This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijacked Computer - Help This Newbie!

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:rofl: :rofl: :rofl:

My computer is going berserk. It started with an AIM click on a stupid WTF… Look at this picture link on a profile. (the bestfriends.scr virus?) Since then, I have had a billion popups, and my computer is running extremely slow. I have about 20 errors every time I turn it on, including a Run Time Error '9' (Subscript out of range). When working online, pages often get stuck, and when trying to delete them, an error comes up saying something like the browser (or ActiveX control) is busy. I have run Adaware, CWShredder, SpySubtract, & Spybot, and they deleted many components, but the popups are still coming up. I have never had problems with my computer, and don't know what to do. I downloaded hijackthis, and this is the results (assuming this will help, I posted everything although I'm not sure if it was necessary.. Sorry if not):

Logfile of HijackThis v1.98.2
Scan saved at 10:17:32 AM, on 11/03/2004
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINNT\System32\PRPCUI.exe
C:\documents and settings\jes\local settings\temp\vgBcr6Qq.exe
C:\WINNT\System32\qctmjczh.exe
C:\documents and settings\jes\local settings\temp\w1ZOn.exe
C:\documents and settings\jes\local settings\temp\EmTR.exe
C:\documents and settings\jes\local settings\temp\gl.exe
C:\documents and settings\jes\local settings\temp\Pc.exe
C:\documents and settings\jes\local settings\temp\qeZDdG.exe
C:\documents and settings\jes\local settings\temp\j.exe
C:\documents and settings\jes\local settings\temp\SH9x.exe
C:\documents and settings\jes\local settings\temp\Ko6O.exe
C:\documents and settings\jes\local settings\temp\YNQ.exe
C:\documents and settings\jes\local settings\temp\tDWU6.exe
C:\documents and settings\jes\local settings\temp\1ocH.exe
C:\documents and settings\jes\local settings\temp\DNRInZZ.exe
C:\documents and settings\jes\local settings\temp\f.exe
C:\documents and settings\jes\local settings\temp\dvJ6mdYt.exe
C:\documents and settings\jes\local settings\temp\bOVu.exe
C:\documents and settings\jes\local settings\temp\tFRb.exe
C:\documents and settings\jes\local settings\temp\q.exe
C:\documents and settings\jes\local settings\temp\Afdh.exe
C:\documents and settings\jes\local settings\temp\RJmV.exe
C:\documents and settings\jes\local settings\temp\O.exe
C:\documents and settings\jes\local settings\temp\MlKGz3bw.exe
C:\documents and settings\jes\local settings\temp\4cGn3FFi.exe
C:\documents and settings\jes\local settings\temp\m3C4xha3.exe
C:\documents and settings\jes\local settings\temp\j01o.exe
C:\documents and settings\jes\local settings\temp\h.exe
C:\documents and settings\jes\local settings\temp\dfC6mqmR.exe
C:\documents and settings\jes\local settings\temp\ac1q.exe
C:\documents and settings\jes\local settings\temp\NXuvlEln.exe
C:\documents and settings\jes\local settings\temp\5OqcPhP9.exe
C:\documents and settings\jes\local settings\temp\37Czc.exe
C:\documents and settings\jes\local settings\temp\lYyhG.exe
C:\documents and settings\jes\local settings\temp\DPuYa.exe
C:\documents and settings\jes\local settings\temp\B8.exe
C:\documents and settings\jes\local settings\temp\95fRc.exe
C:\documents and settings\jes\local settings\temp\6.exe
C:\documents and settings\jes\local settings\temp\JN6fa.exe
C:\documents and settings\jes\local settings\temp\1E2WF.exe
C:\documents and settings\jes\local settings\temp\ZX.exe
C:\documents and settings\jes\local settings\temp\WgrIoPDB.exe
C:\documents and settings\jes\local settings\temp\e7npSs7m.exe
C:\documents and settings\jes\local settings\temp\cqzMf.exe
C:\documents and settings\jes\local settings\temp\uhvuJ.exe
C:\documents and settings\jes\local settings\temp\sA.exe
C:\documents and settings\jes\local settings\temp\Kr.exe
C:\documents and settings\jes\local settings\temp\mQjzc.exe
C:\documents and settings\jes\local settings\temp\Dkrd3.exe
C:\documents and settings\jes\local settings\temp\VbnUx.exe
C:\documents and settings\jes\local settings\temp\d2jB1.exe
C:\documents and settings\jes\local settings\temp\P4byZz0f.exe
C:\documents and settings\jes\local settings\temp\JiZMr.exe
C:\documents and settings\jes\local settings\temp\19VtV.exe
C:\documents and settings\jes\local settings\temp\CQNRT.exe
C:\documents and settings\jes\local settings\temp\UHJyo.exe
C:\documents and settings\jes\local settings\temp\P.exe
C:\documents and settings\jes\local settings\temp\sGZQ5.exe
C:\documents and settings\jes\local settings\temp\Ja8t.exe
C:\documents and settings\jes\local settings\temp\0Fg7.exe
C:\documents and settings\jes\local settings\temp\UUSPSmwe.exe
C:\documents and settings\jes\local settings\temp\w.exe
C:\documents and settings\jes\local settings\temp\8lpN.exe
C:\documents and settings\jes\local settings\temp\FXT1.exe
C:\documents and settings\jes\local settings\temp\XOOI.exe
C:\documents and settings\jes\local settings\temp\no.exe
C:\documents and settings\jes\local settings\temp\z6tYAXhp.exe
C:\documents and settings\jes\local settings\temp\QACCqRv.exe
C:\documents and settings\jes\local settings\temp\3Emw.exe
C:\documents and settings\jes\local settings\temp\eX.exe
C:\documents and settings\jes\local settings\temp\axj6syqR1.exe
C:\documents and settings\jes\local settings\temp\7uIqb.exe
C:\documents and settings\jes\local settings\temp\3q.exe
C:\documents and settings\jes\local settings\temp\FsZIS.exe
C:\documents and settings\jes\local settings\temp\WX8lI.exe
C:\documents and settings\jes\local settings\temp\T.exe
C:\documents and settings\jes\local settings\temp\MMkkU.exe
C:\documents and settings\jes\local settings\temp\nOchSuty.exe
C:\documents and settings\jes\local settings\temp\Z.exe
C:\documents and settings\jes\local settings\temp\BfKf.exe
C:\documents and settings\jes\local settings\temp\SJST.exe
C:\documents and settings\jes\local settings\temp\9e1w.exe
C:\documents and settings\jes\local settings\temp\MCGxKIR.exe
C:\documents and settings\jes\local settings\temp\ZEDX2K.exe
C:\documents and settings\jes\local settings\temp\Sv.exe
C:\documents and settings\jes\local settings\temp\9Z.exe
C:\documents and settings\jes\local settings\temp\q7.exe
C:\documents and settings\jes\local settings\temp\m4wFCj0S.exe
C:\documents and settings\jes\local settings\temp\Zs.exe
C:\documents and settings\jes\local settings\temp\Av3Db.exe
C:\documents and settings\jes\local settings\temp\cTJENJWb.exe
C:\documents and settings\jes\local settings\temp\uKFlhlrX.exe
C:\documents and settings\jes\local settings\temp\MeNY8fFe.exe
C:\documents and settings\jes\local settings\temp\nhF.exe
C:\documents and settings\jes\local settings\temp\eqSthq.exe
C:\documents and settings\jes\local settings\temp\QtKqfq1lV.exe
C:\documents and settings\jes\local settings\temp\sR.exe
C:\documents and settings\jes\local settings\temp\4g5ssQ.exe
C:\documents and settings\jes\local settings\temp\HFKs3zd92.exe
C:\documents and settings\jes\local settings\temp\iH.exe
C:\documents and settings\jes\local settings\temp\V6iqD.exe
C:\documents and settings\jes\local settings\temp\R2.exe
C:\documents and settings\jes\local settings\temp\urmLY.exe
C:\documents and settings\jes\local settings\temp\LVvpO.exe
C:\documents and settings\jes\local settings\temp\nkaqqp5M.exe
C:\documents and settings\jes\local settings\temp\jULGv.exe
C:\documents and settings\jes\local settings\temp\z26h.exe
C:\documents and settings\jes\local settings\temp\QwfU.exe
C:\documents and settings\jes\local settings\temp\6EAu.exe
C:\documents and settings\jes\local settings\temp\HGssJLo.exe
C:\documents and settings\jes\local settings\temp\TYOLKn.exe
C:\documents and settings\jes\local settings\temp\vntLl5pi5.exe
C:\documents and settings\jes\local settings\temp\mzuNaeC6c.exe
C:\documents and settings\jes\local settings\temp\jwT8T2.exe
C:\documents and settings\jes\local settings\temp\UyL5R24Ew.exe
C:\documents and settings\jes\local settings\temp\xX.exe
C:\documents and settings\jes\local settings\temp\PO.exe
C:\documents and settings\jes\local settings\temp\rc1Nz.exe
C:\documents and settings\jes\local settings\temp\pv.exe
C:\documents and settings\jes\local settings\temp\lsCvFpfY5.exe
C:\documents and settings\jes\local settings\temp\h2eMK.exe
C:\documents and settings\jes\local settings\temp\UrTNmcHw.exe
C:\documents and settings\jes\local settings\temp\bV2qc6VN.exe
C:\documents and settings\jes\local settings\temp\M.exe
C:\documents and settings\jes\local settings\temp\Z1Ei66j8.exe
C:\documents and settings\jes\local settings\temp\VY3C.exe
C:\documents and settings\jes\local settings\temp\N8ga05I.exe
C:\documents and settings\jes\local settings\temp\FfG.exe
C:\documents and settings\jes\local settings\temp\Rjq7sjXmU.exe
C:\documents and settings\jes\local settings\temp\aamOXVr78.exe
C:\documents and settings\jes\local settings\temp\7uycjs.exe
C:\documents and settings\jes\local settings\temp\4q.exe
C:\documents and settings\jes\local settings\temp\mh.exe
C:\documents and settings\jes\local settings\temp\E8.exe
C:\documents and settings\jes\local settings\temp\Cr1io1TWg.exe
C:\documents and settings\jes\local settings\temp\yoqC7P.exe
C:\documents and settings\jes\local settings\temp\bM5DJxCYa.exe
C:\documents and settings\jes\local settings\temp\Lsaw.exe
C:\documents and settings\jes\local settings\temp\3j6e.exe
C:\documents and settings\jes\local settings\temp\eBs.exe
C:\documents and settings\jes\local settings\temp\byRRgQT9r.exe
C:\documents and settings\jes\local settings\temp\NXw.exe
C:\documents and settings\jes\local settings\temp\Jx78XElHL.exe
C:\documents and settings\jes\local settings\temp\1o3PshPsZ.exe
C:\documents and settings\jes\local settings\temp\EM.exe
C:\documents and settings\jes\local settings\temp\Vh.exe
C:\documents and settings\jes\local settings\temp\RdgODHLMx.exe
C:\documents and settings\jes\local settings\temp\Mt.exe
C:\documents and settings\jes\local settings\temp\4k.exe
C:\documents and settings\jes\local settings\temp\zftPDfUT.exe
C:\documents and settings\jes\local settings\temp\LjdJz.exe
C:\documents and settings\jes\local settings\temp\nl5Gxfjd.exe
C:\documents and settings\jes\local settings\temp\jVHX.exe
C:\documents and settings\jes\local settings\temp\z32x.exe
C:\documents and settings\jes\local settings\temp\bsHyreI.exe
C:\documents and settings\jes\local settings\temp\n7QU5y.exe
C:\documents and settings\jes\local settings\temp\Z9IS3yJan.exe
C:\documents and settings\jes\local settings\temp\h0EzxadWB.exe
C:\documents and settings\jes\local settings\temp\Tp.exe
C:\documents and settings\jes\local settings\temp\bg.exe
C:\documents and settings\jes\local settings\temp\8cFBmjqJI.exe
C:\documents and settings\jes\local settings\temp\Je.exe
C:\documents and settings\jes\local settings\temp\lDczV.exe
C:\documents and settings\jes\local settings\temp\D7kcM.exe
C:\documents and settings\jes\local settings\temp\xnWUSf459.exe
C:\documents and settings\jes\local settings\temp\3CC5hCYF.exe
C:\documents and settings\jes\local settings\temp\Zcdl.exe
C:\documents and settings\jes\local settings\temp\fkyW.exe
C:\documents and settings\jes\local settings\temp\c.exe
C:\documents and settings\jes\local settings\temp\YB.exe
C:\documents and settings\jes\local settings\temp\eJ.exe
C:\documents and settings\jes\local settings\temp\vd.exe
C:\documents and settings\jes\local settings\temp\8CkLW.exe
C:\documents and settings\jes\local settings\temp\qtgsq.exe
C:\documents and settings\jes\local settings\temp\Ikc9U.exe
C:\documents and settings\jes\local settings\temp\0b8Qp.exe
C:\documents and settings\jes\local settings\temp\Xu.exe
C:\documents and settings\jes\local settings\temp\UrJyuiYh6.exe
C:\documents and settings\jes\local settings\temp\bVSclccyL.exe
C:\documents and settings\jes\local settings\temp\NX.exe
C:\documents and settings\jes\local settings\temp\4rSN.exe
C:\documents and settings\jes\local settings\temp\sdzynn.exe
C:\documents and settings\jes\local settings\temp\HY65X.exe
C:\documents and settings\jes\local settings\temp\iEbZh7nO.exe
C:\documents and settings\jes\local settings\temp\deMfm.exe
C:\documents and settings\jes\local settings\temp\Ktsq.exe
C:\documents and settings\jes\local settings\temp\lvknKAs.exe
C:\documents and settings\jes\local settings\temp\bU.exe
C:\documents and settings\jes\local settings\temp\MW1gX.exe
C:\documents and settings\jes\local settings\temp\oYTdVnam.exe
C:\documents and settings\jes\local settings\temp\jyvu0.exe
C:\documents and settings\jes\local settings\temp\g.exe
C:\documents and settings\jes\local settings\temp\STzPl.exe
C:\documents and settings\jes\local settings\temp\uVrMjZ3s.exe
C:\documents and settings\jes\local settings\temp\LqAq9ThJ.exe
C:\documents and settings\jes\local settings\temp\HZbH.exe
C:\documents and settings\jes\local settings\temp\ZQ7o.exe
C:\documents and settings\jes\local settings\temp\BfMpljd.exe
C:\documents and settings\jes\local settings\temp\Rn8Zxva.exe
C:\documents and settings\jes\local settings\temp\nA0FjVXa8.exe
C:\documents and settings\jes\local settings\temp\DImfw6UXe.exe
C:\documents and settings\jes\local settings\temp\AEKzf.exe
C:\documents and settings\jes\local settings\temp\d3qAQCDZ7.exe
C:\documents and settings\jes\local settings\temp\6W.exe
C:\documents and settings\jes\local settings\temp\oN.exe
C:\documents and settings\jes\local settings\temp\0cPWo.exe
C:\documents and settings\jes\local settings\temp\DAuX0hyP.exe
C:\documents and settings\jes\local settings\temp\U5DARbL6.exe
C:\documents and settings\jes\local settings\temp\PirOi.exe
C:\documents and settings\jes\local settings\temp\oBIEZ79.exe
C:\documents and settings\jes\local settings\temp\DEQ.exe
C:\documents and settings\jes\local settings\temp\nRTtURk.exe
C:\documents and settings\jes\local settings\temp\s33rn5zh0.exe
C:\documents and settings\jes\local settings\temp\2I.exe
C:\documents and settings\jes\local settings\temp\tKe.exe
C:\Documents and Settings\Jes\Application Data\owar.exe
C:\Program Files\Navnt\navapw32.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\AIM\aim.exe
C:\WINNT\system32\??rss.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jes\Desktop\hijackthisupdate.exe
C:\WINNT\System32\iprtrmgr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vt.edu/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll
O2 - BHO: MultimppObj Class - {002EB272-2590-4693-B166-FBD5D9B6FEA6} - C:\WINNT\multimpp.dll
O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6EAA6550-9241-72CE-8259-10550EF62816} - C:\WINNT\System32\ogwy.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll (file missing)
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jes\Local Settings\Temp\uioH6.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\Program Files\SEP\sep.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [Win Comm] C:\Program Files\Win Comm\WinComm.exe
O4 - HKLM\..\Run: [vgBcr6Qq] C:\documents and settings\jes\local settings\temp\vgBcr6Qq.exe
O4 - HKLM\..\Run: [wdvjrxnod] C:\WINNT\System32\qctmjczh.exe
O4 - HKLM\..\Run: [w1ZOn] C:\documents and settings\jes\local settings\temp\w1ZOn.exe
O4 - HKLM\..\Run: [86ff8d962182] C:\WINNT\System32\CNDPTPC0.exe
O4 - HKLM\..\Run: [EmTR] C:\documents and settings\jes\local settings\temp\EmTR.exe
O4 - HKLM\..\Run: [gl] C:\documents and settings\jes\local settings\temp\gl.exe
O4 - HKLM\..\Run: [Pc] C:\documents and settings\jes\local settings\temp\Pc.exe
O4 - HKLM\..\Run: [qeZDdG] C:\documents and settings\jes\local settings\temp\qeZDdG.exe
O4 - HKLM\..\Run: [j] C:\documents and settings\jes\local settings\temp\j.exe
O4 - HKLM\..\Run: [SH9x] C:\documents and settings\jes\local settings\temp\SH9x.exe
O4 - HKLM\..\Run: [7] C:\documents and settings\jes\local settings\temp\7.exe
O4 - HKLM\..\Run: [Ko6O] C:\documents and settings\jes\local settings\temp\Ko6O.exe
O4 - HKLM\..\Run: [YNQ] C:\documents and settings\jes\local settings\temp\YNQ.exe
O4 - HKLM\..\Run: [2SAH4QD2SDAWX7] C:\WINNT\System32\NgiOUeB0.exe
O4 - HKLM\..\Run: [tDWU6] C:\documents and settings\jes\local settings\temp\tDWU6.exe
O4 - HKLM\..\Run: [1ocH] C:\documents and settings\jes\local settings\temp\1ocH.exe
O4 - HKLM\..\Run: [DNRInZZ] C:\documents and settings\jes\local settings\temp\DNRInZZ.exe
O4 - HKLM\..\Run: [f] C:\documents and settings\jes\local settings\temp\f.exe
O4 - HKLM\..\Run: [dvJ6mdYt] C:\documents and settings\jes\local settings\temp\dvJ6mdYt.exe
O4 - HKLM\..\Run: [bOVu] C:\documents and settings\jes\local settings\temp\bOVu.exe
O4 - HKLM\..\Run: [tFRb] C:\documents and settings\jes\local settings\temp\tFRb.exe
O4 - HKLM\..\Run: [q] C:\documents and settings\jes\local settings\temp\q.exe
O4 - HKLM\..\Run: C:\documents and settings\jes\local settings\temp\I.exe
O4 - HKLM\..\Run: [Afdh] C:\documents and settings\jes\local settings\temp\Afdh.exe
O4 - HKLM\..\Run: [RJmV] C:\documents and settings\jes\local settings\temp\RJmV.exe
O4 - HKLM\..\Run: [O] C:\documents and settings\jes\local settings\temp\O.exe
O4 - HKLM\..\Run: [MlKGz3bw] C:\documents and settings\jes\local settings\temp\MlKGz3bw.exe
O4 - HKLM\..\Run: [4cGn3FFi] C:\documents and settings\jes\local settings\temp\4cGn3FFi.exe
O4 - HKLM\..\Run: [m3C4xha3] C:\documents and settings\jes\local settings\temp\m3C4xha3.exe
O4 - HKLM\..\Run: [j01o] C:\documents and settings\jes\local settings\temp\j01o.exe
O4 - HKLM\..\Run: [h] C:\documents and settings\jes\local settings\temp\h.exe
O4 - HKLM\..\Run: [dfC6mqmR] C:\documents and settings\jes\local settings\temp\dfC6mqmR.exe
O4 - HKLM\..\Run: [ac1q] C:\documents and settings\jes\local settings\temp\ac1q.exe
O4 - HKLM\..\Run: [NXuvlEln] C:\documents and settings\jes\local settings\temp\NXuvlEln.exe
O4 - HKLM\..\Run: [5OqcPhP9] C:\documents and settings\jes\local settings\temp\5OqcPhP9.exe
O4 - HKLM\..\Run: [37Czc] C:\documents and settings\jes\local settings\temp\37Czc.exe
O4 - HKLM\..\Run: [lYyhG] C:\documents and settings\jes\local settings\temp\lYyhG.exe
O4 - HKLM\..\Run: [DPuYa] C:\documents and settings\jes\local settings\temp\DPuYa.exe
O4 - HKLM\..\Run: [B8] C:\documents and settings\jes\local settings\temp\B8.exe
O4 - HKLM\..\Run: [95fRc] C:\documents and settings\jes\local settings\temp\95fRc.exe
O4 - HKLM\..\Run: [6] C:\documents and settings\jes\local settings\temp\6.exe
O4 - HKLM\..\Run: [JN6fa] C:\documents and settings\jes\local settings\temp\JN6fa.exe
O4 - HKLM\..\Run: [1E2WF] C:\documents and settings\jes\local settings\temp\1E2WF.exe
O4 - HKLM\..\Run: [ZX] C:\documents and settings\jes\local settings\temp\ZX.exe
O4 - HKLM\..\Run: [WgrIoPDB] C:\documents and settings\jes\local settings\temp\WgrIoPDB.exe
O4 - HKLM\..\Run: [e7npSs7m] C:\documents and settings\jes\local settings\temp\e7npSs7m.exe
O4 - HKLM\..\Run: [cqzMf] C:\documents and settings\jes\local settings\temp\cqzMf.exe
O4 - HKLM\..\Run: [uhvuJ] C:\documents and settings\jes\local settings\temp\uhvuJ.exe
O4 - HKLM\..\Run: [sA] C:\documents and settings\jes\local settings\temp\sA.exe
O4 - HKLM\..\Run: [Kr] C:\documents and settings\jes\local settings\temp\Kr.exe
O4 - HKLM\..\Run: [mQjzc] C:\documents and settings\jes\local settings\temp\mQjzc.exe
O4 - HKLM\..\Run: [Dkrd3] C:\documents and settings\jes\local settings\temp\Dkrd3.exe
O4 - HKLM\..\Run: [VbnUx] C:\documents and settings\jes\local settings\temp\VbnUx.exe
O4 - HKLM\..\Run: [d2jB1] C:\documents and settings\jes\local settings\temp\d2jB1.exe
O4 - HKLM\..\Run: [P4byZz0f] C:\documents and settings\jes\local settings\temp\P4byZz0f.exe
O4 - HKLM\..\Run: [JiZMr] C:\documents and settings\jes\local settings\temp\JiZMr.exe
O4 - HKLM\..\Run: [19VtV] C:\documents and settings\jes\local settings\temp\19VtV.exe
O4 - HKLM\..\Run: [k0Rap] C:\documents and settings\jes\local settings\temp\k0Rap.exe
O4 - HKLM\..\Run: [CQNRT] C:\documents and settings\jes\local settings\temp\CQNRT.exe
O4 - HKLM\..\Run: [UHJyo] C:\documents and settings\jes\local settings\temp\UHJyo.exe
O4 - HKLM\..\Run: [P] C:\documents and settings\jes\local settings\temp\P.exe
O4 - HKLM\..\Run: [sGZQ5] C:\documents and settings\jes\local settings\temp\sGZQ5.exe
O4 - HKLM\..\Run: [Ja8t] C:\documents and settings\jes\local settings\temp\Ja8t.exe
O4 - HKLM\..\Run: [0Fg7] C:\documents and settings\jes\local settings\temp\0Fg7.exe
O4 - HKLM\..\Run: [Y] C:\documents and settings\jes\local settings\temp\Y.exe
O4 - HKLM\..\Run: [UUSPSmwe] C:\documents and settings\jes\local settings\temp\UUSPSmwe.exe
O4 - HKLM\..\Run: [w] C:\documents and settings\jes\local settings\temp\w.exe
O4 - HKLM\..\Run: [8lpN] C:\documents and settings\jes\local settings\temp\8lpN.exe
O4 - HKLM\..\Run: [5] C:\documents and settings\jes\local settings\temp\5.exe
O4 - HKLM\..\Run: [FXT1] C:\documents and settings\jes\local settings\temp\FXT1.exe
O4 - HKLM\..\Run: [XOOI] C:\documents and settings\jes\local settings\temp\XOOI.exe
O4 - HKLM\..\Run: [no] C:\documents and settings\jes\local settings\temp\no.exe
O4 - HKLM\..\Run: [E] C:\documents and settings\jes\local settings\temp\E.exe
O4 - HKLM\..\Run: [z6tYAXhp] C:\documents and settings\jes\local settings\temp\z6tYAXhp.exe
O4 - HKLM\..\Run: [QACCqRv] C:\documents and settings\jes\local settings\temp\QACCqRv.exe
O4 - HKLM\..\Run: C:\documents and settings\jes\local settings\temp\s.exe
O4 - HKLM\..\Run: [3Emw] C:\documents and settings\jes\local settings\temp\3Emw.exe
O4 - HKLM\..\Run: [eX] C:\documents and settings\jes\local settings\temp\eX.exe
O4 - HKLM\..\Run: [axj6syqR1] C:\documents and settings\jes\local settings\temp\axj6syqR1.exe
O4 - HKLM\..\Run: [7uIqb] C:\documents and settings\jes\local settings\temp\7uIqb.exe
O4 - HKLM\..\Run: [3q] C:\documents and settings\jes\local settings\temp\3q.exe
O4 - HKLM\..\Run: [FsZIS] C:\documents and settings\jes\local settings\temp\FsZIS.exe
O4 - HKLM\..\Run: [WX8lI] C:\documents and settings\jes\local settings\temp\WX8lI.exe
O4 - HKLM\..\Run: [T] C:\documents and settings\jes\local settings\temp\T.exe
O4 - HKLM\..\Run: [MMkkU] C:\documents and settings\jes\local settings\temp\MMkkU.exe
O4 - HKLM\..\Run: [nOchSuty] C:\documents and settings\jes\local settings\temp\nOchSuty.exe
O4 - HKLM\..\Run: [Z] C:\documents and settings\jes\local settings\temp\Z.exe
O4 - HKLM\..\Run: [BfKf] C:\documents and settings\jes\local settings\temp\BfKf.exe
O4 - HKLM\..\Run: [SJST] C:\documents and settings\jes\local settings\temp\SJST.exe
O4 - HKLM\..\Run: [9e1w] C:\documents and settings\jes\local settings\temp\9e1w.exe
O4 - HKLM\..\Run: [MCGxKIR] C:\documents and settings\jes\local settings\temp\MCGxKIR.exe
O4 - HKLM\..\Run: [ZEDX2K] C:\documents and settings\jes\local settings\temp\ZEDX2K.exe
O4 - HKLM\..\Run: [Sv] C:\documents and settings\jes\local settings\temp\Sv.exe
O4 - HKLM\..\Run: [9Z] C:\documents and settings\jes\local settings\temp\9Z.exe
O4 - HKLM\..\Run: [q7] C:\documents and settings\jes\local settings\temp\q7.exe
O4 - HKLM\..\Run: [m4wFCj0S] C:\documents and settings\jes\local settings\temp\m4wFCj0S.exe
O4 - HKLM\..\Run: [Zs] C:\documents and settings\jes\local settings\temp\Zs.exe
O4 - HKLM\..\Run: [Av3Db] C:\documents and settings\jes\local settings\temp\Av3Db.exe
O4 - HKLM\..\Run: [cTJENJWb] C:\documents and settings\jes\local settings\temp\cTJENJWb.exe
O4 - HKLM\..\Run: [uKFlhlrX] C:\documents and settings\jes\local settings\temp\uKFlhlrX.exe
O4 - HKLM\..\Run: [MeNY8fFe] C:\documents and settings\jes\local settings\temp\MeNY8fFe.exe
O4 - HKLM\..\Run: [nhF] C:\documents and settings\jes\local settings\temp\nhF.exe
O4 - HKLM\..\Run: [eqSthq] C:\documents and settings\jes\local settings\temp\eqSthq.exe
O4 - HKLM\..\Run: [QtKqfq1lV] C:\documents and settings\jes\local settings\temp\QtKqfq1lV.exe
O4 - HKLM\..\Run: [sR] C:\documents and settings\jes\local settings\temp\sR.exe
O4 - HKLM\..\Run: [4g5ssQ] C:\documents and settings\jes\local settings\temp\4g5ssQ.exe
O4 - HKLM\..\Run: [HFKs3zd92] C:\documents and settings\jes\local settings\temp\HFKs3zd92.exe
O4 - HKLM\..\Run: [iH] C:\documents and settings\jes\local settings\temp\iH.exe
O4 - HKLM\..\Run: [V6iqD] C:\documents and settings\jes\local settings\temp\V6iqD.exe
O4 - HKLM\..\Run: [R2] C:\documents and settings\jes\local settings\temp\R2.exe
O4 - HKLM\..\Run: [urmLY] C:\documents and settings\jes\local settings\temp\urmLY.exe
O4 - HKLM\..\Run: [LVvpO] C:\documents and settings\jes\local settings\temp\LVvpO.exe
O4 - HKLM\..\Run: [nkaqqp5M] C:\documents and settings\jes\local settings\temp\nkaqqp5M.exe
O4 - HKLM\..\Run: [jULGv] C:\documents and settings\jes\local settings\temp\jULGv.exe
O4 - HKLM\..\Run: [z26h] C:\documents and settings\jes\local settings\temp\z26h.exe
O4 - HKLM\..\Run: [QwfU] C:\documents and settings\jes\local settings\temp\QwfU.exe
O4 - HKLM\..\Run: [6EAu] C:\documents and settings\jes\local settings\temp\6EAu.exe
O4 - HKLM\..\Run: [HGssJLo] C:\documents and settings\jes\local settings\temp\HGssJLo.exe
O4 - HKLM\..\Run: [TYOLKn] C:\documents and settings\jes\local settings\temp\TYOLKn.exe
O4 - HKLM\..\Run: [vntLl5pi5] C:\documents and settings\jes\local settings\temp\vntLl5pi5.exe
O4 - HKLM\..\Run: [7M] C:\documents and settings\jes\local settings\temp\7M.exe
O4 - HKLM\..\Run: [KbONzw] C:\documents and settings\jes\local settings\temp\KbONzw.exe
O4 - HKLM\..\Run: [mzuNaeC6c] C:\documents and settings\jes\local settings\temp\mzuNaeC6c.exe
O4 - HKLM\..\Run: [jwT8T2] C:\documents and settings\jes\local settings\temp\jwT8T2.exe
O4 - HKLM\..\Run: [UyL5R24Ew] C:\documents and settings\jes\local settings\temp\UyL5R24Ew.exe
O4 - HKLM\..\Run: [xX] C:\documents and settings\jes\local settings\temp\xX.exe
O4 - HKLM\..\Run: [PO] C:\documents and settings\jes\local settings\temp\PO.exe
O4 - HKLM\..\Run: [rc1Nz] C:\documents and settings\jes\local settings\temp\rc1Nz.exe
O4 - HKLM\..\Run: [pv] C:\documents and settings\jes\local settings\temp\pv.exe
O4 - HKLM\..\Run: [lsCvFpfY5] C:\documents and settings\jes\local settings\temp\lsCvFpfY5.exe
O4 - HKLM\..\Run: [h2eMK] C:\documents and settings\jes\local settings\temp\h2eMK.exe
O4 - HKLM\..\Run: [UrTNmcHw] C:\documents and settings\jes\local settings\temp\UrTNmcHw.exe
O4 - HKLM\..\Run: [bV2qc6VN] C:\documents and settings\jes\local settings\temp\bV2qc6VN.exe
O4 - HKLM\..\Run: [M] C:\documents and settings\jes\local settings\temp\M.exe
O4 - HKLM\..\Run: [JUjITUml] C:\documents and settings\jes\local settings\temp\JUjITUml.exe
O4 - HKLM\..\Run: [Z1Ei66j8] C:\documents and settings\jes\local settings\temp\Z1Ei66j8.exe
O4 - HKLM\..\Run: [VY3C] C:\documents and settings\jes\local settings\temp\VY3C.exe
O4 - HKLM\..\Run: [dsbg] C:\documents and settings\jes\local settings\temp\dsbg.exe
O4 - HKLM\..\Run: [N8ga05I] C:\documents and settings\jes\local settings\temp\N8ga05I.exe
O4 - HKLM\..\Run: [FfG] C:\documents and settings\jes\local settings\temp\FfG.exe
O4 - HKLM\..\Run: [APhtCpJ5f] C:\documents and settings\jes\local settings\temp\APhtCpJ5f.exe
O4 - HKLM\..\Run: [Rjq7sjXmU] C:\documents and settings\jes\local settings\temp\Rjq7sjXmU.exe
O4 - HKLM\..\Run: [aamOXVr78] C:\documents and settings\jes\local settings\temp\aamOXVr78.exe
O4 - HKLM\..\Run: [7uycjs] C:\documents and settings\jes\local settings\temp\7uycjs.exe
O4 - HKLM\..\Run: [4q] C:\documents and settings\jes\local settings\temp\4q.exe
O4 - HKLM\..\Run: [mh] C:\documents and settings\jes\local settings\temp\mh.exe
O4 - HKLM\..\Run: [E8] C:\documents and settings\jes\local settings\temp\E8.exe
O4 - HKLM\..\Run: [Cr1io1TWg] C:\documents and settings\jes\local settings\temp\Cr1io1TWg.exe
O4 - HKLM\..\Run: [yoqC7P] C:\documents and settings\jes\local settings\temp\yoqC7P.exe
O4 - HKLM\..\Run: [bM5DJxCYa] C:\documents and settings\jes\local settings\temp\bM5DJxCYa.exe
O4 - HKLM\..\Run: [Lsaw] C:\documents and settings\jes\local settings\temp\Lsaw.exe
O4 - HKLM\..\Run: [3j6e] C:\documents and settings\jes\local settings\temp\3j6e.exe
O4 - HKLM\..\Run: [eBs] C:\documents and settings\jes\local settings\temp\eBs.exe
O4 - HKLM\..\Run: [byRRgQT9r] C:\documents and settings\jes\local settings\temp\byRRgQT9r.exe
O4 - HKLM\..\Run: [NXw] C:\documents and settings\jes\local settings\temp\NXw.exe
O4 - HKLM\..\Run: [Jx78XElHL] C:\documents and settings\jes\local settings\temp\Jx78XElHL.exe
O4 - HKLM\..\Run: [1o3PshPsZ] C:\documents and settings\jes\local settings\temp\1o3PshPsZ.exe
O4 - HKLM\..\Run: [EM] C:\documents and settings\jes\local settings\temp\EM.exe
O4 - HKLM\..\Run: [Vh] C:\documents and settings\jes\local settings\temp\Vh.exe
O4 - HKLM\..\Run: [RdgODHLMx] C:\documents and settings\jes\local settings\temp\RdgODHLMx.exe
O4 - HKLM\..\Run: [94cv7jgxL] C:\documents and settings\jes\local settings\temp\94cv7jgxL.exe
O4 - HKLM\..\Run: [Mt] C:\documents and settings\jes\local settings\temp\Mt.exe
O4 - HKLM\..\Run: [4k] C:\documents and settings\jes\local settings\temp\4k.exe
O4 - HKLM\..\Run: [mb] C:\documents and settings\jes\local settings\temp\mb.exe
O4 - HKLM\..\Run: [XdBRF] C:\documents and settings\jes\local settings\temp\XdBRF.exe
O4 - HKLM\..\Run: [zftPDfUT] C:\documents and settings\jes\local settings\temp\zftPDfUT.exe
O4 - HKLM\..\Run: [uP55I] C:\documents and settings\jes\local settings\temp\uP55I.exe
O4 - HKLM\..\Run: [LjdJz] C:\documents and settings\jes\local settings\temp\LjdJz.exe
O4 - HKLM\..\Run: [nl5Gxfjd] C:\documents and settings\jes\local settings\temp\nl5Gxfjd.exe
O4 - HKLM\..\Run: [jVHX] C:\documents and settings\jes\local settings\temp\jVHX.exe
O4 - HKLM\..\Run: [z32x] C:\documents and settings\jes\local settings\temp\z32x.exe
O4 - HKLM\..\Run: [bsHyreI] C:\documents and settings\jes\local settings\temp\bsHyreI.exe
O4 - HKLM\..\Run: [n7QU5y] C:\documents and settings\jes\local settings\temp\n7QU5y.exe
O4 - HKLM\..\Run: [Z9IS3yJan] C:\documents and settings\jes\local settings\temp\Z9IS3yJan.exe
O4 - HKLM\..\Run: [h0EzxadWB] C:\documents and settings\jes\local settings\temp\h0EzxadWB.exe
O4 - HKLM\..\Run: [Tp] C:\documents and settings\jes\local settings\temp\Tp.exe
O4 - HKLM\..\Run: [bg] C:\documents and settings\jes\local settings\temp\bg.exe
O4 - HKLM\..\Run: [8cFBmjqJI] C:\documents and settings\jes\local settings\temp\8cFBmjqJI.exe
O4 - HKLM\..\Run: [Je] C:\documents and settings\jes\local settings\temp\Je.exe
O4 - HKLM\..\Run: [lDczV] C:\documents and settings\jes\local settings\temp\lDczV.exe
O4 - HKLM\..\Run: [D7kcM] C:\documents and settings\jes\local settings\temp\D7kcM.exe
O4 - HKLM\..\Run: [VYgTg] C:\documents and settings\jes\local settings\temp\VYgTg.exe
O4 - HKLM\..\Run: [xnWUSf459] C:\documents and settings\jes\local settings\temp\xnWUSf459.exe
O4 - HKLM\..\Run: [Nvhu5r1S] C:\documents and settings\jes\local settings\temp\Nvhu5r1S.exe
O4 - HKLM\..\Run: [3CC5hCYF] C:\documents and settings\jes\local settings\temp\3CC5hCYF.exe
O4 - HKLM\..\Run: [Zcdl] C:\documents and settings\jes\local settings\temp\Zcdl.exe
O4 - HKLM\..\Run: [fkyW] C:\documents and settings\jes\local settings\temp\fkyW.exe
O4 - HKLM\..\Run: [c] C:\documents and settings\jes\local settings\temp\c.exe
O4 - HKLM\..\Run: [YB] C:\documents and settings\jes\local settings\temp\YB.exe
O4 - HKLM\..\Run: [eJ] C:\documents and settings\jes\local settings\temp\eJ.exe
O4 - HKLM\..\Run: [vd] C:\documents and settings\jes\local settings\temp\vd.exe
O4 - HKLM\..\Run: [8CkLW] C:\documents and settings\jes\local settings\temp\8CkLW.exe
O4 - HKLM\..\Run: [qtgsq] C:\documents and settings\jes\local settings\temp\qtgsq.exe
O4 - HKLM\..\Run: [Ikc9U] C:\documents and settings\jes\local settings\temp\Ikc9U.exe
O4 - HKLM\..\Run: [0b8Qp] C:\documents and settings\jes\local settings\temp\0b8Qp.exe
O4 - HKLM\..\Run: [Xu] C:\documents and settings\jes\local settings\temp\Xu.exe
O4 - HKLM\..\Run: [UrJyuiYh6] C:\documents and settings\jes\local settings\temp\UrJyuiYh6.exe
O4 - HKLM\..\Run: [bVSclccyL] C:\documents and settings\jes\local settings\temp\bVSclccyL.exe
O4 - HKLM\..\Run: [NX] C:\documents and settings\jes\local settings\temp\NX.exe
O4 - HKLM\..\Run: [4rSN] C:\documents and settings\jes\local settings\temp\4rSN.exe
O4 - HKLM\..\Run: [DK9DQF] C:\documents and settings\jes\local settings\temp\DK9DQF.exe
O4 - HKLM\..\Run: [UfihGz] C:\documents and settings\jes\local settings\temp\UfihGz.exe
O4 - HKLM\..\Run: [wDXhihMWW] C:\documents and settings\jes\local settings\temp\wDXhihMWW.exe
O4 - HKLM\..\Run: [sdzynn] C:\documents and settings\jes\local settings\temp\sdzynn.exe
O4 - HKLM\..\Run: [HY65X] C:\documents and settings\jes\local settings\temp\HY65X.exe
O4 - HKLM\..\Run: [iEbZh7nO] C:\documents and settings\jes\local settings\temp\iEbZh7nO.exe
O4 - HKLM\..\Run: [deMfm] C:\documents and settings\jes\local settings\temp\deMfm.exe
O4 - HKLM\..\Run: [9] C:\documents and settings\jes\local settings\temp\9.exe
O4 - HKLM\..\Run: [Ktsq] C:\documents and settings\jes\local settings\temp\Ktsq.exe
O4 - HKLM\..\Run: [lvknKAs] C:\documents and settings\jes\local settings\temp\lvknKAs.exe
O4 - HKLM\..\Run: [bU] C:\documents and settings\jes\local settings\temp\bU.exe
O4 - HKLM\..\Run: [MW1gX] C:\documents and settings\jes\local settings\temp\MW1gX.exe
O4 - HKLM\..\Run: [oYTdVnam] C:\documents and settings\jes\local settings\temp\oYTdVnam.exe
O4 - HKLM\..\Run: [jyvu0] C:\documents and settings\jes\local settings\temp\jyvu0.exe
O4 - HKLM\..\Run: [g] C:\documents and settings\jes\local settings\temp\g.exe
O4 - HKLM\..\Run: [STzPl] C:\documents and settings\jes\local settings\temp\STzPl.exe
O4 - HKLM\..\Run: [uVrMjZ3s] C:\documents and settings\jes\local settings\temp\uVrMjZ3s.exe
O4 - HKLM\..\Run: [LqAq9ThJ] C:\documents and settings\jes\local settings\temp\LqAq9ThJ.exe
O4 - HKLM\..\Run: [HZbH] C:\documents and settings\jes\local settings\temp\HZbH.exe
O4 - HKLM\..\Run: [ZQ7o] C:\documents and settings\jes\local settings\temp\ZQ7o.exe
O4 - HKLM\..\Run: [BfMpljd] C:\documents and settings\jes\local settings\temp\BfMpljd.exe
O4 - HKLM\..\Run: [Rn8Zxva] C:\documents and settings\jes\local settings\temp\Rn8Zxva.exe
O4 - HKLM\..\Run: [nA0FjVXa8] C:\documents and settings\jes\local settings\temp\nA0FjVXa8.exe
O4 - HKLM\..\Run: [DImfw6UXe] C:\documents and settings\jes\local settings\temp\DImfw6UXe.exe
O4 - HKLM\..\Run: [AEKzf] C:\documents and settings\jes\local settings\temp\AEKzf.exe
O4 - HKLM\..\Run: [d3qAQCDZ7] C:\documents and settings\jes\local settings\temp\d3qAQCDZ7.exe
O4 - HKLM\..\Run: [Ps] C:\documents and settings\jes\local settings\temp\Ps.exe
O4 - HKLM\..\Run: [6W] C:\documents and settings\jes\local settings\temp\6W.exe
O4 - HKLM\..\Run: [oN] C:\documents and settings\jes\local settings\temp\oN.exe
O4 - HKLM\..\Run: [0cPWo] C:\documents and settings\jes\local settings\temp\0cPWo.exe
O4 - HKLM\..\Run: [DAuX0hyP] C:\documents and settings\jes\local settings\temp\DAuX0hyP.exe
O4 - HKLM\..\Run: [U5DARbL6] C:\documents and settings\jes\local settings\temp\U5DARbL6.exe
O4 - HKLM\..\Run: [PirOi] C:\documents and settings\jes\local settings\temp\PirOi.exe
O4 - HKLM\..\Run: [oBIEZ79] C:\documents and settings\jes\local settings\temp\oBIEZ79.exe
O4 - HKLM\..\Run: [DmgbyBP] C:\documents and settings\jes\local settings\temp\DmgbyBP.exe
O4 - HKLM\..\Run: [DEQ] C:\documents and settings\jes\local settings\temp\DEQ.exe
O4 - HKLM\..\Run: [nRTtURk] C:\documents and settings\jes\local settings\temp\nRTtURk.exe
O4 - HKLM\..\Run: [DZe372h] C:\documents and settings\jes\local settings\temp\DZe372h.exe
O4 - HKLM\..\Run: [s33rn5zh0] C:\documents and settings\jes\local settings\temp\s33rn5zh0.exe
O4 - HKLM\..\Run: [2I] C:\documents and settings\jes\local settings\temp\2I.exe
O4 - HKLM\..\Run: [tKe] C:\documents and settings\jes\local settings\temp\tKe.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [BLMessagingIntegration] C:\Program Files\Common Files\PSD Tools\blengine.exe
O4 - HKCU\..\Run: [iprtrmgr] C:\WINNT\System32\iprtrmgr.exe
O4 - HKCU\..\Run: [Clro] C:\Documents and Settings\Jes\Application Data\owar.exe
O4 - HKCU\..\Run: [Ksxxvrdz] C:\WINNT\System32\??rss.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php…c80e4ac3a715ede
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - file://D:\Installers\AuthorwareWebPlayer\awswax.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/308dedc13bf8d649b620/netzip/RdxIE2.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://198.82.159.134/activex/AxisCamControl.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildApp.cab

Please help!


:scratch:
Greetings and welcome to TomCoyote.org!

Please download and run Spybot-Search&Destroy and Ad-Aware; they are the standard programs for finding and cleaning malware off your system. Here are links to both programs, and instructions for their use.

Get Spybot - Search & Destroy from http://security.kolla.de
(This is the NEW Version 1.3)
Get AdAware SE Personal from http://www.lavasoft.de/support/download
(This is the NEW Build 1.05)

Download and install these programs if you don't already have them. If you do have them, make sure they are UPDATED AND CONFIGURED AS DESCRIBED here:

http://www.cjwd.demon.co.uk/spybot-adaware.html

Reboot after running each program.

Please try these free online virus scans of your system:

Trend-Micro Housecall

Panda Activescan

Etrust Security Advisor

Choose "fix" or "clean".

Let them remove any infections found. Reboot after each scan.

Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
MOVE HijackThis into this folder, andd OFF the desktop.

If required a tutorial is here = Hijackthis Folder Tutorial

Make a new log file, and "copy/paste" it into this thread. :)
Thanks for helping me so far! I did everything you said, updated and ran Adaware & Spybot S&D again… came up with a lot more files to delete. :) Ran 2 of the virus scans (the panda one did not work… error when trying to load window that said something like internal error and window will be shut down). It found one file that it could not delete called 'axp63.exe'. I am also still having Active X errors still.

Here is my new HiJackthis log…Logfile of HijackThis v1.98.2
Scan saved at 12:41:33 PM, on 11/08/2004
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINNT\System32\PRPCUI.exe
C:\documents and settings\jes\local settings\temp\Pc.exe
C:\documents and settings\jes\local settings\temp\Kr.exe
C:\documents and settings\jes\local settings\temp\XOOI.exe
C:\documents and settings\jes\local settings\temp\E.exe
C:\documents and settings\jes\local settings\temp\z6tYAXhp.exe
C:\documents and settings\jes\local settings\temp\xX.exe
C:\documents and settings\jes\local settings\temp\Z9IS3yJan.exe
C:\documents and settings\jes\local settings\temp\0b8Qp.exe
C:\documents and settings\jes\local settings\temp\Xu.exe
C:\documents and settings\jes\local settings\temp\UrJyuiYh6.exe
C:\documents and settings\jes\local settings\temp\bVSclccyL.exe
C:\documents and settings\jes\local settings\temp\ZQ7o.exe
C:\documents and settings\jes\local settings\temp\nA0FjVXa8.exe
C:\Documents and Settings\Jes\Application Data\owar.exe
C:\WINNT\System32\Axp63.exe
C:\WINNT\System32\Axp63.exe
C:\Program Files\Navnt\navapw32.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\System32\iprtrmgr.exe
C:\WINNT\system32\??rss.exe
C:\HJT\hijackthisupdate.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vt.edu/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6EAA6550-9241-72CE-8259-10550EF62816} - C:\WINNT\System32\ogwy.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jes\Local Settings\Temp\uioH6.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [vgBcr6Qq] C:\documents and settings\jes\local settings\temp\vgBcr6Qq.exe
O4 - HKLM\..\Run: [w1ZOn] C:\documents and settings\jes\local settings\temp\w1ZOn.exe
O4 - HKLM\..\Run: [EmTR] C:\documents and settings\jes\local settings\temp\EmTR.exe
O4 - HKLM\..\Run: [gl] C:\documents and settings\jes\local settings\temp\gl.exe
O4 - HKLM\..\Run: [Pc] C:\documents and settings\jes\local settings\temp\Pc.exe
O4 - HKLM\..\Run: [qeZDdG] C:\documents and settings\jes\local settings\temp\qeZDdG.exe
O4 - HKLM\..\Run: [j] C:\documents and settings\jes\local settings\temp\j.exe
O4 - HKLM\..\Run: [SH9x] C:\documents and settings\jes\local settings\temp\SH9x.exe
O4 - HKLM\..\Run: [7] C:\documents and settings\jes\local settings\temp\7.exe
O4 - HKLM\..\Run: [Ko6O] C:\documents and settings\jes\local settings\temp\Ko6O.exe
O4 - HKLM\..\Run: [YNQ] C:\documents and settings\jes\local settings\temp\YNQ.exe
O4 - HKLM\..\Run: [2SAH4QD2SDAWX7] C:\WINNT\System32\NgiOUeB0.exe
O4 - HKLM\..\Run: [tDWU6] C:\documents and settings\jes\local settings\temp\tDWU6.exe
O4 - HKLM\..\Run: [1ocH] C:\documents and settings\jes\local settings\temp\1ocH.exe
O4 - HKLM\..\Run: [DNRInZZ] C:\documents and settings\jes\local settings\temp\DNRInZZ.exe
O4 - HKLM\..\Run: [f] C:\documents and settings\jes\local settings\temp\f.exe
O4 - HKLM\..\Run: [dvJ6mdYt] C:\documents and settings\jes\local settings\temp\dvJ6mdYt.exe
O4 - HKLM\..\Run: [bOVu] C:\documents and settings\jes\local settings\temp\bOVu.exe
O4 - HKLM\..\Run: [tFRb] C:\documents and settings\jes\local settings\temp\tFRb.exe
O4 - HKLM\..\Run: [q] C:\documents and settings\jes\local settings\temp\q.exe
O4 - HKLM\..\Run: C:\documents and settings\jes\local settings\temp\I.exe
O4 - HKLM\..\Run: [Afdh] C:\documents and settings\jes\local settings\temp\Afdh.exe
O4 - HKLM\..\Run: [RJmV] C:\documents and settings\jes\local settings\temp\RJmV.exe
O4 - HKLM\..\Run: [O] C:\documents and settings\jes\local settings\temp\O.exe
O4 - HKLM\..\Run: [MlKGz3bw] C:\documents and settings\jes\local settings\temp\MlKGz3bw.exe
O4 - HKLM\..\Run: [4cGn3FFi] C:\documents and settings\jes\local settings\temp\4cGn3FFi.exe
O4 - HKLM\..\Run: [m3C4xha3] C:\documents and settings\jes\local settings\temp\m3C4xha3.exe
O4 - HKLM\..\Run: [j01o] C:\documents and settings\jes\local settings\temp\j01o.exe
O4 - HKLM\..\Run: [h] C:\documents and settings\jes\local settings\temp\h.exe
O4 - HKLM\..\Run: [dfC6mqmR] C:\documents and settings\jes\local settings\temp\dfC6mqmR.exe
O4 - HKLM\..\Run: [ac1q] C:\documents and settings\jes\local settings\temp\ac1q.exe
O4 - HKLM\..\Run: [NXuvlEln] C:\documents and settings\jes\local settings\temp\NXuvlEln.exe
O4 - HKLM\..\Run: [5OqcPhP9] C:\documents and settings\jes\local settings\temp\5OqcPhP9.exe
O4 - HKLM\..\Run: [37Czc] C:\documents and settings\jes\local settings\temp\37Czc.exe
O4 - HKLM\..\Run: [lYyhG] C:\documents and settings\jes\local settings\temp\lYyhG.exe
O4 - HKLM\..\Run: [DPuYa] C:\documents and settings\jes\local settings\temp\DPuYa.exe
O4 - HKLM\..\Run: [B8] C:\documents and settings\jes\local settings\temp\B8.exe
O4 - HKLM\..\Run: [95fRc] C:\documents and settings\jes\local settings\temp\95fRc.exe
O4 - HKLM\..\Run: [6] C:\documents and settings\jes\local settings\temp\6.exe
O4 - HKLM\..\Run: [JN6fa] C:\documents and settings\jes\local settings\temp\JN6fa.exe
O4 - HKLM\..\Run: [1E2WF] C:\documents and settings\jes\local settings\temp\1E2WF.exe
O4 - HKLM\..\Run: [ZX] C:\documents and settings\jes\local settings\temp\ZX.exe
O4 - HKLM\..\Run: [WgrIoPDB] C:\documents and settings\jes\local settings\temp\WgrIoPDB.exe
O4 - HKLM\..\Run: [e7npSs7m] C:\documents and settings\jes\local settings\temp\e7npSs7m.exe
O4 - HKLM\..\Run: [cqzMf] C:\documents and settings\jes\local settings\temp\cqzMf.exe
O4 - HKLM\..\Run: [uhvuJ] C:\documents and settings\jes\local settings\temp\uhvuJ.exe
O4 - HKLM\..\Run: [sA] C:\documents and settings\jes\local settings\temp\sA.exe
O4 - HKLM\..\Run: [Kr] C:\documents and settings\jes\local settings\temp\Kr.exe
O4 - HKLM\..\Run: [mQjzc] C:\documents and settings\jes\local settings\temp\mQjzc.exe
O4 - HKLM\..\Run: [Dkrd3] C:\documents and settings\jes\local settings\temp\Dkrd3.exe
O4 - HKLM\..\Run: [VbnUx] C:\documents and settings\jes\local settings\temp\VbnUx.exe
O4 - HKLM\..\Run: [d2jB1] C:\documents and settings\jes\local settings\temp\d2jB1.exe
O4 - HKLM\..\Run: [P4byZz0f] C:\documents and settings\jes\local settings\temp\P4byZz0f.exe
O4 - HKLM\..\Run: [JiZMr] C:\documents and settings\jes\local settings\temp\JiZMr.exe
O4 - HKLM\..\Run: [19VtV] C:\documents and settings\jes\local settings\temp\19VtV.exe
O4 - HKLM\..\Run: [k0Rap] C:\documents and settings\jes\local settings\temp\k0Rap.exe
O4 - HKLM\..\Run: [CQNRT] C:\documents and settings\jes\local settings\temp\CQNRT.exe
O4 - HKLM\..\Run: [UHJyo] C:\documents and settings\jes\local settings\temp\UHJyo.exe
O4 - HKLM\..\Run: [P] C:\documents and settings\jes\local settings\temp\P.exe
O4 - HKLM\..\Run: [sGZQ5] C:\documents and settings\jes\local settings\temp\sGZQ5.exe
O4 - HKLM\..\Run: [Ja8t] C:\documents and settings\jes\local settings\temp\Ja8t.exe
O4 - HKLM\..\Run: [0Fg7] C:\documents and settings\jes\local settings\temp\0Fg7.exe
O4 - HKLM\..\Run: [Y] C:\documents and settings\jes\local settings\temp\Y.exe
O4 - HKLM\..\Run: [UUSPSmwe] C:\documents and settings\jes\local settings\temp\UUSPSmwe.exe
O4 - HKLM\..\Run: [w] C:\documents and settings\jes\local settings\temp\w.exe
O4 - HKLM\..\Run: [8lpN] C:\documents and settings\jes\local settings\temp\8lpN.exe
O4 - HKLM\..\Run: [5] C:\documents and settings\jes\local settings\temp\5.exe
O4 - HKLM\..\Run: [FXT1] C:\documents and settings\jes\local settings\temp\FXT1.exe
O4 - HKLM\..\Run: [XOOI] C:\documents and settings\jes\local settings\temp\XOOI.exe
O4 - HKLM\..\Run: [no] C:\documents and settings\jes\local settings\temp\no.exe
O4 - HKLM\..\Run: [E] C:\documents and settings\jes\local settings\temp\E.exe
O4 - HKLM\..\Run: [z6tYAXhp] C:\documents and settings\jes\local settings\temp\z6tYAXhp.exe
O4 - HKLM\..\Run: [QACCqRv] C:\documents and settings\jes\local settings\temp\QACCqRv.exe
O4 - HKLM\..\Run: C:\documents and settings\jes\local settings\temp\s.exe
O4 - HKLM\..\Run: [3Emw] C:\documents and settings\jes\local settings\temp\3Emw.exe
O4 - HKLM\..\Run: [eX] C:\documents and settings\jes\local settings\temp\eX.exe
O4 - HKLM\..\Run: [axj6syqR1] C:\documents and settings\jes\local settings\temp\axj6syqR1.exe
O4 - HKLM\..\Run: [7uIqb] C:\documents and settings\jes\local settings\temp\7uIqb.exe
O4 - HKLM\..\Run: [3q] C:\documents and settings\jes\local settings\temp\3q.exe
O4 - HKLM\..\Run: [FsZIS] C:\documents and settings\jes\local settings\temp\FsZIS.exe
O4 - HKLM\..\Run: [WX8lI] C:\documents and settings\jes\local settings\temp\WX8lI.exe
O4 - HKLM\..\Run: [T] C:\documents and settings\jes\local settings\temp\T.exe
O4 - HKLM\..\Run: [MMkkU] C:\documents and settings\jes\local settings\temp\MMkkU.exe
O4 - HKLM\..\Run: [nOchSuty] C:\documents and settings\jes\local settings\temp\nOchSuty.exe
O4 - HKLM\..\Run: [Z] C:\documents and settings\jes\local settings\temp\Z.exe
O4 - HKLM\..\Run: [BfKf] C:\documents and settings\jes\local settings\temp\BfKf.exe
O4 - HKLM\..\Run: [SJST] C:\documents and settings\jes\local settings\temp\SJST.exe
O4 - HKLM\..\Run: [9e1w] C:\documents and settings\jes\local settings\temp\9e1w.exe
O4 - HKLM\..\Run: [MCGxKIR] C:\documents and settings\jes\local settings\temp\MCGxKIR.exe
O4 - HKLM\..\Run: [ZEDX2K] C:\documents and settings\jes\local settings\temp\ZEDX2K.exe
O4 - HKLM\..\Run: [Sv] C:\documents and settings\jes\local settings\temp\Sv.exe
O4 - HKLM\..\Run: [9Z] C:\documents and settings\jes\local settings\temp\9Z.exe
O4 - HKLM\..\Run: [q7] C:\documents and settings\jes\local settings\temp\q7.exe
O4 - HKLM\..\Run: [m4wFCj0S] C:\documents and settings\jes\local settings\temp\m4wFCj0S.exe
O4 - HKLM\..\Run: [Zs] C:\documents and settings\jes\local settings\temp\Zs.exe
O4 - HKLM\..\Run: [Av3Db] C:\documents and settings\jes\local settings\temp\Av3Db.exe
O4 - HKLM\..\Run: [cTJENJWb] C:\documents and settings\jes\local settings\temp\cTJENJWb.exe
O4 - HKLM\..\Run: [uKFlhlrX] C:\documents and settings\jes\local settings\temp\uKFlhlrX.exe
O4 - HKLM\..\Run: [MeNY8fFe] C:\documents and settings\jes\local settings\temp\MeNY8fFe.exe
O4 - HKLM\..\Run: [nhF] C:\documents and settings\jes\local settings\temp\nhF.exe
O4 - HKLM\..\Run: [eqSthq] C:\documents and settings\jes\local settings\temp\eqSthq.exe
O4 - HKLM\..\Run: [QtKqfq1lV] C:\documents and settings\jes\local settings\temp\QtKqfq1lV.exe
O4 - HKLM\..\Run: [sR] C:\documents and settings\jes\local settings\temp\sR.exe
O4 - HKLM\..\Run: [4g5ssQ] C:\documents and settings\jes\local settings\temp\4g5ssQ.exe
O4 - HKLM\..\Run: [HFKs3zd92] C:\documents and settings\jes\local settings\temp\HFKs3zd92.exe
O4 - HKLM\..\Run: [iH] C:\documents and settings\jes\local settings\temp\iH.exe
O4 - HKLM\..\Run: [V6iqD] C:\documents and settings\jes\local settings\temp\V6iqD.exe
O4 - HKLM\..\Run: [R2] C:\documents and settings\jes\local settings\temp\R2.exe
O4 - HKLM\..\Run: [urmLY] C:\documents and settings\jes\local settings\temp\urmLY.exe
O4 - HKLM\..\Run: [LVvpO] C:\documents and settings\jes\local settings\temp\LVvpO.exe
O4 - HKLM\..\Run: [nkaqqp5M] C:\documents and settings\jes\local settings\temp\nkaqqp5M.exe
O4 - HKLM\..\Run: [jULGv] C:\documents and settings\jes\local settings\temp\jULGv.exe
O4 - HKLM\..\Run: [z26h] C:\documents and settings\jes\local settings\temp\z26h.exe
O4 - HKLM\..\Run: [QwfU] C:\documents and settings\jes\local settings\temp\QwfU.exe
O4 - HKLM\..\Run: [6EAu] C:\documents and settings\jes\local settings\temp\6EAu.exe
O4 - HKLM\..\Run: [HGssJLo] C:\documents and settings\jes\local settings\temp\HGssJLo.exe
O4 - HKLM\..\Run: [TYOLKn] C:\documents and settings\jes\local settings\temp\TYOLKn.exe
O4 - HKLM\..\Run: [vntLl5pi5] C:\documents and settings\jes\local settings\temp\vntLl5pi5.exe
O4 - HKLM\..\Run: [7M] C:\documents and settings\jes\local settings\temp\7M.exe
O4 - HKLM\..\Run: [KbONzw] C:\documents and settings\jes\local settings\temp\KbONzw.exe
O4 - HKLM\..\Run: [mzuNaeC6c] C:\documents and settings\jes\local settings\temp\mzuNaeC6c.exe
O4 - HKLM\..\Run: [jwT8T2] C:\documents and settings\jes\local settings\temp\jwT8T2.exe
O4 - HKLM\..\Run: [UyL5R24Ew] C:\documents and settings\jes\local settings\temp\UyL5R24Ew.exe
O4 - HKLM\..\Run: [xX] C:\documents and settings\jes\local settings\temp\xX.exe
O4 - HKLM\..\Run: [PO] C:\documents and settings\jes\local settings\temp\PO.exe
O4 - HKLM\..\Run: [rc1Nz] C:\documents and settings\jes\local settings\temp\rc1Nz.exe
O4 - HKLM\..\Run: [pv] C:\documents and settings\jes\local settings\temp\pv.exe
O4 - HKLM\..\Run: [lsCvFpfY5] C:\documents and settings\jes\local settings\temp\lsCvFpfY5.exe
O4 - HKLM\..\Run: [h2eMK] C:\documents and settings\jes\local settings\temp\h2eMK.exe
O4 - HKLM\..\Run: [UrTNmcHw] C:\documents and settings\jes\local settings\temp\UrTNmcHw.exe
O4 - HKLM\..\Run: [bV2qc6VN] C:\documents and settings\jes\local settings\temp\bV2qc6VN.exe
O4 - HKLM\..\Run: [M] C:\documents and settings\jes\local settings\temp\M.exe
O4 - HKLM\..\Run: [JUjITUml] C:\documents and settings\jes\local settings\temp\JUjITUml.exe
O4 - HKLM\..\Run: [Z1Ei66j8] C:\documents and settings\jes\local settings\temp\Z1Ei66j8.exe
O4 - HKLM\..\Run: [VY3C] C:\documents and settings\jes\local settings\temp\VY3C.exe
O4 - HKLM\..\Run: [dsbg] C:\documents and settings\jes\local settings\temp\dsbg.exe
O4 - HKLM\..\Run: [N8ga05I] C:\documents and settings\jes\local settings\temp\N8ga05I.exe
O4 - HKLM\..\Run: [FfG] C:\documents and settings\jes\local settings\temp\FfG.exe
O4 - HKLM\..\Run: [APhtCpJ5f] C:\documents and settings\jes\local settings\temp\APhtCpJ5f.exe
O4 - HKLM\..\Run: [Rjq7sjXmU] C:\documents and settings\jes\local settings\temp\Rjq7sjXmU.exe
O4 - HKLM\..\Run: [aamOXVr78] C:\documents and settings\jes\local settings\temp\aamOXVr78.exe
O4 - HKLM\..\Run: [7uycjs] C:\documents and settings\jes\local settings\temp\7uycjs.exe
O4 - HKLM\..\Run: [4q] C:\documents and settings\jes\local settings\temp\4q.exe
O4 - HKLM\..\Run: [mh] C:\documents and settings\jes\local settings\temp\mh.exe
O4 - HKLM\..\Run: [E8] C:\documents and settings\jes\local settings\temp\E8.exe
O4 - HKLM\..\Run: [Cr1io1TWg] C:\documents and settings\jes\local settings\temp\Cr1io1TWg.exe
O4 - HKLM\..\Run: [yoqC7P] C:\documents and settings\jes\local settings\temp\yoqC7P.exe
O4 - HKLM\..\Run: [bM5DJxCYa] C:\documents and settings\jes\local settings\temp\bM5DJxCYa.exe
O4 - HKLM\..\Run: [Lsaw] C:\documents and settings\jes\local settings\temp\Lsaw.exe
O4 - HKLM\..\Run: [3j6e] C:\documents and settings\jes\local settings\temp\3j6e.exe
O4 - HKLM\..\Run: [eBs] C:\documents and settings\jes\local settings\temp\eBs.exe
O4 - HKLM\..\Run: [byRRgQT9r] C:\documents and settings\jes\local settings\temp\byRRgQT9r.exe
O4 - HKLM\..\Run: [NXw] C:\documents and settings\jes\local settings\temp\NXw.exe
O4 - HKLM\..\Run: [Jx78XElHL] C:\documents and settings\jes\local settings\temp\Jx78XElHL.exe
O4 - HKLM\..\Run: [1o3PshPsZ] C:\documents and settings\jes\local settings\temp\1o3PshPsZ.exe
O4 - HKLM\..\Run: [EM] C:\documents and settings\jes\local settings\temp\EM.exe
O4 - HKLM\..\Run: [Vh] C:\documents and settings\jes\local settings\temp\Vh.exe
O4 - HKLM\..\Run: [RdgODHLMx] C:\documents and settings\jes\local settings\temp\RdgODHLMx.exe
O4 - HKLM\..\Run: [94cv7jgxL] C:\documents and settings\jes\local settings\temp\94cv7jgxL.exe
O4 - HKLM\..\Run: [Mt] C:\documents and settings\jes\local settings\temp\Mt.exe
O4 - HKLM\..\Run: [4k] C:\documents and settings\jes\local settings\temp\4k.exe
O4 - HKLM\..\Run: [mb] C:\documents and settings\jes\local settings\temp\mb.exe
O4 - HKLM\..\Run: [XdBRF] C:\documents and settings\jes\local settings\temp\XdBRF.exe
O4 - HKLM\..\Run: [zftPDfUT] C:\documents and settings\jes\local settings\temp\zftPDfUT.exe
O4 - HKLM\..\Run: [uP55I] C:\documents and settings\jes\local settings\temp\uP55I.exe
O4 - HKLM\..\Run: [LjdJz] C:\documents and settings\jes\local settings\temp\LjdJz.exe
O4 - HKLM\..\Run: [nl5Gxfjd] C:\documents and settings\jes\local settings\temp\nl5Gxfjd.exe
O4 - HKLM\..\Run: [jVHX] C:\documents and settings\jes\local settings\temp\jVHX.exe
O4 - HKLM\..\Run: [z32x] C:\documents and settings\jes\local settings\temp\z32x.exe
O4 - HKLM\..\Run: [bsHyreI] C:\documents and settings\jes\local settings\temp\bsHyreI.exe
O4 - HKLM\..\Run: [n7QU5y] C:\documents and settings\jes\local settings\temp\n7QU5y.exe
O4 - HKLM\..\Run: [Z9IS3yJan] C:\documents and settings\jes\local settings\temp\Z9IS3yJan.exe
O4 - HKLM\..\Run: [h0EzxadWB] C:\documents and settings\jes\local settings\temp\h0EzxadWB.exe
O4 - HKLM\..\Run: [Tp] C:\documents and settings\jes\local settings\temp\Tp.exe
O4 - HKLM\..\Run: [bg] C:\documents and settings\jes\local settings\temp\bg.exe
O4 - HKLM\..\Run: [8cFBmjqJI] C:\documents and settings\jes\local settings\temp\8cFBmjqJI.exe
O4 - HKLM\..\Run: [Je] C:\documents and settings\jes\local settings\temp\Je.exe
O4 - HKLM\..\Run: [lDczV] C:\documents and settings\jes\local settings\temp\lDczV.exe
O4 - HKLM\..\Run: [D7kcM] C:\documents and settings\jes\local settings\temp\D7kcM.exe
O4 - HKLM\..\Run: [VYgTg] C:\documents and settings\jes\local settings\temp\VYgTg.exe
O4 - HKLM\..\Run: [xnWUSf459] C:\documents and settings\jes\local settings\temp\xnWUSf459.exe
O4 - HKLM\..\Run: [Nvhu5r1S] C:\documents and settings\jes\local settings\temp\Nvhu5r1S.exe
O4 - HKLM\..\Run: [3CC5hCYF] C:\documents and settings\jes\local settings\temp\3CC5hCYF.exe
O4 - HKLM\..\Run: [Zcdl] C:\documents and settings\jes\local settings\temp\Zcdl.exe
O4 - HKLM\..\Run: [fkyW] C:\documents and settings\jes\local settings\temp\fkyW.exe
O4 - HKLM\..\Run: [c] C:\documents and settings\jes\local settings\temp\c.exe
O4 - HKLM\..\Run: [YB] C:\documents and settings\jes\local settings\temp\YB.exe
O4 - HKLM\..\Run: [eJ] C:\documents and settings\jes\local settings\temp\eJ.exe
O4 - HKLM\..\Run: [vd] C:\documents and settings\jes\local settings\temp\vd.exe
O4 - HKLM\..\Run: [8CkLW] C:\documents and settings\jes\local settings\temp\8CkLW.exe
O4 - HKLM\..\Run: [qtgsq] C:\documents and settings\jes\local settings\temp\qtgsq.exe
O4 - HKLM\..\Run: [Ikc9U] C:\documents and settings\jes\local settings\temp\Ikc9U.exe
O4 - HKLM\..\Run: [0b8Qp] C:\documents and settings\jes\local settings\temp\0b8Qp.exe
O4 - HKLM\..\Run: [Xu] C:\documents and settings\jes\local settings\temp\Xu.exe
O4 - HKLM\..\Run: [UrJyuiYh6] C:\documents and settings\jes\local settings\temp\UrJyuiYh6.exe
O4 - HKLM\..\Run: [bVSclccyL] C:\documents and settings\jes\local settings\temp\bVSclccyL.exe
O4 - HKLM\..\Run: [NX] C:\documents and settings\jes\local settings\temp\NX.exe
O4 - HKLM\..\Run: [4rSN] C:\documents and settings\jes\local settings\temp\4rSN.exe
O4 - HKLM\..\Run: [DK9DQF] C:\documents and settings\jes\local settings\temp\DK9DQF.exe
O4 - HKLM\..\Run: [UfihGz] C:\documents and settings\jes\local settings\temp\UfihGz.exe
O4 - HKLM\..\Run: [wDXhihMWW] C:\documents and settings\jes\local settings\temp\wDXhihMWW.exe
O4 - HKLM\..\Run: [sdzynn] C:\documents and settings\jes\local settings\temp\sdzynn.exe
O4 - HKLM\..\Run: [HY65X] C:\documents and settings\jes\local settings\temp\HY65X.exe
O4 - HKLM\..\Run: [iEbZh7nO] C:\documents and settings\jes\local settings\temp\iEbZh7nO.exe
O4 - HKLM\..\Run: [deMfm] C:\documents and settings\jes\local settings\temp\deMfm.exe
O4 - HKLM\..\Run: [9] C:\documents and settings\jes\local settings\temp\9.exe
O4 - HKLM\..\Run: [Ktsq] C:\documents and settings\jes\local settings\temp\Ktsq.exe
O4 - HKLM\..\Run: [lvknKAs] C:\documents and settings\jes\local settings\temp\lvknKAs.exe
O4 - HKLM\..\Run: [bU] C:\documents and settings\jes\local settings\temp\bU.exe
O4 - HKLM\..\Run: [MW1gX] C:\documents and settings\jes\local settings\temp\MW1gX.exe
O4 - HKLM\..\Run: [oYTdVnam] C:\documents and settings\jes\local settings\temp\oYTdVnam.exe
O4 - HKLM\..\Run: [jyvu0] C:\documents and settings\jes\local settings\temp\jyvu0.exe
O4 - HKLM\..\Run: [g] C:\documents and settings\jes\local settings\temp\g.exe
O4 - HKLM\..\Run: [STzPl] C:\documents and settings\jes\local settings\temp\STzPl.exe
O4 - HKLM\..\Run: [uVrMjZ3s] C:\documents and settings\jes\local settings\temp\uVrMjZ3s.exe
O4 - HKLM\..\Run: [LqAq9ThJ] C:\documents and settings\jes\local settings\temp\LqAq9ThJ.exe
O4 - HKLM\..\Run: [HZbH] C:\documents and settings\jes\local settings\temp\HZbH.exe
O4 - HKLM\..\Run: [ZQ7o] C:\documents and settings\jes\local settings\temp\ZQ7o.exe
O4 - HKLM\..\Run: [BfMpljd] C:\documents and settings\jes\local settings\temp\BfMpljd.exe
O4 - HKLM\..\Run: [Rn8Zxva] C:\documents and settings\jes\local settings\temp\Rn8Zxva.exe
O4 - HKLM\..\Run: [nA0FjVXa8] C:\documents and settings\jes\local settings\temp\nA0FjVXa8.exe
O4 - HKLM\..\Run: [DImfw6UXe] C:\documents and settings\jes\local settings\temp\DImfw6UXe.exe
O4 - HKLM\..\Run: [AEKzf] C:\documents and settings\jes\local settings\temp\AEKzf.exe
O4 - HKLM\..\Run: [d3qAQCDZ7] C:\documents and settings\jes\local settings\temp\d3qAQCDZ7.exe
O4 - HKLM\..\Run: [Ps] C:\documents and settings\jes\local settings\temp\Ps.exe
O4 - HKLM\..\Run: [6W] C:\documents and settings\jes\local settings\temp\6W.exe
O4 - HKLM\..\Run: [oN] C:\documents and settings\jes\local settings\temp\oN.exe
O4 - HKLM\..\Run: [0cPWo] C:\documents and settings\jes\local settings\temp\0cPWo.exe
O4 - HKLM\..\Run: [DAuX0hyP] C:\documents and settings\jes\local settings\temp\DAuX0hyP.exe
O4 - HKLM\..\Run: [U5DARbL6] C:\documents and settings\jes\local settings\temp\U5DARbL6.exe
O4 - HKLM\..\Run: [PirOi] C:\documents and settings\jes\local settings\temp\PirOi.exe
O4 - HKLM\..\Run: [oBIEZ79] C:\documents and settings\jes\local settings\temp\oBIEZ79.exe
O4 - HKLM\..\Run: [DmgbyBP] C:\documents and settings\jes\local settings\temp\DmgbyBP.exe
O4 - HKLM\..\Run: [DEQ] C:\documents and settings\jes\local settings\temp\DEQ.exe
O4 - HKLM\..\Run: [nRTtURk] C:\documents and settings\jes\local settings\temp\nRTtURk.exe
O4 - HKLM\..\Run: [DZe372h] C:\documents and settings\jes\local settings\temp\DZe372h.exe
O4 - HKLM\..\Run: [s33rn5zh0] C:\documents and settings\jes\local settings\temp\s33rn5zh0.exe
O4 - HKLM\..\Run: [2I] C:\documents and settings\jes\local settings\temp\2I.exe
O4 - HKLM\..\Run: [tKe] C:\documents and settings\jes\local settings\temp\tKe.exe
O4 - HKLM\..\Run: [dk2MmqR] C:\documents and settings\jes\local settings\temp\dk2MmqR.exe
O4 - HKCU\..\Run: [BLMessagingIntegration] C:\Program Files\Common Files\PSD Tools\blengine.exe
O4 - HKCU\..\Run: [iprtrmgr] C:\WINNT\System32\iprtrmgr.exe
O4 - HKCU\..\Run: [Clro] C:\Documents and Settings\Jes\Application Data\owar.exe
O4 - HKCU\..\Run: [Ksxxvrdz] C:\WINNT\System32\??rss.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\maxspeed.exe
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\System32\maxspeed.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - file://D:\Installers\AuthorwareWebPlayer\awswax.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/308dedc13bf8d649b620/netzip/RdxIE2.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab

:wavey: Please help
Please download the Peper Uninstaller

You have to remain online to run it.

Run it, then reboot

Run it again, and reboot once more

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {6EAA6550-9241-72CE-8259-10550EF62816} - C:\WINNT\System32\ogwy.dll

O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)

O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jes\Local Settings\Temp\uioH6.dll

O4 - HKLM\..\Run: [vgBcr6Qq] C:\documents and settings\jes\local settings\temp\vgBcr6Qq.exe

O4 - HKLM\..\Run: [w1ZOn] C:\documents and settings\jes\local settings\temp\w1ZOn.exe

O4 - HKLM\..\Run: [EmTR] C:\documents and settings\jes\local settings\temp\EmTR.exe

O4 - HKLM\..\Run: [gl] C:\documents and settings\jes\local settings\temp\gl.exe

O4 - HKLM\..\Run: [Pc] C:\documents and settings\jes\local settings\temp\Pc.exe

O4 - HKLM\..\Run: [qeZDdG] C:\documents and settings\jes\local settings\temp\qeZDdG.exe

O4 - HKLM\..\Run: [j] C:\documents and settings\jes\local settings\temp\j.exe

O4 - HKLM\..\Run: [SH9x] C:\documents and settings\jes\local settings\temp\SH9x.exe

O4 - HKLM\..\Run: [7] C:\documents and settings\jes\local settings\temp\7.exe

O4 - HKLM\..\Run: [Ko6O] C:\documents and settings\jes\local settings\temp\Ko6O.exe

O4 - HKLM\..\Run: [YNQ] C:\documents and settings\jes\local settings\temp\YNQ.exe

O4 - HKLM\..\Run: [2SAH4QD2SDAWX7] C:\WINNT\System32\NgiOUeB0.exe

O4 - HKLM\..\Run: [tDWU6] C:\documents and settings\jes\local settings\temp\tDWU6.exe

O4 - HKLM\..\Run: [1ocH] C:\documents and settings\jes\local settings\temp\1ocH.exe

O4 - HKLM\..\Run: [DNRInZZ] C:\documents and settings\jes\local settings\temp\DNRInZZ.exe

O4 - HKLM\..\Run: [f] C:\documents and settings\jes\local settings\temp\f.exe

O4 - HKLM\..\Run: [dvJ6mdYt] C:\documents and settings\jes\local settings\temp\dvJ6mdYt.exe

O4 - HKLM\..\Run: [bOVu] C:\documents and settings\jes\local settings\temp\bOVu.exe

O4 - HKLM\..\Run: [tFRb] C:\documents and settings\jes\local settings\temp\tFRb.exe

O4 - HKLM\..\Run: [q] C:\documents and settings\jes\local settings\temp\q.exe

O4 - HKLM\..\Run: C:\documents and settings\jes\local settings\temp\I.exe

O4 - HKLM\..\Run: [Afdh] C:\documents and settings\jes\local settings\temp\Afdh.exe

O4 - HKLM\..\Run: [RJmV] C:\documents and settings\jes\local settings\temp\RJmV.exe

O4 - HKLM\..\Run: [O] C:\documents and settings\jes\local settings\temp\O.exe

O4 - HKLM\..\Run: [MlKGz3bw] C:\documents and settings\jes\local settings\temp\MlKGz3bw.exe

O4 - HKLM\..\Run: [4cGn3FFi] C:\documents and settings\jes\local settings\temp\4cGn3FFi.exe

O4 - HKLM\..\Run: [m3C4xha3] C:\documents and settings\jes\local settings\temp\m3C4xha3.exe

O4 - HKLM\..\Run: [j01o] C:\documents and settings\jes\local settings\temp\j01o.exe

O4 - HKLM\..\Run: [h] C:\documents and settings\jes\local settings\temp\h.exe

O4 - HKLM\..\Run: [dfC6mqmR] C:\documents and settings\jes\local settings\temp\dfC6mqmR.exe

O4 - HKLM\..\Run: [ac1q] C:\documents and settings\jes\local settings\temp\ac1q.exe

O4 - HKLM\..\Run: [NXuvlEln] C:\documents and settings\jes\local settings\temp\NXuvlEln.exe

O4 - HKLM\..\Run: [5OqcPhP9] C:\documents and settings\jes\local settings\temp\5OqcPhP9.exe

O4 - HKLM\..\Run: [37Czc] C:\documents and settings\jes\local settings\temp\37Czc.exe

O4 - HKLM\..\Run: [lYyhG] C:\documents and settings\jes\local settings\temp\lYyhG.exe

O4 - HKLM\..\Run: [DPuYa] C:\documents and settings\jes\local settings\temp\DPuYa.exe

O4 - HKLM\..\Run: [B8] C:\documents and settings\jes\local settings\temp\B8.exe

O4 - HKLM\..\Run: [95fRc] C:\documents and settings\jes\local settings\temp\95fRc.exe

O4 - HKLM\..\Run: [6] C:\documents and settings\jes\local settings\temp\6.exe

O4 - HKLM\..\Run: [JN6fa] C:\documents and settings\jes\local settings\temp\JN6fa.exe

O4 - HKLM\..\Run: [1E2WF] C:\documents and settings\jes\local settings\temp\1E2WF.exe

O4 - HKLM\..\Run: [ZX] C:\documents and settings\jes\local settings\temp\ZX.exe

O4 - HKLM\..\Run: [WgrIoPDB] C:\documents and settings\jes\local settings\temp\WgrIoPDB.exe

O4 - HKLM\..\Run: [e7npSs7m] C:\documents and settings\jes\local settings\temp\e7npSs7m.exe

O4 - HKLM\..\Run: [cqzMf] C:\documents and settings\jes\local settings\temp\cqzMf.exe

O4 - HKLM\..\Run: [uhvuJ] C:\documents and settings\jes\local settings\temp\uhvuJ.exe

O4 - HKLM\..\Run: [sA] C:\documents and settings\jes\local settings\temp\sA.exe

O4 - HKLM\..\Run: [Kr] C:\documents and settings\jes\local settings\temp\Kr.exe

O4 - HKLM\..\Run: [mQjzc] C:\documents and settings\jes\local settings\temp\mQjzc.exe

O4 - HKLM\..\Run: [Dkrd3] C:\documents and settings\jes\local settings\temp\Dkrd3.exe

O4 - HKLM\..\Run: [VbnUx] C:\documents and settings\jes\local settings\temp\VbnUx.exe

O4 - HKLM\..\Run: [d2jB1] C:\documents and settings\jes\local settings\temp\d2jB1.exe

O4 - HKLM\..\Run: [P4byZz0f] C:\documents and settings\jes\local settings\temp\P4byZz0f.exe

O4 - HKLM\..\Run: [JiZMr] C:\documents and settings\jes\local settings\temp\JiZMr.exe

O4 - HKLM\..\Run: [19VtV] C:\documents and settings\jes\local settings\temp\19VtV.exe

O4 - HKLM\..\Run: [k0Rap] C:\documents and settings\jes\local settings\temp\k0Rap.exe

O4 - HKLM\..\Run: [CQNRT] C:\documents and settings\jes\local settings\temp\CQNRT.exe

O4 - HKLM\..\Run: [UHJyo] C:\documents and settings\jes\local settings\temp\UHJyo.exe

O4 - HKLM\..\Run: [P] C:\documents and settings\jes\local settings\temp\P.exe

O4 - HKLM\..\Run: [sGZQ5] C:\documents and settings\jes\local settings\temp\sGZQ5.exe

O4 - HKLM\..\Run: [Ja8t] C:\documents and settings\jes\local settings\temp\Ja8t.exe

O4 - HKLM\..\Run: [0Fg7] C:\documents and settings\jes\local settings\temp\0Fg7.exe

O4 - HKLM\..\Run: [Y] C:\documents and settings\jes\local settings\temp\Y.exe

O4 - HKLM\..\Run: [UUSPSmwe] C:\documents and settings\jes\local settings\temp\UUSPSmwe.exe

O4 - HKLM\..\Run: [w] C:\documents and settings\jes\local settings\temp\w.exe

O4 - HKLM\..\Run: [8lpN] C:\documents and settings\jes\local settings\temp\8lpN.exe

O4 - HKLM\..\Run: [5] C:\documents and settings\jes\local settings\temp\5.exe

O4 - HKLM\..\Run: [FXT1] C:\documents and settings\jes\local settings\temp\FXT1.exe

O4 - HKLM\..\Run: [XOOI] C:\documents and settings\jes\local settings\temp\XOOI.exe

O4 - HKLM\..\Run: [no] C:\documents and settings\jes\local settings\temp\no.exe

O4 - HKLM\..\Run: [E] C:\documents and settings\jes\local settings\temp\E.exe

O4 - HKLM\..\Run: [z6tYAXhp] C:\documents and settings\jes\local settings\temp\z6tYAXhp.exe

O4 - HKLM\..\Run: [QACCqRv] C:\documents and settings\jes\local settings\temp\QACCqRv.exe

O4 - HKLM\..\Run: C:\documents and settings\jes\local settings\temp\s.exe

O4 - HKLM\..\Run: [3Emw] C:\documents and settings\jes\local settings\temp\3Emw.exe

O4 - HKLM\..\Run: [eX] C:\documents and settings\jes\local settings\temp\eX.exe

O4 - HKLM\..\Run: [axj6syqR1] C:\documents and settings\jes\local settings\temp\axj6syqR1.exe

O4 - HKLM\..\Run: [7uIqb] C:\documents and settings\jes\local settings\temp\7uIqb.exe

O4 - HKLM\..\Run: [3q] C:\documents and settings\jes\local settings\temp\3q.exe

O4 - HKLM\..\Run: [FsZIS] C:\documents and settings\jes\local settings\temp\FsZIS.exe

O4 - HKLM\..\Run: [WX8lI] C:\documents and settings\jes\local settings\temp\WX8lI.exe

O4 - HKLM\..\Run: [T] C:\documents and settings\jes\local settings\temp\T.exe

O4 - HKLM\..\Run: [MMkkU] C:\documents and settings\jes\local settings\temp\MMkkU.exe

O4 - HKLM\..\Run: [nOchSuty] C:\documents and settings\jes\local settings\temp\nOchSuty.exe

O4 - HKLM\..\Run: [Z] C:\documents and settings\jes\local settings\temp\Z.exe

O4 - HKLM\..\Run: [BfKf] C:\documents and settings\jes\local settings\temp\BfKf.exe

O4 - HKLM\..\Run: [SJST] C:\documents and settings\jes\local settings\temp\SJST.exe

O4 - HKLM\..\Run: [9e1w] C:\documents and settings\jes\local settings\temp\9e1w.exe

O4 - HKLM\..\Run: [MCGxKIR] C:\documents and settings\jes\local settings\temp\MCGxKIR.exe

O4 - HKLM\..\Run: [ZEDX2K] C:\documents and settings\jes\local settings\temp\ZEDX2K.exe

O4 - HKLM\..\Run: [Sv] C:\documents and settings\jes\local settings\temp\Sv.exe

O4 - HKLM\..\Run: [9Z] C:\documents and settings\jes\local settings\temp\9Z.exe

O4 - HKLM\..\Run: [q7] C:\documents and settings\jes\local settings\temp\q7.exe

O4 - HKLM\..\Run: [m4wFCj0S] C:\documents and settings\jes\local settings\temp\m4wFCj0S.exe

O4 - HKLM\..\Run: [Zs] C:\documents and settings\jes\local settings\temp\Zs.exe

O4 - HKLM\..\Run: [Av3Db] C:\documents and settings\jes\local settings\temp\Av3Db.exe

O4 - HKLM\..\Run: [cTJENJWb] C:\documents and settings\jes\local settings\temp\cTJENJWb.exe

O4 - HKLM\..\Run: [uKFlhlrX] C:\documents and settings\jes\local settings\temp\uKFlhlrX.exe

O4 - HKLM\..\Run: [MeNY8fFe] C:\documents and settings\jes\local settings\temp\MeNY8fFe.exe

O4 - HKLM\..\Run: [nhF] C:\documents and settings\jes\local settings\temp\nhF.exe

O4 - HKLM\..\Run: [eqSthq] C:\documents and settings\jes\local settings\temp\eqSthq.exe

O4 - HKLM\..\Run: [QtKqfq1lV] C:\documents and settings\jes\local settings\temp\QtKqfq1lV.exe

O4 - HKLM\..\Run: [sR] C:\documents and settings\jes\local settings\temp\sR.exe

O4 - HKLM\..\Run: [4g5ssQ] C:\documents and settings\jes\local settings\temp\4g5ssQ.exe

O4 - HKLM\..\Run: [HFKs3zd92] C:\documents and settings\jes\local settings\temp\HFKs3zd92.exe

O4 - HKLM\..\Run: [iH] C:\documents and settings\jes\local settings\temp\iH.exe

O4 - HKLM\..\Run: [V6iqD] C:\documents and settings\jes\local settings\temp\V6iqD.exe

O4 - HKLM\..\Run: [R2] C:\documents and settings\jes\local settings\temp\R2.exe

O4 - HKLM\..\Run: [urmLY] C:\documents and settings\jes\local settings\temp\urmLY.exe

O4 - HKLM\..\Run: [LVvpO] C:\documents and settings\jes\local settings\temp\LVvpO.exe

O4 - HKLM\..\Run: [nkaqqp5M] C:\documents and settings\jes\local settings\temp\nkaqqp5M.exe

O4 - HKLM\..\Run: [jULGv] C:\documents and settings\jes\local settings\temp\jULGv.exe

O4 - HKLM\..\Run: [z26h] C:\documents and settings\jes\local settings\temp\z26h.exe

O4 - HKLM\..\Run: [QwfU] C:\documents and settings\jes\local settings\temp\QwfU.exe

O4 - HKLM\..\Run: [6EAu] C:\documents and settings\jes\local settings\temp\6EAu.exe

O4 - HKLM\..\Run: [HGssJLo] C:\documents and settings\jes\local settings\temp\HGssJLo.exe

O4 - HKLM\..\Run: [TYOLKn] C:\documents and settings\jes\local settings\temp\TYOLKn.exe

O4 - HKLM\..\Run: [vntLl5pi5] C:\documents and settings\jes\local settings\temp\vntLl5pi5.exe

O4 - HKLM\..\Run: [7M] C:\documents and settings\jes\local settings\temp\7M.exe

O4 - HKLM\..\Run: [KbONzw] C:\documents and settings\jes\local settings\temp\KbONzw.exe

O4 - HKLM\..\Run: [mzuNaeC6c] C:\documents and settings\jes\local settings\temp\mzuNaeC6c.exe

O4 - HKLM\..\Run: [jwT8T2] C:\documents and settings\jes\local settings\temp\jwT8T2.exe

O4 - HKLM\..\Run: [UyL5R24Ew] C:\documents and settings\jes\local settings\temp\UyL5R24Ew.exe

O4 - HKLM\..\Run: [xX] C:\documents and settings\jes\local settings\temp\xX.exe

O4 - HKLM\..\Run: [PO] C:\documents and settings\jes\local settings\temp\PO.exe

O4 - HKLM\..\Run: [rc1Nz] C:\documents and settings\jes\local settings\temp\rc1Nz.exe

O4 - HKLM\..\Run: [pv] C:\documents and settings\jes\local settings\temp\pv.exe

O4 - HKLM\..\Run: [lsCvFpfY5] C:\documents and settings\jes\local settings\temp\lsCvFpfY5.exe

O4 - HKLM\..\Run: [h2eMK] C:\documents and settings\jes\local settings\temp\h2eMK.exe

O4 - HKLM\..\Run: [UrTNmcHw] C:\documents and settings\jes\local settings\temp\UrTNmcHw.exe

O4 - HKLM\..\Run: [bV2qc6VN] C:\documents and settings\jes\local settings\temp\bV2qc6VN.exe

O4 - HKLM\..\Run: [M] C:\documents and settings\jes\local settings\temp\M.exe

O4 - HKLM\..\Run: [JUjITUml] C:\documents and settings\jes\local settings\temp\JUjITUml.exe

O4 - HKLM\..\Run: [Z1Ei66j8] C:\documents and settings\jes\local settings\temp\Z1Ei66j8.exe

O4 - HKLM\..\Run: [VY3C] C:\documents and settings\jes\local settings\temp\VY3C.exe

O4 - HKLM\..\Run: [dsbg] C:\documents and settings\jes\local settings\temp\dsbg.exe

O4 - HKLM\..\Run: [N8ga05I] C:\documents and settings\jes\local settings\temp\N8ga05I.exe

O4 - HKLM\..\Run: [FfG] C:\documents and settings\jes\local settings\temp\FfG.exe

O4 - HKLM\..\Run: [APhtCpJ5f] C:\documents and settings\jes\local settings\temp\APhtCpJ5f.exe

O4 - HKLM\..\Run: [Rjq7sjXmU] C:\documents and settings\jes\local settings\temp\Rjq7sjXmU.exe

O4 - HKLM\..\Run: [aamOXVr78] C:\documents and settings\jes\local settings\temp\aamOXVr78.exe

O4 - HKLM\..\Run: [7uycjs] C:\documents and settings\jes\local settings\temp\7uycjs.exe

O4 - HKLM\..\Run: [4q] C:\documents and settings\jes\local settings\temp\4q.exe

O4 - HKLM\..\Run: [mh] C:\documents and settings\jes\local settings\temp\mh.exe

O4 - HKLM\..\Run: [E8] C:\documents and settings\jes\local settings\temp\E8.exe

O4 - HKLM\..\Run: [Cr1io1TWg] C:\documents and settings\jes\local settings\temp\Cr1io1TWg.exe

O4 - HKLM\..\Run: [yoqC7P] C:\documents and settings\jes\local settings\temp\yoqC7P.exe

O4 - HKLM\..\Run: [bM5DJxCYa] C:\documents and settings\jes\local settings\temp\bM5DJxCYa.exe

O4 - HKLM\..\Run: [Lsaw] C:\documents and settings\jes\local settings\temp\Lsaw.exe

O4 - HKLM\..\Run: [3j6e] C:\documents and settings\jes\local settings\temp\3j6e.exe

O4 - HKLM\..\Run: [eBs] C:\documents and settings\jes\local settings\temp\eBs.exe

O4 - HKLM\..\Run: [byRRgQT9r] C:\documents and settings\jes\local settings\temp\byRRgQT9r.exe

O4 - HKLM\..\Run: [NXw] C:\documents and settings\jes\local settings\temp\NXw.exe

O4 - HKLM\..\Run: [Jx78XElHL] C:\documents and settings\jes\local settings\temp\Jx78XElHL.exe

O4 - HKLM\..\Run: [1o3PshPsZ] C:\documents and settings\jes\local settings\temp\1o3PshPsZ.exe

O4 - HKLM\..\Run: [EM] C:\documents and settings\jes\local settings\temp\EM.exe

O4 - HKLM\..\Run: [Vh] C:\documents and settings\jes\local settings\temp\Vh.exe

O4 - HKLM\..\Run: [RdgODHLMx] C:\documents and settings\jes\local settings\temp\RdgODHLMx.exe

O4 - HKLM\..\Run: [94cv7jgxL] C:\documents and settings\jes\local settings\temp\94cv7jgxL.exe

O4 - HKLM\..\Run: [Mt] C:\documents and settings\jes\local settings\temp\Mt.exe

O4 - HKLM\..\Run: [4k] C:\documents and settings\jes\local settings\temp\4k.exe

O4 - HKLM\..\Run: [mb] C:\documents and settings\jes\local settings\temp\mb.exe

O4 - HKLM\..\Run: [XdBRF] C:\documents and settings\jes\local settings\temp\XdBRF.exe

O4 - HKLM\..\Run: [zftPDfUT] C:\documents and settings\jes\local settings\temp\zftPDfUT.exe

O4 - HKLM\..\Run: [uP55I] C:\documents and settings\jes\local settings\temp\uP55I.exe

O4 - HKLM\..\Run: [LjdJz] C:\documents and settings\jes\local settings\temp\LjdJz.exe

O4 - HKLM\..\Run: [nl5Gxfjd] C:\documents and settings\jes\local settings\temp\nl5Gxfjd.exe

O4 - HKLM\..\Run: [jVHX] C:\documents and settings\jes\local settings\temp\jVHX.exe

O4 - HKLM\..\Run: [z32x] C:\documents and settings\jes\local settings\temp\z32x.exe

O4 - HKLM\..\Run: [bsHyreI] C:\documents and settings\jes\local settings\temp\bsHyreI.exe

O4 - HKLM\..\Run: [n7QU5y] C:\documents and settings\jes\local settings\temp\n7QU5y.exe

O4 - HKLM\..\Run: [Z9IS3yJan] C:\documents and settings\jes\local settings\temp\Z9IS3yJan.exe

O4 - HKLM\..\Run: [h0EzxadWB] C:\documents and settings\jes\local settings\temp\h0EzxadWB.exe

O4 - HKLM\..\Run: [Tp] C:\documents and settings\jes\local settings\temp\Tp.exe

O4 - HKLM\..\Run: [bg] C:\documents and settings\jes\local settings\temp\bg.exe

O4 - HKLM\..\Run: [8cFBmjqJI] C:\documents and settings\jes\local settings\temp\8cFBmjqJI.exe

O4 - HKLM\..\Run: [Je] C:\documents and settings\jes\local settings\temp\Je.exe

O4 - HKLM\..\Run: [lDczV] C:\documents and settings\jes\local settings\temp\lDczV.exe

O4 - HKLM\..\Run: [D7kcM] C:\documents and settings\jes\local settings\temp\D7kcM.exe

O4 - HKLM\..\Run: [VYgTg] C:\documents and settings\jes\local settings\temp\VYgTg.exe

O4 - HKLM\..\Run: [xnWUSf459] C:\documents and settings\jes\local settings\temp\xnWUSf459.exe

O4 - HKLM\..\Run: [Nvhu5r1S] C:\documents and settings\jes\local settings\temp\Nvhu5r1S.exe

O4 - HKLM\..\Run: [3CC5hCYF] C:\documents and settings\jes\local settings\temp\3CC5hCYF.exe

O4 - HKLM\..\Run: [Zcdl] C:\documents and settings\jes\local settings\temp\Zcdl.exe

O4 - HKLM\..\Run: [fkyW] C:\documents and settings\jes\local settings\temp\fkyW.exe

O4 - HKLM\..\Run: [c] C:\documents and settings\jes\local settings\temp\c.exe

O4 - HKLM\..\Run: [YB] C:\documents and settings\jes\local settings\temp\YB.exe

O4 - HKLM\..\Run: [eJ] C:\documents and settings\jes\local settings\temp\eJ.exe

O4 - HKLM\..\Run: [vd] C:\documents and settings\jes\local settings\temp\vd.exe

O4 - HKLM\..\Run: [8CkLW] C:\documents and settings\jes\local settings\temp\8CkLW.exe

O4 - HKLM\..\Run: [qtgsq] C:\documents and settings\jes\local settings\temp\qtgsq.exe

O4 - HKLM\..\Run: [Ikc9U] C:\documents and settings\jes\local settings\temp\Ikc9U.exe

O4 - HKLM\..\Run: [0b8Qp] C:\documents and settings\jes\local settings\temp\0b8Qp.exe

O4 - HKLM\..\Run: [Xu] C:\documents and settings\jes\local settings\temp\Xu.exe

O4 - HKLM\..\Run: [UrJyuiYh6] C:\documents and settings\jes\local settings\temp\UrJyuiYh6.exe

O4 - HKLM\..\Run: [bVSclccyL] C:\documents and settings\jes\local settings\temp\bVSclccyL.exe

O4 - HKLM\..\Run: [NX] C:\documents and settings\jes\local settings\temp\NX.exe

O4 - HKLM\..\Run: [4rSN] C:\documents and settings\jes\local settings\temp\4rSN.exe

O4 - HKLM\..\Run: [DK9DQF] C:\documents and settings\jes\local settings\temp\DK9DQF.exe

O4 - HKLM\..\Run: [UfihGz] C:\documents and settings\jes\local settings\temp\UfihGz.exe

O4 - HKLM\..\Run: [wDXhihMWW] C:\documents and settings\jes\local settings\temp\wDXhihMWW.exe

O4 - HKLM\..\Run: [sdzynn] C:\documents and settings\jes\local settings\temp\sdzynn.exe

O4 - HKLM\..\Run: [HY65X] C:\documents and settings\jes\local settings\temp\HY65X.exe

O4 - HKLM\..\Run: [iEbZh7nO] C:\documents and settings\jes\local settings\temp\iEbZh7nO.exe

O4 - HKLM\..\Run: [deMfm] C:\documents and settings\jes\local settings\temp\deMfm.exe

O4 - HKLM\..\Run: [9] C:\documents and settings\jes\local settings\temp\9.exe

O4 - HKLM\..\Run: [Ktsq] C:\documents and settings\jes\local settings\temp\Ktsq.exe

O4 - HKLM\..\Run: [lvknKAs] C:\documents and settings\jes\local settings\temp\lvknKAs.exe

O4 - HKLM\..\Run: [bU] C:\documents and settings\jes\local settings\temp\bU.exe

O4 - HKLM\..\Run: [MW1gX] C:\documents and settings\jes\local settings\temp\MW1gX.exe

O4 - HKLM\..\Run: [oYTdVnam] C:\documents and settings\jes\local settings\temp\oYTdVnam.exe

O4 - HKLM\..\Run: [jyvu0] C:\documents and settings\jes\local settings\temp\jyvu0.exe

O4 - HKLM\..\Run: [g] C:\documents and settings\jes\local settings\temp\g.exe

O4 - HKLM\..\Run: [STzPl] C:\documents and settings\jes\local settings\temp\STzPl.exe

O4 - HKLM\..\Run: [uVrMjZ3s] C:\documents and settings\jes\local settings\temp\uVrMjZ3s.exe

O4 - HKLM\..\Run: [LqAq9ThJ] C:\documents and settings\jes\local settings\temp\LqAq9ThJ.exe

O4 - HKLM\..\Run: [HZbH] C:\documents and settings\jes\local settings\temp\HZbH.exe

O4 - HKLM\..\Run: [ZQ7o] C:\documents and settings\jes\local settings\temp\ZQ7o.exe

O4 - HKLM\..\Run: [BfMpljd] C:\documents and settings\jes\local settings\temp\BfMpljd.exe

O4 - HKLM\..\Run: [Rn8Zxva] C:\documents and settings\jes\local settings\temp\Rn8Zxva.exe

O4 - HKLM\..\Run: [nA0FjVXa8] C:\documents and settings\jes\local settings\temp\nA0FjVXa8.exe

O4 - HKLM\..\Run: [DImfw6UXe] C:\documents and settings\jes\local settings\temp\DImfw6UXe.exe

O4 - HKLM\..\Run: [AEKzf] C:\documents and settings\jes\local settings\temp\AEKzf.exe

O4 - HKLM\..\Run: [d3qAQCDZ7] C:\documents and settings\jes\local settings\temp\d3qAQCDZ7.exe

O4 - HKLM\..\Run: [Ps] C:\documents and settings\jes\local settings\temp\Ps.exe

O4 - HKLM\..\Run: [6W] C:\documents and settings\jes\local settings\temp\6W.exe

O4 - HKLM\..\Run: [oN] C:\documents and settings\jes\local settings\temp\oN.exe

O4 - HKLM\..\Run: [0cPWo] C:\documents and settings\jes\local settings\temp\0cPWo.exe

O4 - HKLM\..\Run: [DAuX0hyP] C:\documents and settings\jes\local settings\temp\DAuX0hyP.exe

O4 - HKLM\..\Run: [U5DARbL6] C:\documents and settings\jes\local settings\temp\U5DARbL6.exe

O4 - HKLM\..\Run: [PirOi] C:\documents and settings\jes\local settings\temp\PirOi.exe

O4 - HKLM\..\Run: [oBIEZ79] C:\documents and settings\jes\local settings\temp\oBIEZ79.exe

O4 - HKLM\..\Run: [DmgbyBP] C:\documents and settings\jes\local settings\temp\DmgbyBP.exe

O4 - HKLM\..\Run: [DEQ] C:\documents and settings\jes\local settings\temp\DEQ.exe

O4 - HKLM\..\Run: [nRTtURk] C:\documents and settings\jes\local settings\temp\nRTtURk.exe

O4 - HKLM\..\Run: [DZe372h] C:\documents and settings\jes\local settings\temp\DZe372h.exe

O4 - HKLM\..\Run: [s33rn5zh0] C:\documents and settings\jes\local settings\temp\s33rn5zh0.exe

O4 - HKLM\..\Run: [2I] C:\documents and settings\jes\local settings\temp\2I.exe

O4 - HKLM\..\Run: [tKe] C:\documents and settings\jes\local settings\temp\tKe.exe

O4 - HKLM\..\Run: [dk2MmqR] C:\documents and settings\jes\local settings\temp\dk2MmqR.exe

O4 - HKCU\..\Run: [BLMessagingIntegration] C:\Program Files\Common Files\PSD Tools\blengine.exe

O4 - HKCU\..\Run: [iprtrmgr] C:\WINNT\System32\iprtrmgr.exe

O4 - HKCU\..\Run: [Clro] C:\Documents and Settings\Jes\Application Data\owar.exe

O4 - HKCU\..\Run: [Ksxxvrdz] C:\WINNT\System32\??rss.exe

O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/308dedc13bf8d649b620/netzip/RdxIE2.cab

Then click "Fix checked".

Reboot in "safe" mode.

Delete all files in this FOLDER:

c:\documents and settings\jes\local settings\temp <— FOLDER

Find and delete:

c:\documents and settings\jes\application data\owar.exe <— file

c:\winnt\system32\axp63.exe <— file

c:\winnt\system32\iprtrmgr.exe <— file

c:\winnt\system32\ngioueb0.exe <— file

c:\winnt\system32\ogwy.dll <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
:wavey:
I did what you said, and I believe I got all of the files except for:

c:\winnt\system32\ngioueb0.exe
c:\winnt\system32\ogwy.dll

I may have deleted those files before?
Here is my new log…

Logfile of HijackThis v1.98.2
Scan saved at 5:34:35 PM, on 11/08/2004
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINNT\System32\PRPCUI.exe
C:\Program Files\Navnt\navapw32.exe
C:\HJT\hijackthisupdate.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vt.edu/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jes\Local Settings\Temp\pWT.dll (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKCU\..\Run: [iprtrmgr] C:\WINNT\System32\iprtrmgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - file://D:\Installers\AuthorwareWebPlayer\awswax.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab

Thanks again for your help so far!! :thumbup:
I'm surprised your machine even ran with all that malware on it.

I think you're in the "Top 5" in the contest for "Longest Log of the Year" ;)

But, you've got 99.99% of it off. :thumbup:

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

O2 - BHO: Search Help - {E8EAEB34-F7B5-4C55-87FF-720FAF53D841} - C:\Documents and Settings\Jes\Local Settings\Temp\pWT.dll (file missing)

O4 - HKCU\..\Run: [iprtrmgr] C:\WINNT\System32\iprtrmgr.exe

O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

c:\winnt\system32\iprtrmgr.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
:wavey:
well i sure am glad to have someone help me fix it then!!! and my computer has barely been working.. but it is working much much better now :)

i could not find iprtrmgr.exe.. but i did find iprtrmgr.dll in system32, and I deleted it. i still have it in the trash bin if this file is not right..

here is my new log:Logfile of HijackThis v1.98.2
Scan saved at 6:55:44 PM, on 11/08/2004
Platform: Windows 2000 SP1 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\WINNT\System32\PRPCUI.exe
C:\Program Files\Navnt\navapw32.exe
C:\HJT\hijackthisupdate.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vt.edu/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DadApp] C:\Program Files\DELL\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - file://D:\Installers\AuthorwareWebPlayer\awswax.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP…ol_v1-0-3-9.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
The log looks good now. :thumbup:

Please restore "iprtrmgr.dll" out of the Recycle bin, back to where it was. It is not malware.

GOD bless!!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.
(Personally, I'm NOT recommending SP2 for XP at this time)

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI