3-E7AA-4BC4-B631-84A65F3D1AAF} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {70018AD3-E7AA-4BC4-B631-84A65F3D1AAF} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Corel Network monitor worker - {70018AD3-E7AA-4BC4-B631-84A65F3D1AAF} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {70018AD3-E7AA-4BC4-B631-84A65F3D1AAF} - (no file) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.tncomputers.com
O16 - DPF: {234B7457-1A7E-4268-BA71-9936F0C78BEC} (ContentCleanup3X Control) - http://www.contentwatch.com/cleanup/includ…eanup3Proj1.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/29454ec4dcd3e7…ip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200310…llInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097805915765
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2000i\AcDcToday.ocx
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (NOXLATE) - file://C:\Program Files\AutoCAD 2000i\InstFred.ocx
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2000i\AcPreview.ocx :rant2:
The following have randomly named file names, and as such are normally malware.
Follow their process tree. Right click on the file and go to Properties.
Then go to the Version tab to see what company name it's from:
If it's from some name you never heard of or if it's blank, please check for removal and delete the file also.

O4 - HKCU\..\Run: [ms64] C:\WINDOWS\ms64.exe
O4 - HKCU\..\Run: [sy32orntPE] C:\WINDOWS\system32\sy32orntPE.exe
O4 - HKCU\..\Run: [PEPEPE32] C:\WINDOWS\PEPEPE32.exe
O4 - HKCU\..\Run: [sy646464ms] C:\WINDOWS\system32\sy646464ms.exe
O4 - HKCU\..\Run: [ms3232ntnt] C:\WINDOWS\system32\ms3232ntnt.exe
O4 - HKCU\..\Run: [hh6432PE32] C:\WINDOWS\hh6432PE32.exe
O4 - HKCU\..\Run: [msmsPE] C:\WINDOWS\msmsPE.exe
O4 - HKCU\..\Run: [ororhh] C:\WINDOWS\ororhh.exe
O4 - HKCU\..\Run: [PE32PEsy] C:\WINDOWS\PE32PEsy.exe
O4 - HKCU\..\Run: [6464sy64] C:\WINDOWS\system32\6464sy64.exe
O4 - HKCU\..\Run: [sysy64ms] C:\WINDOWS\sysy64ms.exe

If you know what they are can you please post back With the info


Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R3 - URLSearchHook: (no name) - {AE4A0B26-E61C-BF7C-F8AB-6A66A5AD96D6} - C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
O4 - HKLM\..\Run: [EBC41166] C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
O4 - HKCU\..\Run: [EBC41166] C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe


The following activeX controls( Download Program Files)will reinstall when(and if) you revisit that website,
UNLESS you know they are from a safe source, check to remove.

O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab

Reboot afterwards in SAFE MODE. If you don't know how click here
Delete the following file(s) and folder(s) listed

C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe<
(do a search for this one. It'll probably be in c:\windows or c:\windows\system32.)

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Then Download System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
Okay… I fixed the 4 item that you told me to have HiJackThis fix. What is the best way for me to look up the other 11 items (1st 11 you told me to look up). I went to C drive and pick the windows file, after that I could not find many of them. I did find the following list: PEPEPE32 sy646464ms hh6432PE32 PE32PEsy 6464sy64 Once I found them, I highlighted the name, right clicked the mouse, went to properties. This gave me 3 folders to chose from: General, Compatability and Summary. (this is what the PEPEPE32 file had) = General told me it was a application file, 2.83 kB in size, used 4.00 kB on the disk and was created on October 8th, 2004 @ 10:05 pm. Summary showed title, subject, author, category, keyword and comments. They were all blank. Is this what I was looking for ??? Also all of these programs have been trying to get access to the Internet but Zone Alarm has been asking permission. I have refused all of them access to the Internet and they do not seem to be effecting the computer programs. I do now have multiple windows coming up that says "dialer running" and a big window with terms talking about allowing another dialer beside my own systems to start up and charge me calls to other coutries (I refused this also) This just started after I fixed the 4 files, also I use a cable modem so I don't have a dialer ??? I have not had much trouble with the porn window popping up until today. My wife and myself have different logon and I forgot to use HiJackThis to clean her side.
Here is what the pop up widows are saying, several small windows = Dialer "Already running" .

The large windows say's this = Web Dialer "Please click "YES" to continue:


On accepting this certificate you will be disconnected from your current internet service provider and connected to the internet through an international telephone call. For the costs of these calls please consult your own carrier. You must be at least 18 years of age (21 in some countries) and you must be, or have the permission of, the person responsible for paying the call costs associated with this telephone line. You have an obligation to pay the costs associated with this call. The service providers will not be held responsible for the content you will be able to view on accepting this certificate."


Also here is my new log:

Logfile of HijackThis v1.98.2
Scan saved at 9:47:38 PM, on 10/18/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Smith Micro Shared\FAX\SMLoader.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\MICROS~4\GAMECO~1\Common\SWTrayV4.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\hhSP32s-.exe
C:\WINDOWS\PESPhhPE32.exe
C:\WINDOWS\3232nt64.exe
C:\WINDOWS\3232.exe
C:\WINDOWS\hhs-SP32hh.exe
C:\WINDOWS\system32\msPEsyor.exe
C:\WINDOWS\system32\s-SP.exe
C:\WINDOWS\system32\PE32or.exe
C:\WINDOWS\system32\64ntPEor.exe
C:\WINDOWS\system32\PEhh.exe
C:\WINDOWS\system32\PEsymsntSP.exe
C:\WINDOWS\PEPEPE32.exe
C:\WINDOWS\system32\sy646464ms.exe
C:\WINDOWS\system32\6464sy64.exe
C:\WINDOWS\sysy64ms.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Shawn\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tncomputers.com
R3 - URLSearchHook: (no name) - {AE4A0B26-E61C-BF7C-F8AB-6A66A5AD96D6} - C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe (file missing)
O1 - Hosts: comments (such as these) may be inserted on individual
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SMSI Loader] C:\Program Files\Common Files\Smith Micro Shared\FAX\SMLoader.exe /PRNDRV
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SideWinderTrayV4] C:\PROGRA~1\MICROS~4\GAMECO~1\Common\SWTrayV4.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB002" /M "Stylus CX5400"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EBC41166] C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [hhSP32s-] C:\WINDOWS\system32\hhSP32s-.exe
O4 - HKCU\..\Run: [PESPhhPE32] C:\WINDOWS\PESPhhPE32.exe
O4 - HKCU\..\Run: [3232nt64] C:\WINDOWS\3232nt64.exe
O4 - HKCU\..\Run: [3232] C:\WINDOWS\3232.exe
O4 - HKCU\..\Run: [hhs-SP32hh] C:\WINDOWS\hhs-SP32hh.exe
O4 - HKCU\..\Run: [msPEsyor] C:\WINDOWS\system32\msPEsyor.exe
O4 - HKCU\..\Run: [s-SP] C:\WINDOWS\system32\s-SP.exe
O4 - HKCU\..\Run: [PE32or] C:\WINDOWS\system32\PE32or.exe
O4 - HKCU\..\Run: [64ntPEor] C:\WINDOWS\system32\64ntPEor.exe
O4 - HKCU\..\Run: [PEhh] C:\WINDOWS\system32\PEhh.exe
O4 - HKCU\..\Run: [PEsymsntSP] C:\WINDOWS\system32\PEsymsntSP.exe
O4 - HKCU\..\Run: [ms64] C:\WINDOWS\ms64.exe
O4 - HKCU\..\Run: [sy32orntPE] C:\WINDOWS\system32\sy32orntPE.exe
O4 - HKCU\..\Run: [PEPEPE32] C:\WINDOWS\PEPEPE32.exe
O4 - HKCU\..\Run: [sy646464ms] C:\WINDOWS\system32\sy646464ms.exe
O4 - HKCU\..\Run: [ms3232ntnt] C:\WINDOWS\system32\ms3232ntnt.exe
O4 - HKCU\..\Run: [hh6432PE32] C:\WINDOWS\hh6432PE32.exe
O4 - HKCU\..\Run: [msmsPE] C:\WINDOWS\msmsPE.exe
O4 - HKCU\..\Run: [ororhh] C:\WINDOWS\ororhh.exe
O4 - HKCU\..\Run: [PE32PEsy] C:\WINDOWS\PE32PEsy.exe
O4 - HKCU\..\Run: [6464sy64] C:\WINDOWS\system32\6464sy64.exe
O4 - HKCU\..\Run: [sysy64ms] C:\WINDOWS\sysy64ms.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Corel Network monitor worker - {70018AD3-E7AA-4BC4-B631-84A65F3D1AAF} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {70018AD3-E7AA-4BC4-B631-84A65F3D1AAF} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Corel Network monitor worker - {D92632C9-12D3-4158-A34D-C839C8A0655A} - (no file)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {D92632C9-12D3-4158-A34D-C839C8A0655A} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Corel Network monitor worker - {70018AD3-E7AA-4BC4-B631-84A65F3D1AAF} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Corel Network monitor worker - {70018AD3-E7AA-4BC4-B631-84A65F3D1AAF} - (no file) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.tncomputers.com
O16 - DPF: {234B7457-1A7E-4268-BA71-9936F0C78BEC} (ContentCleanup3X Control) - http://www.contentwatch.com/cleanup/includ…eanup3Proj1.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/29454ec4dcd3e7…ip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200310…llInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1097805915765
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2000i\AcDcToday.ocx
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (NOXLATE) - file://C:\Program Files\AutoCAD 2000i\InstFred.ocx
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2000i\AcPreview.ocx0
Please Zip the files and send it here. If you can.

Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R3 - URLSearchHook: (no name) - {AE4A0B26-E61C-BF7C-F8AB-6A66A5AD96D6} - C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe (file missing)
O4 - HKLM\..\Run: [EBC41166] C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
O4 - HKCU\..\Run: [hhSP32s-] C:\WINDOWS\system32\hhSP32s-.exe
O4 - HKCU\..\Run: [PESPhhPE32] C:\WINDOWS\PESPhhPE32.exe
O4 - HKCU\..\Run: [3232nt64] C:\WINDOWS\3232nt64.exe
O4 - HKCU\..\Run: [3232] C:\WINDOWS\3232.exe
O4 - HKCU\..\Run: [hhs-SP32hh] C:\WINDOWS\hhs-SP32hh.exe
O4 - HKCU\..\Run: [msPEsyor] C:\WINDOWS\system32\msPEsyor.exe
O4 - HKCU\..\Run: [s-SP] C:\WINDOWS\system32\s-SP.exe
O4 - HKCU\..\Run: [PE32or] C:\WINDOWS\system32\PE32or.exe
O4 - HKCU\..\Run: [64ntPEor] C:\WINDOWS\system32\64ntPEor.exe
O4 - HKCU\..\Run: [PEhh] C:\WINDOWS\system32\PEhh.exe
O4 - HKCU\..\Run: [PEsymsntSP] C:\WINDOWS\system32\PEsymsntSP.exe
O4 - HKCU\..\Run: [ms64] C:\WINDOWS\ms64.exe
O4 - HKCU\..\Run: [sy32orntPE] C:\WINDOWS\system32\sy32orntPE.exe
O4 - HKCU\..\Run: [PEPEPE32] C:\WINDOWS\PEPEPE32.exe
O4 - HKCU\..\Run: [sy646464ms] C:\WINDOWS\system32\sy646464ms.exe
O4 - HKCU\..\Run: [ms3232ntnt] C:\WINDOWS\system32\ms3232ntnt.exe
O4 - HKCU\..\Run: [hh6432PE32] C:\WINDOWS\hh6432PE32.exe
O4 - HKCU\..\Run: [msmsPE] C:\WINDOWS\msmsPE.exe
O4 - HKCU\..\Run: [ororhh] C:\WINDOWS\ororhh.exe
O4 - HKCU\..\Run: [PE32PEsy] C:\WINDOWS\PE32PEsy.exe
O4 - HKCU\..\Run: [6464sy64] C:\WINDOWS\system32\6464sy64.exe
O4 - HKCU\..\Run: [sysy64ms] C:\WINDOWS\sysy64ms.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/29454ec4dcd3e7…ip/RdxIE601.cab



Reboot afterwards in SAFE MODE. If you don't know how click here
Delete the following file(s) listed. Do not delete the folders

C:\DOCUME~1\Shawn\LOCALS~1\Temp\i7zyj.exe
C:\WINDOWS\system32\hhSP32s-.exe
C:\WINDOWS\PESPhhPE32.exe
C:\WINDOWS\3232nt64.exe
C:\WINDOWS\3232.exe
C:\WINDOWS\hhs-SP32hh.exe
C:\WINDOWS\system32\msPEsyor.exe
C:\WINDOWS\system32\s-SP.exe
C:\WINDOWS\system32\PE32or.exe
C:\WINDOWS\system32\64ntPEor.exe
C:\WINDOWS\system32\PEhh.exe
C:\WINDOWS\system32\PEsymsntSP.exe
C:\WINDOWS\ms64.exe
C:\WINDOWS\system32\sy32orntPE.exe
C:\WINDOWS\PEPEPE32.exe
C:\WINDOWS\system32\sy646464ms.exe
C:\WINDOWS\system32\ms3232ntnt.exe
C:\WINDOWS\hh6432PE32.exe
C:\WINDOWS\msmsPE.exe
C:\WINDOWS\ororhh.exe
C:\WINDOWS\PE32PEsy.exe
C:\WINDOWS\system32\6464sy64.exe
C:\WINDOWS\sysy64ms.exe

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Then Download System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI